Will AI Replace Detection Roles in Cybersecurity? AI agents are already starting to handle the grunt work of detection engineering, or essentially finding malware. If AI is now doing the job, what's the future of this role? Or will it completely vanish? Check out this post from Caleb Sima of Whiterabbit for the discussion that is the basis of our conversation on this week's episode co-hosted David Spark , the producer of CISO Series, and Yaron Levi , CISO, Dolby Laboratories . Joining is Adrian Ludwig , CSO, Rippling . Thanks to our podcast sponsor, ThreatLocker . The messy middle The challenge facing detection engineering teams goes well beyond writing better rules. "The problem isn't just context and predicting what types of possible threats exist, and it's also not just creating detection rules," said Fred Wilmot of Detecteam . "It means we also have to be able to accurately and completely represent what happens to that contextual value." That scope extends well past detection engineering, he said, into "change management, audit, data provenance, and governance." Meny Har of Spectrum Security described the current model as "entirely unsustainable." The sharpest people on security teams are spending 70% of their time in what he calls the "Messy Middle" — "reconciling threat behaviors with log realities and legacy SIEM logic." Compress that time-to-coverage from weeks to minutes, he said, and the game changes. The 2030 team, in his view, isn't a skeleton crew. "It's a full team of senior practitioners who have transitioned from being mechanics to being conductors. They will direct a fleet of agents to handle the 'Messy Middle' of syntax and tuning, giving them the actual bandwidth to tackle that adversary frontier." The automatable part Cutting detection engineers because AI can handle triage misreads the evidence. Mike McCabe of Cloud