{"id":5753,"date":"2024-10-11T16:17:07","date_gmt":"2024-10-11T21:17:07","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-careers\/ai-hype-drives-demand-ml-secops-skills"},"modified":"2024-10-11T16:17:07","modified_gmt":"2024-10-11T21:17:07","slug":"ai-hype-drives-demand-for-ml-secops-skills","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/10\/11\/ai-hype-drives-demand-for-ml-secops-skills\/","title":{"rendered":"AI Hype Drives Demand For ML SecOps Skills"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltfd06af8af256e09b\/6709a18bb40de2271b260b60\/Skills-gap-1800_designer491_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-hype-drives-demand-for-ml-secops-skills.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In a sign of the growing importance of assessing the risks of artificial language to corporate assets, organizations are increasingly looking for job candidates with skills in machine learning and large language models to fill cybersecurity jobs. In ISACA&#8217;s <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.isaca.org\/resources\/reports\/state-of-cybersecurity-2024\" rel=\"noopener\">2024 State of Cybersecurity report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, just under a quarter of respondents (24%) named LLM SecOps and ML SecOps as the biggest skill gaps they see in cybersecurity. Soft skills \u2014 communication, flexibility, and leadership \u2014 continue to be the biggest category of skills that cybersecurity professionals are missing, according to 51% of respondents.<\/span><\/p>\n<div class=\"ContentImage-Wrapper ContentImage-Wrapper_link\"><img data-recalc-dims=\"1\" decoding=\"async\" data-testid=\"content-image\" data-component=\"image\" class=\"ContentImage-Image ContentImage-Image_align_center\" data-src=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-hype-drives-demand-for-ml-secops-skills-1.jpg\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-hype-drives-demand-for-ml-secops-skills-1.jpg?w=640&#038;ssl=1\" loading=\"lazy\" alt=\"Chart showing the different skills that are in demand for cybersecurity professionals.\" title=\"Chart showing the different skills that are in demand for cybersecurity professionals.\"><a class=\"ContentImage-Link\" target=\"_blank\" href=\"https:\/\/www.isaca.org\/resources\/reports\/state-of-cybersecurity-2024\" rel=\"noopener\">Source: 2024 State of Cybersecurity, ISACA<\/a><\/div>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Wanted: LLM, ML Skills\">Wanted: LLM, ML Skills<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Both LLM SecOps and ML SecOps are fairly new skill sets, but, like the technologies they secure, they now seem to be everywhere.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">MLSecOps is the discipline of integrating security into the development and deployment of machine learning systems. It covers ML-specific processes like securing the data used to train a model and preventing bias through transparency, as well as applying standard security operations tasks such as secure coding, threat modeling, security audits, and incident response to ML systems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">LLM SecOps refers to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/arxiv.org\/html\/2403.12239v1\" rel=\"noopener\">securing the entire lifecycle of LLMs<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, from data preparation to incident response. LLM SecOps covers concerns as varied as ethics reviews in the design phase, data sanitization of training data, analyzing why the system made the decisions it did during training, blocking the generation of harmful content, and monitoring the model once it is deployed.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">There is a growing list of resources for security professionals to build up their skills. For ML SecOps, Benjamin Kereopa-Yorke, a a senior information security specialist and AI security researcher at telecommunications provider Telstra maintains a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/github.com\/Benjamin-KY\/MLSecOps\" rel=\"noopener\">GitHub repository of resources and trainings<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, with courses categorized by prior ML knowledge required and classified as vendor-agnostic or vendor-centric. Open Worldwide Application Security Project&nbsp;(OWASP) has a draft <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/owasp.org\/www-project-machine-learning-security-top-10\/\" rel=\"noopener\">Machine Learning Security Top Ten<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> list describing how ML attacks such as data poisoning or member inference work and how to counter them. OWASP also maintains the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/genai.owasp.org\/llm-top-10\/\" rel=\"noopener\">OWASP Top Ten for LLMs,<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> which covers topics relevant to LLM SecOps such as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/dangerous-ai-workaround-skeleton-key-unlocks-malicious-content\" rel=\"noopener\">prompt injection<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/slack-ai-patches-bug-that-let-attackers-steal-data-from-private-channels\" rel=\"noopener\">sensitive information disclosure<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/unpatched-critical-vulnerabilities-open-ai-models-to-takeover\" rel=\"noopener\">model theft<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Organizations are looking for specific skills to fill open cybersecurity positions. After soft skills, cloud computing was the second biggest skill gap (42%), followed by security controls implementation (35%), and software development (28%).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">With so much of the organization&#8217;s workload now residing in the cloud, it makes sense that organizations need cybersecurity professionals with cloud computing skills. Securing cloud assets require a different mindset and technical skillset than traditional networking, and cloud providers handle certain tasks differently, requiring specialized knowledge.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Security controls implementation refers to protecting endpoints, networks, and applications. The skills gap in software development was not coding related, but rather things such as testing and deployment. Again, this highlights the challenges organizations are having securing their software development pipelines and integrations.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-careers\/ai-hype-drives-demand-ml-secops-skills\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In a sign of the growing importance of assessing the<\/p>\n","protected":false},"author":12,"featured_media":5754,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5753","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-hype-drives-demand-for-ml-secops-skills.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-hype-drives-demand-for-ml-secops-skills.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-hype-drives-demand-for-ml-secops-skills.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-hype-drives-demand-for-ml-secops-skills.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-hype-drives-demand-for-ml-secops-skills.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-hype-drives-demand-for-ml-secops-skills.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-hype-drives-demand-for-ml-secops-skills.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-hype-drives-demand-for-ml-secops-skills.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-hype-drives-demand-for-ml-secops-skills.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-hype-drives-demand-for-ml-secops-skills.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-hype-drives-demand-for-ml-secops-skills.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5753","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5753"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5753\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5754"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5753"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5753"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5753"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}