- Cybersecurity Ecosystem Show
- Posts
- Will AI Replace Cybersecurity Jobs? Lessons From a CIO-CISO Who Has Survived Every Tech Wave
Will AI Replace Cybersecurity Jobs? Lessons From a CIO-CISO Who Has Survived Every Tech Wave
From the Cybersecurity Ecosystem Show conversation with Georgeo Xavier Pulikkathara, CIO and CISO, US Army colonel

Early in his career, at the corporate headquarters of Cooper Industries, someone Georgeo Pulikkathara worked with gave him a piece of advice that sounded absurd: "Technology is a fad. I know you guys love all the stuff you're doing, but this stuff's gonna evolve and change."
Georgeo's colleague argued. Technology is here to stay. But the point was a different one, and thirty-five years later Georgeo says it was absolutely right. The specific technology you love right now is temporary. The evolution is permanent. He has lived through mainframes giving way to client-server computing, the offshoring wave, and the cloud migration that was supposed to kill the data center. "Actually, they have more data centers," he notes.
Now he watches the AI wave from a seat most security leaders never get: he is both CIO and CISO at his company, an Army colonel who started as a private E1, a fifteen-year Microsoft veteran, and a 58-year-old working on his PhD in cybersecurity. On this episode of the Cybersecurity Ecosystem Show, he covered what AI can and cannot replace, the fake-employee fraud most HR departments cannot detect, and why preparation is the entire job.
Here are the biggest lessons from the conversation.
Will AI take your security job?
Georgeo's answer starts with a story about every previous wave. When cloud arrived, everyone said data centers would disappear. When offshoring arrived, everyone said the same about jobs. Some jobs did get displaced. The people who kept evolving kept working.
A parent once asked him whether their son should bother learning to code, since AI seems to make it a waste of time. "We have light switches now where you can go flip a light switch," he said. "Does that mean we don't need any more electricians? No. Somebody's gotta go fix it."
His prediction for which roles survive is specific: the ones that understand the business. "It's the person that understands the business environment, the business priorities, what's important, what's not. That's what human beings bring." He has watched the automation fantasy play out before. "The first thing the CEO sees is, I can automate everything and everything will be fine. I can just fire all of IT. Everywhere they try to go do that, they typically end up hiring people back."
And when executives ask why they need a CISO at all when they could just ask the AI, his answer is blunt: "It means I know what right questions to ask."
AI is a newborn being asked to do brain surgery
Georgeo's framing of where AI actually is right now is the line worth remembering from this episode.
"Basically they gave birth to a child," he said. "And because it's AI, they want their child to do brain surgery tomorrow. The reality is you need to train it, you need to teach it ethics, set up guardrails. Teach it right and wrong, how to make appropriate decisions, because you're gonna give it agency."
The problem is what the child does when it does not know the answer. "Sometimes people ask it questions, it doesn't have access to the data. So what does it do? It does what people do. It makes stuff up."
What worries him more than the hallucinations is how we treat them. "We literally discredit the person with 30 years of experience saying that's a bad idea, and go, well, AI says it's possible, so you're wrong." Thirty-five years of pattern recognition, the thing veterans call instinct or a spidey sense, is trained on more data than any of us gives it credit for. He trusts his.
He pointed to a case involving Workday, where an AI system was rejecting one applicant's resumes in the middle of the night, carrying the biases of the developers who built it, with no way to see the decision process. That, he argues, is why the industry is moving from black-box AI to open-box systems. "You want to see the sausage making. How is it building your car? Why would we do the same thing with the decisions and the actions that AI takes?"
The takeaway is not to avoid AI. It is to run it the way you run any production line: machines doing the work, a human watching with the authority to pull the lever and say stop, this isn't right.
Managing to ROI vs managing to risk
Georgeo's dual role gives him unusual clarity on a distinction most companies blur.
"A CIO manages to the ROI," he said. "They give you a $20 million budget. How do you manage that to get more productivity, cost savings, reduce overhead? Versus if I'm a CISO, I'm managing to the risk. How do I reduce risk?"
He reports to the board in two separate buckets for exactly that reason. The CIO bucket carries service metrics: tickets answered, mean time to resolution, what automation would save. The CISO bucket carries mean time to detect, incident counts and complexity, threat intel matched against what he sees in his own environment, and the top risks currently in flux. For him right now that list is insider threat, regulatory compliance, and ransomware.
And on risk, he has a line he repeats to companies constantly: "You're taking on a risk you don't have to."
This is the same split Rivial builds board reporting around for banks and credit unions: the security program expressed as risk in dollars, distinct from the IT budget conversation, so directors can weigh both without confusing them.
Endpoint protection is not a security program
Everybody thinks that once CrowdStrike is on the endpoints, the job is done. Georgeo walks his stakeholders through four tiers instead.
Tier zero is identity: your identity provider and your MFA. Tier one is production: cloud environments, CI/CD pipelines, anywhere data lives. Tier two is business applications, the Workdays and finance systems and Microsoft 365. Tier three, last, is the endpoint.
"It's great that you got DLP, it's great that you got endpoint protection," he said. "But you need to worry about monitoring the ones above that."
The stakes of the unwatched upper tiers are not hypothetical. He described a breach from this March where attackers came in through an automated CI/CD pipeline nobody was monitoring, because it was automated, so why watch it? They took roughly four terabytes of data in about 40 minutes. "They probably went to lunch, came back and said, what just happened?"
The fake employee problem HR cannot see
The most striking stretch of the episode was about remote gig workforce fraud, and specifically North Korean operators applying for remote jobs as fake American workers.
"Most HR departments and companies are not ready to go detect fraud," Georgeo said. The threat actor shows up as John Smith from Portland or Dallas, passes a video interview, and gets hired. "If they come into our system and they start working with our clients, that's gonna result in our clients getting breached."
His identity verification checks go well beyond the interview. Is the applicant behind an IP proxy? Does their true location match where they claim to be? Has their email address shown up in breach data on haveibeenpwned.com? And then the tell that sounds made up but is not: the bank accounts.
"You'll have four or five people with the same bank account," he said. Different names, unmarried, unrelated, all paid into one shell account funneling money back to North Korea. "If you're doing a quick check, you're like, wait a second, that doesn't look right."
When his team starts asking questions, the applicants simply disappear, then come back later as someone else. If you use remote gig workers anywhere in your delivery chain, this screening is now part of protecting your clients, not an HR nicety.
Ransomware didn't go away, it changed industries
Georgeo pushes back on the comfortable feeling that ransomware has quieted down. "People keep thinking, well, I haven't heard about anything bad lately," he said. "All that means is they just switched industries and the targeting." He watched it firsthand during his time around the mortgage industry, when lenders were getting hit left and right.
His prescription is network observability at whatever price you can afford. "Use Datadog. Use Zabbix if you don't have the money to go buy Datadog. Get some open source network monitoring." Watch north-south traffic for data leaving your network. Watch east-west traffic for ransomware propagating between machines. And keep at least a year of baseline data.
The baseline pays off in ordinary moments too. When someone tells him the network is slow, he pulls up three months of traffic history on the spot. "That's not it. Now let's get back to triaging what's really wrong."
Preparation, preparation, preparation
Georgeo joined the Army at 18 as a private E1. He is a colonel now. Asked for one thing the military gave him that shaped how he runs security, he did not hesitate: "Every day is a training day."
In the infantry, defending a position meant digging the foxhole correctly, stacking sandbags that actually stop a bullet, and digging the grenade sump so a grenade tossed into your hole does not end you. Then rehearsing. Battle drills, rollover drills, until the response is automatic. "We train as we fight."
Translated to security, that becomes the SANS incident response lifecycle, which he pronounces PICERL: preparation, identification, containment, eradication, recovery, lessons learned. The phase he stresses is containment. "I have to be able to contain that breach as quickly as I can, so I can go back and tell my exec leadership team it's been contained. If I fail containment, then you're dealing with having to notify clients, regulatory authorities, what have you."
His planning method has a name too: "I walk backward from the fight." Imagine the breach has already happened, then ask what you wish you had in place. VLANs you could collapse to strand the attacker. Backups that actually restore.
That last one gets his full skepticism. "Many people make the assumption that they got backups. Have you checked it? Can you restore from it? Have you tried?" Restoring one random file proves nothing. Restore an entire application, your whole financial platform, and time it against the recovery objectives in your business continuity plan. Two days and one hour are very different answers, and you want to learn yours in an exercise, not an incident.
He reached back two thousand years for the standard: the Roman army marched eight hours, stopped short, and built a complete fort to standard, every night, before anyone ate. "In three hours they're ready, and then they started eating. Not before."
Character, competency, commitment
Georgeo is finishing the second year of his PhD in cybersecurity, carrying a 3.92 GPA and a conviction that the degree matters less than the habit. "I have a growth mindset and I encourage everybody else to have a growth mindset. It doesn't have to be a PhD program."
When he hires, he looks for three things. Character: they speak the truth and own their mistakes. Competency: practical experience, certifications, some formal education, though he has hired people with no degree and something like a hundred certifications, and they became favorite employees. Commitment: when something is wrong at the end of a shift, do they go home, or do they stick around and hand it off warm?
"Competency, character, commitment. Show me that. That's who I hire."
The flip side is the employee who refuses to evolve. He described one insisting that ten years of doing physical infrastructure meant the work would never go away. "Dude, we're now in infrastructure as code. Your job is actually going away. You need to learn this." The fear underneath is usually about losing hard-won expertise. The answer, in his world, is the same one he got at Cooper Industries all those years ago: the technology is a fad, so keep learning and go with it.
Guardrails first, then agency
Georgeo's core AI argument is the one boards need to hear right now: before you give an AI agency, you teach it the rules, and you keep a human watching with the power to pull the lever. That starts as a written document. If your organization does not have an AI policy yet, don't start from a blank page. Download Rivial's free AI Security Policy Template. It is an instant download, no sales call required, and it puts the guardrails on paper before the agents arrive.
And listen to the full conversation with Georgeo. The arc from private E1 to colonel, with a stop in the finance corps that turned into the infantry, is worth the listen on its own. You can find him on LinkedIn, where he answers, mentors, and connects people to jobs when he can.
Here are the key takeaways from this blog:
Every wave displaces tasks, not the need for judgment: mainframes, offshoring, and cloud all triggered the same fear, and the people who kept learning kept working.
AI needs guardrails before agency: it hallucinates like a person who doesn't know the answer, so run it like a production line with a human able to stop it.
Split ROI from risk: report IT as return on a budget and security as risk reduced, in separate buckets, so the board can reason about each.
Monitor above the endpoint: identity, production pipelines, and business applications sit over the endpoint tier, and unwatched automation is how four terabytes leave in 40 minutes.
Screen your remote workforce like a threat surface: proxy checks, true location, breach history, and shared bank accounts catch the fake employees HR interviews miss.
Walk backward from the fight: assume the breach happened, build what you wish you had, and prove your backups by restoring a full application against your RTO.
Hire the three Cs: character, competency, and commitment, backed by a growth mindset, outlast any single technology skill.
The Cybersecurity Ecosystem Show connects practitioners, investors, vendors, regulators, and everyone in between. New episodes drop weekly. Subscribe so you don't miss one.
Reply