新しい仕事は、いつも新しい名前で現れるわけではない
AIによる雇用変化を考えるとき、新しい職種名を探しがちだ。しかし企業の変化は、既存の肩書きのまま責任範囲だけが変わる形でも起こる。CISOはその例になり得る。
Deloitteの2026 Global Technology Leadership Studyでは、CISOを置くと答えた組織は49%で、2023年の31%から上昇した。さらに同社はCISOをsecurity gatekeeperからenterprise risk orchestratorへ移る役割として描いている。
AIエージェントはセキュリティの基本質問を変える
従来のアクセス管理は「誰が何にアクセスできるか」が中心だった。AIエージェントが企業内で行動すると、「誰または何が、いつ、誰の代理で、何にアクセスできるか」まで問う必要が出る。
エージェントが人に代わってツールを呼び、データを読み、行動するなら、identity、authority、approval、audit trail、escalationの設計もセキュリティの一部になる。
実際のCISO組織にはAI GovernanceとAgentic AI Controlが入り始めている
Temasekの公開中のAVP/VP, Cybersecurity (Governance Oversight)はCISO直属で、cybersecurityに加えてAI security、AI governance、model governance、agentic AI controls、AI assuranceを担当する。
肩書きはCybersecurityのままだが、役割境界にはautonomous agentの安全性や責任あるAI導入の統制が入っている。同じ名前の中で仕事が動く具体例だ。
Agent Assuranceという新しい専門機能が既存役職を書き換える
Temasekは別にAgent Assurance Engineerも募集している。production AI agentが意図した範囲内で一貫して動くかを経験的にテストし、継続監視し、tool permission、behavioural specification、escalation、driftを扱う役割だ。
CISOがすべてを直接実行するという意味ではない。専門機能が増えるほど、経営職の仕事はそれぞれのrisk owner、decision right、controlをつなぐ方向へ移る可能性がある。
BANSEOG VIEW | 同じ肩書きを同じ仕事だと見るとSearchを誤る
Executive Searchでは肩書きが最も簡単なフィルターになる。しかしAIが既存の経営職を書き換えるなら、Titleは粗いproxyになっていく。同じCISOでも、従来のSOC・IAM・incident response中心の経験と、AI governance・agent authority・model risk・board communicationまで含む経験では能力境界が違う。
問うべきことは「CISOだったか」から「その肩書きの下で何を責任として持っていたか」「これからその役職が持つ問題をすでに経験したか」へ移る。
肩書きが残っても、企業が買う能力は変わる
Deloitteの別調査では、3,235人のIT・business leaderのうち成熟したagentic-AI governanceがあると答えたのは21%で、74%は2027年までにAIエージェントを少なくとも中程度以上使うと見込んでいる。deploymentとgovernanceの差が広がるほど、権限とリスクを誰が設計し責任を持つかというリーダーシップ課題が大きくなる。
WiproとCrowdStrikeが9月9日にCISO Command Centerを発表し、tool-driven securityからenterprise-wide risk-led operating modelへの移行を掲げたことも同じ方向のシグナルだ。ただし、これらだけでCISO市場全体の転換を断定することはできない。
BANSEOG VIEW
Banseog View — The title stays. The job moves.
新しいAI職種は必ずしも新しい肩書きで現れない。
同じ経営職でもcapability boundaryとdecision rightは変わり得る。
Executive SearchではTitleより、その肩書きの下で実際に責任を持ったBusiness Problemを見る重要性が増す可能性がある。
SOURCES
参照した主な資料
- Deloitte Insights — Rethinking the CISO role for an AI-saturated enterprise
2026 Global Technology Leadership Study: 662 senior technology leaders; 49% report a CISO role in 2026 versus 31% in 2023. The article frames a shift from security gatekeeper to enterprise risk orchestrator and discusses identity/access for AI agents.
- Temasek — AVP/VP, Cybersecurity (Governance Oversight)
Current role reporting to the CISO, covering AI security, AI governance, agentic AI controls, AI assurance, model governance and emerging technology risk.
- Temasek — Agent Assurance Engineer
Current role for empirically testing, continuously monitoring and governing production AI-agent behaviour, including tool permissions, behavioural specifications and agent drift.
- Deloitte Insights — Agentic AI is scaling faster than guardrails
Survey of 3,235 IT and business leaders across 24 countries: 21% report mature agentic-AI governance; 74% expect at least moderate AI-agent use by 2027.
- CrowdStrike — Wipro and CrowdStrike launch CISO Command Center
2026-09-09 launch describing a move from tool-driven security operations toward an enterprise-wide, risk-led operating model for AI-accelerated risk.
Deloitte調査は大規模組織中心で、Temasek求人は個別企業の事例です。役割変化のシグナルは確認できますが、市場全体へ一般化はしません。