# Zoom CISO Sandra McLeod: AI Will Augment Security Teams, Not Replace Them


As artificial intelligence reshapes cybersecurity at an unprecedented pace, the debate over whether AI will eliminate security jobs has become increasingly heated. But Zoom's Chief Information Security Officer Sandra McLeod offers a measured perspective: AI is a powerful enabler that will free security professionals from repetitive, manual tasks — not a replacement for human judgment, threat analysis, and strategic defense.


In a detailed discussion about the future of digital security, McLeod — who has navigated Zoom's transformation from a niche collaboration tool into a global necessity — shares insights on building diverse security careers, defending against evolving threats, and leveraging AI responsibly to strengthen security operations.


## The Evolution of Zoom's Security Posture


Zoom's rapid ascent during the COVID-19 pandemic exposed the company to unprecedented security scrutiny. The platform became synonymous not only with remote work but also with a specific vulnerability: "Zoom bombing," a phenomenon where unauthorized users infiltrated public meetings and disrupted them with offensive content.


The Zoom bombing crisis forced the company to fundamentally rethink its security approach. Rather than simply hardening defenses at the expense of usability, Zoom adopted a philosophy of "secure by default while maintaining user flexibility." This balance became central to McLeod's security strategy:


  • User education: Addressing the root cause through transparency and training
  • Transparent security controls: Giving users visibility and control over their meetings
  • Incremental hardening: Rolling out default protections without degrading the user experience
  • Community feedback: Incorporating researcher and user input into security design

  • McLeod's approach demonstrates that security at scale requires not just technical controls but cultural change. As Zoom evolved, so did its threat landscape — shifting from external threat actors exploiting platform features to sophisticated adversaries targeting the company itself.


    ## AI as a Force Multiplier, Not a Job Killer


    One of McLeod's most compelling arguments addresses the widespread anxiety in cybersecurity about AI automation. Rather than eliminating security jobs, AI will reallocate them — automating the manual, repetitive work that consumes security analysts' time and freeing them to focus on high-value problem-solving.


    Consider the current state of security operations:


    | Traditional SIEM Work | AI-Augmented Workflows |

    |---|---|

    | Manual log review and correlation | Automated anomaly detection and pattern matching |

    | Repetitive alert triage | Intelligent alert prioritization and context enrichment |

    | Time-consuming incident documentation | Automated playbook execution and report generation |

    | Manual threat hunting | AI-guided hypothesis testing and data exploration |


    The real value proposition isn't elimination — it's elevation. When AI handles routine log analysis, security teams can spend time on:


  • Strategic threat modeling based on organizational risk
  • Adversary research and trend analysis
  • Security architecture design for emerging threats
  • Threat hunting guided by business context, not just data patterns
  • Incident response orchestration that combines automation with human judgment

  • McLeod's perspective aligns with research from industry analysts: cybersecurity talent shortages are projected to worsen in the coming years, not improve. The real question isn't whether AI will replace security professionals — it's whether organizations will have enough skilled people to manage AI-driven security systems responsibly.


    ## Building Careers in an Evolving Field


    McLeod's path to the CISO role at a major global platform wasn't linear. She began in penetration testing at Cisco, worked across multiple security domains, and built her expertise intentionally through exposure to diverse specializations — not by staying siloed in a single technical track.


    Her advice to aspiring cybersecurity professionals is direct: Start where your interests lie, then deliberately build cross-domain expertise.


    This guidance challenges the prevailing assumption that security careers require a specific entry point or credential. Instead, McLeod emphasizes:


  • Technical foundation: Core skills in networking, systems, or programming create flexibility
  • Breadth over depth early: Exposure to application security, cloud security, identity management, and risk builds pattern recognition
  • Intentional networking: Relationships with mentors, sponsors, and peers determine advancement as much as technical skills
  • Diverse representation: Cybersecurity actively needs women, minorities, and people from non-traditional backgrounds — the field benefits from different perspectives on threat modeling and risk

  • ## The Organizational Challenge: Secure by Default Without Friction


    McLeod's "secure by default" philosophy at Zoom reflects a broader industry challenge: how do you protect users without making the product so restrictive that it becomes unusable?


    This tension plays out across nearly every major platform:


  • Video conferencing: Encryption enables privacy but complicates law enforcement cooperation
  • Cloud storage: Zero-knowledge architectures prevent data breaches but complicate account recovery
  • Messaging apps: End-to-end encryption protects users but creates compliance challenges for regulated industries
  • Enterprise software: Security hardening must accommodate legacy integrations and user workflows

  • Zoom's response — transparent defaults with user override capability — represents a deliberate design choice. Users can disable waiting rooms, allow screen sharing, or permit recording if their use case requires it. But new users get secure-by-default settings.


    This approach requires:


    1. Clear security education at signup and onboarding

    2. Visible security controls that users can inspect and adjust

    3. Responsive threat monitoring to quickly identify when new vulnerabilities emerge

    4. Community partnerships with researchers to stay ahead of novel attacks


    ## AI and the Future of Threat Detection


    McLeod's vision for AI-augmented security operates at three levels:


    Level 1: Operational Automation

  • Intelligent alert triage and deduplication
  • Automated response to known attack patterns
  • Rapid forensic data collection and correlation

  • Level 2: Threat Intelligence Enhancement

  • Contextual analysis of emerging attack patterns
  • Cross-organizational threat sharing and analysis
  • Predictive modeling of adversary tactics

  • Level 3: Strategic Security Design

  • AI-assisted security architecture review
  • Risk modeling based on organizational context
  • Threat scenario planning and red-teaming

  • The key distinction McLeod makes is this: AI is most effective when it augments human decision-making, not when it replaces it. A security analyst guided by an AI system that highlights anomalies relevant to their organization is more effective than a system that independently makes defensive decisions.


    ## Implications for Organizations


    McLeod's perspective has direct implications for how enterprises should approach AI and cybersecurity:


  • Invest in security talent: AI won't eliminate the need for skilled analysts — it will increase demand as organizations deploy more AI-driven systems
  • Balance automation and judgment: Implement AI for operational efficiency, but retain human oversight for strategic decisions
  • Design security intentionally: Don't rely on security as an afterthought; build it into product design from the beginning
  • Build diverse teams: Different perspectives on threat modeling and security architecture improve outcomes
  • Educate continuously: As threats evolve, so must user awareness and security education

  • ---


    ## HackWire Analysis


    The cybersecurity industry has spent the past year oscillating between two extremes: unbridled optimism that AI will solve all security problems, and panic that AI will put security professionals out of work. McLeod's actual position — nuanced and grounded in operational reality — cuts through both narratives.


    What makes this commentary valuable now is timing.** We're at an inflection point where early AI-driven security tools are reaching production in enterprises, but widespread implementation hasn't yet revealed the real constraints. McLeod's argument that AI handles *repetitive work* is accurate, but it obscures a harder truth: **the bottleneck in security isn't alert triage or log parsing anymore — it's skilled human judgment under uncertainty.


    The real risk isn't job replacement. It's skill bifurcation. Organizations with access to top security talent and the capital to implement AI-driven security orchestration will pull further ahead. Mid-market and smaller organizations lacking these resources will fall behind, creating a two-tiered security landscape where incidents become increasingly concentrated among defenders without AI leverage.


    McLeod's emphasis on intentional networking and cross-domain expertise also reveals a gap in current cybersecurity education. Most security roles still require specific certifications or narrow specializations. Her advice suggests the field is moving toward generalists who can work across cloud, application, infrastructure, and identity domains — a shift that training programs haven't fully caught up with.


    The most overlooked aspect of McLeod's message: secure-by-default design requires continuous adversary research and rapid iteration. Zoom bombing seemed quaint in retrospect, but it exposed the company's need to understand how users would interact with security controls. This isn't automation — it's anthropology. As AI handles more operational security, the competitive advantage will go to teams that best understand attacker behavior and user expectations.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Cybersecurity Operations](https://www.hackwire.news/category/cybersecurity-operations) coverage
  • Cross-reference with [Threat Intelligence](https://www.hackwire.news/category/threat-intelligence) and [Security Strategy](https://www.hackwire.news/category/security-strategy)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)