A Forward Deployed Engineer for AI and cybersecurity needs two skill sets that rarely live in one person. The builder and the advisor. Most people have one. The rare and valuable ones have both.
Here is why that matters. An engineer who cannot sit with a board ships things nobody trusts or approves. An advisor who cannot build ships slides that never become systems. The FDE has to do both, in the same week, on the same problem. This is the stack that job requires.
The builder half
Start with the part that produces a running system, because without it the rest is just talk.
Shipping production systems with large language models. Not demos. Real systems wired to real payment and data infrastructure, taking live actions. I build these with Claude, GPT, and Gemini. The specific tools matter less than knowing what each is good at and when to use which.
That leads to the first real skill, routing. You do not send every task to one model. You route by cost, speed, and capability. A cheap fast model for classification, a stronger one for judgment, a third for long context. A routing layer decides. Getting that right is the difference between a system that is affordable at scale and one that is not.
Agent loops. Modern AI work is not one prompt and one answer. It is a loop. The model plans, calls a tool, reads the result, and decides the next step. Building that loop so it makes progress without going off the rails is core work.
Guardrails. An AI system wired to live infrastructure can do real damage. Guardrails constrain what it can touch, check its actions before they execute, and stop it when it strays. This is where the security discipline and the building discipline meet. You design the system assuming it will sometimes be wrong.
Evaluations. You cannot ship what you cannot measure. Evals are the tests for AI systems. They tell you whether a change made the system better or worse, on real cases, before it reaches production. Skipping evals is how teams end up with a system that feels good in a demo and fails in the field.
Retrieval. Most useful AI work needs the model to see your data, not just its training. Retrieval pulls the right documents into the model's context at the right moment. Done well it grounds answers in truth. Done badly it feeds the model noise and you get confident nonsense.
Prompt and context engineering. This is the craft of telling the model what it needs, in the space it has, without waste. The difference between a system that works and one that hallucinates is often what you put in the context window and what you leave out.
That is the builder half. It is why so many AI programs stall. Gartner predicted at least 30 percent of generative AI projects would be abandoned after proof of concept by the end of 2025, and more than 40 percent of agentic AI projects canceled by the end of 2027. Most of those deaths are build-quality problems dressed up as strategy problems.
The advisor half
Now the half that makes the building matter.
Board-level communication. You have to explain a technical system to people who control the budget and carry the liability, in plain terms, without dumbing it down to the point of being wrong. An AI failure or a breach is a board event. A breach averages 4.88 million dollars by IBM's count. The person who built the system has to be able to sit in that room and say what is true.
Risk judgment. Knowing what could go wrong, how badly, and what is worth doing about it. This is where the certifications earn their keep. I have held CISSP, ISSAP, and ISSMP for more than twenty years. Those are not decorations. They force a discipline of thinking about failure modes before they happen. I also run incident-response tabletops for executives, where the whole point is to make leaders decide under pressure before a real attacker forces the decision.
AI and cybersecurity assessments and audits. This is the diagnostic that starts every serious engagement. Cybersecurity has run on audits for years. ISO 27001. SOC 2. NIST CSF. AI is now getting the same regime. The NIST AI Risk Management Framework arrived in January 2023. ISO/IEC 42001, for AI management systems, followed in December 2023. The EU AI Act, Regulation 2024/1689, requires conformity assessments for high-risk systems. An FDE has to run these assessments, because they tell you where a business actually stands before you build anything. An MIT NANDA report from August 2025 found around 95 percent of enterprise generative AI pilots delivered no measurable profit impact, and pinned the cause on poor fit with how the business runs, not model quality. The assessment is how you avoid being in that group. The report has taken some methodological criticism, so treat the figure as a signal, not gospel.
Why the combination is rare and paid for
Put the two halves together and you have someone who can decide what to build, build it, and stand in front of a board and own it.
The market has priced this. Andreessen Horowitz called the FDE the hottest job in tech in 2025. OpenAI built a Forward Deployed Engineering team and posted base pay between 162,000 and 280,000 dollars plus equity. In May 2026 it launched a dedicated deployment company with more than 4 billion dollars behind it and roughly 150 forward deployed engineers. The pay reflects the scarcity. Full builders are common. Trusted advisors are common. The overlap is thin.
I have spent a career building the overlap. Five times as a CEO, CIO, and CISO, on the advisor side. Still shipping production AI systems myself, on the builder side. That combination is the FDE, and it is what the work now demands.
What to do
If you are hiring for this, or trying to become it, do not settle for half the stack. Screen for both. Ask the builder to explain risk to a board. Ask the advisor to show you something they shipped. The value is in the overlap.
If your AI or cyber program needs someone who can hold both ends at once, reach me at marklynd.com.
Sources
- https://newsletter.pragmaticengineer.com/p/forward-deployed-engineers
- https://openai.com/careers/forward-deployed-engineer-(fde)-sf-san-francisco/
- https://openai.com/index/openai-launches-the-deployment-company/
- https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027
- https://fortune.com/2025/08/18/mit-report-95-percent-generative-ai-pilots-at-companies-failing-cfo/
- https://www.nist.gov/itl/ai-risk-management-framework
- https://www.iso.org/standard/81230.html
- https://eur-lex.europa.eu/eli/reg/2024/1689/oj