EXPOSED
Tier-1 work — alert triage, log correlation, phishing-report review, vulnerability scan output, policy and control documentation — is exactly what LLMs plus SIEM automation already do at usable quality, and it is where most headcount sits. What holds is the accountable end: deciding whether an incident is a breach, running containment during a live intrusion under executive pressure, and owning risk acceptance decisions that carry regulatory and contractual consequences. No license gates the work, so the moat is judgment and organizational trust, not law.
Mixed — a routine tier and a judgment tier. Alert triage against SIEM rules, enriching IOCs from threat feeds, writing up phishing submissions, and mapping scan findings to CVSS scores are pattern-matching over structured logs that SOAR playbooks and LLM summarizers already handle end to end, while threat hunting on a novel TTP, reverse-engineering an unfamiliar loader, and negotiating a compensating control with an application owner who refuses to patch still need a person — a 9 puts the split roughly at Tier-1 gone, Tier-3 intact.
Fully desk- and screen-based. Everything happens through a console: EDR agents, cloud audit logs, ticketing, and the occasional badge-in to a datacenter for a physical-access review, with a 2 rather than 0 only because some analysts still rack a network tap, image a seized laptop, or run a physical pentest walkthrough.
Certification preferred, not legally required. CISSP, GCIH, and CISA are hiring filters, not licenses; nobody's certification is revoked for missing an intrusion, breach notification is signed by the CISO or general counsel, and the statutory exposure under HIPAA, GLBA Safeguards, or SEC Item 1.05 attaches to the entity — a 5 reflects that certification is near-mandatory in practice while conferring no personal legal standing.
Some relationship component. Analysts are largely interchangeable to the business until an incident, at which point the credibility earned with the app teams, legal, and the audit committee determines whether containment gets approved in twenty minutes or two hours; that credibility is real but attaches to the security function and rebuilds with a new hire, hence 8 and not 14.
Meaningful discretion. Calling whether exfiltrated data triggers a 72-hour GDPR notification, deciding to isolate a revenue-generating production host mid-intrusion, and signing off on a risk acceptance that an auditor will read back to you are ambiguous calls with regulatory consequences made under time pressure — held at 13 rather than higher because the final breach determination and the decision to pay or not pay usually escalate to the CISO, counsel, or the board.
Has AI actually changed your work?