← Risk register SOC 15-1212 · reviewed 2026-08-11

Information Security Analysts

190,650 US workers · median $129,180/yr · Tech

EXPOSED

Tier-1 work — alert triage, log correlation, phishing-report review, vulnerability scan output, policy and control documentation — is exactly what LLMs plus SIEM automation already do at usable quality, and it is where most headcount sits. What holds is the accountable end: deciding whether an incident is a breach, running containment during a live intrusion under executive pressure, and owning risk acceptance decisions that carry regulatory and contractual consequences. No license gates the work, so the moat is judgment and organizational trust, not law.

10-year outlook: Demand for security stays high but headcount concentrates upward — entry-level SOC monitoring thins out while incident leads, architects, and risk owners get scarcer and better paid.

US employment, 2019–2025+51.8%
125,570190,650 workers

Headcount grew steadily across the period.

Median pay $99,730 → $129,180 +3.6% in real terms (nominal +29.5%, less ~25% US inflation over the period)

The job count is not the verdict

This line is counted by the Bureau of Labor Statistics — the one figure on this page that isn't a judgement of ours. Headcount moves on demand, offshoring, demographics and the business cycle, and automation is one term among several, often not the loudest.

So a falling line is not evidence that AI did it, and a rising one is not evidence that it won't. Both happen in this register: some occupations resist automation and shrink anyway, others are highly automatable and keep growing. The marked year is 2020.

BLS projection, 2024–2034

+28.5% 182,800 → 234,900 on the projections basis

Exposed, but growing

AI can already do a lot of these tasks, and the BLS still expects +28.5% more of these jobs by 2034. Demand for the output is growing faster than the work is being automated away — the mechanism BLS gives for software developers, and the combination people most often misread as an error.

Different clocks. The score is what current AI could do to this work today. The projection is how many of these jobs will exist in 2034. Everything between the two — how fast employers actually adopt, whether demand grows in the meantime — is why they can point opposite ways without either being wrong.

~16,000 openings a year on average, including replacing people who leave.

One email if this score changes. Watch as many occupations as you like from the same address — no account, and nothing is sent on a schedule, only when a verdict actually moves.

Also known as — 24 job titles this covers

Titles reported by people doing this work, from the US Department of Labor's O*NET survey. If your job title is here, this page is about your work even though the name doesn't match.

CryptologistThreat HunterCyber OperatorRed Team MemberSystems AnalystWarning AnalystBlue Team MemberSecurity AnalystSecurity AuditorVirus TechnicianAll-Source AnalystIncident ResponderTechnology AnalystCyber Intel PlannerSecurity ConsultantSecurity SpecialistSource Code AuditorExploitation AnalystCyber Defense AnalystCybersecurity AnalystData Security AnalystCyber Security AnalystCybersecurity EngineerCloud Security Engineer

Score — 37/100 resistance

Holding it up: judgment & accountability (13/20). Weakest point: embodiment (2/20).

Five dimensions, 0–20 each, summed. Higher means more protected. The arithmetic is shown so you can check it: 9 + 2 + 5 + 8 + 13 = 37. · Scored 2026-08-11, and re-examined when evidence accumulates rather than on a schedule.

Task resistance 9/20

Mixed — a routine tier and a judgment tier Alert triage against SIEM rules, enriching IOCs from threat feeds, writing up phishing submissions, and mapping scan findings to CVSS scores are pattern-matching over structured logs that SOAR playbooks and LLM summarizers already handle end to end, while threat hunting on a novel TTP, reverse-engineering an unfamiliar loader, and negotiating a compensating control with an application owner who refuses to patch still need a person — a 9 puts the split roughly at Tier-1 gone, Tier-3 intact.

Embodiment 2/20

Fully desk- and screen-based Everything happens through a console: EDR agents, cloud audit logs, ticketing, and the occasional badge-in to a datacenter for a physical-access review, with a 2 rather than 0 only because some analysts still rack a network tap, image a seized laptop, or run a physical pentest walkthrough.

Liability shield 5/20

Certification preferred, not legally required CISSP, GCIH, and CISA are hiring filters, not licenses; nobody's certification is revoked for missing an intrusion, breach notification is signed by the CISO or general counsel, and the statutory exposure under HIPAA, GLBA Safeguards, or SEC Item 1.05 attaches to the entity — a 5 reflects that certification is near-mandatory in practice while conferring no personal legal standing.

Trust premium 8/20

Some relationship component Analysts are largely interchangeable to the business until an incident, at which point the credibility earned with the app teams, legal, and the audit committee determines whether containment gets approved in twenty minutes or two hours; that credibility is real but attaches to the security function and rebuilds with a new hire, hence 8 and not 14.

Judgment & accountability 13/20

Meaningful discretion Calling whether exfiltrated data triggers a 72-hour GDPR notification, deciding to isolate a revenue-generating production host mid-intrusion, and signing off on a risk acceptance that an auditor will read back to you are ambiguous calls with regulatory consequences made under time pressure — held at 13 rather than higher because the final breach determination and the decision to pay or not pay usually escalate to the CISO, counsel, or the board.

Confidence: high · reviewed 2026-08-11 · how scoring works

What this job involves — and which parts are yours

The verdict above describes this occupation as a whole. Almost nobody does the typical version of a job — tick what's actually in your week and see how your own mix sits.

AI already does these at usable quality

These still need a person

Active moats on the surviving side: judgment, trust

How to future-proof this job

Where to go deeper on what this job runs on: Khan Academy — reading and vocabulary, all levels, free free · Coursera — critical thinking and logic, audit free free to audit · Coursera — active listening and communication skills free to audit · MIT OpenCourseWare — problem-solving and analytical method courses free · Toastmasters — public speaking practice at local clubs worldwide low · Purdue OWL — the standard reference for professional writing free

All 35 skills ranked by how many jobs they open →

Where this experience transfers — nothing clears the bar

No occupation passed every test: close enough to information security analysts on skills and subject matter, at least 10 points more resistant, no big jump in training, no new licence, no pay cut, and not shrinking on its own. That happens for 223 of the 654 occupations here that aren't SAFE, and it is worth stating plainly rather than leaving the section off.

The usual reason is that exposure travels with the skill profile. The jobs most similar to yours tend to be exposed for the same reasons yours is, so the near neighbours don't clear the gap — and the ones that do are a different kind of work, not a transfer of what you already know. Read that as a limit of this method, not a verdict that you're stuck: it only compares whole occupations, and it cannot see specialisation, industry, or anything you'd bring that isn't in a federal skill survey.

Here is that claim on your own job rather than in the abstract. These are the three occupations closest to this one by skill and subject matter — the places the work would most naturally transfer — with what the register scores them:

Computer Occupations, All Other EXPOSED 34/100 (-3) · 84% overlap
Database Administrators EXPOSED 38/100 (+1) · 82% overlap
Computer Systems Analysts EXPOSED 37/100 (+0) · 75% overlap

That is the whole problem in three lines. The nearest work is not meaningfully safer, so there is no move here that trades a similar skill set for a better verdict. This is not us running out of ideas — it is what the neighbourhood looks like.

What would move this occupation up is the other direction, and on this page it's the more useful one.

What would move this back up — beyond any one person

The moves above are yours to make. This is the other half: what would have to change in the world for the occupation itself to score higher. None of it is in any one person's gift, but it is where the floor actually comes from. Scores here are not a one-way ratchet. Only two of the five dimensions — task resistance and embodiment — track what machines can do. The other three track law, what buyers will pay for, and who is answerable, and those move in both directions, often in response to the same pressure AI creates. If every lever below landed, this occupation would score around 55/100, still EXPOSED.

6 specific changes that would raise this score
  • already happening liability shield +4

    SEC cyber disclosure rules (Item 1.05, in force since Dec 2023) already require a named officer's materiality determination on 8-K filings; if enforcement actions extend personal liability down to the analyst/CISO chain — as in the SEC's SolarWinds case against CISO Tim Brown — or if state breach-notification statutes require a named accountable individual to attest that an AI-generated incident assessment was human-reviewed, a sign-off role hardens

  • already happening task resistance +4

    Genuine two-tier occupation: as SIEM/LLM automation absorbs alert triage, log correlation and phishing review, the surviving role is adversary-facing judgment — threat hunting against an active human attacker, deciding scope of containment during a live intrusion, and interpreting whether an anomaly is compromise or noise. Task-mix shift raises measured resistance for those who remain even with zero new law, while cutting headcount

  • already happening judgment accountability +3

    If DORA (EU, in force Jan 2025) and CIRCIA reporting deadlines (72-hour / 72-hour and 24-hour ransom payment) force a named individual to make the reportability call on a clock, the risk-acceptance decision becomes formally owned rather than diffuse

  • already happening task resistance +2

    AI systems themselves becoming the attack surface — prompt injection, model supply chain, agent permission scoping. NIST AI RMF and the EU AI Act Article 15 security requirements create work with no established playbook for automation to have learned from

  • plausible liability shield +3

    Cyber insurers conditioning coverage or claim payout on attestation by a named, credentialed human (CISSP/GIAC) that controls were validated and incident response followed policy — already appearing in ransomware policy warranties; extension to explicit human-attestation clauses would make the signature contractual rather than optional

  • plausible trust premium +2

    Buyers of penetration testing and red-team engagements specifying human operators in scope-of-work — driven by PCI DSS 4.0 requirements for penetration testing by qualified personnel and by client insistence that adversary simulation not be purely automated scanning

The limit. No license gates this work and none is realistically coming — there is no state board for security analysts, and CISSP is a private credential with no statutory force. The liability and accountability levers concentrate at the CISO/incident-commander tier, not across the 190k headcount; most of the gains described accrue to a shrinking senior slice while the tier-1 base erodes. Aggregate score movement is likely modest even if every lever fires.

These are conditions, not forecasts — what would have to happen, not what will. Specific rules, cases and bills are named so you can go and check whether they exist and where they stand; verify before relying on any of them. Nothing here is legal or financial advice.

Where this work is, and what it pays there

BLS metro figures for 253 areas. The verdict above does not change by city — the rubric judges what the work involves, not where it happens — but pay and headcount do, and the national median hides a very wide range.

Most of these jobs

Washington-Arlington-Alexandria, DC-VA-MD-WV 16,560 $148,950 +15%
New York-Newark-Jersey City, NY-NJ 11,330 $140,470 +9%
Dallas-Fort Worth-Arlington, TX 7,080 $133,610 +3%
Boston-Cambridge-Newton, MA-NH 5,220 $136,550 +6%
Los Angeles-Long Beach-Anaheim, CA 4,820 $129,630 +0%
Seattle-Tacoma-Bellevue, WA 4,700 $161,780 +25%
Baltimore-Columbia-Towson, MD 4,600 $138,170 +7%
Atlanta-Sandy Springs-Roswell, GA 4,550 $131,490 +2%

Best paid

San Jose-Sunnyvale-Santa Clara, CA 2,280 $176,120 +36%
San Francisco-Oakland-Fremont, CA 3,730 $162,310 +26%
Seattle-Tacoma-Bellevue, WA 4,700 $161,780 +25%

Percentages are against this occupation's national median of $129,180. Counts are jobs in that metro, not vacancies. Metros where the BLS suppressed the cell are absent rather than shown as zero.

Who is actually doing this

The score above is about what the work exposes. This is reporting about real deployments in this occupation — the difference between "could be automated" and "somebody automated it."

Rapid7

1 of 1 reported case, with sources

Quick take — do you do this job?

Has AI actually changed your work? One tap, anonymous, and the running tally is public. Nothing else is asked of you.

Self-reported and unverified — a sentiment signal, not a survey. One response per person per occupation; you can change your answer.

Field reports — what people say has changed

No field reports yet. A written account takes a paragraph rather than a tap, goes to an editor before it appears, and is the one thing on this page the rubric cannot produce on its own.

File a field report

Concrete beats general: a tool that arrived, a task that moved, a headcount decision you watched happen. Don't include anything that identifies you or your employer if that would put you at risk.

Watch this verdict
Kept current

Rather than check back: get the digest and we'll tell you what changed — or watch a single occupation from its own page.