← Risk register SOC 15-1212 · reviewed 2026-08-11

Information Security Analysts

190,650 US workers · median $129,180/yr · Tech

EXPOSED

Tier-1 work — alert triage, log correlation, phishing-report review, vulnerability scan output, policy and control documentation — is exactly what LLMs plus SIEM automation already do at usable quality, and it is where most headcount sits. What holds is the accountable end: deciding whether an incident is a breach, running containment during a live intrusion under executive pressure, and owning risk acceptance decisions that carry regulatory and contractual consequences. No license gates the work, so the moat is judgment and organizational trust, not law.

10-year outlook: Demand for security stays high but headcount concentrates upward — entry-level SOC monitoring thins out while incident leads, architects, and risk owners get scarcer and better paid.

Score — 37/100 resistance

Five dimensions, 0–20 each, summed. Higher means more protected. The arithmetic is shown so you can check it: 9 + 2 + 5 + 8 + 13 = 37.

Task resistance 9/20

Mixed — a routine tier and a judgment tier. Alert triage against SIEM rules, enriching IOCs from threat feeds, writing up phishing submissions, and mapping scan findings to CVSS scores are pattern-matching over structured logs that SOAR playbooks and LLM summarizers already handle end to end, while threat hunting on a novel TTP, reverse-engineering an unfamiliar loader, and negotiating a compensating control with an application owner who refuses to patch still need a person — a 9 puts the split roughly at Tier-1 gone, Tier-3 intact.

Embodiment 2/20

Fully desk- and screen-based. Everything happens through a console: EDR agents, cloud audit logs, ticketing, and the occasional badge-in to a datacenter for a physical-access review, with a 2 rather than 0 only because some analysts still rack a network tap, image a seized laptop, or run a physical pentest walkthrough.

Liability shield 5/20

Certification preferred, not legally required. CISSP, GCIH, and CISA are hiring filters, not licenses; nobody's certification is revoked for missing an intrusion, breach notification is signed by the CISO or general counsel, and the statutory exposure under HIPAA, GLBA Safeguards, or SEC Item 1.05 attaches to the entity — a 5 reflects that certification is near-mandatory in practice while conferring no personal legal standing.

Trust premium 8/20

Some relationship component. Analysts are largely interchangeable to the business until an incident, at which point the credibility earned with the app teams, legal, and the audit committee determines whether containment gets approved in twenty minutes or two hours; that credibility is real but attaches to the security function and rebuilds with a new hire, hence 8 and not 14.

Judgment & accountability 13/20

Meaningful discretion. Calling whether exfiltrated data triggers a 72-hour GDPR notification, deciding to isolate a revenue-generating production host mid-intrusion, and signing off on a risk acceptance that an auditor will read back to you are ambiguous calls with regulatory consequences made under time pressure — held at 13 rather than higher because the final breach determination and the decision to pay or not pay usually escalate to the CISO, counsel, or the board.

Confidence: high · reviewed 2026-08-11 · how scoring works

Tasks already automatable

What survives

Active moats: judgment, trust

How to future-proof this job

Field report — do you do this job?

Has AI actually changed your work?

Self-reported and unverified — a sentiment signal, not a survey. One response per person per occupation; you can change your answer.

From people who do this job

Nobody has filed one yet. If you do this work, you know things the rubric can't see.

What has actually changed in your work?

Concrete beats general: a tool that arrived, a task that moved, a headcount decision you watched happen. Don't include anything that identifies you or your employer if that would put you at risk.