{
  "source": "Cooked Index — occupational AI risk register",
  "page": "https://cookedindex.com/jobs/information-security-analysts/",
  "methodology": "https://cookedindex.com/methodology",
  "notice": "Verdicts are re-examined as evidence accumulates. Re-fetch before relying on this; the page above always carries the current score.",
  "scored_at": "2026-08-11",
  "model": "claude-opus-5",
  "occupation": {
    "title": "Information Security Analysts",
    "soc_code": "15-1212",
    "category": "Tech",
    "us_employment": 190650,
    "median_annual_wage": 129180
  },
  "verdict": "EXPOSED",
  "risk_resistance": 37,
  "contested": false,
  "near_boundary": false,
  "dimensions": {
    "task_resistance": 9,
    "embodiment": 2,
    "liability_shield": 5,
    "trust_premium": 8,
    "judgment_accountability": 13
  },
  "reasoning": {
    "task_resistance": "Alert triage against SIEM rules, enriching IOCs from threat feeds, writing up phishing submissions, and mapping scan findings to CVSS scores are pattern-matching over structured logs that SOAR playbooks and LLM summarizers already handle end to end, while threat hunting on a novel TTP, reverse-engineering an unfamiliar loader, and negotiating a compensating control with an application owner who refuses to patch still need a person — a 9 puts the split roughly at Tier-1 gone, Tier-3 intact.",
    "embodiment": "Everything happens through a console: EDR agents, cloud audit logs, ticketing, and the occasional badge-in to a datacenter for a physical-access review, with a 2 rather than 0 only because some analysts still rack a network tap, image a seized laptop, or run a physical pentest walkthrough.",
    "liability_shield": "CISSP, GCIH, and CISA are hiring filters, not licenses; nobody's certification is revoked for missing an intrusion, breach notification is signed by the CISO or general counsel, and the statutory exposure under HIPAA, GLBA Safeguards, or SEC Item 1.05 attaches to the entity — a 5 reflects that certification is near-mandatory in practice while conferring no personal legal standing.",
    "trust_premium": "Analysts are largely interchangeable to the business until an incident, at which point the credibility earned with the app teams, legal, and the audit committee determines whether containment gets approved in twenty minutes or two hours; that credibility is real but attaches to the security function and rebuilds with a new hire, hence 8 and not 14.",
    "judgment_accountability": "Calling whether exfiltrated data triggers a 72-hour GDPR notification, deciding to isolate a revenue-generating production host mid-intrusion, and signing off on a risk acceptance that an auditor will read back to you are ambiguous calls with regulatory consequences made under time pressure — held at 13 rather than higher because the final breach determination and the decision to pay or not pay usually escalate to the CISO, counsel, or the board."
  },
  "rationale": "Tier-1 work — alert triage, log correlation, phishing-report review, vulnerability scan output, policy and control documentation — is exactly what LLMs plus SIEM automation already do at usable quality, and it is where most headcount sits. What holds is the accountable end: deciding whether an incident is a breach, running containment during a live intrusion under executive pressure, and owning risk acceptance decisions that carry regulatory and contractual consequences. No license gates the work, so the moat is judgment and organizational trust, not law.",
  "outlook": "Demand for security stays high but headcount concentrates upward — entry-level SOC monitoring thins out while incident leads, architects, and risk owners get scarcer and better paid.",
  "what_would_raise_it": {
    "levers": [
      {
        "dimension": "liability_shield",
        "change": "SEC cyber disclosure rules (Item 1.05, in force since Dec 2023) already require a named officer's materiality determination on 8-K filings; if enforcement actions extend personal liability down to the analyst/CISO chain — as in the SEC's SolarWinds case against CISO Tim Brown — or if state breach-notification statutes require a named accountable individual to attest that an AI-generated incident assessment was human-reviewed, a sign-off role hardens",
        "plausibility": "already happening",
        "would_add": 4
      },
      {
        "dimension": "liability_shield",
        "change": "Cyber insurers conditioning coverage or claim payout on attestation by a named, credentialed human (CISSP/GIAC) that controls were validated and incident response followed policy — already appearing in ransomware policy warranties; extension to explicit human-attestation clauses would make the signature contractual rather than optional",
        "plausibility": "plausible",
        "would_add": 3
      },
      {
        "dimension": "task_resistance",
        "change": "Genuine two-tier occupation: as SIEM/LLM automation absorbs alert triage, log correlation and phishing review, the surviving role is adversary-facing judgment — threat hunting against an active human attacker, deciding scope of containment during a live intrusion, and interpreting whether an anomaly is compromise or noise. Task-mix shift raises measured resistance for those who remain even with zero new law, while cutting headcount",
        "plausibility": "already happening",
        "would_add": 4
      },
      {
        "dimension": "task_resistance",
        "change": "AI systems themselves becoming the attack surface — prompt injection, model supply chain, agent permission scoping. NIST AI RMF and the EU AI Act Article 15 security requirements create work with no established playbook for automation to have learned from",
        "plausibility": "already happening",
        "would_add": 2
      },
      {
        "dimension": "judgment_accountability",
        "change": "If DORA (EU, in force Jan 2025) and CIRCIA reporting deadlines (72-hour / 72-hour and 24-hour ransom payment) force a named individual to make the reportability call on a clock, the risk-acceptance decision becomes formally owned rather than diffuse",
        "plausibility": "already happening",
        "would_add": 3
      },
      {
        "dimension": "trust_premium",
        "change": "Buyers of penetration testing and red-team engagements specifying human operators in scope-of-work — driven by PCI DSS 4.0 requirements for penetration testing by qualified personnel and by client insistence that adversary simulation not be purely automated scanning",
        "plausibility": "plausible",
        "would_add": 2
      }
    ],
    "ceiling_note": "No license gates this work and none is realistically coming — there is no state board for security analysts, and CISSP is a private credential with no statutory force. The liability and accountability levers concentrate at the CISO/incident-commander tier, not across the 190k headcount; most of the gains described accrue to a shrinking senior slice while the tier-1 base erodes. Aggregate score movement is likely modest even if every lever fires."
  },
  "adjudication": null,
  "employment_history": {
    "points": [
      {
        "y": 2019,
        "emp": 125570,
        "wage": 99730
      },
      {
        "y": 2020,
        "emp": 138000,
        "wage": 103590
      },
      {
        "y": 2021,
        "emp": 157220,
        "wage": 102600
      },
      {
        "y": 2022,
        "emp": 163690,
        "wage": 112000
      },
      {
        "y": 2023,
        "emp": 175350,
        "wage": 120360
      },
      {
        "y": 2024,
        "emp": 179430,
        "wage": 124910
      },
      {
        "y": 2025,
        "emp": 190650,
        "wage": 129180
      }
    ],
    "from": 2019,
    "to": 2025,
    "change_pct": 51.8,
    "comparable_from": 2019,
    "spans_soc_revision": false
  },
  "pivots": [],
  "license": "https://cookedindex.com/terms"
}