top of page

The SOC Analyst Job Didn't Shrink, the Bar Moved

soc analyst


SOC ANALYST

Let me tell you what it looks like to open a ticket in a modern SOC.

Something has already happened to it. The alert is enriched, related events are attached, and sitting right at the top of the page is a verdict. Malicious or benign, with a confidence percentage next to it and two paragraphs of clean reasoning underneath explaining how it got there. An agent wrote all of that before you ever sat down.


That's not everywhere yet, and it might not be in your SOC. But it is what a lot of analysts are walking into in the morning, and more importantly, it is what hiring managers have started hiring for.


What's Already in Your Stack

This isn't a prediction, it already shipped.


Microsoft extended agentic investigation into identity and cloud alerts. Palo Alto took Cortex AgentiX standalone. Cisco announced six agents for Splunk Enterprise Security at RSAC. Google added threat hunting agents, and CrowdStrike launched a whole ecosystem for building your own.


If your SOC runs any of those platforms, the capability is sitting inside a product your company already pays for. Whether your team has turned it on is a different question, and honestly most haven't. Real deployment is still pretty thin. But the buying decision got made a couple of levels above you, and the people interviewing you next month have read the same roadmaps their vendors have been sending them.


About Those Numbers You've Been Fed

Before we go further I want to talk about the statistics, because if somebody has convinced you this field is desperate for you, it probably came from one of two places, and you deserve to know what you're actually looking at.


The 4.8 Million "Workforce Gap"

That number came from ISC2's 2024 workforce study, and you've seen it in a hundred LinkedIn posts.


Here's what it actually measured. ISC2 asked security professionals how many people they felt they'd need to properly secure their organization, then subtracted how many people are working in the field. That's it. It is a measurement of how understaffed people feel. ISC2 even said in the report itself that it is not an estimate of current job openings, which is right there in the document, and just about every article that quoted it went ahead and treated it like open jobs anyway. Nobody at a training and certification company is in a big hurry to correct that, because a world with five million empty chairs is a world where a lot of people buy certifications.


Now here's the part almost nobody covered. ISC2 dropped the number. It isn't in the 2025 study at all. Their explanation is that the people they survey now rate critical skills as more important than raw headcount. This came after Ira Winkler, a field CISO, wrote an open letter criticizing the gap as a measure of demand, which he wrote after talking with dozens of unemployed cybersecurity professionals who were reading that statistic and wondering what was wrong with them.


If you want to see how soft that methodology was, look at the UK. ISC2 put the UK gap at 93,000 people. The UK government ran its own survey through Ipsos and came back with 3,800. Same country, same time frame, and the two numbers are twenty-four times apart. One of them asked employers what they wished they had. The other one counted.


For comparison, CyberSeek actually counts posted openings in the US, and that number lands somewhere around 514,000. Real, measured, and a fraction of the headline everybody was repeating.


The 29% Growth Projection

I want to be fair about this one, because it's a different situation and the difference matters.


The Bureau of Labor Statistics isn't selling you anything. There's no certification at the end of it. It's a federal statistical model and it's honest work.


The problem is what people do with it. It is a ten-year projection, running out to 2034, for an occupational category called "Information Security Analysts" that includes GRC people, appsec engineers, and compliance folks right alongside SOC analysts. And that figure you've seen about roughly 16,000 openings a year includes replacing people who leave the occupation. It is not 16,000 new seats. Most people quoting it think it is.


So it's not dishonest data. It's honest data being used dishonestly, to describe a job market that you are applying into this month rather than in 2034.


What People Are Actually Seeing

Set the projections aside for a minute and look at what's on the record instead.

During the same years everybody was loudest about the shortage, roughly a quarter of organizations reported cybersecurity layoffs, and budget cuts ran higher than that. In ISC2's own most recent numbers, about a third of the people they surveyed said their organization doesn't have the resources to staff adequately, and nearly as many said they can't afford to hire people with the skills they need. Read that again, because it isn't a talent shortage. It's a budget decision.


Demand at the entry level specifically has flattened out. That's the consistent read from anybody watching actual posting volume instead of survey sentiment, and in the UK core cybersecurity postings dropped by a third.

And then there's the part nobody publishes, which is what it feels like on your end. Two hundred applications and four responses. Postings that say entry-level and then ask for three years of experience and two certs. Requisitions that sit open for months and then get filled by somebody's cousin internally. Automated screening that tosses you before a human being ever opens your resume.


Both things are true at the same time, and I know that's frustrating. Employers genuinely cannot find people who can do the hard part of this job. And they are also not hiring five million of anybody.


What I've Seen From the Hiring Side

I've spent a decade in security operations, working my way from analyst to architect, and I've sat on enough hiring panels to tell you something that cuts against the whole shortage story.


We were never short of applicants.


Not one time. Every posting we put up came back with a pile of resumes. What we were short of were applicants who could take an alert that nobody had written a playbook for and reason their way to an answer they could defend in a room.


What's changed is how you used to get that skill. You'd get hired on potential, and then you'd learn it on the queue over about eighteen months. The queue was the classroom. Automation is eating the classroom, and that's the real disruption here. It isn't that jobs are disappearing. It's that the on-ramp got a lot steeper.


So What's in Demand

Supervising the Machine

Don't take my word for this one. Go pull fifty SOC analyst postings today and count how many of them mention AI, automation, or agentic tooling in the requirements. Then go pull fifty from two years ago off the Wayback Machine and count again. It'll take you twenty minutes and it will convince you a lot harder than anything I could tell you.


What those postings mean by "AI skills" is almost never building models. What they mean is, can you tell when the thing is wrong?


Every vendor selling autonomous triage tells their buyers to train analysts on AI supervision. Then you go looking for that training and what you find is generic machine learning coursework. Supervised versus unsupervised learning, anomaly detection, maybe an executive AI strategy program from some university extension program. None of it teaches an analyst how to catch a confident agent making a bad call.


Here's what that skill actually looks like day to day. You need to know what telemetry the agent's integrations actually reach and what they don't, because its verdict is only ever a conclusion drawn from whatever it was able to query. You need to read a confident verdict and ask what it couldn't see before you ask yourself whether you agree with it. You need to be able to tune the thing so a whole class of error stops recurring, without burying your queue in noise doing it. And you need to be able to write the override in a way that survives a skeptical room.


Nobody is hiring for a job title called that yet. They're hiring for it inside job titles that still say SOC Analyst II.


Hypothesis-Driven Investigation

Following playbooks was always the automatable part of this job, and now it's automated.


What's left over is the work that starts when you look at something and think, that doesn't fit. And it ends with a pivot that nobody wrote down for you in advance. That was always the part I could never teach quickly, and it's the part that decides who gets promoted.


You can practice this without having a job. Take a closed incident writeup, read only the alert at the top, and try to get to the conclusion yourself. Then go check which step you would have missed. Do that thirty times and you'll be sharper than a lot of people sitting on a queue with two years in.


Detection Engineering

This has been the clearest path out of tier one for years and it still is.

It's judgment work, but with an artifact attached to it. The rule either fires on the right things or it doesn't, and you own the tradeoff between coverage and noise. It also happens to transfer straight into supervising agents, because a guardrail on an autonomous system is really just a detection rule wearing a different hat. Learn one and you've mostly learned the other.


Cloud, and I Mean Identity Specifically

"Learn cloud" is useless advice, so let me be more specific.


The alerts that matter are identity alerts. An access key getting used from an ASN you've never seen before. An OAuth consent grant to some application nobody vetted. Role assumption chains that have no business existing. A federated sign-in from a device that isn't what it says it is.


The perimeter is an identity boundary now. If you can read CloudTrail and Entra sign-in logs and you can look at a permission grant and tell me what it lets somebody do, you are more employable than a person holding a general cloud certification who has never read a log. That one isn't close.


Writing, and I'm Not Being Polite About It

This is the skill people skip, and it's the one that sets your ceiling.

Think about it this way. If the machine is handling volume, then your output is no longer tickets closed. Your output is judgment, and judgment doesn't exist inside a company until somebody writes it down well enough that another person can act on it.


An analyst who catches something real and then writes three vague sentences about it is going to get overruled by a manager who would rather not wake anybody up at two in the morning. An analyst who catches that same thing and writes one specific sentence naming the evidence that decides it gets action inside the hour. Same catch, same analyst, and two completely different careers.


What's Depreciating

I'd rather just tell you this than let you figure it out slowly over a couple of years.


Stacking certifications will still get you past automated filters, and I hold several of them so take this as criticism of myself too, but they don't differentiate you anymore. Five certs and no hands-on reps reads to a hiring manager like somebody who studied the job instead of doing it.


Memorizing tools has a short shelf life. Knowing where the buttons live in one particular SIEM is worth something right up until you change employers. Knowing what questions to ask a log doesn't expire.


And volume as a metric is done. "I closed 200 alerts a shift" used to be a flex. Today it's a description of the exact work your employer is out shopping for software to stop paying a human to do.


If You're Trying to Break In

The fundamentals still gate everything, and nothing about AI changes that. Networking, Windows and Linux internals, log analysis, ATT&CK fluency. No amount of AI literacy is going to cover for you not knowing what a normal authentication sequence looks like.


What's changed is what you stack on top of that.


Get reps on real investigations instead of buying more coursework, and write up every single one of them. Publicly if you can stand to. A portfolio of clear investigation writeups will do more for you right now than another certificate will, and it demonstrates two of the demand skills at the same time.


Then get deliberate about the agent problem, because almost nobody has. And I don't mean "I've used ChatGPT." I mean being able to say, in an interview, that you have practiced disagreeing with an automated verdict, and you can tell them about a time you were right to do it and a time you weren't.


Almost no candidate can say that sentence out loud today. And it lands directly on the thing that's keeping your future manager awake.


Wrapping Up

The field didn't get smaller. It got a lot less forgiving of people coasting on the volume work, and quite a bit more rewarding for the people who can do the part that still needs a human being in the chair.


If that sounds like bad news, try reading it the other way. The barrier that just went up is made out of judgment, and judgment is something you can build. It takes reps. It doesn't take luck, it doesn't take money, and it doesn't take anybody's permission.


Tyler Wall is the author of Jump-start Your SOC Analyst Career and the founder of Cyber NOW Education. He spent over a decade in security operations, working from analyst to architect.

Product Title

16 px collapsible text is perfect for longer content like paragraphs and descriptions. It’s a great way to give people more information while keeping your layout clean. Link your text to anything, including an external website or a different page. You can set your text box to expand and collapse when people click, so they can read more or less info.

$320

Product Title

16 px collapsible text is perfect for longer content like paragraphs and descriptions. It’s a great way to give people more information while keeping your layout clean. Link your text to anything, including an external website or a different page. You can set your text box to expand and collapse when people click, so they can read more or less info.

$900

Product Title

16 px collapsible text is perfect for longer content like paragraphs and descriptions. It’s a great way to give people more information while keeping your layout clean. Link your text to anything, including an external website or a different page. You can set your text box to expand and collapse when people click, so they can read more or less info.

$560

Product Title

16 px collapsible text is perfect for longer content like paragraphs and descriptions. It’s a great way to give people more information while keeping your layout clean. Link your text to anything, including an external website or a different page. You can set your text box to expand and collapse when people click, so they can read more or less info.

$280

Recommended Products For This Post
 
 
 

Comments


Get Your Dream Cybersecurity Job

Cyber NOW R2 black transparent_edited_ed

Courses  :  Certifications  :  Job Boards  :  Knowledge Base  :  Webinars  : Sequre Style Store

Jump Start Your SOC Analyst Career

Get the new book, Jump-start Your SOC Analyst Career, authored by Tyler Wall.  

 

Winner of the Cybersecurity Excellence Awards and runner-up of the Best Book Awards.

Contact us

bottom of page