Mon · 29 Jun 2026·Issue 030
Decoded.
·Subscribe →
Professional Impacts·Knowledge Workers·v 1.0·Last updatedJun 22 · 2026

Cybersecurity Analyst.

Cybersecurity analyst demand keeps growing, but AI agents are absorbing the tier-1 triage work that used to train new analysts.

Snapshot · 2026
Risk level
LOW
Transformation
HIGH
Median wage
$124,910
information security analyst (BLS May 2024)
Job growth
+29%
2024 to 2034 (BLS)
Annual openings
16,000+
projected through 2034
Tier-1 triage
73%
automation success rate (Gurucul, 2025)
Position · 02

Low risk, high transformation.

The federal government projects 29% employment growth for information security analysts through 2034, far faster than almost any other occupation, with roughly 16,000 openings a year. That demand is not slowing down. What is shifting is the shape of the work: AI agents now handle the bulk of tier-1 alert triage, the repetitive task that used to be where junior analysts learned the job. The role is not disappearing. The path into it, and the daily mix of tasks once inside it, are both changing fast.

CategoryKnowledge Workers
Median wage$124,910 (BLS May 2024)
Outlook (BLS)+29% through 2034
Tier-1 automation73% success rate
Emerging impactHeavily transformedStableWidely adopted
LOW · ADOPTION RATEHIGH
LOW · IMPACTHIGH
Software Engineer
Graphic Designer
Marketing Manager
Financial Analyst
Lawyer
Academic Researcher
Brand Manager
Sales Rep
Recruitment Coord.
Journalist
Equity Research
Compliance Officer
Truck Driver
HR Recruiter
Nurse
K-12 Teacher
Grid Engineer
Policy Advisor
Operations Manager
Cybersecurity Analyst
Defense Analyst
What is changing · 03

3 shifts already visible in the data, in order of magnitude.

01
73%

Tier-1 alert triage is now the most successfully automated task in the SOC.

Gurucul's 2025 Pulse of the AI SOC survey found 73% of organizations report successful automation of alert triage and prioritization, the highest figure among the SOC workflows it measured. This is also the work that historically trained new analysts, which is narrowing the entry point into the field even as overall demand for the role keeps growing.

02
200 hrs/mo

AI agents are closing out routine alerts without a human in the loop.

At St. Luke''s University Health Network, Microsoft Security Copilot''s triage agent now handles phishing alert investigation around the clock, saving nearly 200 hours of analyst time per month and cutting incident report creation from hours to minutes.

03
New asset class

Analysts are being asked to secure AI agents, not just networks.

Google DeepMind''s AI Control Roadmap treats capable AI agents like potential insider threats that need least-privilege access, monitoring, and escalation paths of their own. That work is landing on security teams as a new category of system to defend.

Company adoptions · 04

What the leaders are doing.

2 entries · sources cited
CompanySectorWhat they are doingYearSource
01St. Luke's University Health NetworkHealthcareDeployed Microsoft Security Copilot's alert triage agent to autonomously handle phishing alerts, saving the security team nearly 200 hours per month and cutting incident report creation from hours to minutes.2026microsoft.com
02BlackbaudSoftwareSecurity operations team used CrowdStrike's Charlotte AI over 30,000 times in 30 days for detection triage and investigation, reporting a 3x improvement in mean time to resolve and freeing analysts to focus on higher-priority threats.2026crowdstrike.com
Skills matrix · 05

What is declining, growing, emerging.

Declining
  • 01Manual log correlation and first-pass alert triage on high-volume, low-signal events
  • 02Writing detection queries from scratch for routine, well-understood threat patterns
  • 03Closing out confirmed false positives by hand
Growing
  • 01Reviewing and validating an AI agent's triage decisions and investigative reasoning
  • 02Threat hunting and proactive investigation work freed up by automated triage
  • 03Identity and access management extended to machine accounts and AI agent permissions
  • 04Incident response coordination across cloud, identity, and endpoint telemetry
Emerging
  • 01Securing AI agents and models as a distinct asset class, including monitoring agent behavior for anomalies
  • 02Auditing AI-driven security decisions for accuracy, bias, and escalation failures
  • 03Zero-trust architecture design that accounts for non-human, agentic identities
Tools worth knowing · 06

Set up your stack.

Recommended reading · 07

Three sources.