Mon · 27 Jul 2026·Issue 034
Decoded.
·Subscribe →
Professional Impacts·Knowledge Workers·v 1.0·Last updatedJul 27 · 2026

Penetration Tester.

AI agents can now find real vulnerabilities at scale, compressing routine testing work while pushing human testers toward scoping, exploit chaining, and business judgment.

Snapshot · 2026
Risk level
MED
Transformation
HIGH
Median wage
$124,910
information security analyst (BLS May 2024)
Job growth
+29%
2024 to 2034 (BLS)
Annual openings
16,000+
projected through 2034
HackerOne US
AI #1
first non-human to top the leaderboard (2025)
Position · 02

Medium risk, high transformation.

Adoption of AI testing tools is high and rising fast, and the role sits in the heavily transformed part of the map. Penetration testing is not disappearing: demand for security testing keeps growing, and the federal government projects 29% employment growth through 2034 for information security analysts, the broader occupation that includes penetration testers. What is shifting is the daily work. The routine discovery tasks at the core of the job are being automated fastest, so the human value is moving up toward scoping, exploit chaining, judgment about business impact, and accountability for results.

CategoryKnowledge Workers
Median wage$124,910 (BLS May 2024)
Outlook (BLS)+29% through 2034
AI on HackerOne#1 US, 2025
Emerging impactHeavily transformedStableWidely adopted
LOW · ADOPTION RATEHIGH
LOW · IMPACTHIGH
Software Engineer
Graphic Designer
Marketing Manager
Financial Analyst
Lawyer
Academic Researcher
Brand Manager
Sales Rep
Recruitment Coord.
Journalist
Equity Research
Compliance Officer
Truck Driver
HR Recruiter
Nurse
K-12 Teacher
Grid Engineer
Policy Advisor
Operations Manager
Cybersecurity Analyst
Defense Analyst
QC Inspector
Bookkeeper
Penetration Tester
What is changing · 03

3 shifts already visible in the data, in order of magnitude.

01
#1

An AI system reached the top of HackerOne's US bug-bounty leaderboard.

In June 2025, XBOW became the first non-human to top HackerOne''s US leaderboard, submitting nearly 1,060 vulnerability reports in a few months. On an internal benchmark of 104 challenges it matched a veteran pentester''s 40-hour result in 28 minutes, a direct signal that the routine, high-volume end of testing can now be automated.

02
CVE-2025-6965

AI agents are finding real zero-days in production code.

Google''s Big Sleep agent, built by DeepMind and Project Zero, identified a critical SQLite zero-day that was known only to threat actors, before it could be exploited, and has reported roughly twenty previously unknown flaws in widely used open-source software.

03
Open-sourced

DARPA's AI Cyber Challenge produced systems that find and patch bugs on their own.

The two-year competition concluded at DEF CON 2025 with AI systems that autonomously detect, exploit, and patch vulnerabilities in open-source software that underpins critical infrastructure. Team Atlanta''s ATLANTIS won the $4M grand prize, and all seven finalist teams are open-sourcing their systems.

Company adoptions · 04

What the leaders are doing.

3 entries · sources cited
CompanySectorWhat they are doingYearSource
01XBOWSecurityIts autonomous AI penetration tester became the first non-human to top HackerOne's US bug-bounty leaderboard, submitting nearly 1,060 vulnerability reports in a few months and matching a veteran pentester's 40-hour benchmark in 28 minutes.2025darkreading.com
02GoogleTechnologyIts Big Sleep agent, built by DeepMind and Project Zero, found CVE-2025-6965, a critical SQLite zero-day known only to threat actors, before it could be exploited, and has reported roughly twenty previously unknown flaws in open-source software.2025therecord.media
03DARPAGovernmentRan the two-year AI Cyber Challenge, concluded at DEF CON 2025, where AI systems autonomously found and patched vulnerabilities in open-source software behind critical infrastructure. Team Atlanta's ATLANTIS won the $4M grand prize; all seven finalist teams are open-sourcing their tools.2025cybersecuritydive.com
Skills matrix · 05

What is declining, growing, emerging.

Declining
  • 01Routine web-application and external network scanning on well-understood vulnerability classes
  • 02First-pass reconnaissance and enumeration done by hand
  • 03High-volume, low-complexity bug bounty submissions on common flaw types
Growing
  • 01Scoping engagements and defining rules of engagement for a specific business and threat model
  • 02Chaining multiple low-severity findings into a demonstrable, high-impact attack path
  • 03Judging real-world exploitability and business impact given a client's environment and controls
  • 04Reviewing and validating findings produced by autonomous testing tools, and filtering false positives
Emerging
  • 01Testing AI systems themselves: prompt injection, agent permission abuse, and model supply-chain weaknesses
  • 02Operating and directing autonomous pentest agents as a force multiplier across a wider attack surface
  • 03Adversarial red teaming of AI-powered defenses and detection systems
Tools worth knowing · 06

Set up your stack.

Recommended reading · 07

Three sources.