Cover art for the blog titled "We Read 1,000 SOC Job Postings. Security Teams Are Hiring Three Builders for Every Analyst." by D3 Security

We Read 1,000 SOC Job Postings. Security Teams Are Hiring Three Builders for Every Analyst.

The last SOC requisition your team wrote says more about the future of security operations than analyst forecasts. It has a title, a salary range, and a duties list that a budget owner signed. Multiply that by 665 and you have a record of what US security teams decided to pay for this year. We built that record.

Last month, we collected more than 1,600 security operations postings, read more than 1,000 of them in full, and coded 665 in-scope US roles against a fixed rubric: role family, tier, employer type, compensation, a 0 to 3 AI-requirement scale with quoted evidence, detection engineering signals, entry-level status, and platforms named. The result is The SOC Rebuild Index: 2026 Edition, with the headline data on an interactive page. Five findings stood out in our analysis:

1. The biggest job in the SOC is building the SOC

Security operations engineer is the largest role family in the dataset: 134 postings, one in five. The classic SOC analyst seat, the person watching the queue, ranks fourth at 10%.

Add up every family that builds (SecOps engineering, detection engineering, automation engineering, AI security engineering, and architecture) and you get 247 postings, 37% of the dataset. Set those against 68 SOC analyst postings and the ratio is roughly three to one. For every seat that monitors the queue, security teams are hiring about three people to shrink it. Leadership accounts for another 14%, which is the seat that runs the transition.

2. Pay rises with each step from watching to building

Median advertised compensation runs $125k for the SOC analyst, $142k for the SecOps engineer, $148k to $151k for hunters and responders, $152k for the automation engineer, $161k for the detection engineer, $175k for the architect, and $180k for leadership. The market pays a premium of roughly $17k to $36k to move from monitoring the queue to building what replaces it.

The analyst family is also the least AI-touched. Hands-on AI requirements appear in 9% of triage-centered analyst postings, against 42% in automation engineering and 31% in detection engineering. Where the traditional analyst job survives, it is the smallest, lowest-paid, and least automated family in the set.

3. One posting in four asks for hands-on AI. Two in three never mention it.

22.7% of postings carry an active AI or automation requirement. 67% contain no AI language at all, at the peak of the 2026 AI SOC news cycle. There is almost nothing in between: about a tenth of the market is rebuilding around AI and two thirds are posting 2022-style jobs.

The rebuilding tenth is already mainstream. 76 postings, 11.4% of the dataset, describe building, operating, or validating AI-driven security operations. A global pharmaceutical company is hiring incident response leadership to “operationalize agentic SIEM features, XDR and SOAR playbooks, LLM-assisted runbooks, and automated triage.” An industrial manufacturer wants IR engineers to “design, build, and enable agentic AI and automation workflows.” At a consumer fitness brand, security engineers “identify repetitive, high-volume SOC workflows and systematically eliminate them through AI-powered triage pipelines.” Wealth management, dental insurance, e-commerce, and enterprise software appear in the same list. The agentic SOC job description has left Silicon Valley.

4. AI SOC platforms just entered the hiring record

Seven of 665 postings name an AI SOC or AI-automation platform as a requirement. That is about 1%. One platform accounts for three of them, including a role whose title carries the product name. Four other platforms appear once each.

Seven is a small number. It is also the first time this category appears as a requirement line, the way a named SIEM does today. The highest-paid AI SOC roles sit at integrators and consultancies in the $160k to $200k range, which tells you where enterprises are getting the skill for now: they rent it before they hire it.

The same postings confirm the stack those platforms have to work across. The median posting names eight tools. 77% name five or more. 18% require fluency across two or more core SIEM or EDR platforms. Vendors pitch consolidation. The hiring record shows teams paying for people who can operate a mixed stack.

5. Entry-level roles are 6% of the market

Entry-level roles are 39 postings, 5.9% of the dataset. Where enterprises still hire at entry level, the seat is moving to the engineering track. At one hyperscaler the entry role is “Security Engineer I, Threat Hunting.” At an investment bank and a fintech, the entry seats are Security Engineer IIs. The zero-experience triage seat survives mainly at MSSPs, MDR providers, staffing contracts, and state government, often on night shifts, at $60k to $83k.

One more finding from the vendor side. A company selling the agentic SOC employs human Security Analysts across three tiers whose written duty is to “analyze and validate investigations completed by the AI Agents for accuracy and completeness.” A vendor built on autonomous investigation staffs a tiered human organization to check it. The people doing that validation are becoming more senior, better paid, and harder to replace.

What to do with this

For leaders, the postings describe a sequence that several Fortune 500 companies are already running. Keep the analyst tier and redefine it around validating automated output. Stand up build roles where engineering and automation own the pipeline. Fund the leadership seat that runs the transition. Teams that cut the junior seat instead will have nobody ready for senior seats in three years, and 39% of organizations already report that non-entry roles take three to six months to fill.

For practitioners, every pay gradient and every AI-ask rate in the dataset points the same direction: own the automation. Detections-as-code shows up in 46% of plain SOC analyst postings, so learn to write detections alongside triaging their output. Hunting is a duty in 38% of jobs and a title in 8%, so build the skill wherever you sit. And validation work is everywhere, at vendors and enterprises alike. If your current role is manual triage at flat pay, these postings show you the next one.

Seven questions to ask any AI SOC platform

The report closes with seven questions drawn from the data. They apply to any agentic SOC platform, including Morpheus, and to your own staffing plan.

  • Does it address the work that is growing or the work that is shrinking?
  • Does it return hours to your senior people, whom the postings show doing four jobs at once?
  • Can it absorb the duties, like hunting and detection validation, that land on whoever is nearest?
  • Does the math convert queue budget into build budget?
  • Does it work across the eight tools a median posting names?
  • Is triage joined to governed response in one loop, with human approval gates and an audit trail?
  • And can your whole team operate it in plain language, or only the people who speak SPL?

Question six is the one we built Morpheus around. Attack Path Discovery investigates each alert across your stack and through 90 days of telemetry. Morpheus generates the response plan from that investigation, and the plan runs only after an analyst approves it, inside four autonomy modes you set per alert type. Morpheus triages up to 95% of alerts in under two minutes at L2+ depth. When Morpheus is uncertain, it defers to a human.

Read the postings, not the predictions

Preview image of the report by D3 security titled The SOC Rebuild Index, tracking SOC transformation through job listings on public boards

Read the full SOC Rebuild Index in the Morpheus Research Library: every coded figure, the methodology and its limits, the Canadian sample, and the agentic-era job descriptions quoted in full.

Or start with the interactive data page, where the charts behind each finding scroll with you and the free PDF is behind a short form. Every figure is verified and sized for a board deck.

Learn More About Morpheus

Powering the World’s Best SecOps Teams

Ready to see Morpheus?