SOC Rebuild Index
The SOC is being rebuilt around the people who automate it. In August 2026 we read more than 1,000 job postings in full. This report covers what US security jobs pay, how employers design them, and which AI skills they require.
Executive summary
Everyone has an opinion about what AI is doing to SOC jobs. We wanted evidence, so we went to one of the few places where security leaders state their intentions in writing and attach budget to them: job postings. In August 2026 we collected more than 1,600 security operations, incident response, threat intelligence, and threat hunting listings, read over 1,000 of them in full, and coded the 665 in-scope US roles for role design, compensation, and exactly what each employer asks of a human in the age of AI.
The security operations job market is inverting. Engineering-family roles outnumber SOC analyst roles roughly three to one in the dataset. Median advertised pay climbs in a nearly straight line as work moves from watching a queue ($125k) to building automation that replaces the queue ($142k–$161k) to leading the rebuild ($180k). One in four postings carries a hands-on AI or automation requirement. One in nine describes work we'd call agentic-era: building, operating, or validating AI-driven security operations. The employers writing those postings include AstraZeneca, Eaton, Raymond James, and Peloton, well beyond Silicon Valley. For the first time, AI SOC platforms have begun appearing by name in hiring requirements: seven postings, about one percent, a number small enough to date the exact moment a category entered the labor market. The 2026 SANS SOC Survey calls the AI-skilled analyst “an anticipated role, though the transition is not yet reflected in current hiring data.” This report reads the hiring data in full; the transition is occurring now.
Meanwhile, two-thirds of postings contain no AI language of any kind, entry-level roles account for just six percent of the postings we analyzed, and the traditional analyst job, where it survives, is the least AI-touched and lowest-paid role family in security operations. The restructuring is real, it is early, and it is uneven in ways that should change how practitioners plan careers and how leaders plan headcount.
The one-pager: who security operations is hiring in 2026
Full-read dataset, n=665 in-scope US postings, deduplicated. AI ask = share of the family's postings with a hands-on AI/automation requirement (level 2+ on our 0–3 scale). Median comp = midpoint of posted ranges where disclosed.
| Role family | Median advertised pay | What the job is |
|---|---|---|
| SOC analyst | $125k | Watching the queue |
| SecOps engineer | $142k | Running and improving the pipeline |
| Threat hunter / incident responder | $148k–$151k | Proactive and reactive investigation |
| Automation engineer | $152k | Building what replaces the queue |
| Detection engineer | $161k | Writing and tuning detection logic |
| Architect | $175k | Designing the rebuilt function |
| Leadership | $180k | Owning the transition |
The new roles
“Agentic AI Security Engineer” (LTS). “Senior Agentic Security Automation Engineer” (NowSecure). And at 7AI, tiered human Security Analysts whose written job is validating AI agent investigations.
Platforms named in requirements
Splunk, Sentinel, CrowdStrike, QRadar, XSOAR, Chronicle dominate. AI SOC platforms appear in 7 of 665 postings, including Torq, Prophet, Dropzone, D3 and Microsoft Security Copilot.
One posting in four asks for hands-on AI. One in nine is already agentic-era.
Across 665 fully-read postings, 22.7% carry an active AI or automation requirement. That means SOAR development in core duties, automation scripting in requirements, or explicit AI-tooling expectations. The requirements span the full operations lifecycle: the AI ask is strongest in automation engineering (42%), detection engineering (31%), and incident response (17%), while triage-centered analyst roles carry the lowest AI ask of any family (9%). The figure has an interesting precedent: an independent analysis of 607 marketing job postings across the a16z portfolio earlier this year found the same rough quarter of roles requiring hands-on AI.1 Different profession, same adoption curve.
Higher up the scale, 76 postings (11.4% of the dataset) describe agentic-era work, and they span the mainstream economy. AstraZeneca's incident response leadership is hired to “operationalize agentic SIEM features, XDR and SOAR playbooks, LLM-assisted runbooks, and automated triage.” Eaton hires IR engineers to “design, build, and enable agentic AI and automation workflows.” Peloton's security engineers “identify repetitive, high-volume SOC workflows and systematically eliminate them through AI-powered triage pipelines.” Raymond James applies “AI engineering principles within security operations.” Delta Dental leads “responsible adoption of AI to improve detection, response, and analyst workflows.” Shutterfly's senior SOC analysts validate AI-assisted triage outputs; Zoom's contribute to an “agentic, LLM-powered auto-triage framework” with a published path into automation engineering. Pharma, industrial manufacturing, wealth management, dental insurance, e-commerce. The agentic SOC job description has left Silicon Valley.
At the other end, 67% of postings contain no AI language of any kind. This is 2026, at the peak of the AI SOC news cycle. The market is barbelled between a tenth that is rebuilding operations around AI and two-thirds still posting the 2022 job, with remarkably little middle. The buyer side shows the same shape: IBM's 2026 Cost of a Data Breach study finds 36% of organizations using security AI and automation extensively while 64% report limited or no use, a near-mirror of the two-thirds of postings with no AI language. Whichever side of that barbell your organization occupies, the other side exists, and it is hiring for a different SOC than yours.
1. The Boring Marketer (@boringmarketer), analysis of 607 marketing job postings on the a16z Consider job board, X, 2026: https://x.com/boringmarketer/status/2072318229268070418, the nugget that inspired this study.
It’s a builder’s market, and the pay gradient proves it
Pool every family and the engineering side of security operations (SecOps, detection, automation, AI security, architecture) outnumbers the SOC analyst family roughly three to one. Leadership is another 14%. Organizations are hiring people to redesign the function at nearly the rate they hire people to staff it.
Compensation tells the same story with fewer words. Median advertised pay runs $125k for SOC analysts, $142k for SecOps engineers, $148k–$151k for hunters and responders, $152k for automation engineers, $161k for detection engineers, $175k for architects, $180k for leadership. The market pays a premium of roughly $17k–$36k to move from watching the queue to building what replaces it, and the AI-specialized build roles at services firms are posted at $160k–$200k. Money is flowing up the build stack.
The AI-title evidence shows which door AI is entering through. The dataset contains 25 postings in a role family that did not exist as a title 18 months ago (AI security engineer), plus AI-titled architects, consultants, and directors. AI-titled analyst postings at end-user enterprises: zero. And the employers have gone mainstream. Perdue Farms posted two separate AI security engineering leadership roles. Huntington Bank posted a Principal AI Cybersecurity Engineer. EMCOR, a Fortune 500 construction services firm, posted an AI Security Engineer. Milbank, a law firm, posted an AI Security Specialist. Surveyed employers expect more of these: 63% anticipate a greater need for AI oversight and governance roles within three years, and 49% expect to create new AI-driven roles outright (Fortinet 2026). When the poultry company, the regional bank, and the white-shoe law firm are all hiring AI security builders, that is what mainstream adoption looks like.
The platforms just entered the labor market, and you can watch it happen
Seven of 665 postings name an AI SOC or AI-automation platform in their requirements. That one percent may be the most interesting number in this report, because of what sits inside it. Torq appears, including in a senior incident response role and in a federal integrator posting titled, verbatim, “Sr. TORQ/SOAR Engineer.” The vendor has reached the job title. An ad-tech enterprise names Prophet and Dropzone in a detection and response engineering role, the first customer-side posting we found requiring experience with named AI SOC platforms. D3 and Microsoft Security Copilot appear once, at service provider organizations.
Seven postings out of 665. Torq ×3, Prophet ×1, Dropzone ×1, D3 ×1, Microsoft Security Copilot ×1. About one percent of the dataset, and small enough to date the exact moment a category entered the labor market.
Set that against the 67% of postings with no AI language and you get the defining gap of this market: adoption of AI SOC tooling is running well ahead of the hiring system's ability to describe it. Organizations are buying the capability, mostly through the services layer first. The highest-paid AI SOC jobs in the dataset sit at integrators and consultancies: forward-deployed engineering, AI-native security architecture, and agentic-titled consulting roles, posted in the $160k–$200k range. The pattern reads as classic early market: enterprises accessing a capability through services before buying it for themselves. For practitioners, the arbitrage is plain: the skills to operationalize AI in a SOC currently command a services-firm premium precisely because so few in-house teams have them. For leaders, the seven postings are a preview. If the pattern continues, platform-specific AI SOC experience could become a requirement line much the way “Splunk” is today, and the teams writing those requirements first will have their pick of a thin market.
Threat hunting lives inside other jobs, detections-as-code is table stakes, and the median job requires eight tools
Two skills findings the salary guides miss. First: threat hunting appears as a listed duty in 38% of all postings, while hunter-titled roles are 8% of the dataset. The market wants hunting done everywhere and hires for it almost nowhere. It's an expectation folded into responder, engineer, and analyst jobs, with the dedicated title concentrated at federal contractors, defense-adjacent shops, and security vendors. If you're waiting for a “Threat Hunter” req at a mainstream enterprise, the market's advice is to build the skill without waiting for the title.
Second: detections-as-code has crossed from elite to expected. It appears in 31% of all postings: 90% of detection engineering roles, naturally, but also 46% of plain SOC analyst postings. Nearly half of analyst jobs now involve writing or tuning detection logic on top of triaging its output. The queue job and the build job are merging from the bottom up, which is precisely what an industry automating its Tier 1 would look like in hiring data.
Third, and underneath both: the modern security operations job is a multi-vendor job. The median posting names eight tools. 77% name five or more, 55% name eight or more, and 18% explicitly require fluency across two or more core SIEM/EDR platforms: the Splunk-and-Sentinel job, the QRadar-and-CrowdStrike job. Whatever consolidation vendors promise, the hiring record shows security teams operating sprawling, heterogeneous stacks and paying for humans who can move across them.
The entry door, measured
Entry-level roles are 5.9% of the dataset, or 39 postings. Enterprises do still open the door: SouthState Bank posts a Cybersecurity Analyst I, RTX a cyber defense analyst in Puerto Rico, Hawaiian Electric an information assurance analyst, Barton Malow a Cybersecurity Analyst 1. But the shape of the door has changed in two ways. The enterprise entry job is migrating from the analyst queue to the engineer track: Amazon's entry security role is “Security Engineer I, Threat Hunting”; Stifel's and Circle's are Security Engineer IIs. And the classic zero-experience triage seat survives mainly at MSSPs, MDR providers, staffing contracts, and state-government work, frequently on nights: $60k–$83k with 12-hour overnight shifts at one MSSP, roughly $32/hour at the national junior average. Employer surveys state the same skew as preference: 51% of organizations say they most need senior-level skills, against 13% for entry-level (Fortinet 2026). One Fortune 500 company's “Cybersecurity Operations Service Owner” posting turned out, on full read, to be a 12-week fellowship for transitioning service members, a good on-ramp that could lead to eventual employment.
The wider context says security is living through the same early-career squeeze as the rest of knowledge work. Stanford's research measures a 13% relative decline in employment for workers aged 22 to 25 in the most AI-exposed occupations,2 and ISC2's 2024 workforce study found 31% of organizations have no entry-level security staff at all. The Stanford data also locates the mechanism: declines concentrate in occupations where AI automates work, not where it augments it, and the dataset's AI-ask distribution (highest in the build roles, lowest in triage) sits on the augmentation side of that line. In security, the shape is specific: the way in now runs through the services sector and the engineer track. And in the darkest artifact we collected, gig platforms are running ads recruiting experienced SOC analysts to help train AI chatbots as flexible side work. Seasoned analysts are training their successors: machines, not juniors.
2. Brynjolfsson, Chandar, and Chen, “Canaries in the Coal Mine? Six Facts about the Recent Employment Effects of Artificial Intelligence,” Stanford Digital Economy Lab, 2025. The 13% figure controls for firm-level shocks; the lab’s August 2026 update widens the gap to about 19%.
The market is still learning to describe these jobs, including the AI SOC vendors
The analysis that inspired this project concluded that companies were posting AI roles they couldn't define. Security is no different, and the evidence ranges from funny to profound. We collected a posting that calls itself a career-starting opportunity, lists entry certs, then demands seven years of experience. Thirty percent of raw “SOC analyst” search results weren't SOC jobs at all, mostly SOC 2 compliance, and the incident response title family is even noisier: the full-read pass surfaced SREs, breach attorneys, pharmacy complaint desks, and a municipal firefighter, all posted under “incident response.”
The profound version is at 7AI, an agentic security platform company whose mission is putting AI agents in the hands of defenders to offload non-human work. 7AI employs human Security Analysts at three tiers whose written duty is to “analyze and validate investigations completed by the AI Agents for accuracy and completeness, evaluating risk,” with senior analysts serving as escalation for juniors triaging the agents' output. Once more: a company selling the autonomous SOC runs a tiered human analyst organization to validate its agents. Across the AI SOC vendor hiring we examined and the agentic-era enterprise postings we read, the labor market's revealed position is that AI investigation output requires structured human oversight, and that the humans doing it are becoming more senior, better paid, and harder to replace. The operational data agrees: SANS finds 79% of SOCs using AI or ML tools while only 36% have integrated them into a defined workflow (SANS 2026), and Gartner expects 70% of large SOCs to pilot AI agents for Tier 1 and Tier 2 operations by 2028, while only 15% achieve measurable improvement without structured evaluation (Gartner, Validate the Promises of AI SOC Agents With These Key Questions, 2026). The gap between “we have AI” and “it's in the workflow” is where every new job in this report is being created.
The revealed position of the labor market. A company selling the autonomous SOC runs a tiered human analyst organization to validate its agents. Across every agentic-era posting we read, AI investigation output requires structured human oversight, and the humans doing it are becoming more senior, better paid, and harder to replace.
What this means
For leaders
For leaders, the posting data describes a sequence. The organizations whose job descriptions already read like 2028 (the AstraZenecas and Eatons) kept the analyst tier and redefined it around validating and improving automated output, stood up engineering and automation roles to own the pipeline, and in several Fortune 500 cases created SOC engineering leadership to run the transition. The bench math is unforgiving for teams that skip the redefinition step: with 55% of teams understaffed and 39% of organizations reporting that non-entry-level (mid- and senior-level) roles take 3–6 months to fill (ISACA 2025), cutting junior hires today means having no one ready to fill those senior seats in a few years, and no easy way to buy your way out, because everyone else will be short the same people. The teams that keep a funded, redesigned junior seat (detection validation, automation upkeep, AI-output QA) are building the pipeline their competitors are abandoning to the MSSPs. The seven platform-named postings are a two-year warning: the requirement lines are coming, and the talent that satisfies them is currently renting itself out through integrators at a 30% premium.
Keep the analyst tier
redefined around validating automated output
Stand up the build roles
engineering and automation own the pipeline
Fund the leadership seat
SOC engineering leadership runs the transition
For practitioners
For practitioners, the market's message is legible and, read correctly, encouraging: the jobs being posted are bigger than the jobs being eliminated. ISC2's 2025 workforce study hears the same thing from the profession itself, with 72% expecting AI to create the need for more strategic roles and skills. Every dollar gradient and every AI-ask rate in this report points the same direction: own the automation. Detections-as-code is already in half of analyst postings; learn to write detections as well as triage them. Hunting is a duty in 38% of jobs; build the skill wherever you sit. The hiring criteria are moving the same way: ISACA finds adaptability, offered as a survey option for the first time in 2025, displaced prior work experience as the top factor in judging a candidate's qualifications. The highest ground is validation: every agentic posting we read, from 7AI to AstraZeneca, needs humans who can check an AI's work and make it better. If your current role is manual triage at flat pay, the postings in this report are the market telling you, in writing, where it wants you next.
Whether you’re hiring analysts or evaluating agents, this is what the data says to ask
Many of the teams reading this are weighing the same decision the postings describe from the other side: whether to staff the gap or deploy agents into it. The findings above translate into seven questions. Ask them of a platform, or of your own plan.
Does it address the work that's growing, or the work that's shrinking?
The AI ask concentrates in detection, response, automation, and hunting; triage-centered analyst roles are the smallest, least AI-touched, lowest-paid family in the dataset. An agent that only closes Tier 1 alerts is automating the slice of work the market is already deprecating. Ask what it does for the other 90% of the lifecycle. Early deployment data agrees on where the value sits: among SOCs that have deployed AI agents, use concentrates in threat hunting and in automated response and containment, at 56% and 54% (IBM 2026).
Does it un-crush your senior people?
Agentic SOC targets the seniors doing four jobs, not the Tier 1 seat you already barely hire for. The postings show hunting, detection engineering, and response collapsing into single seats. The evaluation metric that matters is senior hours returned (investigation, hunting, quality and accuracy improvement), measured before and after, on your own workload.
Can it absorb the duties that used to be jobs?
Threat hunting is a listed duty in 38% of postings and a staffed title in 8%. Enrichment, detection validation, and hunt cadences are being assigned to whoever is nearest. Ask whether agents can own that duty-ized work continuously, under your direction, so it stops landing on someone who already carries four or five other responsibilities.
Does the math convert queue budget into build budget?
The pay gradient runs $125k for the analyst seat to $161k–$180k for the detection engineers and leaders every team is struggling to fund, and teams currently bridge the gap by renting AI SOC skills from integrators at $160k–$200k. Run the arithmetic: what does the platform free up, and does deploying it require hiring the $200k engineer anyway?
Does it work across the stack you actually run?
The median posting names eight tools; one in five requires fluency in two or more SIEM/EDR platforms. Your environment is heterogeneous and will stay that way. An agent designed around a single-vendor environment leaves more of the integration burden outside the agent. Platform-native agents are built around their own ecosystems; the hiring data suggests the average SOC operates across a much broader one.
Is triage joined to governed response, one loop with human gates?
The agentic-era postings hire one human to govern the whole cycle: AstraZeneca's role spans “agentic SIEM features, XDR and SOAR playbooks, LLM-assisted runbooks, and automated triage” in a single mandate. And the AI SOC vendor hiring we examined, 7AI's three tiers of human validators above all, treats oversight as structural. Ask where the human approval gates sit, what the audit trail shows, and whether triage and response orchestration are one governed system or two products that someone, sometimes you, must tape together.
Can your whole team drive it, or only the ones who speak SPL?
Detection and query-language requirements gate nearly half of analyst postings, while hunting is demanded of almost everyone. If operating the agent requires the specialist languages your team is short on, you've bought another skills bottleneck. Natural-language operation is the difference between a tool for the two people who know KQL and a capability for the whole roster.
One more, from the operational data. SANS finds 38% of SOC AI tools running exactly as the vendor shipped them, and only 36% of SOCs have folded AI into a defined workflow (SANS 2026). Whatever you evaluate, ask for evidence of time-to-operationalization: the market is full of deployed tools nobody made work.
The Canadian sample
A smaller, fully-coded Canadian sample (n=32, supplemented by several hundred listing-card observations) suggests the same restructuring on a lag, with one distinctive twist: leadership density. Nine of the 32 Canadian postings are leadership roles, a higher share than the US dataset, spanning employers from Brookfield and Agropur to Alberta Blue Cross and the Canadian Nuclear Safety Commission, a sign Canadian organizations are hiring people to plan the AI-era SOC ahead of staffing it. Active AI asks appear in roughly one posting in six (5 of 32), just below the US rate. The practitioner market skews public-sector and financial, with Rockstar's Oakville studio hiring threat intelligence as a notable outlier. The sample is small and we present it as directional; a dedicated Canadian cut is a natural follow-up study. (Full fidelity note in methodology.)
Methodology and limitations
In August 2026 we collected more than 1,600 job postings across the SOC analyst, security operations, SOC engineering/architecture, incident response, threat intelligence, and threat hunting title families, primarily via leading aggregator sites that index employer ATS systems directly, supplemented by verification searches on public job boards. More than 1,000 postings were read in full and coded against a fixed rubric: role family, tier, employer type, compensation, a 0–3 AI-requirement scale with quoted evidence, detection engineering signals, entry-level status, and platforms named, via an AI-assisted pipeline with human review of every exclusion decision and all boundary cases. After removing duplicates, reposts, and out-of-scope roles, 665 unique US security-operations postings form the analysis set. Out of scope covers non-US listings, SOC 2 compliance and GRC roles, physical-security operations centers, IT/SRE “incident response,” legal breach-response, trust-and-safety “threat” roles, and intelligence-community all-source analysis (a real but separate, clearance-driven labor market).
Honest limits. This is a point-in-time convenience sample of publicly posted openings, and posting share differs from headcount share: one listing can represent ten hires or none. Employers who hire through staffing intermediaries are underrepresented, and pay medians reflect only the subset of postings that disclose ranges. Annual survey sources are cited for context (ISC2, SANS, ISACA, Fortinet, IBM, Gartner, Stanford). Nothing here supports a causal claim that AI SOC products produced these patterns; what the data shows is the shape of demand at a moment in time.

