Information security analysts: AI and the work ahead
Tools can summarize alerts and assist investigation, but security decisions depend on the environment, the evidence and the consequences of action. Automated recommendations can create risk when context is missing.
Monitoring, incident response and governance use different skills. The occupation's growth projection is a national employment estimate and does not guarantee an entry-level vacancy or a particular specialization.
Compare the duties below with a normal week in your own role. Time
spent, responsibility, employer tools and access to reliable data can
change the picture substantially. Use the personal task audit to
identify those differences.
Task-by-task exposure
We selected 8 of 11 O*NET core
tasks by importance. Importance is an O*NET rating on a 1–5 scale; it
is not the percentage of time spent. The category and explanation are
our interpretation, not an O*NET assessment of AI.
0 routine automation 5 ai-assisted 3 human-led
Reading uncertainty: changing one task by one
category step would put this index at approximately 25–38/100. This is a
sensitivity example, not a statistical confidence interval. Small
score differences are not a sound reason to change careers.
Selected core tasks and our interpretation
Task and source detail
Assessment and reason
Develop plans to safeguard computer files against accidental or unauthorized modification, destruction, or disclosure and to meet emergency data processing needs.
O*NET task 5314 · Importance 4.40/5
Task source: 08/2018 · Rating: 08/2018
Human-led
A safeguard plan depends on assets, threats and business tolerance. Generated proposals need an accountable owner who knows the environment and recovery requirements.
Monitor current reports of computer viruses to determine when to update virus protection systems.
O*NET task 5316 · Importance 4.23/5
Task source: 08/2018 · Rating: 08/2018
AI-assisted
Advisory summaries can prioritize investigation. Asset relevance and the risk of a particular update must be verified in the organization's environment.
Encrypt data transmissions and erect firewalls to conceal confidential information as it is being transmitted and to keep out tainted digital transfers.
O*NET task 5321 · Importance 4.18/5
Task source: 08/2018 · Rating: 08/2018
AI-assisted
Configuration assistance can reduce preparation work. Key handling, access paths and the impact of a firewall change require authorized implementation and validation.
Perform risk assessments and execute tests of data processing system to ensure functioning of data processing activities and security measures.
O*NET task 5320 · Importance 4.12/5
Task source: 08/2018 · Rating: 08/2018
AI-assisted
Evidence gathering and test interpretation can be assisted. Scope, authorization and whether controls actually reduce the relevant risk remain analyst responsibilities.
Modify computer security files to incorporate new software, correct errors, or change individual access status.
O*NET task 5317 · Importance 4.10/5
Task source: 08/2018 · Rating: 08/2018
AI-assisted
Suggested changes can help maintain configurations. Access decisions and production effects must be reviewed against the authorized change rather than accepted from a generated recommendation.
Review violations of computer security procedures and discuss procedures with violators to ensure violations are not repeated.
O*NET task 5323 · Importance 4.04/5
Task source: 08/2018 · Rating: 08/2018
Human-led
Investigating a violation involves context, evidence and communication with people. An alert or summary cannot establish intent or decide the appropriate response.
Confer with users to discuss issues such as computer data access needs, security violations, and programming changes.
O*NET task 5315 · Importance 3.94/5
Task source: 08/2018 · Rating: 08/2018
Human-led
Access needs and security changes require agreement on legitimate use. A tool can organize requests without deciding whose access is justified.
Policy and incident-document drafts can be assisted. They must match real controls, verified events and the procedures that staff can actually carry out.
Routine automation includes conventional configured software; it does
not imply autonomous AI or adoption by every employer. Human-led
allows supporting tools. Vendor links document a capability, not a
validated rating of this complete task. Older task dates are shown
even though the database release is August 2026.
Task wording and importance: O*NET occupation 15-1212.00,
O*NET 31.0 Database
, U.S. Department of Labor, Employment and Training Administration, CC BY 4.0.
Selected and adapted by Career Risk Score; USDOL/ETA has not approved,
endorsed or tested these changes.
What assistance looks like in practice
Hypothetical workflow to illustrate the boundary; not a reported case
study.
A tool summarizes suspicious account activity. The analyst checks the timeline, affected assets and normal behavior before deciding whether the event is benign, needs further investigation or requires escalation.
What must be checked
Verify the underlying logs and their coverage, distinguish observations from hypotheses and follow the organization's response authority. A fluent incident narrative can omit contradictory events.
Practical skills to strengthen
Practice evidence-based investigation in an authorized lab.
Learn how identity, networks and applications interact in a real system.
Write an incident handoff that separates verified facts from open questions.
Changes worth watching
Watch whether alert triage is increasingly automated while escalation work expands.
Track demand for cloud, identity and communication skills in the roles you target.
There is no supported date when this occupation becomes “safe” or
disappears. Revisit these observations as your tasks and tools change.
Tools behind these capability examples
These are relevant documented capabilities, not endorsements,
adoption statistics or hands-on product reviews. Features depend on
the product, plan and employer configuration. References checked
September 2026.
Microsoft Security CopilotAssistance with security information and workflows; incident authority and environment context remain essential.
BLS reports median annual pay of $129,180
in 2025, with 14,100 projected
openings per year on average during 2025–35. Openings include
replacement needs as well as growth; they are not a count of currently
advertised vacancies.
The projected employment change is + 21%
over ten years. Employment growth can coexist with automation of particular tasks. It does not make every worker or location equally likely to benefit.
Typical entry education
Bachelor's degree
Related work experience
Less than 5 years
Typical on-the-job training
None
Security work often builds on practical systems knowledge. A certificate or tool demonstration does not by itself establish readiness to make production response decisions.
BLS categories describe typical entry, not a complete qualification
checklist. “None” does not mean no learning is needed. National
medians are not starting salaries; location, sector, experience, hours
and benefits matter. Wage data exclude self-employed earnings. Consult
local job descriptions and relevant credential authorities before
paying for training.
These links identify transferable work and a concrete gap to explore.
They are not guaranteed pathways, “AI-proof” jobs or recommendations
based on a small score difference.
Map a system's business dependencies and identify where requirements create security constraints.
BLS typical entry: Bachelor's degree; related experience: None.
10 shared skills among each role's top
12
Reading Comprehension, Critical Thinking, Active Listening, Complex Problem Solving, Speaking, Writing, Monitoring, Judgment and Decision Making, Systems Analysis, Active Learning.
These broad O*NET skills are selected by importance, with
ties broken by skill ID. Overlap does not measure
proficiency or hiring readiness.
Implement and test a small security-related feature, adding development workflow experience.
BLS typical entry: Bachelor's degree; related experience: None.
8 shared skills among each role's top
12
Reading Comprehension, Critical Thinking, Active Listening, Complex Problem Solving, Writing, Judgment and Decision Making, Systems Analysis, Active Learning.
These broad O*NET skills are selected by importance, with
ties broken by skill ID. Overlap does not measure
proficiency or hiring readiness.
Use your own plausible pay figures to explore a move. Both pay fields start
at this occupation's national median so the calculator does not imply a
salary increase. A destination median describes existing workers, not your
likely starting offer.
A fixed-pay illustration in nominal dollars. Unpaid months occur at the
start of preparation; costs are charged at the start. Transition must fit
within the comparison period. Excludes taxes, benefits, raises, inflation,
investment returns and the chance of getting a job. A negative result is
possible. No inputs are saved or sent by this calculator.
Calculation and a worked example
Stay = current pay × years. Move = preparation pay × (preparation years −
unpaid months ÷ 12) + new pay × (years − preparation years) − one-time
cost.
For $60,000 current pay, $70,000 new pay, $50,000 preparation pay, two
years preparing, three unpaid months, $8,000 costs and a ten-year
comparison: stay = $600,000; move = $639,500. The $39,500 difference is a
scenario result, not a forecast. Break-even checks cumulative totals each
month under these same assumptions.
Check the evidence and limits
The index weights these sampled tasks equally. It does not measure
time, adoption, cost savings, unemployment or individual ability. The
examples and transition exercises are editorial inferences. Product
documentation supports the narrower capability described, not the
claim that a whole job can be replaced.