D3 Security pulled together what might be the most concrete data yet on how the SOC analyst job itself is changing: they collected over 1,600 US security operations job postings, read more than 1,000 in full, and coded 665 in-scope roles against a fixed rubric covering role family, seniority tier, compensation, AI requirements, and which tools each posting named. The resulting SOC Rebuild Index shows security operations engineer as the single largest role family in the dataset at one in five postings, while the classic SOC analyst seat, the person watching the alert queue, ranks only fourth at 10%. Add up every role family focused on building rather than watching (SecOps engineering, detection engineering, automation engineering, AI security engineering, and architecture) and that group accounts for 37% of all postings, roughly three build-focused hires for every SOC analyst hire.
The compensation data tells the same story from a different angle. Median advertised pay climbs steadily as a role moves from watching to building: $125k for a SOC analyst, $142k for a SecOps engineer, $148k-$151k for hunters and responders, $152k for automation engineers, $161k for detection engineers, and $175k for architects. The analyst family is also the least touched by AI requirements, appearing in only 9% of triage-focused analyst postings versus 42% for automation engineering roles, meaning the traditional analyst job, where it still exists, is simultaneously the smallest, lowest-paid, and least automated role in the current market. Overall, only about 23% of postings carry an active AI or automation requirement, while two-thirds mention no AI language at all, so despite the volume of AI SOC conversation in the industry, roughly a tenth of the market is actively rebuilding around it while the rest is still posting jobs that could have been written in 2022.
Where AI does show up, it's concentrated and specific. About 11% of postings describe building, operating, or validating AI-driven security operations directly, spanning industries as varied as pharmaceuticals, industrial manufacturing, consumer fitness, wealth management, and dental insurance, indicating the agentic SOC job description has moved well past early adopters. Interestingly, named AI SOC platforms appear as an explicit requirement in only about 1% of postings so far, suggesting most enterprises are still renting this expertise through integrators and consultancies (where AI SOC-specific roles pay $160k-$200k) rather than hiring for it directly. Entry-level roles, meanwhile, have shrunk to under 6% of the market, and where they still exist, they're increasingly framed as engineering seats rather than pure triage seats, with the zero-experience triage job surviving mainly at MSSPs, MDR providers, and government contracts.
For security staff reading this, the report's practical message is about which skills to build regardless of where someone currently sits. Detections-as-code shows up in 46% of plain SOC analyst postings, meaning writing detections alongside triaging alerts is becoming a baseline expectation rather than a specialization. Threat hunting appears as a duty in 38% of postings and as a dedicated title in 8%, making it a skill worth developing no matter the current job title. And validating automated or AI-generated output is emerging as work that spans both vendor and enterprise roles alike, since even companies selling autonomous SOC platforms are staffing tiered human teams specifically to check the AI's work. The report's underlying advice for anyone in a manual, flat-paid triage role is straightforward: the pay gradient and the AI-adoption data both point toward owning automation and detection work as the next step, rather than treating the current queue-watching job as a stable long-term seat.