A Security Operations Center (SOC) Analyst serves as a frontline defender against cyberattacks, watching over an organization's networks, servers, and endpoints for signs of malicious activity. Using SIEM tools, intrusion detection systems, and threat intelligence feeds, they triage alerts, investigate suspicious behavior, and respond to incidents ranging from phishing attempts to full-scale breaches. SOC Analysts often work in tiered structures, with Tier 1 analysts handling initial alert triage and escalating complex cases to Tier 2 and Tier 3 specialists who perform deeper forensic analysis.
| Entry level | $58,000 |
| Median | $85,000 |
| Senior | $115,000 |
| Top 10% | $145,000 |
| Job growth | +32% |
| Professionals in the USA | 0.4 million |
| Typical hours/week | 42 hrs |
| Remote work share | 45% |
| Annual job openings | 38,000/yr |
| Demand | Very High |
AI-powered SIEM and SOAR tools are automating alert triage, log correlation, and initial threat detection, significantly reducing the manual workload of Tier 1 SOC analysts. However, complex investigations, incident response decisions, and contextual judgment still require human analysts, shifting the role toward oversight of AI-driven systems.
Automation exposure: Alert triage, log correlation, false-positive filtering, basic pattern matching, and routine ticket generation are increasingly automated by AI/ML-based security tools and SOAR platforms.
The human edge: Humans excel at contextual reasoning, understanding business risk, making judgment calls during ambiguous incidents, communicating with stakeholders, and adapting to novel attack techniques that AI hasn't been trained on.
Figures are estimates for exploration — verify current data with BLS.gov.