A Security Operations Center (SOC) Analyst is the front line of defense against cyber threats, watching over an organization's networks, endpoints, and systems for signs of malicious activity. Using SIEM tools, intrusion detection systems, and threat intelligence feeds, SOC analysts triage alerts, investigate suspicious behavior, and respond to incidents ranging from phishing attempts to ransomware outbreaks. The role often operates in shifts to provide 24/7 coverage, making rapid decision-making and calm, methodical thinking essential.
| Entry level | $58,000 |
| Median | $85,000 |
| Senior | $115,000 |
| Top 10% | $145,000 |
| Job growth | +32% |
| Professionals in the USA | 0.6 million |
| Typical hours/week | 42 hrs |
| Remote work share | 45% |
| Annual job openings | 70,000/yr |
| Demand | Very High |
AI-powered SIEM and SOAR tools are automating alert triage, correlation, and initial incident classification, significantly reducing the volume of manual work for Tier 1 analysts. However, complex incident response, threat hunting, and nuanced decision-making under ambiguity still require human judgment. The role is evolving toward higher-level analysis as routine detection tasks become automated.
Automation exposure: Alert triage, log correlation, false-positive filtering, basic pattern matching, routine reporting, and initial classification of common threats are increasingly handled by AI/ML-driven SIEM, SOAR, and XDR platforms.
The human edge: Humans excel at contextual judgment during novel or sophisticated attacks, understanding organizational nuance and business risk, creative adversarial thinking during threat hunting, cross-team communication during crises, and making high-stakes decisions with incomplete information.
Figures are estimates for exploration — verify current data with BLS.gov.