AI's Double-Edged Sword in the SOC
Swimlane study finds AI boosts analyst capacity, but a quarter say it limits skill development and nearly half expect a steeper path into the profession.
Security operations center analysts are gaining time for complex investigations and strategic work as AI takes over repetitive tasks, but the same automation that frees them up may also be eroding the hands-on learning that builds seasoned investigators, according to a new study.
The findings come from Swimlane, a security operations specialist, which polled 500 security professionals and leaders at US and UK organizations using AI for its report, The New SOC Career Ladder. The study paints a picture of a workforce that is broadly satisfied with AI but uneasy about what it means for the next generation of analysts.
Capacity Gains Come With Trade-offs
Nearly half of respondents (47%) identified "greater capacity" as one of the two biggest impacts of using AI in the SOC. More than a third said they now have more time to investigate complex threats (35%) and have been able to focus more on strategic or cross-functional work (35%) thanks to the technology. A slightly larger share (43%) reported spending less time on repetitive work and more time on broader responsibilities.
Those numbers suggest AI is delivering on its promise to relieve analysts of routine alert triage and other manual chores. But the study also found that some of that freed-up time is not translating into skill growth.
Overall, 88% of respondents said AI has improved their job satisfaction. Yet a quarter (24%) complained that it has also limited their ability to build skills. The report noted that job satisfaction levels remained virtually unchanged among the cohorts claiming AI is boosting skills development and those saying the opposite — a finding that suggests satisfaction and skill-building are not as tightly linked as might be assumed.
Skill Development Concerns Emerge
The tension between productivity and professional growth is not lost on Swimlane's leadership. "The challenge is that routine work has also been one of the ways analysts learn the fundamentals," said Cody Cornell, CEO of Swimlane. "As more of that work is automated, organizations need to rethink training and career paths so people still develop the judgment to know when AI is right and when it is not."
That judgment is a recurring theme in the report. The vast majority of respondents (92%) said they are confident they could identify an "incorrect or incomplete AI recommendation." Nearly half (48%) said they would rely on their own judgment if an AI recommendation conflicts with available evidence or could disrupt business operations.
But confidence in their own abilities does not resolve the underlying problem: if analysts never cut their teeth on routine work, where do they learn to second-guess a machine? The report's authors argue that organizations need to be deliberate about creating opportunities for junior staff to develop investigative skills even as automation takes over more of the day-to-day.
Trust Requires Transparency
Swimlane's CISO, Mike Lyborg, framed the issue as one of information rather than faith. "The issue is not whether analysts should trust AI. It is whether they have enough information to decide when to trust it," he said. "Security teams need to see how a recommendation was reached, understand what action will follow and be able to step in before a consequential decision is made. AI may be taking on more work in the SOC, but accountability still belongs with people."
"The issue is not whether analysts should trust AI. It is whether they have enough information to decide when to trust it."
— Mike Lyborg, CISO of Swimlane
That emphasis on accountability is reflected in how respondents say they would handle disagreements with AI. The 48% who would rely on their own judgment when evidence conflicts with an AI recommendation represent a significant bloc of analysts who are not prepared to defer blindly to automation. The 92% who are confident they could spot an incorrect or incomplete AI recommendation suggests that overconfidence may not be the primary risk — rather, the risk is that the information needed to make those calls may not always be available.
Recruitment and Career Path Pessimism
The study also surfaced widespread concern about how AI will reshape the pipeline of new talent into the SOC. Nearly half of respondents (47%) said they expect AI to create a steeper path into the profession. Within that group, 37% think there will be higher requirements for entry-level roles, while 10% expect fewer opportunities for junior analysts to gain experience.
At the same time, 41% anticipate new specialized roles focused on AI oversight, validation, and orchestration. Only 1% expect the SOC career path to remain largely unchanged — a figure that underscores just how much disruption respondents expect.
Those expectations align with other industry research. A report from Abnormal AI published in 2025 found that 44% of SOCs were developing plans to migrate Tier 1 analysts to more senior Tier 2-3 roles, and that 73% of responding analysts said manual or reactive tasks were stalling their career growth. Together, the two studies suggest a growing consensus that the traditional SOC ladder is due for a rethink.
What the Numbers Show
- 500 security professionals and leaders polled across US and UK organizations.
- 47% said "greater capacity" is one of the two biggest impacts of using AI.
- 35% have more time to investigate complex threats; another 35% focus more on strategic or cross-functional work.
- 43% spend less time on repetitive work and more on broader responsibilities.
- 92% are confident they could identify an incorrect or incomplete AI recommendation.
- 48% would rely on their own judgment if an AI recommendation conflicts with evidence or disrupts operations.
- 88% said AI has improved job satisfaction, but 24% said it has limited their ability to build skills.
- 47% expect AI to create a steeper path into the profession: 37% foresee higher entry-level requirements, 10% expect fewer junior opportunities.
- 41% expect new specialized roles in AI oversight, validation, and orchestration; only 1% expect the career path to remain largely unchanged.
Redesigning the Career Ladder
The report's conclusion calls for a structured approach to workforce planning. "The next phase of adoption will depend on workforce design," the authors wrote. "Security leaders need to establish AI oversight as a formal responsibility, measure skill growth separately from employee satisfaction and give junior analysts structured opportunities to develop investigative judgement."
That recommendation speaks directly to the gap identified by the survey. If AI is absorbing the routine work that once served as on-the-job training, organizations cannot assume that analysts will pick up investigative judgment by osmosis. The report suggests that skill growth must be tracked as its own metric rather than inferred from satisfaction scores, and that AI oversight should be a defined role rather than an informal expectation.
The Road Ahead
The study's findings point to a fork in the road for security operations. On one side, AI is clearly easing the burden of repetitive tasks and giving analysts room to focus on higher-value work — a change that 88% say has improved their job satisfaction. On the other, the same automation may be hollowing out the apprenticeship model that has traditionally produced skilled investigators.
How organizations respond to that tension could determine whether the SOC of the future is staffed by analysts who can effectively supervise AI or by a shrinking pool of senior staff with few successors. The report's call to formalize AI oversight and create structured development opportunities for junior analysts is, in effect, a proposal for how to keep the career ladder intact even as the rungs shift.
For security leaders, the practical takeaway is that AI adoption in the SOC is not just a technology deployment — it is a workforce design problem. The 47% who expect a steeper path into the profession are signaling that without deliberate intervention, the pipeline of new talent could narrow. The 41% who anticipate new specialized roles see an opportunity to reshape the ladder rather than dismantle it. Which vision prevails will depend on choices made now, while the technology is still new enough to be shaped.
Sources
- Infosecurity Magazine Original source
Continue Reading
Why AI Jails Can't Hold Alone
An OpenAI agent swarm incident shows containment is a security architecture problem, not a guarantee, with every boundary a potential failure point.
AI Doomsday Scenarios Face Skeptics
Researchers debate whether AI's catastrophic risks are real threats or marketing, from nuclear war to bioweapons and runaway models.
Snorkel AI's $3.5B bet on training data
Snorkel AI raised $350 million at a $3.5 billion valuation, nearly tripling its worth as demand for AI training data surges.