Information Security Analysts
Scrub through 48years of this role's history, from when it first emerged, through every wave of technology that reshaped it, to the cited projections for where it's heading next.
The tools that defined the work
Select an era to see how it reshaped the work.
Physical access controls + mainframe password systems
The first generation of computer security was about physical locks and logical access codes. Mainframe security meant controlling who could sit at a terminal, enforcing password policies, and auditing access logs printed on greenbar paper. The 1972 Air Force Anderson Report formalized this era's threat taxonomy: the "threat monitoring" paradigm, where security meant watching access and audit trails rather than the network perimeter that did not yet exist.
Mainframe processingComputerized records First commercial antivirus (McAfee VirusScan, 1987) + first firewalls
The Brain virus (1986) and the Morris Worm (1988) made antivirus software and network perimeter defense into commercial products. John McAfee released VirusScan as shareware in 1987; G Data released the first commercial antivirus in the same year. DEC SEAL (1989) is widely cited as the first commercial firewall. This era created the "antivirus + firewall" two-layer security model that would dominate corporate IT for the next two decades and produced the first dedicated security product vendors.
Effect on the workThe Morris Worm response directly created the CERT Coordination Center at Carnegie Mellon (1988) — the first institutional role for coordinated security response — and the (ISC)² credentialing body (also 1988), which would certify the profession's first specialists.
Work toolChanging equipment SSL/TLS + PKI + IDS (Snort, 1998)
The browser era forced a new layer onto the security stack: cryptographic authentication for public internet transactions. Netscape's SSL 2.0 (1995) and its successor TLS (RFC 2246, 1999) created the certificate authority industry. Simultaneously, Martin Roesch released Snort in 1998 — an open-source network intrusion detection system that would become the most widely deployed IDS in the world and the foundation of a generation of security analysts's monitoring workflows.
Work toolChanging equipment SIEM (QRadar 2001, Splunk 2003) + compliance-driven security
September 11, 2001 triggered a cascade of federal security legislation (the USA PATRIOT Act, FISMA 2002, Homeland Security Act 2002) that mandated formal security programs across government contractors and financial institutions. The Sarbanes-Oxley Act (2002) required public companies to document and audit IT controls. These compliance mandates created demand for information security professionals at organizations that had never hired one. Q1 Labs released QRadar in 2001; Splunk was founded in 2003. The SIEM category — Security Information and Event Management — gave analysts their first unified log-aggregation and correlation platform.
Effect on the workSOX compliance (2002) is widely credited with driving a first wave of corporate security hiring. Many organizations hired their first dedicated information security analyst specifically to satisfy SOX audit requirements.
Compliance systemsControls and audit files APT-era defense (Stuxnet 2010 → Mandiant APT1 report 2013)
Stuxnet (discovered June 2010) was the first publicly known cyberweapon designed to cause physical damage to industrial infrastructure — a joint US-Israeli operation targeting Iranian uranium centrifuges. It changed what the information security profession understood itself to be defending against. The Mandiant APT1 report (February 2013) publicly attributed a sustained campaign against 141 US organizations to a specific unit of the Chinese People's Liberation Army — the first major public attribution of state-sponsored industrial espionage. Together these events created the "advanced persistent threat" (APT) category, gave analysts new threat intelligence frameworks (kill-chain, diamond model), and drove demand for threat hunters as distinct from perimeter monitors.
Work toolChanging equipment SOAR + EDR/XDR (Phantom 2014, CrowdStrike Falcon 2013)
The volume of security alerts grew faster than analyst headcount. Security Orchestration, Automation, and Response (SOAR) platforms — Phantom (2014), Demisto (2016), both eventually acquired by Splunk and Palo Alto — automated repetitive enrichment and response workflows so analysts could focus on genuine decisions. CrowdStrike launched in 2011 and its Falcon endpoint detection and response platform reached mainstream enterprise adoption around 2016-18, replacing signature-based antivirus with behavioral detection. The analyst role shifted from "watching logs" to "investigating behavioral detections and tuning automated playbooks."
Work toolChanging equipment Ransomware as a service (WannaCry 2017, LockBit 2019)
WannaCry (May 2017) and NotPetya (June 2017) paralyzed global logistics at Maersk, FedEx, and the UK National Health Service — organizations that had not thought of themselves as high-value targets. These were not sophisticated APT campaigns; they were opportunistic ransomware spread via an NSA-developed exploit, EternalBlue, leaked by the Shadow Brokers. Ransomware-as-a-service platforms (REvil, LockBit from 2019 onward) industrialized the attack model, making destructive intrusions accessible to organized criminal groups. Every mid-market company became a potential victim, and every mid-market company that had deferred security hiring reconsidered.
Effect on the workThe ransomware era (2017-2022) is the clearest driver of the 131,000 (2019) → 163,000 (2022) employment surge. ISC2's workforce gap estimates doubled during this period as insurance carriers began requiring documented security programs for cyber-liability coverage.
Work toolChanging equipment Cloud-native security (CSPM, CNAPP) + supply-chain defense
The SolarWinds breach (December 2020) — in which attackers compromised a software update mechanism used by 18,000 organizations including nine US federal agencies — demonstrated that traditional perimeter defense was structurally inadequate against software supply-chain attacks. Cloud Security Posture Management (CSPM) tools (Wiz, Orca, Prisma Cloud) emerged as the primary tool class for securing cloud infrastructure. The analyst role acquired a new vocabulary: IAM misconfiguration, cloud workload protection, shift-left security, software composition analysis. The former "network security analyst" was expected to know AWS IAM as fluently as they had once known firewall ACLs.
Work toolChanging equipment AI-augmented SOC (CrowdStrike Charlotte AI, Microsoft Security Copilot 2024)
CrowdStrike announced Charlotte AI at the RSA Conference in April 2023; Microsoft Security Copilot reached general availability in April 2024, integrated into Defender and Sentinel. Both products changed the analyst's daily workflow in the same direction: AI handles Tier-1 alert triage (enrichment, correlation, false-positive filtering) and the analyst reviews AI-generated findings rather than raw log data. CrowdStrike claimed Charlotte AI saved analysts more than 40 hours per week on average and reduced investigation effort by 70%. Palo Alto's XSIAM platform reported 75% reduction in manual SOC work. At the same time, AI-enabled attackers grew faster: Mandiant's M-Trends 2026 report found attacker initial-access-to-lateral-movement time had collapsed to 22 seconds in documented 2025 incidents. The arms race accelerated on both sides simultaneously.
Effect on the workISC2 2025 Cybersecurity Workforce Study: 73% of practitioners believe AI creates MORE demand for specialized cyber skills; global workforce gap estimated at 4.8 million unfilled positions. BLS +33% projection (2023-33) is the highest growth rate of any IT occupation. The productivity gains from AI are being absorbed by a larger attack surface, not a smaller workforce.
AI audit toolsPattern detection
What credible sources project
Scrub the slider past now to anchor each scenario on the scrubber. The spread is the range of futures credible sources project for this role.
What's shifting in the work right now
The historical view above shows how this role has moved. This is the present-day detail: which AI tools are picking up which tasks, where the edge still is, and the natural directions this work can grow.
What's changing in your day
Three parts of your work where AI is already doing real lifting, and what stays yours.
AI is sitting alongside you hereReview AI-prioritized SIEM alert queues in Microsoft Sentinel or Splunk Enterprise Security — validating triage decisions made by the AI agent, escalating confirmed incidents, and closing false positives with documented rationale.
Review AI-prioritized SIEM alert queues in Microsoft Sentinel or Splunk Enterprise Security — validating triage decisions made by the AI agent, escalating confirmed incidents, and closing false positives with documented rationale.[9],[10],[8]
Build fluency in prompt-driven investigation: learn to ask the right natural-language questions inside Security Copilot and Charlotte AI to surface context the AI surface didn't show, and develop a disciplined false-positive taxonomy so you can tune alert logic over time.
AI is sitting alongside you hereMonitor cloud security posture using CSPM tools (Wiz, Orca, Prisma Cloud) — reviewing AI-generated risk scores for misconfigured resources, enforcing compliance guardrails, and coordinating with DevOps to fix issues before they reach production.
Monitor cloud security posture using CSPM tools (Wiz, Orca, Prisma Cloud) — reviewing AI-generated risk scores for misconfigured resources, enforcing compliance guardrails, and coordinating with DevOps to fix issues before they reach production.[11],[2]
Earn cloud-platform depth beyond the CSPM dashboard: understand the IAM, networking, and data-plane fundamentals behind the findings so you can distinguish critical-path misconfigurations from lower-priority hygiene issues that AI over-weights.
AI is sitting alongside you hereManage vulnerability backlogs using AI-assisted risk scoring — reviewing Tenable or Wiz findings ranked by real-world exploitability, coordinating patch prioritization with engineering teams, and tracking remediation SLAs.
Manage vulnerability backlogs using AI-assisted risk scoring — reviewing Tenable or Wiz findings ranked by real-world exploitability, coordinating patch prioritization with engineering teams, and tracking remediation SLAs.[12],[11]
Go beyond raw CVSS scores: learn to interrogate AI-generated exploitability ratings using threat intelligence context (active exploitation in the wild, asset criticality, blast radius) so you own the remediation priority decision rather than rubber-stamp the scanner output.
Where this role is heading
Natural next steps for someone with your foundation: not exits, evolutions.
Computer and Information Systems Managers
Senior security analysts who build credibility with executive stakeholders during incident response and risk briefings often move into security management or CISO-track roles. The 2026 market shows rising demand for security managers who can set AI-tool adoption strategy, manage vendor relationships for agentic SOC platforms, and translate technical risk into board-level language.
See the same long-arc view for your own profession.
Browse the directory by industry, or search by title or SOC code. New roles ship every few weeks. Every profile cites every claim.
Browse all roles