Skip to sources
Time Machine

Information Security Analysts

Scrub through 48years of this role's history, from when it first emerged, through every wave of technology that reshaped it, to the cited projections for where it's heading next.

2026drag to travel through time
2000now
Country
2026
Known today as Information Security Analyst (BLS SOC 15-1212)
US Employment
191K
OEWS is a point-in-time survey snapshot, not a continuous time series; BLS advises against using it for year-over-year trend comparison.
Median Annual Wage
$129,180
≈ $125,868 in 2024 dollars
Each dot is a cited figure over time; the dotted line only links them (values between aren't measured). Hollow dots are estimates.
Tools of the era

The tools that defined the work

Select an era to see how it reshaped the work.

  • Physical access controls + mainframe password systems

    The first generation of computer security was about physical locks and logical access codes. Mainframe security meant controlling who could sit at a terminal, enforcing password policies, and auditing access logs printed on greenbar paper. The 1972 Air Force Anderson Report formalized this era's threat taxonomy: the "threat monitoring" paradigm, where security meant watching access and audit trails rather than the network perimeter that did not yet exist.

    Mainframe processingComputerized records
  • First commercial antivirus (McAfee VirusScan, 1987) + first firewalls

    The Brain virus (1986) and the Morris Worm (1988) made antivirus software and network perimeter defense into commercial products. John McAfee released VirusScan as shareware in 1987; G Data released the first commercial antivirus in the same year. DEC SEAL (1989) is widely cited as the first commercial firewall. This era created the "antivirus + firewall" two-layer security model that would dominate corporate IT for the next two decades and produced the first dedicated security product vendors.

    Effect on the work

    The Morris Worm response directly created the CERT Coordination Center at Carnegie Mellon (1988) — the first institutional role for coordinated security response — and the (ISC)² credentialing body (also 1988), which would certify the profession's first specialists.

    Work toolChanging equipment
  • SSL/TLS + PKI + IDS (Snort, 1998)

    The browser era forced a new layer onto the security stack: cryptographic authentication for public internet transactions. Netscape's SSL 2.0 (1995) and its successor TLS (RFC 2246, 1999) created the certificate authority industry. Simultaneously, Martin Roesch released Snort in 1998 — an open-source network intrusion detection system that would become the most widely deployed IDS in the world and the foundation of a generation of security analysts's monitoring workflows.

    Work toolChanging equipment
  • SIEM (QRadar 2001, Splunk 2003) + compliance-driven security

    September 11, 2001 triggered a cascade of federal security legislation (the USA PATRIOT Act, FISMA 2002, Homeland Security Act 2002) that mandated formal security programs across government contractors and financial institutions. The Sarbanes-Oxley Act (2002) required public companies to document and audit IT controls. These compliance mandates created demand for information security professionals at organizations that had never hired one. Q1 Labs released QRadar in 2001; Splunk was founded in 2003. The SIEM category — Security Information and Event Management — gave analysts their first unified log-aggregation and correlation platform.

    Effect on the work

    SOX compliance (2002) is widely credited with driving a first wave of corporate security hiring. Many organizations hired their first dedicated information security analyst specifically to satisfy SOX audit requirements.

    Compliance systemsControls and audit files
  • APT-era defense (Stuxnet 2010 → Mandiant APT1 report 2013)

    Stuxnet (discovered June 2010) was the first publicly known cyberweapon designed to cause physical damage to industrial infrastructure — a joint US-Israeli operation targeting Iranian uranium centrifuges. It changed what the information security profession understood itself to be defending against. The Mandiant APT1 report (February 2013) publicly attributed a sustained campaign against 141 US organizations to a specific unit of the Chinese People's Liberation Army — the first major public attribution of state-sponsored industrial espionage. Together these events created the "advanced persistent threat" (APT) category, gave analysts new threat intelligence frameworks (kill-chain, diamond model), and drove demand for threat hunters as distinct from perimeter monitors.

    Work toolChanging equipment
  • SOAR + EDR/XDR (Phantom 2014, CrowdStrike Falcon 2013)

    The volume of security alerts grew faster than analyst headcount. Security Orchestration, Automation, and Response (SOAR) platforms — Phantom (2014), Demisto (2016), both eventually acquired by Splunk and Palo Alto — automated repetitive enrichment and response workflows so analysts could focus on genuine decisions. CrowdStrike launched in 2011 and its Falcon endpoint detection and response platform reached mainstream enterprise adoption around 2016-18, replacing signature-based antivirus with behavioral detection. The analyst role shifted from "watching logs" to "investigating behavioral detections and tuning automated playbooks."

    Work toolChanging equipment
  • Ransomware as a service (WannaCry 2017, LockBit 2019)

    WannaCry (May 2017) and NotPetya (June 2017) paralyzed global logistics at Maersk, FedEx, and the UK National Health Service — organizations that had not thought of themselves as high-value targets. These were not sophisticated APT campaigns; they were opportunistic ransomware spread via an NSA-developed exploit, EternalBlue, leaked by the Shadow Brokers. Ransomware-as-a-service platforms (REvil, LockBit from 2019 onward) industrialized the attack model, making destructive intrusions accessible to organized criminal groups. Every mid-market company became a potential victim, and every mid-market company that had deferred security hiring reconsidered.

    Effect on the work

    The ransomware era (2017-2022) is the clearest driver of the 131,000 (2019) → 163,000 (2022) employment surge. ISC2's workforce gap estimates doubled during this period as insurance carriers began requiring documented security programs for cyber-liability coverage.

    Work toolChanging equipment
  • Cloud-native security (CSPM, CNAPP) + supply-chain defense

    The SolarWinds breach (December 2020) — in which attackers compromised a software update mechanism used by 18,000 organizations including nine US federal agencies — demonstrated that traditional perimeter defense was structurally inadequate against software supply-chain attacks. Cloud Security Posture Management (CSPM) tools (Wiz, Orca, Prisma Cloud) emerged as the primary tool class for securing cloud infrastructure. The analyst role acquired a new vocabulary: IAM misconfiguration, cloud workload protection, shift-left security, software composition analysis. The former "network security analyst" was expected to know AWS IAM as fluently as they had once known firewall ACLs.

    Work toolChanging equipment
  • AI-augmented SOC (CrowdStrike Charlotte AI, Microsoft Security Copilot 2024)

    CrowdStrike announced Charlotte AI at the RSA Conference in April 2023; Microsoft Security Copilot reached general availability in April 2024, integrated into Defender and Sentinel. Both products changed the analyst's daily workflow in the same direction: AI handles Tier-1 alert triage (enrichment, correlation, false-positive filtering) and the analyst reviews AI-generated findings rather than raw log data. CrowdStrike claimed Charlotte AI saved analysts more than 40 hours per week on average and reduced investigation effort by 70%. Palo Alto's XSIAM platform reported 75% reduction in manual SOC work. At the same time, AI-enabled attackers grew faster: Mandiant's M-Trends 2026 report found attacker initial-access-to-lateral-movement time had collapsed to 22 seconds in documented 2025 incidents. The arms race accelerated on both sides simultaneously.

    Effect on the work

    ISC2 2025 Cybersecurity Workforce Study: 73% of practitioners believe AI creates MORE demand for specialized cyber skills; global workforce gap estimated at 4.8 million unfilled positions. BLS +33% projection (2023-33) is the highest growth rate of any IT occupation. The productivity gains from AI are being absorbed by a larger attack surface, not a smaller workforce.

    AI audit toolsPattern detection
Projection cone · present → 2033

What credible sources project

Scrub the slider past now to anchor each scenario on the scrubber. The spread is the range of futures credible sources project for this role.

Employment outlook
Projected change in the number of people doing this work.
ISC2 2025 Cybersecurity Workforce Study
2030
+40%
ISC2 estimates a global cybersecurity workforce gap of 4.8 million unfilled positions as of 2025 — the largest gap ever recorded in their annual study. The gap is growing despite record hiring because AI expands the attack surface faster than the workforce grows. The 40% figure is curator-estimated from the demand-growth trajectory implied by ISC2's hiring-need data; ISC2 does not publish a single US-only employment count for the 15-1212 category. 73% of practitioners surveyed say AI will increase demand for specialized cyber skills, not reduce it.
BLS Occupational Outlook Handbook 2023-33
2033
+33%
BLS Employment Projections — industry-occupation matrix + labor productivity assumptions. The 2023-33 OOH edition projects 33% employment growth for 15-1212, the highest rate of any IT occupation and among the top projected growth rates in the entire BLS dataset. The projection cites expanding attack surfaces, healthcare and government digitization, and increasing regulatory requirements as the primary drivers. Approximately 16,800 annual openings projected over the decade.
AI task exposure
Share of the role’s tasks that researchers estimate AI can do. This is a measure of task exposure, not a forecast of jobs lost.
Eloundou et al. — "GPTs are GPTs" (2023)
2030
28%
of tasks
GPT-4 task-by-task LLM-exposure labeling against O*NET task statements. Information Security Analysts fall in the medium-high exposure range in the Eloundou dataset — the documentation, reporting, and routine investigation tasks carry high LLM exposure, but the threat hunting, incident command, and adversarial-simulation tasks carry low exposure. The -28% figure represents the β exposure measure (fraction of tasks where LLMs could assist meaningfully). Note: Eloundou "exposure" is capability, not substitution — high-exposure tasks could equally be AI-augmented as AI-replaced, and in this role the augmentation interpretation is the better fit given strong employment-demand growth.
Goldman Sachs (March 2023)
2030
22%
of tasks
Goldman maps O*NET work-activity importance scores to LLM capability ratings. Computer & Mathematical occupations show approximately 29% of tasks automatable by current LLM capabilities; Information Security Analysts are at the lower end of this range due to the adversarial and judgment-heavy nature of the role. The -22% figure is a curator estimate within the Goldman Computer & Mathematical range. As with Eloundou, "automatable tasks" is not "jobs lost" — for security specifically, automation of Tier-1 triage frees analyst capacity for more complex work rather than reducing headcount.
Today, in this role

What's shifting in the work right now

The historical view above shows how this role has moved. This is the present-day detail: which AI tools are picking up which tasks, where the edge still is, and the natural directions this work can grow.

What's changing in your day

Three parts of your work where AI is already doing real lifting, and what stays yours.

AI is sitting alongside you hereReview AI-prioritized SIEM alert queues in Microsoft Sentinel or Splunk Enterprise Security — validating triage decisions made by the AI agent, escalating confirmed incidents, and closing false positives with documented rationale.

Review AI-prioritized SIEM alert queues in Microsoft Sentinel or Splunk Enterprise Security — validating triage decisions made by the AI agent, escalating confirmed incidents, and closing false positives with documented rationale.[9],[10],[8]

Where your edge is

Build fluency in prompt-driven investigation: learn to ask the right natural-language questions inside Security Copilot and Charlotte AI to surface context the AI surface didn't show, and develop a disciplined false-positive taxonomy so you can tune alert logic over time.

AI is sitting alongside you hereMonitor cloud security posture using CSPM tools (Wiz, Orca, Prisma Cloud) — reviewing AI-generated risk scores for misconfigured resources, enforcing compliance guardrails, and coordinating with DevOps to fix issues before they reach production.

Monitor cloud security posture using CSPM tools (Wiz, Orca, Prisma Cloud) — reviewing AI-generated risk scores for misconfigured resources, enforcing compliance guardrails, and coordinating with DevOps to fix issues before they reach production.[11],[2]

Tools picking this up
Where your edge is

Earn cloud-platform depth beyond the CSPM dashboard: understand the IAM, networking, and data-plane fundamentals behind the findings so you can distinguish critical-path misconfigurations from lower-priority hygiene issues that AI over-weights.

AI is sitting alongside you hereManage vulnerability backlogs using AI-assisted risk scoring — reviewing Tenable or Wiz findings ranked by real-world exploitability, coordinating patch prioritization with engineering teams, and tracking remediation SLAs.

Manage vulnerability backlogs using AI-assisted risk scoring — reviewing Tenable or Wiz findings ranked by real-world exploitability, coordinating patch prioritization with engineering teams, and tracking remediation SLAs.[12],[11]

Tools picking this up
Where your edge is

Go beyond raw CVSS scores: learn to interrogate AI-generated exploitability ratings using threat intelligence context (active exploitation in the wild, asset criticality, blast radius) so you own the remediation priority decision rather than rubber-stamp the scanner output.

Where this role is heading

Natural next steps for someone with your foundation: not exits, evolutions.

A direction you could grow

Computer and Information Systems Managers

Senior security analysts who build credibility with executive stakeholders during incident response and risk briefings often move into security management or CISO-track roles. The 2026 market shows rising demand for security managers who can set AI-tool adoption strategy, manage vendor relationships for agentic SOC platforms, and translate technical risk into board-level language.

What you'd add
· Security program governance: CISO-track skills, board reporting, security metrics and KPIs
· AI tool adoption strategy: evaluating CrowdStrike Charlotte AI, Cortex XSIAM, and Security Copilot for SOC ROI
· Budget management: headcount planning, security tooling licensing, vendor negotiations
What it takesA real upskill, but a natural one
Share this year
Drops anyone you send it to straight into 2026.
Preview card
Part of Tech & Data · see all 28roles →
Different role?

See the same long-arc view for your own profession.

Browse the directory by industry, or search by title or SOC code. New roles ship every few weeks. Every profile cites every claim.

Browse all roles

The data behind this timeline

On record since1988
Latest tracked employment190,650 (US, 2025)
Latest median pay$129,180 (2025)
Outlook+33% by 2033 (BLS Occupational Outlook Handbook 2023-33)
View all 9 cited data points
YearUS employmentMedian annual paySource
200050,000n/aESTIMATE
201275,000n/aBLS-OEWS
2019131,000$99,730BLS-OEWS
2020138,000$103,590BLS-OEWS
2021157,220$102,600BLS-OEWS
2022163,000$112,000BLS-OEWS
2023175,350$120,360BLS-OEWS
2024180,000$120,360BLS-OEWS
2025190,650$129,180BLS-OEWS
Embed this timeline on your site

Free for any site. Paste this where the timeline should appear; it stays interactive, every datapoint stays cited, and it sets no cookies on your page. How embedding works

<iframe src="https://futurehistory.earth/embed/15-1212"
  width="100%" height="430" style="border:0"
  title="Information Security Analysts, a Future History timeline"
  loading="lazy"></iframe>

See all roles in Tech & Data