Skip to main content
CybersecurityIncident Response

AI Augments SOC Analyst Capacity, Raises Skill Development Concerns

Security analysts work at desks surrounded by multiple screens in a dimly lit operations center.

“The issue is not whether analysts should trust AI. It is whether they have enough information to decide when to trust it,” said Mike Lyborg, CISO of Swimlane.

Swimlane poll of 500 US and UK security professionals

Swimlane polled 500 security professionals and leaders at organizations in the United States and the United Kingdom for its report, The New SOC Career Ladder. The survey sought to capture how AI is reshaping day-to-day work inside security operations centers (SOCs) and how those shifts are affecting skills, career paths and workforce design.

Productivity effects: greater capacity and time for complex work

Respondents reported measurable capacity gains linked to AI. Nearly half (47%) named “greater capacity” as one of the two biggest impacts of AI use in the SOC. More than a third (35%) said they now have more time to investigate complex threats, and an identical share (35%) said AI has allowed them to focus more on strategic or cross‑functional work. Relatedly, 43% reported they are spending less time on repetitive tasks and more time on broader responsibilities.

Skills development and career-path concerns for junior analysts

Despite clear productivity benefits, the survey surfaced significant concern about on‑the‑job learning. Overall, 88% of respondents said AI has improved their job satisfaction, yet 24% also said AI has limited their ability to build skills. Swimlane’s CEO Cody Cornell framed the tension succinctly: “The challenge is that routine work has also been one of the ways analysts learn the fundamentals,” said Swimlane CEO, Cody Cornell.

Those worries extend to recruitment and the pipeline into SOC work. Nearly half (47%) of respondents said they expect AI to create a steeper path into the profession. Within that group, 37% said they expect higher requirements for entry‑level roles and 10% expect fewer opportunities for junior analysts to gain experience. Only 1% of respondents expect the SOC career path to remain largely unchanged.

Swimlane’s findings align with a separate 2025 report from Abnormal AI, which found 44% of SOCs were developing plans to migrate Tier 1 SOC analysts into more senior Tier 2–3 roles, and that 73% of responding analysts said manual or reactive tasks are stalling their career growth.

Oversight, explainability and accountability in practice

Respondents reported high confidence in their ability to spot AI errors: 92% said they could identify an “incorrect or incomplete AI recommendation.” Nevertheless, nearly half (48%) said they would rely on their own judgment when an AI recommendation conflicted with available evidence or could disrupt business operations. Lyborg pressed the operational point: “Security teams need to see how a recommendation was reached, understand what action will follow and be able to step in before a consequential decision is made. AI may be taking on more work in the SOC, but accountability still belongs with people.”

What this means for security teams, recruiters, and SOC leaders

  • Security teams: Expect shifts in day‑to‑day work mix — more time for investigative and cross‑functional tasks, less repetitive triage — but also a need to retain hands‑on practice so analysts can validate and override AI outputs.
  • Recruiters and HR teams: Anticipate rising entry requirements for junior vacancies; 37% of respondents expect higher standards for entry‑level roles and 10% expect fewer on‑the‑job learning opportunities, which will affect hiring criteria and onboarding design.
  • SOC leaders and workforce planners: Prepare to create explicit oversight roles — 41% of respondents expect new specialized roles focused on AI oversight, validation and orchestration — and to measure skill growth separately from employee satisfaction.

Swimlane’s report concluded with a direct prescription for the next phase of AI adoption in SOCs: “The next phase of adoption will depend on workforce design,” the report concluded. “Security leaders need to establish AI oversight as a formal responsibility, measure skill growth separately from employee satisfaction and give junior analysts structured opportunities to develop investigative judgement.”

The numbers describe a familiar paradox: AI is expanding what SOC analysts can do, while also shrinking routine work that traditionally taught them how to do it. The practical question the report leaves for organizations is concrete and immediate — will they redesign training, hiring and oversight to preserve investigative judgement even as automation reallocates tasks?

Original story: https://www.infosecurity-magazine.com/news/ai-boosts-soc-analyst-capacity/