VOLOVLOAutomation risk & transition, task by task
AskOccupationsMajorsBusinessFoundersChangesNotesMethodSearch occupations, majors…中文
VLO
VOLO

Understanding how automation changes work — task by task, with the evidence shown and the uncertainty admitted.

AskOccupationsMajorsBusinessFoundersChangesNotesMethodAboutRole diagnosisPrivacyTerms
© 2026 VOLO
Occupations
All occupations
AI / software
Translator / InterpreterBank tellerCopywriterCustomer service representativeAdministrative assistantSoftware tester / QA engineerGraphic designerParalegalVideo editorAccountant / BookkeeperMarketing specialistFrontend developerData analystInsurance claims handlerTechnical writer / documentation engineerJunior software developerHR / recruiterLoan officer / credit officerFinancial analystProcurement / supply chain specialistJournalistSales / account managerReal estate agentIT support specialist / helpdeskAuditorManagement consultantBackend developerAI researcherProduct / UX designerBusiness systems ownerE-commerce operations specialistRadiologistData engineerLawyerMedical assistant / clinic assistantMachine learning engineerExperienced software engineerDevOps / platform / SRE engineerProduct managerPharmacistPartnerships / channel managerSecurity analyst (SOC)Compliance officerArchitectFirst-line manager / team supervisorCounsellor / therapistRetail salesperson / shop assistantSecurity guardSchool teacherGeneral practitioner / primary care doctorWaiter / restaurant serverAuto mechanic / vehicle technicianPhysiotherapist / rehabilitation therapistConstruction workerRegistered nurseCare worker / nursing assistantAI implementation lead
RPA / self-service
Government service clerkOperations coordinatorReceptionist / front desk
Robotics
Retail cashier / shop assistantWarehouse workerAssembly line workerMedical laboratory technicianChef / cookCleaner / janitorElectrician
Autonomous driving
Ride-hail / taxi driverTruck driverDelivery rider / courier
Majors
All majorsEnglish / Foreign languagesComputer scienceAccountingPsychologyJournalism / CommunicationFinance / EconomicsLawVisual communication designMarketingNursingBusiness administrationEducation and teacher trainingArchitecturePublic administration
Guides
Ask VOLOFor businessFor foundersRecent changesNotesRole diagnosisMethod & evidenceAboutFollow an occupationSearch
You are reading as:I have a jobI am studyingI run a companyI am building something
On this pageTask breakdownHow it got hereRecent changesWhat it means for youMethod & sources
Occupations›Security analyst (SOC)

Get told when a verified record lands on this occupation →

Security analyst (SOC)

Watches an alert queue for the one event that matters, decides whether it is an incident, and is the person who says out loud that the company is under attack.

cybersecurity-analystSee your options ↓Information securityAssessed 2026-09-14
Automation impact index
44/100
low confidence · not a job-loss probability
Tasks automating
1of 4
1 being augmented
Still human-led
2of 4
0 new tasks
Evidence-backed judgements
0of 4
0 verified records
44/100
Automation impact indexLow confidence

This is not a probability of losing your job. It combines how much of the role's task load is exposed to automation with how far adoption has actually gone — useful for comparing occupations on one consistent basis, and for nothing else.

Where this applies

Covers defensive security operations — monitoring, triage, incident response, threat hunting. It does not cover penetration testing, governance and compliance work, or security architecture, which are different jobs often sharing the word security. Whether your organisation runs its own operations centre or buys one as a service changes what the job contains more than any tool does.

Every judgement on this page is platform inference, not sourced evidence.

The evidence base holds verified records for other occupations, but not one for this one yet. Until it does, the analysis below is reasoning about task structure and known technical capability — for this job in particular it is not backed by traceable sources, and we would rather say so than cite things we have not verified. An empty section here is a gap in our coverage, not a finding about the work.

What is actually changing#

The unit of analysis is the task, not the job title. A role is not replaced — its task mix shifts.

Automating×1Being augmented×1Still human-led×2

Is this your job? Say so and this page narrows to your share of it.

A job title is a bundle of tasks bought together, and no two people hold the same bundle. Nothing is sent anywhere — it stays in this browser.

Working the alert queue

Automating≈ Platform inference

Going through hundreds of alerts a shift and deciding which two are worth looking at.

AI / software
Why

This is the same task as a guard watching camera feeds and it fails for the same reason: sustained vigilance collapses in about twenty minutes and the base rate of true positives is brutal, so the human baseline is poor and software does not get bored. Correlation and enrichment are also machine-checkable in a way the rest of this job is not — the alert either matches a known pattern or it does not.

What this does NOT mean

The alert queue is where this occupation hires, so automating it removes the training ground rather than the work — the judgement needed further up is currently built by grinding through the queue, and nobody has said what replaces that. Automating triage also does not reduce alerts; it moves the analyst from reading them to tuning what generates them, which is a different and less staffed job.

Deciding it is an incident

Still human-led≈ Platform inference

Calling it: waking people up, pulling a system off the network, telling the business it has a problem — on incomplete information and before you can be sure.

AI / software
Why

The cost of the two errors is wildly asymmetric and both are expensive: pulling a production system on a false positive and missing a real intrusion are both career events, and the decision is made with authority rather than certainty. No system is given that authority anywhere we can verify, and the reason is accountability rather than accuracy.

What this does NOT mean

The decision staying with a person does not mean the person is in your building: this is the task most commonly outsourced to a managed service, which moves it without automating it. Read the direction as being about what kind of thing it is, not as a guarantee that your employer will keep employing someone to do it.

Writing the detection

Being augmented≈ Platform inference

Turning what you learned from one incident into a rule that catches the next one without drowning the queue.

AI / software
Why

Writing the query is now cheap and models do it well, because a detection rule is code with a testable output. Deciding what to detect is not: it requires knowing what normal looks like in this specific estate, which is knowledge held by people and written down almost nowhere.

What this does NOT mean

Cheap rule-writing makes the false-positive problem worse rather than better, because the constraint was never the writing. A team that can now produce ten times the detections has to be ten times more disciplined about retiring them, and nobody staffs for that — which is how a tool that helps an individual degrades the queue everyone works.

Looking for what nothing alerted on

Still human-led≈ Platform inference

Starting from a hypothesis rather than an alert — assuming something is already inside and going to look for it.

AI / software
Why

Hunting is defined by the absence of a trigger, which removes the input every detection tool needs. What replaces the trigger is a guess about an adversary's goal in this particular organisation, and that guess is made from knowing what the company has that is worth taking.

What this does NOT mean

This is the first activity cut when the queue is loud, because it produces no ticket and no metric. A task can be entirely human and still disappear from a team's week without anybody deciding to remove it — and in this occupation that is the usual way it goes.

Which technologies matter here#

Four separate signals. They are deliberately not added together — a job exposed to two technologies is not twice as exposed.

Cognitive automation
Working the alert queueDeciding it is an incidentWriting the detectionLooking for what nothing alerted on

How it got here#

The index is not a static number. This is where it would have sat at each capability checkpoint since ChatGPT — reconstructed, and labelled as such.

Reconstructed · platform inferenceEstimated today for each past checkpoint — not measured at the time. 28 → 44.
1007550250
not assessed
2022 H22024 H2Now

The rise is one task, and it is the same task that lifts the security-guard curve on this site: working an alert queue is sustained visual vigilance, which humans fail at within about twenty minutes while software does not get bored — and correlation is machine-checkable in a way the rest of this job is not. It flattens because calling an incident is made with authority rather than certainty, and no organisation we can verify has delegated that. Two things the curve cannot show, both of which matter more than its height: the alert queue is where this profession hires, so automating it removes the rung senior judgement was built on; and outsourcing to a managed service moves this work without automating any of it, and arrives faster than any tool.

2022 H228General-purpose text generation reaches the public. Before this point, exposure came from automation that was already deployed — OCR, RPA, machine vision, self-checkout, dispatch algorithms. ChatGPT research preview (2022-11-30) ↗
2023 H131A general model that passes professional exams. First-draft quality crosses the threshold where professional work starts using it. GPT-4 (2023-03-14) ↗
2023 H235Vision input, long context and tool calling. Models can be pointed at documents and connected to systems, which is what moves process work rather than writing work. GPT-4 Turbo:128k 上下文、视觉、工具调用(DevDay) (2023-11-06) ↗
2024 H139The same capability gets much cheaper and faster. Nothing new becomes possible; a lot becomes affordable at volume, which is when deployment decisions change.
2024 H242Reasoning models that work through multi-step problems, and the first models that operate a computer by looking at the screen. The second one is what reaches software-operating jobs. OpenAI o1(推理);同期 Claude 的 computer use 进入公测 (2024-09-12) ↗
2025 H143Agents begin operating real software end to end rather than producing text for a person to paste. This is also when the first public reversals appear — organisations that automated and partly undid it. Claude 3.7 Sonnet 与 Claude Code:混合推理 + 命令行编码代理 (2025-02-24) ↗
2025 H244Long context and tool use become the default rather than a feature. Capability gains continue; the visible constraint shifts from what models can do to liability, procurement and cost. GPT-5(2025-08-07);Claude Opus 4.5(2025-11-24) (2025-08-07) ↗
2026 H144Long-horizon agents land inside specific industry workflows. Adoption becomes sector-specific rather than general. GPT-5.5:「专为实际工作打造」 (2026-04-23) ↗
Now44The current assessment — this point is the impact index published on the occupation's page, so the curve is anchored to a number the site already stands behind. Worth noting for the flat curves: in the same weeks, a research preview of a shared specification for AI agents to operate physical devices was opened to research labs and manufacturers. That is the first capability class pointed at the physical occupations whose lines here barely move. GPT-6 Astra(2026-09-03);Claude Fable 5.1 / Mythos 5.1(2026-09-01);Model Hardware Standard 研究预览(2026-08-27) (2026-09-03) ↗

A flat line is not a forecast of safety. It says which tasks automation has reached so far — the occupations that moved least here are the ones where the constraint is physical or regulatory, and both of those can change.

Recent changes#

No verified events recorded yet.

This section will fill from the monitoring pipeline as events are collected, de-duplicated, graded and linked to the tasks above. An empty list here means we have not verified anything — it does not mean nothing is happening.

"We found no news" is not the same as "you are safe."

What this means for you#

If you are starting out

The entry rung in this field is the alert queue, and it is the rung with the clearest automation mechanism pointed at it. That is a genuine problem for the profession and not only for you: the judgement senior analysts have was built by grinding that queue, and nobody has designed a replacement for it. Get to incident work early, and treat any team that lets you sit in on a real incident as worth more than a pay rise.

If you are experienced

Two numbers decide your team's future and both are yours to produce: the true-positive rate of your queue, and how many detections you retired last quarter. A team that cannot answer the second will find its tooling budget spent on generating more of what it already cannot read.

Your options#

Four directions, each with its real constraints and one thing you can test this week. Continuing as you are is a legitimate choice — it just has to be a chosen one.

Stay and strengthen

Move up the queue, not along it

The people who survive triage automation are the ones who tune what generates the alerts rather than the ones who read them faster.

Real constraints

Detection engineering is a different skill set that most SOCs will not train you in on shift.

Test this week

Measure the true-positive rate of the noisiest rule you have. If it is under one in fifty, you have found this quarter's project.

Reshape the role

Be the person who knows this estate

Every tool needs a baseline for normal and no vendor can supply one for your company. That knowledge is the input nothing can buy and it is what hunting runs on.

Real constraints

It makes you valuable to this employer specifically, which is leverage in a negotiation and a weakness in a job search.

Test this week

Try to write down what normal looks like for your busiest system in five sentences. If you cannot, that is the gap and it is yours to fill.

Common questions#

Will AI replace security analysts?

Triage is genuinely moving, and for a reason worth understanding: it is the same task as a guard watching camera feeds, and humans fail at it the same way — sustained vigilance collapses in about twenty minutes while software does not get bored. What is not moving is calling an incident, because that decision is made with authority rather than certainty and the cost of both errors is severe. The real risk to the profession is not replacement, it is that automating triage removes the rung where analysts' judgement was built.

How long do I have?

No date. The signal is the true-positive rate of your own queue and what share of your shift goes to alerts a system could correlate without you. Both are measurable this week. The organisational signal to watch is different and more predictive: whether your employer is talking about a managed service, because outsourcing moves this work without automating any of it and it arrives much faster than any tool.

If models write detection rules, is detection engineering safe?

Writing the rule is the cheap half and models do it well, because a rule is code with a testable output. Deciding what to detect is the other half and it depends on knowing what normal looks like in your specific estate — knowledge held by people and written down almost nowhere. The caution is that cheap rule-writing makes the false-positive problem worse, because the constraint was never the writing: a team producing ten times the detections has to be ten times more disciplined about retiring them, and almost nobody staffs for that.

Is threat hunting protected because it needs judgement?

Protected from automation, yes — hunting is defined by the absence of a trigger, which removes the input every detection tool needs. But it is the first activity cut when the queue is loud, because it produces no ticket and no metric. That is the pattern worth internalising: a task can be entirely human and still vanish from a team's week without anyone deciding to remove it, and in this occupation that is the usual way it goes.

Method and sources#

Assessment date
2026-09-14
Basis of the task judgements
0 evidence-backed · 4 platform inference · 0 not enough evidence
Verified events
0

How we assess an occupation →