Security analyst (SOC) — how we know
The page itself gives the judgements. This one gives what they rest on: which technologies bear on the work, how the estimate moved since language models reached the public, and the method behind both.
Which technologies matter here#
Four separate signals. They are deliberately not added together — a job exposed to two technologies is not twice as exposed.
How it got here#
The index is not a static number. This is where it would have sat at each capability checkpoint since ChatGPT — reconstructed, and labelled as such.
—— this stretch contains a verified event- - - no event in this stretch — reconstruction only0 = no task exposed, 100 = every task exposed
● 3 verified events for this occupation, plotted at the date it happened — the parts of the line near a marker are anchored to something checkable.
The rise is one task, and it is the same task that lifts the security-guard curve on this site: working an alert queue is sustained visual vigilance, which humans fail at within about twenty minutes while software does not get bored — and correlation is machine-checkable in a way the rest of this job is not. It flattens because calling an incident is made with authority rather than certainty, and no organisation we can verify has delegated that. Two things the curve cannot show, both of which matter more than its height: the alert queue is where this profession hires, so automating it removes the rung senior judgement was built on; and outsourcing to a managed service moves this work without automating any of it, and arrives faster than any tool.
A flat line is not a forecast of safety. It says which tasks automation has reached so far — the occupations that moved least here are the ones where the constraint is physical or regulatory, and both of those can change.
Method and sources#
- Assessment date
- 2026-09-14
- Basis of the task judgements
- 2 evidence-backed · 2 platform inference · 0 not enough evidence
- Verified events
- 4