Cybersecurity Analyst

You’re the detective: you catch the one real attack hiding in a thousand false alarms, and then you prove it. Demand is huge, and the routine first-pass sorting is automated now, so the edge is your judgment about which one is real.

Related: Software Engineer, Data Analyst, AI Application Builder

The day in the life

The pile · emails people sent in

6 sent in by staff this morning

  • every one of them sent in by a real person who thought it looked wrong
  • nobody has opened any of them yet, just the subject and who sent it

the pile, before you read a single one

I'll be right here the whole time, and nothing goes to my boss till you say so.

Six emails, and one of them might be a real trick. Where do you start?

Get the obvious junk out of the way firstRead all six carefully, no shortcuts

Try a day as a cybersecurity analyst

A short, playful taste of the real work.

Try it out
Where it’s going

One of the fastest-growing kinds of work, but the jobs you would start in are unusually hard to get.

Getting in

Most people do a job looking after other people’s computers first, then pass one exam to prove they know the basics.

Pay
Starting out$62-75KA few years in$85-115KExperienced$120-165K

BLS Information Security Analysts (SOC 15-1212, median $124,910, May 2024; +29% 2024-34; that median runs high because the same code covers the senior security engineer and architect roles analysts grow into); PayScale analyst-title experience bands (2026).

What you’d actually do

The picture is breaking into systems on purpose to test them, but that’s a separate track that’s harder to get into. The common entry job is defending: watching security dashboards, reading logs, and triaging alerts, which means sorting which ones are a real threat and which are false alarms, plus a lot of compliance paperwork.

That first-pass sorting is increasingly automated now. So the durable part is the investigation a tool can’t finish: hunting what it misses and judging what an attacker is actually trying to do.

  • Monitoring & alert triage45%
  • Investigation & response20%
  • Threat hunting & analysis10%
  • Tooling & automation10%
  • Reporting, strategy & meetings15%

Almost half the day is watching warnings come in and sorting the real ones from the false ones. That is exactly the part computers are starting to do.

Rough split, based on how the work is described. Varies by org.

“Cybersecurity” splits into a few very different jobs, from watching alerts to breaking in on purpose.

  • Watching for attackssitting on alerts in real time and deciding what’s actually a threat.
  • Responding to breachesshowing up after something’s been hacked, to contain it and figure out what happened.
  • Checking the rulesmaking sure a company actually follows the security rules it’s supposed to.
  • Breaking in on purposetesting a system’s defenses by trying to break into it yourself, with permission.

A typical early-career day

  1. 9:00Watch the dashboards

    Scan the stream of security alerts. Most are noise; the job is spotting the one that isn’t.

  2. 10:30Investigate a suspicious one

    Dig into an alert: real threat or false alarm? This is the core judgment call, made over and over.

  3. 1:00Document & escalate

    Write up what you found and route it to the right people. Careful records are a big part of the job.

  4. 2:30Trace what happened

    When something’s real, dig through the logs to reconstruct it, patient, detailed detective work.

  5. 4:30The first pass, sorted

    The first-pass alert sorting gets done automatically now; you hunt what it misses and make the calls it can’t.

A rough entry-level (SOC) day, often on-call. The flashy offensive-security work most people picture is a separate track that itself takes experience to enter.

The outlook

Where it’s going

Cybersecurity is one of the fastest-growing fields anywhere: the BLS projects about 29% growth, and there are hundreds of thousands of unfilled US openings. But AI is reshaping it from the bottom: it’s automating tier-1 alert triage, the classic entry job, so some teams are shrinking those roles. The value is moving up to hands-on investigation, threat hunting, and securing the newer systems themselves.

Right now

Here’s the paradox: demand is enormous and the talent gap is famous, yet the junior door is brutally hard. Entry jobs expect experience and certs you can’t easily get without a job, and the exact tier-1 work that used to be the training ground is now automated. The field is booming, but breaking in rewards demonstrated, hands-on skill and a clear specialty over a generic résumé.

Sources: BLS OOH Information Security Analysts (SOC 15-1212, May 2024); ISC2 2024/25 Workforce Study (global gap); SANS/GIAC 2026 (AI cutting tier-1 roles); CyberSeek US openings. Dated June 2026.

Would you actually like it?

Worth a look if you are patient, you notice small things, and you like working out whether an alarm means someone is really getting into the computers, or it is nothing.

In practice, people realize it’s their thing when…

  • they are patient and they notice small things: the one line that looks wrong in a screen full of what the computers did all day
  • working out whether a warning means someone really is breaking in, or nothing at all, feels like a puzzle
  • they stay calm under pressure and like having a clear, careful process
  • they are curious about how the people breaking in think, and how to stay a step ahead of them

…and it probably isn’t their thing when

  • they pictured dramatic break-ins: most of the job is watching, sorting the real alarms from the rest, and paperwork
  • they want an easy way in: the first job here is famously hard to get, because it asks for experience and passed exams at the same time
  • the first job is hard to get twice over: you need those exams before anyone lets you in, and deciding which alarms are real, the work beginners used to do, is exactly what computers now do

Catch a Phish: Investigate a Suspicious Email

Work a suspicious email the way the job really works: gather the evidence, spot the small things that give a fake away, and decide whether someone is trying to trick you, without being fooled and without scaring everyone over an email that turns out to be fine. Looking at the evidence and deciding, quickly and calmly when you cannot be sure, is what the people who guard a company’s computers do every day.

3-4 hours
Try it

Explore other careers

See all →