In a SOC Full of Agents, the Scarce Skill Isn’t Doing the Work. It’s Knowing What Good Looks Like.

For most of my career, the way you proved yourself in security operations was by doing the work. You closed the alerts. You pivoted across the email logs and the endpoint telemetry and the threat feed, you built the timeline by hand, you wrote the report. The analyst who could grind through a queue without missing the real signal in the noise was the one who got promoted. Doing was the job, and doing well was the proof.

That proof is quietly becoming worthless, and a lot of good people haven’t noticed yet.

The thing you were rewarded for is now the cheap part

Walk into an AI-augmented SOC in 2026 and the grind is mostly gone. The agent receives the alert, pulls the telemetry across identity, endpoint, cloud and email, correlates it, and hands a human a pre-assembled investigation with the likely next steps already suggested. The work that used to take a Tier 1 analyst twenty to thirty minutes per phishing alert now arrives mostly finished.

This isn’t a forecast. Swimlane and others are reporting AI resolving or escalating the large majority of Tier 1 alerts already, and Gartner expects autonomous AI to handle around half of all Tier 1 responsibilities within a couple of years. The mechanical skill, the thing the profession spent two decades selecting and promoting for, is the part that just got commoditised. Fast, cheap, tireless, and it doesn’t need a coffee break.

Here’s the trap. When the doing gets automated, the instinct is to ask “what can I still do that the machine can’t?” That’s the wrong question, and it leads people to cling to tasks that are already lost. The right question is sharper and more uncomfortable: can you tell the machine what a good outcome actually looks like, precisely enough that it can go and produce one?

Knowing what good looks like is harder than it sounds

That sounds easy until you try to write it down. Most experienced practitioners carry their standard of “good” as instinct, not specification. They know a real investigation from a shallow one the way they know a phishing email from a real one, on sight, without being able to fully articulate why. That tacit knowledge was fine when they were the ones doing the work. It’s a problem when the work is being done by an agent that only knows what you can tell it.

The agent will give you exactly what you specified, not what you meant. Ask it to “investigate this alert” and it will investigate, competently, generically, to nobody’s particular standard. Ask it to check whether this specific pattern of failed logins followed by a privilege change matches the three intrusion paths that actually threaten your environment, and tell you which evidence would rule each one in or out, and you get something else entirely. The difference between those two prompts isn’t prompt-engineering trickery. It’s whether you know, concretely, what a good investigation of that alert contains. The agent just exposes whether you ever really knew.

This is the part that should worry security leaders more than the automation itself. We have a generation of analysts who learned the trade by grinding the queue, and we’re removing the queue. The old apprenticeship, get good by doing the repetitive work until the judgment forms, doesn’t run any more.

The judgment was a byproduct of the grind, and we just automated the grind.

The skills we called “soft” were the hard ones all along

Look at what the agent is genuinely bad at, and you find the new centre of gravity. The recurring finding across SOC hiring in 2026 is striking: the hardest gaps to fill aren’t technical. ISC2’s research keeps naming communication, problem-solving, and tolerance of ambiguity as the scarcest qualities in technical hires. The things interviewers now test hardest are writing a clear incident summary for a non-technical executive, asking a stakeholder the right clarifying question, and making the judgment call the model couldn’t.

The shortage isn’t analysts who understand threats, it’s analysts who can interrogate the AI’s reasoning and catch the cases it quietly gets wrong. That is a different hiring profile than the one most of us built our teams around, and it rewards a person we have historically undervalued: the one who can articulate, not just execute.

Because that is the failure mode now. Not the analyst who can’t do the investigation, the agent does that. The analyst who nods at a confident, fluent, completely wrong agent report and passes it up the chain, because they never had a clear enough picture of “good” to notice it was “plausible but false.” The most dangerous person in an agentic SOC isn’t the one who can’t keep up. It’s the one who can’t tell when the machine is wrong.

What this means for the people you lead

So the development path for your team inverts. The career advice that held for twenty years, get fast at the task, was training people for the part of the job that’s now done by software. Here’s what I’d be building for instead.

  • Make the tacit explicit. Get your best people to write down what a good investigation, a good detection, a good escalation actually contains, in enough detail that an agent, or a junior, could follow it. This is hard, it surfaces disagreements you didn’t know your team had, and it’s the single most valuable thing they can produce right now.
  • Teach evaluation, not just execution. The durable skill is judging whether an output is good, fast, and saying precisely why it isn’t. Train people to red-team the agent’s reasoning, not just consume its output. An analyst who can find the flaw in a plausible-looking agent report is worth more than three who can generate one.
  • Hire for the questions, not the keystrokes. The certifications proved someone could do the mechanical work. Weight your hiring toward the person who asks the sharp clarifying question and can hold ambiguity without panicking, because those are the qualities the machine can’t supply and your standard of “good” depends on.

None of this is a story about AI replacing your people. It’s a story about which of their skills just changed price. The ability to do the work fell toward free. The ability to know what good looks like, and to say it clearly enough that an agent can deliver it, just became the most valuable thing in the room. The practitioners who thrive from here won’t be the fastest hands. They’ll be the clearest minds, the ones who can look at a finished piece of work and say, with precision, whether it’s actually any good. That was always the real skill. We just used to be able to hide it inside the doing.

Newsletter Form

Subscribe to our newsletter

Curated insights on AI's impact on information security and cyber warfare - real-world use cases and the critical skills your organization needs to stay ahead.


Related Articles

What Is NeMoClaw? Nvidia’s Answer to the AI Agent Security Problem.

An AI agent doesn’t answer questions. It takes actions, with your credentials, until a goal is met. That power went viral before anyone built the safety layer, and agents were soon confidently deleting people’s email. Nvidia’s NeMoClaw is the industry’s answer: sandboxing, least privilege, audit trails, which are the oldest principles in security, repackaged because the gold rush outran them.

Responses