In my last few years working in capital markets, I kept asking the people around me the same question: “Does anyone else notice our jobs being automated?” I meant it as a real question, and mostly I got shrugs. I worked in sales, where large institutional clients called us to buy and sell bonds and derivatives, and the business often happened because of the relationship on the other end of the line. Then the screens started doing something new. You would see a trade come through that the client had placed on an electronic platform, shopping it to several banks at once, and they didn’t have to call you. Sometimes it was a miss, a trade the client had given to a competitor, and you learned about that from the screen too.
What I was watching, one ticket at a time, was the value of my relationships degrading in real time. Nobody announced it. The team still had its seats and the phone still rang, just less often and about less. I decided I needed a way out that nobody around me seemed to be planning, and I took it before the door closed. That was the first industry where I watched software absorb the work. Cybersecurity is the second.
Three Waves, and the Same Habit Each Time
We Are Automating the Job That Made Us argued that the people who came up through this work are the ones automating it, and the three waves below are the evidence. Security has been automating parts of its entry-level work in successive waves, and this is the third, a history that most of what I have read about AI and the profession leaves out. Each time, the savings were counted, and I have found no record of what that work had been doing for the people learning on it. This wave also goes further than the first two, because it automates the first look at each case it reaches, the moment when a new practitioner has to form a view of their own before anyone tells them the answer.
Compliance evidence is the wave that has run furthest. From about 2020, a new class of platforms turned control monitoring and evidence collection into something a company could subscribe to. The first year of a compliance analyst’s job (taking screenshots of configuration settings, chasing control owners for proof, and filling in security questionnaires) became a product. It ran on integrations and templates rather than agents, and the agents began arriving on top of it only in the last year and a half. I count it anyway, because it took the same kind of entry-level work from the same kind of person, and because it is the one case where we can look at the ending.
Offensive testing has moved over roughly the past eighteen months. According to a September 2026 industry review of these tools, agents now speed up much of what a new penetration tester used to bill for: reconnaissance, enumeration, generating payload variants, drafting the first write-up of findings, and part of the retest, the round of checking whether a finding still reproduces. Retest was close to pure new-practitioner labor, the work you gave someone in their first year because it was repetitive, bounded, and safe to get slightly wrong.
Detection and vulnerability work is going now, and in my view the sharpest change to entry-level work is in vulnerability management. A new practitioner’s week there used to be chasing system owners, cutting tickets, and reconciling one scanner’s output against another’s until the numbers agreed. That week is being handed to software now, and it draws a fraction of the attention that the security operations center and its alert queue receive. The alert queue is the loudest part of this wave and further behind than the noise suggests.
Detection’s wave started before either of the others, if you count the playbook automation of the late 2010s. In 2019 one of the largest security companies announced the purchase of an automation startup, citing its claim that the startup’s playbooks cut the alerts needing human review by as much as 95 percent. That was the buyer’s own number, and I know of no independent check of it, but it tells you what the industry believed it was buying. I count those playbooks as the opening of the detection wave, which makes the habit older than any of the dates above.
The Wave Nobody Measured
Go back to compliance, because it is the case that has run furthest. What happened to the people whose first year became a product? I went looking, and the honest answer is that nobody knows. I could not find a published series that counts the people doing compliance work in security specifically, so there is no before-and-after to read. Nobody measured what those new practitioners stopped doing, what they started doing instead, or what they learned along the way. A whole tier of entry-level work was reorganized over four years, and the field kept no record of what it cost the people doing it.
That is what the phrase I keep repeating means, and compliance is its cleanest example. The work at the bottom is being hollowed, not eliminated. The seat stayed, and compliance analyst roles are still advertised, but its first year was emptied one task at a time. Because the seat stayed, nobody went looking for what had left with the tasks.
The work at the bottom is being hollowed, not eliminated.
What the Machine Can Do Today
Start with offensive testing, because its results can be checked. A penetration-testing agent’s findings end up in public vulnerability records and bug-bounty ledgers where anyone can look, and those results are impressive and narrower than the headlines suggest. In one widely cited 2024 study, an agent given the published advisory for each of fifteen known vulnerabilities exploited 87 percent of them, and 7 percent without the advisory. A larger 2025 benchmark of forty real web-application flaws found the best agent setup succeeding about 13 percent of the time, even with a description of each flaw and five attempts. Both studies used models that have since been superseded, so the numbers will move, and the gap between 87 and 7 percent in the first study is the part worth remembering.
On the detection side, agents today triage alerts, gather the context around them, and take a narrow set of actions that a person approved in advance. That boundary is moving outward, carefully and under guardrails. What nobody has yet is an independent scoreboard. Offensive results are public and checkable, while claims about how accurately an agent triages alerts are, for now, reported by the people selling the agents. Until an independent scoreboard exists, read any vendor’s accuracy figure as a claim rather than a measurement.
Where Judgment Still Lives
What the machine does least well is the work that depends on judgment. The same industry review that documents the speed-ups in offensive testing notes that some vulnerabilities “require intuition, a deep understanding of the business and scope, and the ability to assess impact beyond a proof of concept,” and that these remain difficult to automate. Detection runs the same way. Whether an alert matters depends on what the business is doing this week, and whether an investigation has found something new depends on having seen enough of the old to recognize the difference. Whether an action is worth the disruption it causes is a call about consequences, and consequences belong to the people who answer for them.
Most experienced practitioners I know built that judgment in a similar way. They made calls on real cases, early and often, were wrong some of the time, and had someone more experienced show them what they had missed. The calls that built it were mostly ordinary ones, the hundredth case that turned out to be nothing and the hundred-and-first that did not, made by a new practitioner who had to commit to a view before anyone confirmed it. I would call the limits above durable, which is a different word from permanent, and the gap on novel threats is narrowing. The more pressing question is where the next generation makes those early calls if software is making them first.
Why This Wave Is Different
The playbook tools of 2019 ran a decision that somebody had already made. A person wrote the playbook, the playbook fired, and the judgment inside it was old judgment, captured once and replayed on every matching alert. Agents produce the reasoning fresh, case by case. The alert now arrives pre-triaged, already worked into a verdict with a tidy summary attached, and the person receiving it is asked whether they agree.
For as long as this field has existed, the case that reached a person arrived unresolved, and a new practitioner and an experienced one could both look at the same messy thing before anyone knew what it was. That shared first look is what this wave takes, and with it the first call a new practitioner used to make on their own. The agent now takes that look before either of them sees the case, and what it leaves behind is a verdict to accept or overturn. Reviewing a verdict and making the call yourself are very different experiences, even when the right answer is the same, and only the second one asks you to commit to a view before you know whether you are right.
Reviewing a verdict and making the call yourself are very different experiences, even when the right answer is the same, and only the second one asks you to commit to a view before you know whether you are right.
In We Are Automating the Job That Made Us I wrote that a seat losing three of its ten tasks is a different problem from a seat losing seven, and that which one we are in decides almost everything. I cannot tell you which one we are in, and neither can anyone else, because nobody measures the share of entry-level security tasks being automated. A task count also misses the stage this wave removes, the first look, which reaches all ten tasks at once. A seat can keep seven of its ten tasks and still lose the first look at every one of them, and the first look is where a new practitioner’s judgment begins.
A seat can keep seven of its ten tasks and still lose the first look at every one of them, and the first look is where a new practitioner’s judgment begins.
The Next Honest Step
If the case is being resolved before anyone sees it, the more useful question is who was doing the teaching in the first place, and whether they still can. That is the next issue, and I think the answer is more hopeful than the nostalgic one.
If you are trying to get in: before you apply, find out how far automation has reached into the work you are applying for. A compliance analyst role today is a different job from the one that carried the same title in 2019, and a vulnerability management role posted this month may describe work that is already moving to software. Ask in the interview how a new person on that team first sees a real case, and who is looking at it with them. A team whose entry-level work has already been automated can still be a good place to start, provided someone there has decided how new people will see real cases and make their own calls. A team in the middle of its wave is a bet worth making only with your eyes open.
If you are an experienced practitioner or you lead a team: list the entry-level work your organization has already automated, starting with compliance evidence, and next to each item write down what it was carrying besides the work. Some answers will be nothing, because a lot of that toil deserved to go. Some will be the only place a new practitioner and an experienced one ever looked at the same problem together, or the only place a new practitioner made a call of their own. You will not find that second column on any dashboard, which is the reason to write it down yourself. In my judgment more waves are coming, so the list is a standing job for whoever leads the team.
I watched one job move from the phone to the screen without anyone announcing it. As the first look moves to software, I would like us to write down where new practitioners will form their judgment instead.
— Oritse
A note on where I stand: I spent years running security inside large financial institutions, and I sit on the advisory board of a company building autonomous security tools, which is the category this issue describes. Nothing non-public, from anywhere I have worked, goes into what I write here.
Next: who was doing the teaching, and whether they still can.
