Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Palo Alto Warns High-Severity Bug Is Being Actively Exploited

June 2, 2026

Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software

June 2, 2026

AI SOCs Will Still Need SOC Analysts, Security Vendors Say

June 2, 2026
Facebook X (Twitter) Instagram
Tuesday, June 2
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»AI SOCs Will Still Need SOC Analysts, Security Vendors Say
Cyber Security

AI SOCs Will Still Need SOC Analysts, Security Vendors Say

Team-CWDBy Team-CWDJune 2, 2026No Comments5 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Offerings of fully autonomous security operations centers (SOCs) are flourishing on the cybersecurity market and trigger anxiety about a future with empty desks.

In reality, however, top security vendors exhibiting at Infosecurity Europe 2026 actually agree on one thing: AI won’t replace the SOC. It will replace the mind-numbing copy-pasting and routine ticket-taking.

Speaking to Infosecurity, Brett Candon, VP of International at Dropzone AI, said AI is shifting the traditional multi-tiered SOC model into a leaner, smarter operation powered by accelerated ‘tier-1.5’ analysts and strategic engineers.

AI SOC: A Glass Box, Not a Black Box

Automation has promised to fix the SOC for over fifteen years, but vendors argue that true autonomy requires absolute transparency.

Candon emphasized that AI must be treated as a supportive “glass box” rather than a mysterious black box. The goal, he noted, is to replace heavy manual investigation work while logging every procedural step so human analysts can easily audit the machine’s rationale.

Patricia Titus, Field CISO at Abnormal AI, agreed that human-in-the-loop validation remains a non-negotiable safety net. Organizations still need sharp minds to verify that the machine is performing accurately.

“You actually need someone who understands that to be able to go back and analyze  the data periodically to make sure the tool, the AI tool, is actually catching what you want it to catch,” she said.

Furthermore, an AI is only as good as the security data infrastructure supporting it. Yonni Shelmerdine, chief product officer at Vega Security, pointed out that AI cannot bypass fundamental data architecture gaps. If critical security logs are frozen or filtered out due to high cloud storage costs, human engineering is required to fix the underlying pipeline.

Shelmerdine warned that if the data is gone, “no super-duper AI bot will be able to help.”

Intern Tier-1 and Professional Tier-1.5 SOC Analysts

Rather than eliminating entry-level professionals, this technological shift is entirely redefining their daily responsibilities, the three vendors told Infosecurity.

Instead of losing hours to repetitive data gathering, junior defenders are stepping straight into the role of what Candon called “tier-1.5 analysts,” acting as supervisors and auditors of AI-driven investigations from day one.

According to Candon, when AI handles tedious initial triage at machine speed, the human impact changes drastically. He noted that job satisfaction has increased and employees feel like they are doing more useful tasks within the SOC, allowing organizations to promote junior staff into specialized roles much faster than traditional timelines allowed.

Titus echoed this sentiment, noting that while tier-1 is traditionally where green SOC analysts “cut their teeth” on foundational security concepts, AI radically accelerates this onboarding period. Analysts can learn the basics significantly faster by reviewing and dissecting the automated workflows generated by an AI companion.

To operationalize this shift, Titus shared a practical blueprint from her own security team’s experience. After deploying Abnormal AI’s behavioral models, her team realized they no longer needed to hire five permanent, full-time “tier-1 ticket takers,” as she put it.

Instead, existing full-time staff were instantly elevated to handle high-risk, “truly tier-3 level investigations,” she explained.

Titus then transformed the remaining tier-1 responsibilities into a university intern program, bringing in college students to learn the grassroots basics of email security and behavioral analytics alongside the AI.

Titus strongly advocated against completely erasing entry-level roles, stating: “I think we would be foolish to eliminate tier-1 SOC analysts, largely because what happens if something happens and AI stops working, you need people to be able to go back to the grassroots and handle that tier-1.”

She explained that, by the time these interns graduate, they intimately understand how to audit AI systems and manage security posture, creating a direct pipeline of highly skilled full-time hires.

Emergence of A “Cyber Defense Engineer” Role in AI SOCs

As analysts climb the value chain, Vega’s Shelmerdine anticipates the rise of an entirely new industry archetype: the cyber defense engineer. Advanced defenders are increasingly shedding the passive analyst title to think of themselves as active system builders.

“AI isn’t going to replace the SOC, it’s a cyber defense engineer who will,” Shelmerdine said.

He described these modern professionals as engineers who control their SecOps platforms using advanced management protocols and natural language, effectively “vibe coding their queries, their hunts, their dashboards, their reports, [and] their triage.”

Rather than reacting defensively to an infinite queue of alerts, their daily focus shifts toward proactively engineering better detection postures and tuning AI tools.

Ultimately, the consensus across security vendors is clear: the autonomous SOC is not an empty room, but a significantly smarter one.

By stripping away the manual triage work that has plagued security operations for more than a decade, AI is acting less like a human replacement and more like a talent rescue mission, transforming burned-out ticket takers into strategic cyber engineers.

However, against a stark backdrop of sweeping corporate layoffs currently hitting the broader tech and cybersecurity sectors, it remains to be seen whether this idealistic vendor optimism will hold true or if economic pressures will ultimately tempt enterprises to sacrifice human expertise for pure automation.

You will be able to find Abnormal AI, Dropzone AI and Vega Security at Infosecurity Europe at Booths #D145, #E40 and #F160, respectively. Register for Infosecurity Europe here.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleLaravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer
Next Article Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software
Team-CWD
  • Website

Related Posts

Cyber Security

FSB Group Gamaredon Hides Worm in Windows Data Streams

June 1, 2026
Cyber Security

The Beginning of the End of Human Penetration Testing

May 29, 2026
Cyber Security

Microsoft Condemns “Uncoordinated” Zero Day Disclosures

May 28, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

AI-powered financial scams swamp social media

September 11, 2025

Look out for phony verification pages spreading malware

September 14, 2025

When ‘hacking’ your game becomes a security risk

October 17, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.