I have a lot of people asking me ‘Will SOAR / Automation in general replace SOC/Cybersecurity Analyst jobs in X number of years’
My opinion - Simple answer, no.
Long answer, it is already (and will in all SOCs in the future) replace simple tasks such as copy pasting info
1/
From tools into ticketing platforms, sorting mailboxes, running scans on IOCs and things such as this. (Which in a lot of cases are currently classed as Tier/Level 1 analysts tasks)
It will not replace expert knowledge, such as in-depth analysis skills, remediating difficult
2/
Problems (Incident Response), threat Intel investigations / reporting, risk mitigation etc etc. The list goes on of tasks and skills which SOAR/Automation will not replace any time soon.
So don’t be worried - SOAR/Automation should be thought of as an assistant for us all
3/
That can get rid of the boring / repetitive tasks and leave us more time to do in-depth, difficult tasks which do not suit automation.
The number of Security/SOC Analyst jobs will continue to go up, there will just not be roles anymore where it is like “copypasta this info
4/
From X to Y, search these IOCs for me...”
So what can you do? Ensure you have good analysis skills, understand networking / sysadmin / cybersecurity well (Example for SOC Analyst) This applies to any role within cybersecurity - ensure you have a skill level above ‘click here
5/
click there etc’ The same applies to a vulnerability management role as an example, ensure you understand vulnerabilities, patching etc in depth rather than just running scans.
TLDR : Our jobs are safe, and automation is our friend. 😀
Interested on other peoples opinions on this however. Do you agree with me, do you think I am wrong?
• • •
Missing some Tweet in this thread? You can try to
force a refresh
Intel Owl (Threat intel data about a specific file IOC from a single API at scale) - github.com/intelowlprojec…
Cyber Chef (Web app for carrying out all manner of "cyber" operations within a web browser.) - gchq.github.io/CyberChef/
TheHive (Scalable Incident Response Platform designed to make life easier for SOCs, CSIRTs, and CERTs, featuring integration with MISP.) - thehive-project.org
CertSpotter (Alerts you when a SSL/TLS certificate is issued for one of your domains.) - github.com/SSLMate/certsp…