TL;DR: The analysis of 665 US security operations job postings shows the SOC market shifting from queue-watching to pipeline-building, with 37% of roles now in engineering and automation families and 22.7% carrying active AI or automation requirements, according to D3. The hiring data suggests validation, detections-as-code, and mixed-stack fluency are becoming the durable SOC skills, not manual triage alone.
NHIMG editorial — based on content published by D3: The SOC Rebuild Index: 2026 Edition
By the numbers:
- The report coded 665 in-scope US security operations roles against a fixed rubric.
- 22.7% of postings carry an active AI or automation requirement.
- 67% of postings contain no AI language at all, even at the peak of the 2026 AI SOC news cycle.
Questions worth separating out
Q: What should security teams do first when rebuilding a SOC around automation?
A: Start by separating investigative, engineering, and approval duties.
Q: Why does AI-assisted SOC work still need human validation?
A: Because AI can summarise and prioritise, but it cannot be trusted to own final operational judgment without oversight.
Q: What are the signs that a SOC has become too dependent on manual triage?
A: The signs are flat compensation for queue work, few detection engineering roles, weak automation language in job descriptions, and too many people spending time on repetitive enrichment.
Practitioner guidance
- Re-segment SOC roles by control function Separate alert triage, detection engineering, automation engineering, and response approval into distinct role families so access rights match actual responsibility.
- Scope automation access with privileged identity controls Treat SOAR runners, API tokens, and cross-tool credentials as privileged identities, then restrict them with least privilege, logging, and approval gates.
- Build human validation into AI-assisted workflows Require analysts to verify AI-generated investigations before execution, and keep an auditable trail for every override, approval, and response action.
What's in the full report
D3's full report covers the operational detail this post intentionally leaves for the source:
- The full coding methodology for 665 in-scope roles, including the rubric used for AI requirement scoring and role-family classification
- Interactive charts showing pay bands, role mix, and tool-stack frequency across the SOC hiring dataset
- Quoted job-description excerpts for AI-enabled SOC, detection engineering, and validation roles
- The report's seven decision questions for platform and staffing planning across agentic SOC workflows
👉 Read D3's full SOC Rebuild Index 2026 analysis →
SOC rebuild index 2026: what the hiring data means for teams?
Explore further
The SOC is moving from human triage to governed automation, and that makes access control part of the operating model. The report shows the market paying for people who build and validate workflows, not only people who inspect alerts. That shift means identities attached to automation, detection engineering, and response orchestration now matter as much as analyst seats. Teams should read this as an access-governance problem as much as a staffing trend.
A question worth separating out:
Q: How should organisations govern access to SOC automation tools and AI workflows?
A: Treat them as privileged systems. Use role-scoped access, separate approval from execution, log every change, and review which identities can alter detections, launch playbooks, or approve machine-generated actions. That governance is essential when the SOC stack spans multiple tools and the same workflow can affect many systems at once.
👉 Read our full editorial: The SOC is being rebuilt around automation, validation and AI