■ MODERATE RISK ■ Technology
No — transformed, not replaced. Security is adversarial, and adversarial fields don't stabilize into automatable routines because the other side upgrades whenever you do.
“AI creates new attack vectors as fast as it patches old ones. This arms race needs humans on both sides.”
Our AI replacement risk score — how we score jobs
Security engineering spans a wide range: hardening infrastructure, reviewing code and architecture for weaknesses, running vulnerability management, building detection rules, investigating alerts, doing incident response when something gets in, managing identity and access, and arguing with product teams about why the shortcut they want is a bad idea. Add compliance evidence, threat modelling for new systems, and the occasional 4am call that a ransomware note has appeared on a file share.
Automation has already taken large bites out of the routine layer. Scanners and dependency tools find known vulnerabilities without human effort. SOAR platforms auto-triage and enrich alerts, closing the false positives that used to consume an analyst's shift. Models write detection rules, summarize malware behaviour, generate compliance documentation, and assist code review at a speed no human matches. Tier-one security operations analysis — the alert-queue job — is under genuine pressure and looks a lot like the help desk did five years ago. That's the part of the field with real displacement risk.
The reason our score sits at 35 rather than higher is that attackers get the same tools. AI-generated phishing is more convincing, exploit development is faster, and models themselves introduce new attack surface — prompt injection, poisoned dependencies, agents with over-broad credentials, data leaking through inference. Every capability that helps defenders creates work for defenders. Beyond that, security carries irreducible human elements: deciding an acceptable risk posture, threat modelling a system nobody has built before, running an incident where the response is as much legal and communications as technical, and being the accountable name when a regulator asks. Adversarial dynamics plus accountability plus a persistent talent shortage make this one of the more defensible technical careers — but the entry-level alert queue is not where that defensibility lives.
Automatability: our editorial assessment of current and near-term AI capability
Change is continuous rather than cliff-edged. Tier-one SOC analysis is being automated now and will be largely machine-handled within a few years. Senior security engineering, by contrast, faces rising demand through 2030 and beyond as AI systems expand the attack surface and regulation tightens. The realistic 2040 picture is a smaller junior tier and a larger, better-paid senior tier — a field reshaped rather than reduced.
Among the safer technical fields, which is why our risk score is only 35. Security is adversarial: as defenders automate, attackers automate too, so the work never settles into a stable routine that a model can fully absorb. The caveat is that entry-level alert monitoring is genuinely exposed, so early-career positioning matters more here than seniority-adjusted salary does.
Two ways. It makes existing attacks cheaper and more convincing — phishing at scale with fluent, personalized text, faster exploit development, and automated reconnaissance. And it creates new attack surface: prompt injection, compromised model supply chains, agents holding credentials broader than their task requires, and sensitive data leaking through inference. Both directions generate defensive work.
The tier-one version, largely. Alert enrichment, correlation, and false-positive filtering are pattern tasks that automation handles well and tirelessly. What survives is the analyst who investigates the ambiguous case, hunts proactively for threats nobody alerted on, and can reason about an attacker's intent rather than matching a signature. Plan to be that analyst quickly.
AI and machine learning security is the clearest gap — organizations are deploying models faster than anyone can secure them, and expertise is scarce. Cloud security architecture, identity and access management, and incident response leadership also hold up well. The common thread is judgment applied to systems that keep changing, rather than execution of a defined procedure.