
Your SOC Has 10 Analysts. AI Is About to Make 7 of Them Redundant. Here Is What the Other 3 Need to Become.
AI is automating alert triage, investigation and response, and the SOC analyst's job is being redesigned around it. What the remaining roles have to become, and which skills to build before the transition accelerates.
Summary
- AI tools already triage and resolve much routine L1 alert work, handling 60-70% of that volume with higher accuracy than human analysts.
- The analysts who remain become threat hunters, incident commanders or security automation engineers, roles built on adversarial thinking, crisis judgment and systems skills.
- Indian MSSPs built on labour-cost arbitrage must reprice around outcomes and build scarce skills within roughly 3-5 years, before AI removes the work they sell.
The automation of routine security work is not coming. It is already here. The question is what happens to the humans on the other side of it.
Let us be precise about what is happening, because the conversation around AI and cybersecurity jobs tends toward two unhelpful extremes: panic (AI will replace everyone) and dismissal (AI is just a tool, humans are always necessary). Neither is accurate. What is actually happening is more specific, more immediate, and more actionable than either framing suggests.
A standard Security Operations Centre receives thousands of alerts per day. The majority are either false positives or low-complexity events that follow a predictable pattern: an unusual login time, a known malicious IP address, a file hash that matches a known malware signature. These alerts require a human to read them, apply a predefined decision rule, and either dismiss them or escalate them.
This is the work of a Level 1 (L1) SOC analyst. It is important work. It is also work that AI does better than humans, faster than humans, and without the attention fatigue that makes human alert triage increasingly inaccurate after the first two hours of a shift.
Microsoft Security Copilot can triage security alerts in seconds. CrowdStrike Charlotte AI can correlate signals across an enterprise environment and generate natural language summaries of what is happening and why it matters. Palo Alto's AI-driven XSIAM platform autonomously resolves low-complexity incidents without any human intervention. These are not future capabilities. They are deployed and in production at enterprise clients today.
The automation of L1 SOC work is not a future risk to model. It is a present reality to respond to. The question is not whether it will happen. It is what security teams and MSSPs do with the humans whose primary job was doing what AI now does.
What AI Can and Cannot Do in a SOC
What AI handles well today:
• Reading incoming alerts, matching against known threat signatures, and determining whether to dismiss or escalate. AI handles 60-70% of this volume with higher accuracy than human L1 analysts working at scale. Alert triage and classification:
• Connecting multiple low-level signals into a coherent incident narrative. What took a human analyst 45 minutes to piece together, an AI surfaces in under 2 minutes. Incident correlation: • Matching file hashes, IP addresses, and domain names against threat intelligence feeds. Fully automatable and already largely automated in modern EDR platforms. Known malware detection:
• Isolating an infected endpoint, blocking a suspicious IP, revoking a compromised credential. AI executes these faster and more consistently than humans. Automated response to defined playbooks: • Producing incident summaries, shift handover reports, and client-facing security briefings from structured alert data. Natural language report generation:
What AI cannot reliably do yet:
• Identifying attack patterns never seen before requires adversarial reasoning that current AI systems do not perform reliably. A skilled threat hunter who thinks like an attacker remains irreplaceable here. Novel threat detection: • When evidence is incomplete, contradictory, or deliberately obfuscated by a sophisticated attacker, human judgment remains superior. Contextualised judgment under ambiguity: • Explaining a breach to a board, managing stakeholder communications during an active incident, and making judgment calls about public disclosure require human judgment. Client communication and crisis management: • Designing attack scenarios, understanding attacker motivation and methodology, and probing defences from an offensive mindset are distinctly human capabilities. Adversarial thinking and red teaming:
The 3 Analysts Who Survive: What They Need to Become
If AI handles 60-70% of alert volume, a SOC that needed 10 analysts for the same client workload now needs 3-4. This is not a projection. MSSPs that have implemented AI-powered triage tools are already reporting analyst-to-client ratios improving from 1:5 to 1:15 or better. The 3 analysts who remain are doing fundamentally different work.
Profile 1: The Threat Hunter
The threat hunter does not wait for alerts.
She actively searches for evidence of adversary presence in environments that have not yet triggered any detection. She understands attacker tactics, techniques, and procedures (TTPs) at a level that allows her to hypothesise where an attacker might be hiding and then design the queries that would expose them. She uses AI as a research assistant, not as a replacement for her judgment. Required skills: MITRE ATT&CK framework expertise, proficiency in threat hunting languages (KQL, SPL, Sigma), familiarity with adversary emulation tools, and the adversarial mindset that formal certifications rarely produce. India has very few of these people. It needs many more.
Profile 2: The Incident Commander
When a serious incident occurs and automated response tools hit their limit, a human takes over the investigation, coordinates response across technical, legal, communications, and business teams, makes containment decisions involving business trade-offs, and manages the client relationship throughout. This requires technical depth combined with crisis management capability, business judgment, and communication skills that allow a security professional to explain a ransomware attack to a board in plain language while simultaneously directing technical containment. In India's MSSP context, this integrated incident command function is extremely rare.
Profile 3: The Security Engineer and Automation Architect
The AI tools automating L1 work do not configure themselves. They require engineers who understand both the security domain and the automation logic: who can write detection rules that minimise false positives, tune AI models on the specific client environment's baseline, build SOAR playbooks that automate response to the right scenarios, and continuously evaluate whether AI decisions are making the organisation safer or merely generating the appearance of security activity. This profile requires a combination of software engineering, security domain knowledge, and systems thinking that is currently rare and will become extremely valuable.
What This Means for MSSPs
The MSSPs that navigate this transition well will use AI to reduce their cost-to-deliver on existing clients, reinvest the savings in hiring and developing the three profiles above, and reprice their contracts around outcomes rather than headcount. The MSSPs that navigate it poorly will wait for clients to notice that AI platforms can replace their L1 analyst roster, and find themselves in a price war they cannot win.
The specific risk for Indian MSSPs is that their competitive advantage has historically been arbitrage: delivering analyst services at 40-60% of the onshore cost.
If global AI platforms eliminate the work that Indian L1 analysts were doing, the arbitrage disappears before Indian MSSPs have built the alternative differentiation that would allow them to compete on something other than cost.
The window to build that differentiation is approximately 3-5 years. The MSSPs that start now will have it when clients start asking for it. The MSSPs that wait will be discovering the problem at the same time their clients do.
For individual security professionals: the certification that matters in 2026 is not CompTIA Security+. It is GIAC's GCTI (threat intelligence), GIAC GCTH (threat hunting), or a demonstrated ability to build and maintain AI-augmented security operations. The L1 analyst role that most cybersecurity training programmes are producing graduates for will look very different in five years. The professionals who invest in the skills that AI cannot replace will find a labour market where their specific capability is scarce and extremely well compensated.
How useful was this article?
One tap. It tells us what to write more of.
About the author
SRF Capital Studio
The next one
Get what we publish next, by email.
Working notes on raising, borrowing, protecting, growing and structuring capital in India. One email a week at most, and you can leave any time.
We use your address only to send this. See our privacy policy.
We store your address to send you these emails and nothing else. See our privacy policy.
Related reading
Why the Cheapest Cybersecurity Decision an Indian SME Can Make Is Also the Most Expensive6 min read
3,195 Attacks Per Week. And Most Indian Companies Are Still Running Antivirus From 2019.6 min read
India Processes One-Third of the World's Security Alerts. Why Does It Still Import Its Security Thinking?6 min read
