No. 15 / 339
What happens to junior security hiring when AI eats the entry-level triage rung?
The shift
Tier-1 SOC triage — reading an alert, pulling context, deciding escalate/dismiss — is high-volume pattern-matching against precedent, which is exactly what current models do well and cheaply: correlate a SIEM alert against threat intel, prior tickets, and asset context, and draft a verdict in seconds. AI doesn't just help junior analysts do triage faster — it makes the triage pass itself abundant, collapsing the queue that used to require headcount to work through.
The axioms
- Tier-1 exists as a separate role because alert volume was too cheap to generate and too expensive for senior people to personally review — rests on human attention being the scarce gate on alert-to-decision throughput.
- Junior hires learn judgment by doing thousands of boring triage reps first — there's no shortcut to pattern recognition except volume of repetition (the apprenticeship model). Rests on judgment being built through reps, and reps being the only route to it.
- Junior roles double as a cheap screening mechanism — you hire cheap labor to find out who's actually good before investing senior salary in them. Rests on signal-from-noise being expensive to determine any other way.
- Tier-1/Tier-2/Tier-3 is split by task because Tier-1 logic is codifiable and mechanical while Tier-2/3 requires context and stakes-aware judgment. Rests on a real gap between mechanical pattern-matching and judgment under ambiguity.
- Certifications plus a stint in Tier-1 are the trust proxy employers use before handing someone access to production systems and incident authority. Rests on trust being slow to build and needing an observable, time-consuming proxy.
- Headcount is pyramid-shaped (many juniors, few seniors) because junior labor is the affordable way to buy triage throughput. Rests on junior labor being the cheapest available unit of throughput.
Invalid axioms
- Tier-1 exists to absorb alert volume senior staff can't personally review. AI made first-pass triage abundant — near-zero-cost, second-latency correlation against precedent and threat intel. The habit-trap: SOCs still budget and staff a standing Tier-1 shift roster sized for manual queue-clearing, when the queue-clearing itself is now a solved throughput problem. The job that's left is reviewing what the model flagged as ambiguous or high-stakes, which is a smaller and different job than "work the queue."
- Junior headcount is the cheapest way to buy triage throughput. Labor cost is no longer the constraint on throughput — compute is, and it's far cheaper per alert than a salary. The habit-trap: pricing and headcount planning that treats "we need N more bodies to clear the backlog" as the lever, when the backlog itself shrinks by an order of magnitude before headcount enters the conversation.
Unchanged axioms
- Judgment on ambiguous, high-stakes calls is built through repetition. AI can draft a verdict, but deciding whether a novel, oddly-shaped incident is a false positive or the start of a breach — with business and legal consequences riding on the call — is exactly the "no pattern to match" case models are weak at. That judgment still seems to require having personally sat with enough real incidents to develop instinct for what's off. The open question is whether reviewing AI-drafted triage at volume builds that instinct as well as doing the triage manually did — nobody has run this cohort long enough to know.
- Someone accountable has to sign off before access is granted or an incident is escalated to the business. A model can draft the verdict; it can't be the party liable when the call is wrong, and regulators, insurers, and boards want a named accountable human. This doesn't shrink — if anything it concentrates onto fewer people reviewing more model output, raising the stakes per reviewer.
- Trust to act on production systems is still earned slowly. Handing someone credentials to touch live infrastructure or make containment calls is a trust decision, not a knowledge-test decision. AI collapses the time to competence on paper; it doesn't collapse the time an organization needs to watch someone perform under real pressure before trusting them with authority.
New axioms
- How does anyone become a senior analyst if the rung that used to build seniority is gone? The apprenticeship model assumed thousands of low-stakes reps before someone touched a high-stakes call. If AI absorbs the low-stakes reps, the pipeline that manufactures Tier-2/3 judgment has no obvious replacement — and nobody has designed the alternative training path yet.
- Confidently-wrong triage at volume is a different risk profile than a slow human backlog. A human Tier-1 queue that falls behind is a visible, boring risk (alert fatigue, missed items sitting in a queue). An AI clearing the same queue at 100x speed with a plausible-but-wrong dismissal is a silent risk — the alert doesn't sit unresolved, it gets closed with a confident rationale attached. Detecting systematic AI mis-triage requires a different kind of audit than detecting an overworked human backlog, and most SOCs don't have that audit built.
- Entry-level hiring used to double as a screening filter for who's worth investing senior salary in — what replaces that filter? If there's no cheap job to observe candidates in, employers lose their lowest-cost way of finding out who has good instincts before paying senior wages for them.
Where it breaks
Cut Tier-1 headcount because AI now clears the queue (INVALID #1), and you've also cut the only pipeline that trains someone into the Tier-2/3 judgment role AI still can't do (NEW #1) — the org saves on junior salaries this year and finds itself with no bench of trained seniors in five. Nobody is currently pricing that trade; it shows up as a hiring-budget win now and a capability shortage later, on a timeline too long for anyone to trace back to the triage cut.
Related axioms
Cybersecurity
What changes for cybersecurity with AI?
Cybersecurity
Who's liable for a breach an AI security agent missed or misclassified?
Cybersecurity
How does a CISO's risk calculus change when both attackers and defenders run autonomous AI agents?
Cybersecurity
Does human penetration testing still matter when AI can run continuous automated red-teaming?
Cybersecurity
Is the Tier-1 SOC analyst job already gone now that AI triages the alert queue?
Cybersecurity
Is human threat-intelligence analysis still worth doing manually, or is AI synthesis good enough now?
Other axioms
Engineering
Is the blameless postmortem still meaningful when the responder was an AI agent, not a person?
Industries
What changes for upstream oil and gas with AI?
Hospitality
Is the human travel agent obsolete for complex, multi-leg trip planning, or does the job just move to handling what AI itineraries get wrong?
Finance
What changes for finance and banking with AI?
HR
What changes for HR with AI?
Retail
Do we still need a human styling/personal-shopper role when AI recommendation is free and personalized?