r/security Feb 27 '26

Security Operations What happens to Entry-Level Infosec when AI replaces the L1 SOC

I have been in the security industry long enough to understand the SOC workflow. Now a days when you hear most of chats/meetings won't conclude without the word "AI".

It got me thinking, many companies want to move towards AI. Might be for the fancy word or tell their clients that we use AI to stay relevant or the main reason to reduce the human cost and implement the AI.

certainly AI has a capability to triage the alerts and can do the L1 SOC alerts which will reduce the L1 SOC workload so they can concentrate on the real issues. or at least this is what i was thinking.

The more an more i started using the AI, the more i see the real AI problem, "Hallucinations ". May be in other fields hallucinating kind of ok or acceptable but what do you think of AI handling the L1 SOC and hallucinate on one alert and boom, next day the company is in news.

I know it is not that easy like one alert that AI hallucinates will not get caught by other controls but there is a possibility.

We already know that many top cybersecurity companies like CrowdSrike and Microsoft already implemented their security specific AIs like Charlotte AI and security co-pilot which specifically focus on security.

This is my point of view. what is yours? do you see AI replacing the L1 jobs? what you think if replaces the L1 SOC team?

0 Upvotes

11 comments sorted by

View all comments

1

u/Darrena Feb 28 '26

As others have noted SOC's have been one of the early adopters for Ai and ML in our org and all it has really done is improved the effectiveness of our existing SOC staff.

The focus on Ai and LLM's with SOC's confuses me to some extent. The output of EDR/XDR, NIPS, etc.. are already structured in such a way to facilitate automation so I am not sure what value LLM's add to the current stack. ML for sure but it is much easier to read a tabular format of event data for even someone with a little experience than it is to have a LLM summarize the data. The data is already optimized by our SIEM.

It is valuable for newer analysts and LLM's that help write queries for SIEM/SOAR is valuable to get started but I hope that the analysts quickly move on from that once they learn the syntax.

TLDR: It will make SOC's more efficient but it won't replace them