Loading
Comparison · dataset August 2026

Cybersecurity Analyst vs Security Engineer: which is more exposed to AI?

Cybersecurity Analyst carries 10 points more AI exposure than Security Engineer.

Cybersecurity Analyst sits at 50% time-weighted AI exposure against 40% for Security Engineer, a 10-point gap driven by the 28% of cybersecurity analyst work time that current models can already substitute outright. Security Engineer holds a larger human-critical core — 47% of the role's time sits in work like "advise leadership on risk acceptance" that models score poorly on. Both roles sit inside Computer & Math, so the exposure difference reflects task design rather than a change of field.

10PP GAP

Seven dimensions, side by side.

METRICCYBERSECURITY ANALYSTSECURITY ENGINEERDELTA
AI exposure50%40%10pp gap
Resilience score76/10076/1000pt gap
Substitutable work time28%19%Fully automatable today
Human-critical work time46%47%Models score poorly here
Median salary$108k$125k$17k apart
10-year growth32%30%Cybersecurity Analyst
US workforce168k170kBLS OEWS
Task level

What actually creates the gap.

Cybersecurity Analysts spend 28% of their time-weighted week on tasks a current model can produce end-to-end, against 19% for Security Engineers. The single largest contributor is "analyse security logs and alerts", graded at 82% and worth 18% of the role's time. That one task accounts for more of the gap than any difference in seniority, tooling, or industry.

Cybersecurity Analyst
MOST EXPOSED TASKS
  • Analyse security logs and alerts82% · 18% time
  • Write security reports and documentation74% · 10% time
HUMAN-CRITICAL CORE
  • Regulatory and compliance negotiation16% · 4% time
  • Security architecture design21% · 10% time
  • Incident response and containment24% · 18% time
Security Engineer
MOST EXPOSED TASKS
  • Generate security reports82% · 5% time
  • Run automated vulnerability scans78% · 6% time
  • Draft security policies74% · 4% time
  • Summarize threat intelligence72% · 4% time
HUMAN-CRITICAL CORE
  • Advise leadership on risk acceptance12% · 8% time
  • Respond to active intrusions15% · 16% time
  • Lead red-team exercises20% · 9% time
What transfers

Both roles lean on judgement, cognitive, procedural — that is the part of your experience that travels intact. Beyond that, the two capability profiles are unusually close: no dimension separates them by more than 15 points, which is why the switch difficulty below reads the way it does.

Switching between them
LowDIFFICULTY

Security Engineer appears in our dataset as a mapped adjacent career for Cybersecurity Analysts: the move lowers exposure by 10 points, landing at 40%. Switch difficulty reads low — capability profiles are 9 points apart on average and both sit in the same family.

Score your own exposure in 8 questions →

Common questions.

Is Cybersecurity Analyst or Security Engineer more at risk from AI?

Cybersecurity Analyst. It scores 50% time-weighted AI exposure against 40% for Security Engineer — a 10-point gap. 28% of cybersecurity analyst work time is already fully substitutable by current models, versus 19% for Security Engineers.

Which pays more, Cybersecurity Analyst or Security Engineer?

Security Engineer, by roughly $17k at the median ($125k versus $108k). Note that the higher-paying role here is also the less AI-exposed one, which matters if you are weighing pay against durability.

Can a cybersecurity analyst switch to being a security engineer?

Security Engineer appears in our dataset as a mapped adjacent career for Cybersecurity Analysts: the move lowers exposure by 10 points, landing at 40%. Switch difficulty reads low — capability profiles are 9 points apart on average and both sit in the same family.

Which role is growing faster, Cybersecurity Analyst or Security Engineer?

Cybersecurity Analyst, at 32% projected ten-year growth versus 30% — a 2-point difference. Growth and AI exposure are separate signals: a role can grow in headcount while the content of the work is substantially rewritten.

Career families
Computer & Math
Methodology
Scores are time-weighted across each role's canonical O*NET tasks, graded against current frontier-model capability. How we score.