Visualização normal

Antes de ontemCybersecurity Blog | SentinelOne
  • ✇Cybersecurity Blog | SentinelOne
  • From Triage Grind to Strategic Operator: The New AI SOC Career Path Arijeet Ghatak
    AI is absorbing the volume work that makes up the fundamental architecture of the Security Operations Center (SOC) tier system. While the tiers and the work aren’t going away, a junior and senior analyst’s day-to-day is changing fast. At some point in the last week, every analyst on your team made the same call. Close an alert uninvestigated, because the queue was too long and triage ate the time real investigation and deep analysis was needed. Most of those calls were right, but odds are that a
     

From Triage Grind to Strategic Operator: The New AI SOC Career Path

22 de Julho de 2026, 12:00

AI is absorbing the volume work that makes up the fundamental architecture of the Security Operations Center (SOC) tier system. While the tiers and the work aren’t going away, a junior and senior analyst’s day-to-day is changing fast.

At some point in the last week, every analyst on your team made the same call. Close an alert uninvestigated, because the queue was too long and triage ate the time real investigation and deep analysis was needed. Most of those calls were right, but odds are that at least one critical threat will eventually be overlooked.

The root cause here is the mathematical disparity. Nearly half of SOC teams lack the capacity to investigate more than fifty percent of the alerts they generate daily. Analyst capacity grows linearly while data volume compounds exponentially.

According to findings from SentinelOne®’s Annual Threat Report, what’s worse is that the math leans heavily towards the adversaries. Automated exploits have been recorded escalating privileges within a target environment in approximately 30 milliseconds. Similarly, malicious attack chains can progress from initial network access to establishing persistent footholds in under 50 seconds. No manual workflow currently matches these kinds of machine speed tempos.

As a result, the traditional tier structure of the SOC is transforming in real time. AI is already absorbing the triage and correlation work that that structure was originally built to manage. The critical call-out here is understanding that these tiers are not dissolving; rather, they are evolving. Junior and senior analysts still exist and hold their titles, and continue to have a clear career path ahead of them. What’s changing is the nature of the tasks that fills their day.

Analyst Tiers, Redefined by Depth

Historically, the distinctions between Level 1, Level 2, and Level 3 analysts were established primarily to manage high-volume workloads. Those distinctions were built to manage volume: Alerts routed to the right skill level, junior analysts escalating what they couldn’t resolve, senior time reserved for what actually needed it. AI now handles the triage and correlation volume those tiers existed to manage. Volume stops being the variable that defines the role. As a result, analyst tiers are being redefined by depth of expertise rather than the ability to process large queues.

That evolution isn’t limited to junior and senior analysts:

  • Threat intel analysts move from manual feed correlation to directing AI-correlated intelligence
  • Security engineers move from manual rule-writing to guiding AI-generated detection logic
  • SOC managers move from tactical management to strategic leadership and AI governance

Depth of expertise replaces volume as the key differentiator: cloud architecture, identity, adversarial tradecraft. The kind of judgment that only comes from watching an environment long enough to know what normal looks like. AI can’t replicate nuanced, environment-specific skills that the legacy, volume-driven tiered system was never able to encourage or reward.

A Day in the Life, Before and After

In the legacy model, an analyst’s day typically begins by facing a queue containing hundreds of unvetted overnight alerts. Three or four hours go to manual triage, pivoting between tools to reconstruct what happened. The vast majority of the queue closes as false positives. The real threat, if there is one, surfaces hours later, pieced together across five or more disconnected consoles.

Adding in the administrative paperwork widens the gap even further. The legacy model requires analysts to spend upwards of an hour writing an incident report that adds nothing to the actual technical investigation. The new model allows the analyst to review and approve an AI-generated summary, adds environment-specific context, and closes the case in minutes.

In a modern model, the day starts with a prioritized queue instead of a noise wall: evidence-backed verdicts already assembled, ready for review. Thirty minutes go towards confirming the highest-priority case. That confirmation triggers a pre-approved response workflow within defined policy. Critical hours that were parcelled off to triage are used for proactive threat hunting instead.

Teams operating this way report the difference in hard numbers, according to two IDC research studies commissioned by SentinelOne.

  • Teams using AI-powered investigation report 63% faster threat identification and 41% more efficient investigation. (IDC Business Value of Purple AI®, July 2025)
  • AI SIEM customers on the Singularity™ Platform report 55% more efficient security operations and 4x more threats handled, at 55% lower solution costs. (IDC Business Value of Singularity AI SIEM, May 2026)

That time moves to where the judgment actually matters.

Governance is the New Core Skill

Recovered time only pays off if real judgment fills it. The most important judgment now is knowing when to distrust the AI.

The analyst who knows exactly where their AI is unreliable is more operationally effective than the one who trusts it uniformly. That skepticism is a skill and it has to be built on purpose, case by case.

Four capabilities define the analyst role going forward:

  • Validating AI output instead of accepting it by default
  • Designing the automation workflows that execute at machine speed
  • Forming hypotheses worth hunting instead of only answering tickets
  • Translating what the AI found into what it means for the business

Escalation frameworks must be designed to reflect that same judgment. Teams building trust in a new workflow route more cases to a human by default. Mature teams narrow that escalation path as their confidence in specific alert types grows. Either way, the analyst decides where the line sits, not the AI.

On top of this, analysts must govern the response earlier, setting the policy before events are triggered instead of reacting to it. Every automated action is scoped to a policy an analyst defined in advance. This keeps all of the details of the logged and fully auditable after the fact. The quality of what fires automatically traces back to the quality of that workflow.

The Career Path Forward

The evolution we are seeing in SecOps is directly addressing systemic issues of burnout and attrition, both significant risks to retaining talent within the cybersecurity industry. Under an AI-augmented model, every rung on the SOC career ladder gets more strategic:

  • Junior analysts move from manual triage to verdict review
  • Senior analysts move from reactive response to strategic hunting
  • Managers move from daily firefighting to designing the system everyone else works inside

None of this happens in one leap. Adoption works crawl-walk-run, workflow by workflow. ‘Crawl’ starts with AI-assisted triage, validated against your own judgment, alert by alert. ‘Walk’ enables automated responses for well-understood, lower-risk cases, with human approval required for anything novel. ‘Run’ hands full workflows to AI for established threat patterns, with analyst time going to verdict review and hunting. Different parts of a SOC can sit at different stages of that maturity at the same time.

Start with the First 90 Days in the AI SOC checklist, a concrete plan for the next ninety days. For the full argument behind it, check out the Analyst’s Guide to the Autonomous SOC and see how SentinelOne is building toward this model.

Third-Party Trademark Disclaimer:

All third-party product names, logos, and brands mentioned in this publication are the property of their respective owners and are for identification purposes only. Use of these names, logos, and brands does not imply affiliation, endorsement, sponsorship, or association with the third-party.

  • ✇Cybersecurity Blog | SentinelOne
  • From Access to Execution: Securing Identity in the Age of Autonomous Agents Arijeet Ghatak
    The definition of identity is expanding. Employees are no longer the only actors – or ‘workers’ – inside enterprise environments. Service accounts, APIs, workload identities, and increasingly autonomous AI agents are now executing actions on behalf of humans and systems at machine speed and scale. This is the next generation of identity and its risks. At SentinelOne®, we believe identity security must evolve to meet this reality by going beyond static gatekeeping. It must validate behavioral int
     

From Access to Execution: Securing Identity in the Age of Autonomous Agents

25 de Fevereiro de 2026, 11:00

The definition of identity is expanding. Employees are no longer the only actors – or ‘workers’ – inside enterprise environments. Service accounts, APIs, workload identities, and increasingly autonomous AI agents are now executing actions on behalf of humans and systems at machine speed and scale. This is the next generation of identity and its risks.

At SentinelOne®, we believe identity security must evolve to meet this reality by going beyond static gatekeeping. It must validate behavioral intent, ensuring protection is a continuous evaluation of what happens after access is granted.

The Authorization Gap

Many security frameworks focus heavily on the moment of authentication. The focus has long been on stronger gates: we see this in the push towards tighter governance and more granular permission models – these controls are fundamental. But authentication alone does not validate intent, and authorized access does not guarantee safe behavior.

A user can be fully authenticated and still perform reconnaissance, exfiltrate data via a browser, or feed proprietary code into a GenAI tool. A service account or AI agent can be correctly provisioned and still be used for lateral movement. Once access is granted, traditional identity controls assume legitimacy, and that assumption creates an authorization gap: a blind spot between who is allowed in and what they actually do once inside.

As the industry explores centralized broker models for agents and non-human identities, one principle remains constant: authorization alone is not sufficient. Access must be continuously validated and, when necessary, withdrawn at runtime. SentinelOne’s execution-first architecture is designed to ensure that even approved actions remain bounded by real-time behavioral guardrails within the execution layer, where intent turns into observable technical behavior. Our approach is an end-to-end execution defense that spans endpoints, browsers, and AI workflows to stop misuse as it happens. This creates a security model that ensures defense is defined by session behavior, not simply initiation.

The New Execution Surface

In the modern enterprise, the browser has become one of the most important operating environments. It’s where SaaS applications run and where cloud infrastructure is managed. At the same time, it’s operating alongside rich endpoint software, including local AI workloads and integrated development environments (IDEs) – all contributing to a complex digital footprint. Consequently, it’s also where identity risk increasingly manifests. Browsers now represent sophisticated execution surfaces where users (and attackers) interact with company secrets and sensitive intellectual property. Misuse shows up in interaction patterns, prompt content, and data movement across tools.

SentinelOne secures this surface through recently acquired Prompt Security, monitoring the execution signals that define modern work. This approach avoids the friction of specialized enterprise browsers or the instability of JavaScript virtualization, both of which can increase operational complexity and expand the attack surface. By delivering native inspection within the browsers enterprises already use, we enable security that is seamless, flexible and unobtrusive, allowing organizations to protect AI-driven workflows without disrupting user choice or productivity.

And because Prompt is deeply integrated within the Singularity™ Platform, browser and AI execution is correlated with identity context and endpoint telemetry. This unified view reveals how an identity is interacting with AI tools and web applications. When activity begins to drift into malicious behavior, the platform identifies the shift and autonomously mitigates risk in real time.

Identity Beyond Humans: Securing Non-Human Execution

Identity today extends far beyond employees – non-human identities (NHIs) are now one of the fastest growing and most critical areas in identity security. Service accounts, APIs, workload identities, and increasingly autonomous AI agents are executing actions across cloud, SaaS, and AI environments. These NHIs often operate with persistent privileges, broad access, and limited visibility. As organizations automate more workflows and adopt agentic AI systems, NHIs represent one of the fastest growing and least understood attack surfaces.

Traditional identity solutions were built around human users and their authentication lifecycles. That model does not translate cleanly to machine identities – NHIs are ephemeral, programmatic, and operate at a scale that far exceeds human activity. Superimposing human-oriented controls onto an ever expanding population service accounts and AI agents is neither scalable nor sufficient. Securing NHIs requires a different paradigm defined by a fundamental shift from authorization to behavioral validation.

SentinelOne is already protecting non-human identities through that lens. Within Singularity Identity, we provide a first-class inventory of service accounts and workload identities, applying identity security policies, detections, and posture checks purpose-built for non-human misconfigurations and misuse. On the AI front, Prompt Security extends visibility into emerging agentic AI activity and MCP monitoring. Through our agentic AI discovery capabilities – now in beta – organizations can identify autonomous AI identities interacting with enterprise systems, bringing clarity to a rapidly expanding class of machine actors.

These capabilities reflect a broader execution-first principle: non-human identities should be evaluated not only by what permissions they hold, but by how they behave over time. As automation accelerates, cohesion across human and non-human identity controls becomes essential. Aligning inventory and detection & response into a unified NHI control model is a natural next step in extending execution-based security across all identities operating in the enterprise.

Meet the New Singularity Identity: Simplified, Unified, Powerful

To support this evolution toward execution-based security, we are introducing the next chapter of our identity portfolio with the general availability of three critical capabilities across our unified identity protection experience, which spans on-premises and cloud identity providers:

  • Policy-based Conditional Access: We are moving beyond static rules. This provides the granular, real-time control necessary to ensure that access is a living evaluation based on defined conditions across human and non-human identities.
  • Compromised Credential Protection: We are stopping attacks before they even hit the front door by proactively identifying and neutralizing credentials that have been exposed in the wild.
  • A Unified Approach to Identity Protection: This evolution is mirrored in our new streamlined portfolio. We have consolidated all of our identity capabilities into a single, unified solution: Singularity Identity. By bringing our identity innovations together into one comprehensive layer of the Singularity Platform, we have made it simpler for organizations to deploy the high-fidelity behavioral signals and autonomous containment required for modern defense – and to validate identities, not just authorize them.

But this launch represents more than a packaging update. It reflects a broader strategy that extends beyond traditional identity boundaries across the Singularity Platform. Prompt Security empowers visibility into browser activity, interactions with SaaS-based AI platforms, and emerging agentic AI behavior. This ensures that identity context is not confined to authentication events or directory objects, but enriched by real execution signals across AI and web workflows.

One Platform, One Continuous Execution Fabric

Modern attacks unfold across identities, browsers, endpoints, AI tools, and automated workloads. Securing authorized paths requires continuous validation across all of them.

As agentic AI proliferates, non-human identities now vastly outnumber human users. Every AI agent requires credentials, permissions, and governance. Traditional identity platforms were designed for human users and static service accounts, not autonomous agents executing and disappearing in milliseconds.

While human identity requires continuous verification of who is acting, non-human identity requires continuous verification of intent – whether a service account or AI agent is performing the actions it is supposed to, based on expected behavior patterns. Authorization alone cannot provide that validation, as a compromised non-human identity may still hold valid credentials and appear authorized, yet its behavior can deviate from its intended purpose. This creates the gap between access and safe execution. In practice, the framework splits: human identity is continuously verified for authenticity, non-human identity is continuously validated for intent, and both feed attribution and accountability across the enterprise.

SentinelOne’s architecture is built for this evolution. Grounded in execution, SentinelOne delivers end-to-end visibility and response across both human and non-human activity:

  • Singularity Identity provides critical context for who or what is acting
  • Prompt Security surfaces misuse within the browser and AI tools
  • Singularity Endpoint validates behavior at the system level

Together, these capabilities form a continuous execution fabric, correlating activity across human and non-human identities, applications, and devices. SentinelOne is the only major platform delivering immediate, complete GenAI visibility and data protection at the point of every employee interaction on every managed device – all deployable without SASE rearchitecture or API-level code changes.

In an era where sophisticated threats are hiding behind legitimate access and automation is accelerating machine-driven activity, enterprise resilience depends on securing execution itself – at machine speed. SentinelOne is transforming identity from a static gate into a continuous engine of behavioral validation – securing the integrity of every action taken within the modern enterprise, whether initiated by a person, a service account, or an AI agent.

Ready to explore the new features?

Take the next step in securing your execution layer. See Singularity Identity in action against real-world attack scenarios. Contact us or request a demo to get started.

Existing identity customers can talk to their account manager for more information about the new Singularity Identity and its expanded capabilities.

❌
❌