Get started

Job family

Assessing security operations

Roles that triage alerts, decide which ones are real, and contain the ones that are.

Security operations is the rare technical family where the labour market has explicitly reframed its own problem. For years the industry talked about a headcount gap. ISC2's 2025 study of 16,029 practitioners declined to publish a gap estimate at all, on the grounds that respondents now rate the shortage of specific skills as more critical than the shortage of people — while 88 percent reported at least one security consequence traceable to those skills gaps, and substantial minorities reported hiring freezes and budget cuts. In plain terms: the roles are open, the applications arrive, and buyers cannot tell from the applications who can actually do the work. That is a screening problem, not a supply problem, and it sits on top of 21 percent projected growth and roughly 14,100 US openings a year.

What separates a strong analyst is triage judgment under a high false-positive rate. The work is a queue of alerts, most of which are noise, a few of which are not, and the skill is deciding quickly which pattern deserves a second look, what evidence would confirm or kill the hypothesis, and at what point to escalate rather than keep investigating alone. The characteristic failures are directional: the analyst who closes real incidents as benign because the alert looked familiar, and the analyst who escalates everything and burns the organisation's tolerance for their pages. Both look identical on a CV, and both hold the same certifications.

Certifications are, in fact, the core of the status quo screen, alongside a CV filter on years of experience and a conversational interview about frameworks. ISC2's own research describes the mismatch: curricula and certification content are not keeping pace with applied practice in areas like cloud and AI security. A credential establishes that someone studied a body of knowledge. It does not establish that they can look at a suspicious authentication sequence and say what they would check next.

Savvanta's fit here is high because the entire investigative loop is text-and-conversation. Give the candidate a monitored environment containing log and alert data with one genuine incident and several convincing decoys, and watch the sequence of queries they run — the order of investigation is the signal, far more than the final answer. Then run a containment judgment scenario where isolating the affected host has a real business cost, and finish with a short spoken escalation to an AI stakeholder who is not technical and wants to know whether customer data left the building. One constraint must be stated plainly to buyers: this design assesses investigative and communication judgment. It cannot verify clearances, background checks or credentials, and should never be sold as if it does.

Why this work can be assessed

The job is investigation and escalation under noise — a monitored sandbox over log and alert data, a judgment scenario about containment, and a live briefing to a stakeholder reproduce nearly all of it without ever touching a real network.

Sources

Every figure on this page is traceable. Where a claim could not be sourced it is stated qualitatively instead.

  1. US Bureau of Labor Statistics, Occupational Outlook Handbook, Information Security Analysts, 2025, https://www.bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm
  2. ISC2, A Focus on Skills: the 2025 ISC2 Cybersecurity Workforce Study, 16,029 respondents, 4 December 2025, https://www.isc2.org/Insights/2025/12/a-focus-on-skills-isc2-workforce-study

Hiring for one of these? We build the assessment for the specific role, run it under your brand, and return a ranked list with the evidence behind every score.

Book a walkthrough