You build the controls that analysts watch, which means your day is more tickets and pull requests than blinking alerts. The job sits between the security operations team and the engineers who own the systems, and a lot of it is persuading people to change things they'd rather leave alone. Here's a normal day at a mid-sized company with most of its workloads in the cloud.
You open the cloud security posture tool and the vulnerability scanner before Slack. Overnight, Wiz or Prisma Cloud flagged a storage bucket that went public and a handful of container images carrying a critical library flaw. You sort them: the bucket gets a ticket to its owning team right now, the images get grouped so one base-image fix clears most of them.
The security operations lead wants an alert for service accounts logging in from somewhere they never have. You write the query in Splunk or Microsoft Sentinel, run it against last month's logs, and find it would fire constantly because of a backup job. You tune it, add an exclusion with a comment explaining why, and push the rule through the same code review your developers use.
A developer pings you: a secret scanner in the CI pipeline found a live API key committed to a public repository. Lunch waits. You get the key revoked and rotated with the owning team, check the provider's logs for any use of it, and write up what you found. Most weeks something like this eats an afternoon you had planned for project work.
You're rolling out a policy that blocks new databases from being created without encryption. That means reviewing Terraform modules, writing the policy as code, and running it in warn-only mode first so teams see what would break. Two platform engineers push back on the timeline, and you agree to a longer grace period instead of forcing it.
A product team is launching a service that takes file uploads from customers. You sit in their design review, sketch the trust boundaries, and ask how uploads are scanned, where they're stored and who can read them. You leave with a short list of follow-ups in Jira and a note to check their IAM roles before launch.
Job boards blur these titles, so read postings closely. An analyst mostly watches and responds: triaging alerts, investigating incidents, escalating. You mostly build: the logging pipeline, the detections, the hardened images, the identity rules, the automation that closes a finding without a human touching it. If a posting talks about shift rotations and alert queues, it's an analyst job with an engineer title. If it asks for Terraform, Python and CI/CD, it's the real thing. The hardest part of the engineering version isn't technical. It's getting a team with a deadline to fix something that hasn't hurt them yet, without becoming the person everyone routes around.
This is the most common route. You already know what alerts look like and which ones waste time, so learn scripting and infrastructure as code, then start writing detections and automations for your own team before you ask for the title.
You already build infrastructure, so you add the security layer: identity and access design, logging, hardening baselines. Volunteer for the security findings nobody on your team wants and you'll have a portfolio within a few quarters.
Developers move into application and product security work: code review, threat modelling, dependency scanning, secure defaults in shared libraries. Teams with a lot of in-house code often prefer this background because you already speak the developers' language.
6% of openings are fully remote.
$109,210 – $180,126
Typical range in the 32 of the newest 60 postings that list pay.
Many postings list a degree, but plenty of hiring managers will take a strong infrastructure or SOC background instead. What they won't skip is proof you can build things: scripts, Terraform, detections, a home lab you can talk through in detail. A certificate like CompTIA Security+ helps you past early screens, and it doesn't replace hands-on work.
Often, yes, though it's usually lighter than an analyst's shift work. You'll be the escalation point when an incident needs someone who understands the infrastructure, like revoking access, isolating a workload or rolling back a change. Ask about the on-call rotation in interviews, because it varies a lot between teams.
More technical in the building sense. You'll write code and infrastructure changes most days, review pull requests and own systems in production. Analysts need sharp investigation skills, but you're expected to change the environment so the same problem can't come back.
HeroApply applies to them for you, so you can keep doing the job you have.