◆ Cybersecurity

What a cybersecurity analyst
really does.

20 tasks, each one witnessed by the sources that watched the job — and behind every one, a prompt you can use tonight.

20evidenced tasks
190,650in the US (2025)
$129,180median pay / year
8systems it runs on
This is what one task looks like here
Ensure compliance with relevant laws and standards
Confirm our controls map covers GDPR, PCI-DSS, and NIST 800-53 for the…2 sources agree

The shape of the day

tap a movement to see its tasks

Which one is you, right now?

Pick the moment · no score, no sign-up
Which moment is you right now?
Whichever you pick, the task behind it opens below.

The work, task by task

20 tasks
Hands on the work12
Ensure compliance with relevant laws and standards+
Confirm our controls map covers GDPR, PCI-DSS, and NIST 800-53 for the payments platform, list gaps with evidence and legal citation, and prepare a one-page remediation plan for the CISO by next Wednesday.
jdwiki2 agree
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
Implement security measures to protect data+
Harden the data access layer by enforcing least-privilege for the finance ingest pipeline, rotate keys that are older than 90 days, deploy the approved firewall ruleset to the staging environment, and open a change request for production deployment on Friday.
jdonetwiki3 agree
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
Design and implement security policies+
Draft and publish a role-based security policy that limits trading-data access to the analytics team, include audit requirements and breach response steps, circulate to Legal and Compliance for sign-off by Thursday, and update the access control matrix.
jdwiki2 agree
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
Analyse financial risk+
Run a systemic analysis of our exposure to market-driven cyber fraud over the past 12 months: pull traded-instrument transaction logs, map breaches to dollar losses per quarter, quantify likely tail losses under a 1-in-100 shock, and produce an executive one-page risk brief for Friday.
esco
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
Stock market+
Produce a market surveillance report correlating unusual login and trade patterns with price movements for the last six months: extract trades, user session anomalies, compute abnormal return windows, flag top five suspicious tickers with suggested containment actions by Wednesday.
esco
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
Coordinate implementation of computer system plan with establishment personnel and outside vendors.+
Arrange and lead the implementation meeting with facilities IT, procurement lead Sarah Ortiz, and vendor SecureWave next Tuesday, agree deployment windows, device access, rollback plan, and who will validate each milestone.
onet
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
Manage vulnerabilities and system hardening+
Run the vulnerability scan results, prioritise remediation by risk and exploitability, apply system hardening templates to high-risk hosts, and record configuration baselines for audit before Friday close.
jd
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
Help users install and learn security products+
Prepare step-by-step install guides and host three 45-minute training sessions next Wednesday for staff to walk through the new endpoint protection features, capture common questions and follow-up actions.
jd
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
Grow the practice4
Watch and assess2
Work with people1
Keep the record1

What the work runs on

named inside the evidenced tasks
7 tasksAnsibleorchestrates configuration checks and gathers evidence across servers for compliance reporting
5 tasksApache Kafkadelivers and tracks training notifications and simulation events to multiple endpoints in real time
3 tasksApache Hivedefine and enforce data access controls and prepare audit queries over large datasets
3 tasksApache Hadoopprocess and analyse large-scale logs and configuration data for audit evidence
2 tasksAmazon Web Services AWSmanage cloud identities, key rotation, and staging environment resources
2 tasksAmazon Redshiftstores and queries large transaction and log datasets for time-series and aggregation analysis
1 taskApache Mavenpackage and deploy policy enforcement components where needed
1 taskApache Cassandraquery distributed configuration and account metadata during the audit

The same task, four heights

this page is height one
ExecuteDo today's task, with fewer mistakesyou are here → ImproveMake it easy for the next person to acceptin the atlas → DecideWork out the right move when it is unclearin the atlas → BecomeLearn the pattern so it stops coming backin the atlas →

Can AI actually do this job?

the honest answer

It can

where it genuinely helps
  • Explain the theory behind the work
  • Draft, tidy and structure your writing
  • Rehearse a hard conversation before you have it
  • Build a study plan that fits your gaps

It cannot

where it stops, completely
  • Be in the room where a cybersecurity analyst actually works
  • Carry the responsibility when the call is wrong — that weight stays yours
  • Notice what no one wrote down: the hesitation, the thing left unsaid
  • Live with the outcome

What the work pays

two countries, two different measures

United States

this exact occupation · BLS 2025
  • $129,180 a year — the middle: half earn more, half earn less
  • The lowest tenth earn near $75,090; the top tenth near $199,850
  • 190,650 people employed in this occupation

Where the evidence lives

open any of it yourself

Close to this work

4 nearby
CybersecuritySoc Analyst20 evidenced tasks CybersecurityPenetration Tester20 evidenced tasks CybersecuritySecurity Engineer20 evidenced tasks CybersecurityDigital Forensics Analyst20 evidenced tasks

Questions people actually ask

You usually split the day between monitoring and project work. Morning: check AWS CloudWatch, intrusion alerts, and Apache Kafka logs for unusual spikes or failed auth attempts.

Afternoon: patching and hardening (Ansible playbooks to update servers), meetings with devs about Apache Hive/Hadoop access controls, and writing or updating incident response steps if you found anything suspicious. Expect routine user help for security tools and one audit or compliance task each week.

Start with Ansible for automation and patching — most teams use it to push configuration and fixes at scale. Learn basic Linux shell, SSH, and how Ansible playbooks apply changes.

Next, learn how to read logs from Apache Kafka and AWS services (CloudTrail, GuardDuty). Familiarity with Apache Cassandra, Hadoop, or Redshift helps if the employer stores big data, because you need to know how to restrict access and encrypt data.

A network administrator focuses on routers, switches, and daily network uptime. A security engineer often builds security tools and architectures. A cybersecurity analyst sits between: you monitor for breaches, run audits, train staff, and respond to incidents rather than designing whole products.

Analysts are more operation- and investigation-focused: monitoring logs, applying patches, developing incident response plans, and ensuring compliance with laws and standards. You’ll also work closely with both network admins and security engineers.

Yes, but cautiously. Use automation like Ansible to apply verified patches and AWS alerts to triage events. Machine learning can flag anomalies in Kafka or Hive logs, but always have a human review before changing access or deleting data.

Never let an AI auto-deploy firewall rules or delete user accounts without human approval. Save playbooks and response steps in version control and test them in a staging AWS account first.

BLS reports about 190,650 employed in this occupational area (SOC 15-1212.00). The median pay is $129,180 per year. The lowest tenth earn about $75,090, and the top tenth about $199,850. (Source: BLS 2025.)

Local pay depends on industry, experience, and whether you’re handling big-data systems like Hadoop, Cassandra, or Redshift — employers that need those skills often pay toward the higher end.

Begin with fundamentals: basic networking, Linux command line, and one cloud platform (start with AWS free tier). Follow hands-on labs: set up a small EC2 instance, install an Apache web server, and practice securing it.

Learn Ansible for automation and how to read logs from Apache Kafka or simple syslog files. Take an introductory cert like CompTIA Security+ when you’ve done a few projects, then move to cloud certs (AWS Security Specialty) or entry-level SOC analyst training.

Log analysis and query skills. Being able to read and search logs from Apache Kafka, AWS CloudTrail, or Hadoop/Hive will let you spot anomalies, track breaches, and answer incident questions fast.

Practice using grep, jq, and cloud log consoles. Combine that with basic knowledge of authentication flows and encryption so you can interpret what the log lines actually mean.