Why I'm Betting on IAM Over Generic SOC Work

I'm currently working through CompTIA CySA+, a cybersecurity analyst certification built around detection and response. It's a good cert, and I'll finish it. But it's worth being honest about why I'm not building my career around general SOC work, and why identity is where I'm actually placing my bet.

Every day I administer access for a large, HIPAA-regulated healthcare system. That work has made one thing obvious to me faster than any cert or course could: a huge amount of security operations is pattern matching at scale. And pattern matching at scale is exactly what AI is getting good at, fast.

What's actually getting automated first

Look at what fills most SOC analyst job descriptions: triaging alerts, correlating logs, flagging anomalies, writing up incidents that follow a template. That's high-volume, repetitive, and well-documented, which sounds like a bad thing to say out loud, but it's also exactly the profile of work that copilots and AI-assisted security tooling are built to absorb. Microsoft is already shipping Security Copilot. SailPoint is building AI into its own platform. The vendors whose tools I use every day are actively automating the most repeatable parts of the job I'm studying for.

I don't think that makes CySA+ a waste of time. I think it means I shouldn't plan to live in Tier 1 triage work for the next ten years.

Why identity is different

Identity and access management has its own automatable layer too. Nobody should pretend entitlement reviews and access certifications are immune. But underneath that layer is something AI doesn't replace nearly as easily: judgment calls about who should have access to what, in a specific organizational and regulatory context, with real consequences if you get it wrong.

In a hospital, that's not abstract. A wrong access decision isn't just a compliance flag, it can be the difference between a clinician getting to a patient record fast enough and a HIPAA violation that takes months to clean up. Someone has to own that judgment, defend it to an auditor, and be accountable when it's wrong. That accountability doesn't transfer to a model.

The AI-agent piece nobody's solved yet

This last point is the one I actually find most interesting. As organizations adopt AI agents that can take real actions, somebody has to govern their identities too: what they're allowed to access, how their permissions get reviewed, what happens when one starts behaving in a way it shouldn't. SailPoint has already started building dedicated products for non-human identity. That's not a coincidence. It's a sign that identity governance isn't shrinking as AI adoption grows, it's becoming the thing that has to exist because AI adoption is growing.

That's the bet, basically. Generic SOC triage is the part of security most exposed to automation right now. IAM, especially access governance and the emerging non-human identity space, is the part that gets more important, not less, the more AI shows up inside an organization. CySA+ still earns its place on my roadmap because detection and response are real skills I use, but I'm not building my identity around being a SOC analyst. I'm building it around being the person who decides who, and what, gets access in the first place.

// NOTE
These are my own observations from day-to-day IAM work and ongoing cert study, not employer commentary. No employer-specific or PHI-related detail is referenced here.
// Talk Shop

Working In IAM Too?

I'm always glad to trade notes with other folks building toward IAM, cloud security, or healthcare compliance, or talk to teams looking to hire in that space.

Book a Call More Field Notes

// mark@markschwinn.com