The Death of the Analyst: Why Security Careers Need a Culture Shift

Bronson Peto (Vail Resorts · Security Architect)

SAINTCON 2025 · Day 2 · Main Track 1

Overview

Bronson Peto’s talk, "The Death of the Analyst: Why Security Careers Need a Culture Shift," delivers a provocative and essential critique of the modern cybersecurity industry. Peto, a seasoned security professional with a diverse background ranging from analyst to architect, argues that the foundational role of the security analyst is being systematically devalued, commoditized, and ultimately, sidelined by a pervasive overreliance on outsourced services, excessive tooling, and the burgeoning promise of artificial intelligence. His core thesis challenges the prevailing notion that career progression in security must lead away from hands-on analysis, advocating instead for a renewed appreciation of curiosity, deep system intuition, and human context as the indispensable elements of effective security.

Watch on YouTube

Visual summary for The Death of the Analyst: Why Security Careers Need a Culture Shift by Bronson Peto
Visual summary for The Death of the Analyst: Why Security Careers Need a Culture Shift by Bronson Peto

Key moments

  1. 0:00 Speaker introduction and diverse career journey
  2. 0:40 Challenging industry notions on security career progression
  3. 1:30 Hacker culture and vital role of curiosity in security
  4. 3:00 First security job: building path from chaos
  5. 4:40 "Death of the analyst": losing curiosity in security
  6. 6:00 Early analyst role encompassed many security disciplines

The Death of the Analyst: Why Security Careers Need a Culture Shift

Speakers: Bronson Peto, Security Architect, Vail Resorts

Conference: SAINTCON

YouTube: https://www.youtube.com/watch?v=yM8FRDvZPg0

Overview

Bronson Peto’s talk, "The Death of the Analyst: Why Security Careers Need a Culture Shift," delivers a provocative and essential critique of the modern cybersecurity industry. Peto, a seasoned security professional with a diverse background ranging from analyst to architect, argues that the foundational role of the security analyst is being systematically devalued, commoditized, and ultimately, sidelined by a pervasive overreliance on outsourced services, excessive tooling, and the burgeoning promise of artificial intelligence. His core thesis challenges the prevailing notion that career progression in security must lead away from hands-on analysis, advocating instead for a renewed appreciation of curiosity, deep system intuition, and human context as the indispensable elements of effective security.

The talk resonates as a timely intervention amidst a landscape increasingly dominated by vendors promising "autonomous SOCs" and a complete elimination of alert fatigue. Peto contends that this trajectory, while seemingly efficient, actually leads to "security theater" where organizations triage effectively but fail to understand or mitigate root causes. He implores the industry to reclaim the analyst role, fostering an environment where critical thinking, internal threat intelligence generation, and horizontal mastery are celebrated, rather than treating analysis as merely a stepping stone to engineering or management. This perspective is vital for practitioners, leaders, and anyone concerned with the long-term efficacy and talent pipeline of cybersecurity.

Peto's message is not one of technological Luddism but a call for strategic integration of tools and automation in service of the human analyst, not in their replacement. He uses vivid analogies, from his own formative experiences building an MDR-like service from scratch to the intricate data analysis in Formula 1 racing, to illustrate the irreplaceable value of human insight. The talk highlights a critical disconnect: as outsourcing and automation spend soar, so do security incidents and their associated costs, suggesting that the industry is addressing symptoms rather than cultivating the deep, contextual understanding required to build truly resilient security programs.

Background

▶ Watch: Speaker introduction and diverse career journey (0:00)

Bronson Peto's journey into cybersecurity was far from conventional, laying the groundwork for his unique perspective on the analyst role. Before entering the security field, he accumulated a wealth of hands-on experience in "strange and esoteric jobs," including automating OS installs for a school district, building Linux from source for PBX phone systems, and managing field IT teams. This diverse background, characterized by a constant engagement with how systems work and a drive to "poke at the underbelly," instilled in him a profound sense of curiosity – a trait he now identifies as fundamental to a successful security career.

His formal entry into security was equally unconventional. His first security analyst role at an outsourced SOC vendor, predating Gartner's coining of "MDR," was marked by a complete lack of formal onboarding, ticketing systems, or even a robust SIEM. Peto found himself thrust into making sense of chaos, building processes, templates, and reporting mechanisms from scratch, driven purely by an innate hacker's curiosity. This experience forced him to "build his own path," learning to identify distinct threats, understand authentication protocols, and dig deep into any technology appearing in customer logs. He describes this period as an "exploratory grind" that solidified his love for security, providing a "healthy perspective" on what it truly means to be an effective analyst – performing threat hunting, detection engineering, threat intelligence, and incident response without any formal frameworks.

Peto's subsequent career progression, from security analyst to engineer at companies like Tableau and Wizards of the Coast, and eventually to Security Architect at Vail Resorts, was largely motivated by a desire to improve the analyst experience. He sought to create better tools and business alignment, ensuring analysts could be more effective. This "business-minded security expert" approach, focused on delivering value and protecting what truly matters to the business, further cemented his understanding of the critical link between deep technical insight and organizational context. He learned the "art" of collecting logs at scale and the pain points of failing to do so effectively, emphasizing the value of logs over mere collection.

The problem, as Peto sees it, is that the industry has increasingly adopted a "kabonetized" and formulaic approach to security. This shift, driven by a focus on certifications, rapid job acquisition, and the promise of shiny new tools, has led to a decline in genuine curiosity and creative problem-solving. Analysts are often viewed as mere "tool operators" or a "starter role," a "stepping stone" to more "prestigious" positions like engineering or management. This tunnel vision, he argues, diminishes the immense value that can be fostered within the analyst community. The industry's overemphasis on reactive alert response, often outsourced to Managed Detection and Response (MDR) vendors or increasingly, automated by AI, actively discourages the deep, contextual understanding that defines a truly impactful security analyst.

Key Findings

▶ Watch: Hacker culture and vital role of curiosity in security (1:30)

Bronson Peto's talk delivers several critical findings that challenge the status quo in cybersecurity:

  1. The Devaluation of the Analyst Role: Peto argues that the industry's default career model treats the analyst role as a transient "way station" – a necessary entry point before moving "up and out" into engineering, management, or architecture. This perspective fundamentally misunderstands and devalues the profound depth, impact, and specialized knowledge that a senior analyst can bring, leading to a "death of the analyst" in terms of perceived worth and career longevity within the hands-on analysis domain.
  1. Irreplaceable Value of Human Curiosity and Context: The core finding is that curiosity, system intuition, and the ability to dig into patterns others overlook are the defining characteristics of a great analyst. These human traits, coupled with an understanding of infrastructure, human error, business nuance, and the attacker mindset, enable analysts to be "part detective, part sysadmin, part sociologist, and part evildoer." This holistic understanding cannot be replicated by tools, outsourced services, or AI alone.
  1. MDR and Outsourcing as Incomplete Solutions: While acknowledging the benefits of MDR (e.g., 24/7 alerting for the cost of a single senior analyst), Peto highlights its critical limitations. MDR is primarily triage, lacking the business context and deep system knowledge necessary for effective remediation. Outsourcing analysts leads to outsourcing understanding, as vendors, even with advanced capabilities like threat hunting, lack the internal domain memory, mission-critical awareness, and organizational nuances of an in-house team. This creates a disconnect where symptoms are treated, but root causes (process weaknesses, misconfigurations, business gaps) remain unaddressed.
  1. AI's Promise vs. Reality: Summarization Without Understanding: Peto cautions against the industry's rush towards "Level 5 autonomous SOCs" promised by vendors like CrowdStrike (e.g., Charlotte AI). While AI can summarize logs, map alerts, and automate workflows, it doesn't understand. It can lead to "unaccountable automation," "hallucinated correlations," and "opaque logic," creating outcomes that no one can explain or verify without human intervention. AI, if not carefully implemented, risks turning security into an "expensive security theater machine" that loses touch with what it's defending.
  1. Internal Threat Intelligence is Paramount: True threat intelligence moves a security program forward by learning from internal incidents and patterns. Peto advocates for treating threat intel as something an organization primarily builds internally, rather than solely buys externally. Analysts reviewing incidents, connecting patterns, and feeding insights back into tooling, detections, and processes provide far more value than a "thousand IoCs that likely won't ever hit" from external feeds. This horizontal mastery creates feedback loops essential for continuous improvement and resilience.
  1. The Disconnect Between Spend and Effectiveness: Peto points out a stark paradox: despite massive investments in MDR (projected to grow from $2 billion in 2024 to $8-12 billion in 5-10 years) and other outsourced services, traditional security metrics (records exposed, attack frequency, severity) are consistently rising. This disconnect suggests that the current approach of "more people watching alerts and paying vendors" is not making businesses more secure or resilient, underscoring the need for a fundamental shift in strategy.

Technical Deep Dive

▶ Watch: First security job: building path from chaos (3:00)

Peto's talk, while focused on cultural shifts, is deeply rooted in the technical realities of modern security operations, highlighting how current practices and emerging technologies often fail to leverage human expertise effectively.

MDR and the Black Box Problem:

A significant technical concern raised by Peto revolves around Managed Detection and Response (MDR) services. While MDR offers 24/7 alerting and a response to service level agreements (SLAs) for critical, high, and medium alerts (e.g., criticals within 1 hour, highs within 2 hours), its inherent structure creates technical limitations. Most third-party MDR vendors re-ingest customer data into their own black-box SIEM or SOAR platforms. This abstraction means that the client organization loses visibility and control over the underlying analytics, detection engineering, and analyst workflows. "You can't influence the outcomes that come from that platform and all the analyst work and engineering is going to be abstracted away from your team." This abstraction prevents in-house teams from gaining deeper insight into how their data is processed, how detections are built, or how the vendor's analysts operate, hindering their ability to learn and mature their own security posture.

Furthermore, MDR is primarily focused on triage and containment (e.g., isolating an infected host). While they may provide recommendations for firewall rules or system hardening, actual remediation requires validation and action by the client. Peto emphasizes that "every MDR finding still needs validation" because vendors lack the intimate knowledge of a client's environment, its "knowing good things," or accepted behaviors that might otherwise trigger an alert. This necessitates a strong in-house team to interpret, apply business context, and execute the necessary fixes, highlighting that MDR is not a complete, self-sufficient solution.

The Perils of Tooling and Automation Without Intent:

The proliferation of security tools has inadvertently created a new set of technical challenges. Analysts are often faced with "25 different alert sources, a dozen dashboards, 40 tabs," leading to alert fatigue and skill erosion. This "tool bloat" and "automation without intent" result in a "weird mental distance" between the analyst and the systems they are meant to protect. Tools are powerful, but when they abstract away too much context and ownership, analysts become disengaged, merely acknowledging alerts rather than investigating their root causes. Peto argues that this over-reliance on aggregated "insight, context, [and] enrichment" from tools can lead to analysts losing "the grip on what it is that we're actually analyzing in the first place."

AI: Summarization, Not Understanding:

Peto critically examines the role of Artificial Intelligence (AI) in security, particularly the vendor promise of an "autonomous SOC" (Level 5 automation). He acknowledges AI's capabilities in "summarizing logs," "attempting to map alerts back to incidents," and "automating some workflows." However, he draws a crucial distinction: AI can summarize, but it doesn't understand. Citing examples like CrowdStrike's Charlotte AI, he asserts that while it excels at information summarization, it cannot replicate the human context an analyst brings.

The technical risks of an autonomous SOC are significant:

  • Unaccountable Automation: AI-driven decisions can be opaque, leading to "hallucinated correlations" and "opaque logic" that nobody can explain or verify.
  • Loss of Context and Learning: If analysts are reduced to merely approving "a thousand AI generated decisions," they lose the opportunity to learn, gain context, and contribute to feedback loops, thereby ceasing to generate valuable business intelligence.
  • Security Theater: An autonomous SOC without human oversight risks becoming a "very expensive security theater machine," where "nothing actually knows what it's defending anymore."

Peto emphasizes that AI should be in service of the analyst, helping them "operate at greater effectiveness," reduce noise, and get better data, allowing humans to focus on investigation, tuning, detection, and advising. It should "amplify some signals" but not replace the "better thinking" security truly needs.

The Analyst's Technical Depth:

Contrary to the perception of analysts as mere button-clickers, Peto highlights the profound technical depth required for the role. Great analysts are intimately familiar with system internals and data flows. This includes:

  • Log Collection at Scale: Understanding the complexities and "pain" of collecting diverse logs, such as Windows event logs at scale, and prioritizing the value of logs over just collecting everything.
  • Protocol Understanding: Reading RFCs for fundamental protocols like email or DNS to truly grasp how systems operate.
  • Authentication Flows: Knowing what Entra logs look like for critical processes such as MFA resets or password resets, and being able to simulate and understand the full sequence of events.
  • Detection Engineering Collaboration: Collaborating with engineers to ensure better logging, identifying when logs are malformed, or validating the presence of specific authentication logs mentioned in advisories (e.g., F5 advisories).
  • Data Analysis and Visualization: Moving beyond simple alert triage to export low-fidelity alerts, using tools like Python with Pandas for data visualization to detect anomalies and patterns that would otherwise be missed.

This deep technical understanding allows analysts to build feedback loops, generate internal threat intelligence, and form the foundation for effective threat hunting and detection engineering. It's about caring for the system, not just the alert.

Demo / Proof of Concept

▶ Watch: "Death of the analyst": losing curiosity in security (4:40)

Bronson Peto's talk, "The Death of the Analyst: Why Security Careers Need a Culture Shift," is a conceptual and strategic discussion about the state and future of the security analyst role. As such, it does not include a technical demonstration or a proof of concept of any specific tool, exploit, or defensive technique. The speaker relies on personal anecdotes, industry observations, and analogies to convey his message rather than live technical demonstrations.

Defensive Implications

▶ Watch: Early analyst role encompassed many security disciplines (6:00)

The insights shared by Bronson Peto carry significant defensive implications for organizations striving to build resilient and effective security programs. His core message is a call to action for leaders and practitioners to fundamentally rethink how they value and empower their security analysts.

  1. Invest in a Hybrid Security Model: Organizations should adopt a hybrid security model that strategically combines outsourced MDR services with robust in-house analyst capabilities. While MDR can provide 24/7 alert monitoring and initial triage, it must be complemented by internal analysts who can apply business context, validate findings, and drive remediation efforts. Relying solely on MDR risks treating symptoms without addressing root causes, leaving critical business processes vulnerable due to a lack of domain-specific understanding.
  1. Empower and Elevate In-House Analysts: Security leaders must stop viewing the analyst role as a "starter" position. Instead, they should actively create career paths that allow for horizontal mastery within analysis, rewarding curiosity, deep investigation, and specialized knowledge (e.g., threat hunting, adversary emulation) without requiring a move into management or engineering. This means providing analysts with:
  • Time for Deep Investigation: Allocate dedicated time (Peto suggests an "80/20 ratio" where 20% of time is for "pet projects" or deep dives) to go beyond alert queues, allowing for correlation, system understanding, and threat hunting.
  • Access to Systems and Context: Ensure analysts can "dig into those other systems" – understanding MFA reset flows, examining network engineer scripts, and interacting with developer teams to gain a comprehensive view of the environment.
  • Training and Learning Opportunities: Encourage learning offensive security techniques (without necessarily becoming an OCP hacker), reading RFCs (e.g., for email, DNS), and engaging with data science principles (e.g., Python with Pandas for anomaly detection).
  1. Build, Don't Just Buy, Threat Intelligence: A critical defensive strategy is to shift from primarily purchasing external IoC feeds to building internal threat intelligence. Analysts are uniquely positioned to generate valuable intelligence by:
  • Reviewing Internal Incidents: Connecting patterns from past incidents, even unsuccessful attempts, to understand specific threats targeting the organization.
  • Developing Custom Detections: Using insights from internal logs and observed attacker techniques to create bespoke detections that are highly relevant to the organization's unique environment.
  • Creating Feedback Loops: Continuously feeding insights from analysis back into tooling, detection rules, processes, and meaningful reports to iteratively improve the security program. This "horizontal mastery" ensures the program learns and adapts from its own experiences.
  1. Strategic Use of Automation and AI: Automation and AI should be implemented as enablers for human analysts, not as replacements. Defenders should leverage these technologies to:
  • Reduce Repetitive Tasks: Automate low-value, repetitive tasks to free up analysts' time for more complex investigations and critical thinking.
  • Amplify Signals and Context: Use AI for summarization and initial correlation to help analysts quickly prioritize and gain context, but always with human oversight for validation and understanding.
  • Improve Data Quality: Automate data collection and enrichment to provide analysts with better, more reliable data for their investigations. The goal is to help "a great analyst operate at greater effectiveness," not to achieve an "autonomous SOC" that operates without accountability or understanding.
  1. Cultivate a Culture of Curiosity and Collaboration: Security leaders must actively foster a culture where curiosity, critical thinking, and collaboration are celebrated. This involves:
  • Rewarding Analytical Depth: Recognizing and promoting analysts who demonstrate deep system intuition and pattern recognition, rather than just those who move into management.
  • Cross-Functional Engagement: Encouraging analysts to interact with help desk staff, understand onboarding pain points, and collaborate with engineers to improve logging and infrastructure visibility.
  • Advocacy for the Analyst Role: Leaders must advocate internally for the value of their analysts, ensuring they have the resources, time, and empowerment to contribute meaningfully to the business's security posture. Ignoring this leads to "cannibalizing your detection and response capability" and remaining stuck in a reactive mode.

By embracing these defensive implications, organizations can move beyond merely triaging alerts to building genuinely resilient security programs driven by deeply embedded, context-aware human intelligence.

Key Takeaways

  • The Security Analyst is the Heartbeat: The security analyst role, driven by curiosity, deep system intuition, and the ability to find patterns, is indispensable and should be celebrated as the core of any effective security program, not a mere stepping stone.
  • Context Trumps Automation: While MDR, advanced tools, and AI can provide volume and speed, they cannot replace the human analyst's unique ability to apply business context, understand nuances, and grasp the "why" behind an alert. Over-reliance on automation without human understanding leads to "security theater" and ineffective defense.
  • Build Internal Threat Intelligence: True threat intelligence that moves a security program forward comes from within the organization. Analysts should be empowered to review internal incidents, connect patterns, and generate tailored insights, rather than solely relying on external IoC feeds.
  • Empower Analysts with Time and Growth: Organizations must provide analysts with dedicated time for deep investigation, threat hunting, learning new systems (e.g., reading RFCs, understanding log flows), and even offensive security. Career paths should offer horizontal mastery within analysis, rewarding specialized technical depth.
  • AI as an Amplifier, Not a Replacement: AI should be strategically used to augment human analysts by reducing repetitive tasks, summarizing data, and amplifying signals. However, it must always be in service of better human understanding and decision-making, not as a means to achieve an unaccountable "autonomous SOC."
  • Address the Talent Pipeline Disconnect: The industry's overreliance on outsourced vendors for entry-level roles risks sapping the creativity and contextual learning of new talent. Organizations must actively invest in establishing in-house security programs that nurture analytical talent from the ground up, fostering curiosity and independent exploration.

About the Speaker(s)

Bronson Peto, who also goes by the handle "@dumb," is a Security Architect at Vail Resorts. His career in security is marked by a diverse range of experiences and a consistent drive to understand the "underbelly" of systems. He began his security journey as a security analyst for an outsourced SOC vendor, where he gained invaluable experience building detection and response capabilities from the ground up in an environment with minimal existing infrastructure.

Peto's background includes roles as a Security Engineer at prominent companies like Tableau and Wizards of the Coast, as well as a stint as a Sales Engineer for an MDR company, giving him deep insights into both the technical and business aspects of managed security services. Prior to his security career, he worked in various "strange and esoteric" IT roles, such as automating OS installs, building Linux from source for PBX phone systems, and managing field IT teams, which cultivated his innate curiosity and hands-on approach. He identifies as a "hacker at heart" and a "business-minded security expert," always seeking to understand how systems work, how they can break, and how security can genuinely deliver value to an organization. His passion lies in challenging industry norms and advocating for the empowerment and recognition of security analysts.

All talks from SAINTCON 2025