How exposed to AI is a Penetration Tester?

Of the 22 tasks O*NET lists for penetration testers, 7 could be done in half the time with a chat window today. 3 cannot be sped up at all. Here is which.

Exposure means published research judged an AI could halve the time a task takes, at the same quality. It does not mean the task stops needing a person. How to read this


Also called
Reachable today Needs software built first Cannot be sped up
22
tasks rated for this occupation
370k
people do this job in the US
28 of 36
least protected in computing and maths

Every task, and what AI can do with it

These are O*NET's task statements for this occupation, exactly as written, sorted into the three bands by the ratings behind this report. Nothing has been reworded.

Reachable with a chat window today

7
  • Develop infiltration tests that exploit device vulnerabilities
  • Develop presentations on threat intelligence
  • Develop security penetration testing processes, such as wireless, data networks, and telecommunication security tests
  • Document penetration test findings
  • Prepare and submit reports describing the results of security fixes
  • Update corporate policies to improve cyber security
  • Write audit reports to communicate technical and procedural findings and recommend solutions

Only with software built on top

12
  • Collect stakeholder data to evaluate risk and to develop mitigation strategies
  • Conduct network and security system audits, using established criteria
  • Configure information systems to incorporate principles of least functionality and least access
  • Design security solutions to address known device vulnerabilities
  • Develop and execute tests that simulate the techniques of known cyber threat actors
  • Discuss security solutions with information technology teams or management
  • Evaluate vulnerability assessments of local computing environments, networks, infrastructures, or enclave boundaries
  • Gather cyber intelligence to identify vulnerabilities
  • Identify security system weaknesses, using penetration tests
  • Investigate security incidents, using computer forensics, network forensics, root cause analysis, or malware analysis
  • Keep up with new penetration testing tools and methods
  • Maintain up-to-date knowledge of hacking trends

Cannot be sped up

3
  • Assess the physical security of servers, systems, or network devices to identify vulnerability to temperature, vandalism, or natural disasters
  • Identify new threat tactics, techniques, or procedures used by cyber threat actors
  • Test the security of systems by attempting to gain access to networks, Web-based applications, or computers
What this does not say

This is not a prediction about your job

Nobody surveyed an employer. Tasks are counted equally, so a percentage here is a share of the list rather than a share of your week. And the ratings were made in 2023, which makes every figure a floor rather than a ceiling.

It must never be used to select anyone for redundancy. The full limits are here.

Where to go next

This is the standard task list for the title. The useful next question is which of the tasks you actually do should go near AI, and which should not.


Exposure ratings from Eloundou, Manning, Mishkin and Rock, GPTs are GPTs: Labor market impact potential of LLMs, Science 384, 1306–1308, 2024, used under the MIT licence. This page includes information from the O*NET Database by the U.S. Department of Labor, Employment and Training Administration (USDOL/ETA), used under the CC BY 4.0 license. O*NET® is a trademark of USDOL/ETA. People Team AI has modified all or some of this information. USDOL/ETA has not approved, endorsed, or tested these modifications. Employment figures from the US Bureau of Labor Statistics.