AI Delegation Index

What work could you hand off to an AI agent?

Penetration Testers

Strong

AI agents could handle several recurring digital workflows in this job, while people remain responsible for judgment and final decisions.

Where agents can help most

  1. 1

    Update penetration test methods

    Use an agent to review your notes on new attack methods, recent tools, and threat writeups, then organize them into an updated testing checklist for the next approved engagement.

  2. 2

    Find likely vulnerabilities from recon

    Use an agent to collect scan results, exposed-service notes, threat intelligence, and your recon findings, then sort them into a shortlist of likely weaknesses with supporting evidence.

  3. 3

    Verify security fixes and close findings

    Use an agent to compare your before-and-after test notes, retest documented fixes on approved systems, and draft a clear summary showing whether the original issue is gone or only partly reduced.

Search another job

O*NET-SOC 15-1299.04 · #38 of 923

Result context

How to read this result

Evaluate network system security by conducting simulated internal and external cyberattacks using adversary tools and techniques. Attempt to breach and exploit critical systems and gain access to sensitive information to assess system security.

National position
#38 of 923 occupations
Top 5% of occupations
Overall AI delegation potential
Strong
Potential of score-contributing workflows
Strong · 83/100
Meaningful work covered
70%

The overall rating combines how useful the best agent workflows are with how much of the occupation they address. It is not an estimate of job automation or replacement.

Recommended agent uses

3 workflows you could delegate to AI

1

Update penetration test methods

How you could use an agent

Use an agent to review your notes on new attack methods, recent tools, and threat writeups, then organize them into an updated testing checklist for the next approved engagement. It can help you compare the old approach with current techniques and draft safer ways to simulate realistic activity in the lab or on authorized targets.

Where you stay involved

You decide which methods belong in the next test plan, confirm what is allowed for the engagement, and approve anything new or unusually intrusive before it is used.

Review level: Low

2

Find likely vulnerabilities from recon

How you could use an agent

Use an agent to collect scan results, exposed-service notes, threat intelligence, and your recon findings, then sort them into a shortlist of likely weaknesses with supporting evidence. It can help you line up each candidate issue with the artifacts that point to it so you can focus your testing time where it matters most.

Where you stay involved

You decide which findings deserve deeper testing, confirm whether the evidence really supports the weakness, and stop before any test that needs extra approval.

Review level: Medium

3

Verify security fixes and close findings

How you could use an agent

Use an agent to compare your before-and-after test notes, retest documented fixes on approved systems, and draft a clear summary showing whether the original issue is gone or only partly reduced. It can pull together the evidence for each fix so you have a clean closeout report for the team that made the changes.

Where you stay involved

You decide whether the fix is strong enough, note any remaining exposure, and send unresolved items back to the responsible team.

Review level: Medium

Supporting analysis

Why this occupation's AI delegation potential is Strong

Underlying methodology score

79 / 100

This technical score determines the qualitative rating; it is not an estimate of the share of the occupation that can be automated.

Importance & frequency82
AI capability87
Digital actionability90
End-to-end leverage86
Safety & reversibility73
Meaningful-work coverage
70%
Physical-work modifier
Limited
Safety modifier
Limited
Qualitative judgment
No material constraint
O*NET task evidence
22 tasks

O*NET 31.0 · methodology 3.3.0. Every workflow passes an action-level physical-execution and protected human-and-veterinary clinical-action gate. Documentation workflows must own a complete digital loop and use digital task evidence only; support-only workflows are disclosed separately and excluded from scoring. Artistic, editorial, normative, and policy-dependent work receives a transparent human-judgment constraint. National ranking within 923 scored O*NET occupations under methodology 3.3.0.

Useful comparisons

Similar occupations

Compare side by side