Will AI replace Penetration Testers?

AI can do 82% of the work Penetration Testers do at least twice as fast. Real use has not caught up: none of their tasks show up in real AI use yet, but AI could speed up 19 of them. 3 still need a person.

AI is already doing this0 · 0% of time

People already use AI for these tasks in real work, based on Anthropic's analysis of how Claude is used.

  • Real AI use has not reached any of this job's tasks yet.

AI could do this next19 · 82% of time

AI can speed these up by at least half, but real use has not caught up yet. These are next in line.

  • Develop and execute tests that simulate the techniques of known cyber threat actors.10% of time
  • Document penetration test findings.10% of time
  • Identify security system weaknesses, using penetration tests.9% of time
  • Develop infiltration tests that exploit device vulnerabilities.6% of time
  • Evaluate vulnerability assessments of local computing environments, networks, infrastructures, or enclave boundaries.6% of time
  • Discuss security solutions with information technology teams or management.5% of time
  • Write audit reports to communicate technical and procedural findings and recommend solutions.5% of time
  • Collect stakeholder data to evaluate risk and to develop mitigation strategies.4% of time
  • Conduct network and security system audits, using established criteria.4% of time
  • Develop security penetration testing processes, such as wireless, data networks, and telecommunication security tests.4% of time
  • Gather cyber intelligence to identify vulnerabilities.4% of time
  • Keep up with new penetration testing tools and methods.4% of time
  • Design security solutions to address known device vulnerabilities.2% of time
  • Investigate security incidents, using computer forensics, network forensics, root cause analysis, or malware analysis.2% of time
  • Maintain up-to-date knowledge of hacking trends.2% of time
  • Prepare and submit reports describing the results of security fixes.2% of time
  • Configure information systems to incorporate principles of least functionality and least access.1% of time
  • Develop presentations on threat intelligence.1% of time
  • Update corporate policies to improve cyber security.1% of time

Still needs a person3 · 18% of time

No real AI use, no proven AI speedup and no robot that can do it yet. This is the part of the job to build on.

  • Test the security of systems by attempting to gain access to networks, Web-based applications, or computers.15% of time
  • Identify new threat tactics, techniques, or procedures used by cyber threat actors.2% of time
  • Assess the physical security of servers, systems, or network devices to identify vulnerability to temperature, vandalism, or natural disasters.1% of time

Your week is not the average

Describe what you actually do and get a personal report: your own tasks, what AI can already do, what stays yours and a 90 day plan.

Get my personal report

What this means

AI can already do almost all of this work at least twice as fast. Real use is still behind at 0 out of 100, so the change here is only getting started. Expect the role to shift toward deciding what to do, checking AI's work and owning the result.

What to do next

  • Get ahead on the 19 tasks AI could do next. These move as tools improve, so learning them early pays off.
  • Build on the 3 tasks that stay human. This is where your judgment, skill and relationships matter most.

Get the weekly brief

One short email a week on how AI is changing work, including jobs like this one.

Check another job