On my end the growingest vector is audit remediation. Your cyber insurance providers have noticed that you constructed your environments out of swiss cheese and are now mandating actual pentesting and practical demonstrations of your fixes if you want to maintain your policy. Those self service checklists seem to be going away.
gotta say, audit remediation is a pretty chill field to be in as well. The recent round of 'hackers dont sleep for the holidays' articles made me feel glad to get out of the incident response game.