The median cybersecurity salary in the United States sits at $112,000 per year — more than double the national median wage — and the Bureau of Labor Statistics projects 32% job growth through 2032. That's not a typo. The field is outpacing nearly every other in tech, yet employers report hundreds of thousands of unfilled positions globally. If you're weighing a move into cybersecurity, salary is the right thing to research first.
This guide breaks down actual cybersecurity salary ranges by role, experience level, location, and certification — then shows you which courses will get you there fastest.
What Cybersecurity Professionals Actually Earn in 2026
Cybersecurity salary varies significantly by role, but the floor is high. Even entry-level analysts at companies you've heard of earn well above the median US household income. Here's what the numbers look like across experience bands:
- Entry-level (0–2 years): $65,000–$90,000
- Mid-level (2–5 years): $90,000–$130,000
- Senior (5–10 years): $130,000–$175,000
- Principal / Staff (10+ years): $175,000–$250,000+
- CISO (large enterprise): $250,000–$500,000+ including equity
The cybersecurity salary ceiling is genuinely high. A Chief Information Security Officer at a Fortune 500 firm routinely clears $400,000 in total comp. But the more relevant question for most people is: what does a solid first job pay? The answer is typically $70,000–$85,000 in mid-sized cities and $90,000–$110,000 in major tech hubs for someone coming in with a relevant certification and no prior security experience.
Cybersecurity Salary by Role: Where the Real Money Is
Not all cybersecurity jobs pay the same. The field has distinct specializations, and some command serious premiums. Below are the roles most worth knowing about, ranked roughly by median total compensation.
Penetration Tester (Ethical Hacker)
Median: $115,000–$145,000. Pentesters are paid to break into systems before attackers do. The role demands strong technical depth — networking, scripting, exploit frameworks — but salaries reflect that. Freelance pentesters on bug bounty platforms can supplement base salary significantly, with some clearing six figures from bounties alone.
Security Engineer
Median: $120,000–$160,000. Security engineers build and maintain defensive infrastructure: firewalls, SIEM platforms, zero-trust architectures. The blend of software engineering and security commands top dollar, particularly at cloud-native companies.
Security / SOC Analyst
Median: $75,000–$110,000. This is the most common entry point. SOC analysts monitor alerts, triage incidents, and escalate threats. Pay is lower than engineering roles but the volume of open positions is massive — it's where most career changers start.
Cloud Security Architect
Median: $145,000–$185,000. As organizations migrated to AWS, Azure, and GCP, demand for professionals who understand cloud-native security controls exploded. This is one of the fastest-moving and highest-paying specializations right now.
GRC Analyst (Governance, Risk, Compliance)
Median: $85,000–$120,000. Less technical than the roles above, GRC focuses on frameworks like NIST, ISO 27001, and SOC 2. It's an underrated entry path for people with strong communication skills and a business background.
What Actually Moves Your Cybersecurity Salary
Raw years of experience matter less in cybersecurity than in most fields. Three factors consistently move the needle more than tenure alone.
Certifications
Certifications are one of the few places where a single credential can mean a $15,000–$30,000 salary bump, especially early in your career. The hierarchy roughly looks like this:
- CompTIA Security+ — The baseline. Required by the DoD and accepted by thousands of employers. Gets you past HR filters for entry-level roles.
- CompTIA CySA+ — Analyst-focused, one step above Security+. Shows threat-hunting and SIEM competency.
- CISSP — Senior-level standard. Average CISSP salary: $130,000+. Requires 5 years of experience to sit.
- CEH / OSCP — Penetration testing credentials. OSCP in particular is regarded as a genuine proof-of-skill rather than a multiple-choice exam, and commands a premium.
- Cloud security certs (AWS Security Specialty, Google Professional Cloud Security Engineer) — High demand, relatively low supply of certified candidates.
Location and Remote Work
Cybersecurity salary varies by geography more than most people expect. Washington D.C. leads all US metros because of federal contractor demand — median security clearance roles pay $120,000–$160,000 at mid-level. San Francisco and New York follow. But remote work has partially equalized things: many remote security roles now pay near coastal rates regardless of where you live.
Industry
Finance and defense pay the most. Healthcare and education pay least but offer stability and sometimes loan forgiveness. Big tech sits in between on base but adds equity that can dwarf base salary.
Top Courses to Build Cybersecurity Skills and Salary Power
If you're transitioning from IT support or starting from scratch, structured courses are the fastest way to build a certifiable, demonstrable skill set that employers recognize. These are the ones worth your time.
Foundations of Cybersecurity (Coursera)
Google's foundational course is the best starting point if you're new to security. It covers core concepts — threats, vulnerabilities, the CIA triad — in plain language without assuming prior security knowledge. Ideal for IT support professionals who want to formalize what they already know and build toward Security+.
Cybersecurity Assessment: CompTIA Security+ & CySA+ (Coursera)
Directly aligned with the two certifications most likely to improve your starting cybersecurity salary. The course uses practice assessments structured like the real exams, which means you're studying for the credential at the same time you're building the knowledge. Strong value-to-cost ratio.
IBM and ISC2 Cybersecurity Specialist Professional Certificate (Coursera)
A joint credential from two of the most recognized names in enterprise security. This is heavier than the Google course and is better suited for people who want to go from zero to job-ready rather than just test the waters. The ISC2 name on the certificate carries weight with hiring managers.
Computer Science for Cybersecurity (edX)
For career changers who want to understand why security works the way it does, not just how to click through a SOC dashboard. This course covers algorithms, cryptography fundamentals, and systems concepts that separate solid analysts from button-pushers — the kind of depth that shows up in interviews and eventually in salary negotiations.
Cybersecurity for Business Specialization (Coursera)
If your goal is GRC, leadership, or eventually moving into a CISO track, this specialization is more relevant than purely technical courses. It covers risk frameworks, security policy, and communication with non-technical stakeholders — skills that become increasingly valuable (and compensated) as you move up.
Generative AI Cybersecurity & Privacy for Leaders (Coursera)
AI is reshaping both the threat landscape and the tools defenders use. This course is aimed at professionals who want to understand how LLMs introduce new risks and how organizations should respond. It's a forward-looking credential that signals you're thinking about where the field is going, not just where it's been.
From IT Support to Cybersecurity: The Salary Jump
IT support professionals are among the best-positioned career changers in this field. The average help desk technician earns $45,000–$60,000. The average entry-level SOC analyst earns $70,000–$85,000. That's a $20,000–$25,000 salary increase for a transition that can happen in 6–12 months with the right coursework and a Security+ certification.
The skills transfer more directly than most people realize. Troubleshooting a user's login issue teaches you about Active Directory and authentication flows. Managing endpoints teaches you about attack surfaces. Understanding why the VPN behaves differently on certain networks teaches you routing and protocol behavior. These aren't adjacent skills — they're foundational ones.
The main gap is usually in security-specific frameworks (MITRE ATT&CK, NIST CSF), tooling (SIEM platforms, EDR solutions), and the attacker mindset. Courses bridge that gap faster than most people expect.
FAQ
What is the average cybersecurity salary in the US?
The Bureau of Labor Statistics reports a median annual wage of approximately $112,000 for information security analysts. Total compensation including bonuses and equity can push this significantly higher at larger employers and in finance or tech sectors.
Can I get a cybersecurity job without a degree?
Yes, and it's increasingly common. Employers in cybersecurity have shifted toward skills-based hiring more than most other fields. CompTIA Security+ is recognized by the DoD and accepted by thousands of private employers as a baseline credential. A combination of certs, a home lab portfolio, and practical coursework can substitute for a four-year degree at many companies.
How long does it take to transition into cybersecurity from IT support?
Most IT support professionals can transition in 6–12 months with focused preparation. The typical path: study for and pass Security+ (2–3 months), complete one hands-on specialization course (2–3 months), apply for SOC analyst or junior security analyst roles. Existing networking and OS knowledge from IT support significantly compresses this timeline.
Which cybersecurity certification pays the most?
At the senior level, CISSP consistently correlates with the highest base salaries ($130,000+ median). For penetration testers, OSCP is the gold standard and commands similar premiums. For early-career, Security+ has the best return on investment because it's the fastest to obtain and unlocks the most job postings.
Does location still matter for cybersecurity salary with remote work available?
Somewhat. Remote cybersecurity roles are widely available, but many still use geographic pay bands — a remote role headquartered in San Francisco often pays more than one headquartered in a lower-cost city. Government and defense contractor roles in the D.C. corridor tend to require in-person presence but pay accordingly. On balance, remote availability has reduced — but not eliminated — geographic salary gaps.
What cybersecurity roles are growing the fastest right now?
Cloud security, AI/ML security (adversarial ML, model security), and OT/ICS security (industrial control systems) are the fastest-growing specializations with the largest salary premiums and the fewest credentialed candidates. These are worth targeting if you're building skills from scratch and willing to go deeper than generalist content.
Bottom Line
The cybersecurity salary opportunity is real and well-documented — median pay above $112,000, 32% projected job growth, and a persistent talent shortage that keeps employer negotiating power low. The field rewards certifications and demonstrated skills over credentials and tenure, which makes it unusually accessible for career changers.
If you're coming from IT support, start with the Foundations of Cybersecurity to formalize your existing knowledge, then stack the CompTIA Security+ & CySA+ course to build toward the credentials that unlock the most hiring. If you're starting from scratch and want the most comprehensive path to a job, the IBM and ISC2 Professional Certificate is the most thorough option available online.
The first job in cybersecurity is the hardest to land. After that, demand is high enough that motivated professionals rarely stay at their starting salary for long.