The median cybersecurity salary in the US sits at $112,000, according to BLS data — but that number is nearly useless on its own. A helpdesk analyst who just earned CompTIA Security+ is not in the same market as a cloud security architect with a CISSP and ten years of incident response behind them. This guide breaks down what cybersecurity professionals actually earn, by role and seniority, and which credentials move the needle versus which ones employers have stopped caring about.
Cybersecurity Salary by Job Title
The range across cybersecurity roles is wider than most career guides acknowledge. Here's what the realistic market looks like in 2026, pulling from Glassdoor, Levels.fyi, and LinkedIn Salary data:
- SOC Analyst (Tier 1): $52,000–$72,000. The entry point for most people. Shift work, high alert volume, significant false-positive fatigue. Real learning happens here, but you will not stay here long if you're good.
- SOC Analyst (Tier 2/3): $75,000–$105,000. Threat hunting, incident response ownership, SIEM tuning. This is where the job becomes interesting.
- Penetration Tester / Ethical Hacker: $85,000–$145,000. Highly variable. Independent contractors and consultants often bill $150–$200/hour. OSCP is effectively a hiring filter at mid-market and above.
- Security Engineer: $95,000–$155,000. The most in-demand title right now. Spans cloud security, application security, and infrastructure hardening. Strong overlap with DevSecOps.
- Cloud Security Engineer: $115,000–$175,000. AWS/Azure/GCP-specific security architecture. One of the fastest-growing sub-disciplines and commanding a 15–20% premium over on-prem equivalents.
- Security Architect: $130,000–$195,000. Requires 8–12 years of experience in most shops. Owns the enterprise security design decisions.
- CISO (Chief Information Security Officer): $175,000–$350,000+. Compensation includes equity at most companies above Series B. At Fortune 500s, total comp can exceed $500K.
Geographic premiums still matter even in a remote-first market. San Francisco and New York roles pay 20–35% above national median. But fully remote positions at large tech firms are now priced closer to the SF rate regardless of where you live, which has substantially changed the math for people in mid-sized cities.
How Certifications Affect Cybersecurity Salary
Certifications don't uniformly increase salary — some function as hiring filters (you can't get the interview without them), while others actually command a measurable premium once you're in the seat. Here's the practical breakdown:
CompTIA Security+
Required for DoD 8570 compliance, which means it's effectively mandatory for any US federal contractor role. In the private sector, it marks the entry-level floor. Hiring managers at managed security providers treat it as table stakes, not a differentiator. Average salary premium: minimal on its own, but opens access to the $65K–$85K entry range.
CISSP (Certified Information Systems Security Professional)
The clearest credential-to-salary correlation in the field. ISC2 surveys consistently show CISSP holders earning $25,000–$35,000 more than peers without it in equivalent roles. The five-year experience requirement means it functions as a mid-career accelerator rather than an entry point. This is the cert that separates security engineers from security architects in most enterprise job descriptions.
OSCP (Offensive Security Certified Professional)
The standard filter for penetration testing roles at serious security firms. Unlike most certs, OSCP requires demonstrating actual attack skills in a 24-hour hands-on exam. Holders average $110,000–$150,000. Its value is concentrated in offensive security and red team roles — less relevant for GRC or defensive positions.
AWS/Azure Security Specialty
Cloud-specific security certs are adding meaningful premiums right now because the supply of cloud security specialists still doesn't meet demand. AWS Security Specialty holders report 10–18% higher offers than comparable candidates without it. This trend will likely flatten over the next three to five years as more people enter the pipeline.
CISM (Certified Information Security Manager)
Management-track credential that pairs well with CISSP for people moving toward director or CISO roles. High correlation with salaries above $140,000. Less useful if you want to stay technical.
Entry-Level Cybersecurity Salary: What to Realistically Expect
Job postings will say "$65,000–$95,000" for an analyst role. In practice, most employers start entry-level hires at the lower end unless you bring a specific skill stack they need (malware analysis, cloud familiarity, scripting). Here's what actually determines where in that band you land:
- Certifications at time of hire: Security+ alone gets you in the door. Network+ or CySA+ alongside it, and you're negotiating from a stronger position.
- Demonstrated hands-on work: A TryHackMe or HackTheBox profile, a home lab write-up, or a CTF competition result carries more weight than a cert in a portfolio review. Employers are increasingly skeptical of cert collectors who can't explain what they actually did.
- Degree vs. bootcamp vs. self-taught: For SOC analyst and entry security engineer roles, this matters less than it did five years ago. A CS degree helps at enterprise employers and government contractors. At startups and mid-market tech companies, a strong portfolio beats a degree almost every time.
- Industry vertical: Finance and healthcare pay 15–25% above retail and nonprofit for equivalent roles due to regulatory burden and breach risk.
Top Courses to Increase Your Cybersecurity Salary
Not every course moves your compensation. The ones below are worth your time specifically because they build verifiable, job-interview-relevant skills rather than theory you'll forget in six months.
Put It to Work: Prepare for Cybersecurity Jobs
Google's capstone course on Coursera is genuinely practical — it focuses on the job-readiness gap that kills most candidates: translating what you know into what employers can evaluate. Rated 9.7/10. If you're making the jump from IT support or another field, this is a better investment than another cert prep course.
A Practical Guide to Cybersecurity Operations Foundations
Udemy course rated 9.6/10 that covers the operational day-to-day of a SOC role rather than just exam content. Particularly useful for understanding incident triage workflows, SIEM platforms, and log analysis — the three things a Tier 1 analyst actually does all day.
CompTIA SecAI+ Fundamentals: AI Cybersecurity Basics
AI-specific security skills are becoming a hiring differentiator faster than most people expected. This Udemy course (rated 9.6/10) covers the CY0-001 exam domain but more importantly gives you vocabulary and context for defending AI systems — a gap that's showing up in job descriptions at tech firms right now.
Building and Configuring Your Cybersecurity Attack Lab
This is the hands-on lab setup course (rated 9.6/10) that the cert prep courses won't teach you. Knowing how to build a test environment where you can actually practice attack and defense scenarios is what separates candidates who interview well from those who only pass written exams.
Unspoken Rules of Cybersecurity: A CISO's 20-Year Playbook
Rated 9.5/10. More relevant to people at the $90K–$130K level who want to understand how security decisions actually get made inside organizations — the organizational dynamics, stakeholder management, and risk communication that determine who gets promoted. Technical skills get you hired; this is what gets you to $150K+.
The Official ISC2 CC Certified in Cybersecurity Exam Prep (2026)
ISC2's entry-level CC cert is currently free to test for, which makes this 9.5-rated prep course one of the best ROI moves for someone without credentials. Getting CC on your resume while you build toward CISSP is a legitimate strategy for breaking into the field faster.
Cybersecurity Salary FAQ
What is the average cybersecurity salary in the US?
BLS reports the median annual wage for information security analysts at $112,000 as of 2024. But the useful number depends on your role. Entry-level analysts typically start at $60,000–$75,000. Experienced security engineers and architects average $130,000–$170,000. CISO compensation at mid-sized companies commonly exceeds $200,000 total.
Do cybersecurity certifications actually increase salary?
Yes, but not equally. CISSP has the most consistent premium ($25,000–$35,000 across studies). CompTIA Security+ functions more as a hiring gate than a salary booster on its own. Cloud security certs (AWS, Azure) are currently commanding premiums because supply is still short. OSCP matters if you're targeting penetration testing specifically. Stacking certs without hands-on experience adds cost and diminishing returns after the first two or three.
Can you make six figures in cybersecurity without a degree?
Yes, and it's fairly common. The field has historically been more credential- and skills-based than degree-based. A combination of CompTIA Security+, a cloud cert, and demonstrable lab or CTF work lands many people in the $80,000–$110,000 range without a four-year degree. The exception is government and DoD contracting, where degree requirements are often written into contract minimums regardless of ability.
What cybersecurity role pays the most at entry level?
Cloud security roles tend to start higher ($85,000–$105,000) than traditional SOC or helpdesk-adjacent security positions, because cloud security requires an overlap of infrastructure knowledge and security practice that's currently undersupplied. DevSecOps roles at tech companies also start high, typically $90,000–$115,000 for someone with development experience who pivots to security.
How long does it take to reach a $100K cybersecurity salary?
Most people with a structured learning path — relevant cert, hands-on practice, entry-level role — cross $100,000 within 3–5 years. Moving faster (2–3 years) requires either a cloud or DevSecOps angle (higher floor), a CISSP within the first few years (unusual but possible with prior IT experience), or getting into a high-paying vertical like financial services early. The traditional SOC → security engineer track typically takes 4–6 years to reliably clear $100K at most employers.
Is the cybersecurity job market still strong in 2026?
Demand remains structurally high. ISC2 estimates the global cybersecurity workforce gap at 4.8 million unfilled positions. The caveat is that the entry-level market has gotten more competitive — bootcamps flooded it with certificate-holders who lack hands-on skills. Candidates who can demonstrate real capabilities through a portfolio, lab work, or CTF participation are still in strong demand. The weak market is specifically for people who completed training programs without building applied skills alongside the credentials.
Bottom Line
Cybersecurity salary potential is real, but it tracks skills and specialization more than it tracks credentials or time served. The clearest path to $100,000+ in under five years is to pick a lane — cloud security, penetration testing, or DevSecOps — and build specific, demonstrable skills in that area rather than collecting broad certifications across every domain.
If you're starting out: CompTIA Security+ gets you through the door, a home lab or TryHackMe profile gets you the offer, and your first 18–24 months in a real SOC or security team will teach you more than any course. Once you have that foundation, the CISSP is the single most cost-effective credential for moving into the $120,000–$160,000 range.
The courses listed above are selected for building skills that show up in interviews, not just on a resume. Start with the one that matches where you actually are in the progression, not where you want to end up.