The median cybersecurity analyst salary in the United States hit $112,000 in 2025 — more than double the median US wage. Entry-level roles start around $65,000, and experienced security engineers at major tech companies routinely clear $180,000–$220,000 before equity. If you're weighing a career move, the cybersecurity salary landscape is one of the most favorable in tech right now.
This guide breaks down real pay numbers by role, experience level, city, and certification so you can set accurate expectations — and understand exactly which credentials move the needle.
Average Cybersecurity Salary by Role in 2026
Cybersecurity isn't one job — it's a cluster of specializations with very different pay ceilings. Here's where the money actually sits:
| Role | Median US Salary | Senior / Top 10% |
|---|---|---|
| Information Security Analyst | $112,000 | $165,000 |
| Penetration Tester / Ethical Hacker | $118,000 | $180,000 |
| Security Engineer | $135,000 | $210,000 |
| Cloud Security Engineer | $148,000 | $220,000 |
| Security Architect | $158,000 | $230,000 |
| Chief Information Security Officer (CISO) | $238,000 | $400,000+ |
| SOC Analyst (Tier 1) | $65,000 | $95,000 |
| Incident Response Analyst | $108,000 | $155,000 |
Sources: Bureau of Labor Statistics (May 2024), Glassdoor, Levels.fyi, LinkedIn Salary 2025.
The wide range between SOC Tier 1 and Cloud Security Engineer reflects genuine skill differences — not just title inflation. SOC analysts are monitoring dashboards; cloud security engineers are designing zero-trust architectures. If salary is your primary goal, the engineering track pays materially more than the analyst track.
Cybersecurity Salary by Experience Level
Career stage matters more than role in the early years. Here's how cybersecurity salary scales with experience:
Entry Level (0–2 years)
Most people enter through SOC analyst, junior security analyst, or IT security specialist roles. Expect $55,000–$80,000 nationally, with higher numbers in tech hubs. CompTIA Security+ is the baseline certification employers look for at this level. Google's Cybersecurity Professional Certificate has become a popular and recognized fast-track credential for career changers.
Mid-Level (3–6 years)
This is where pay accelerates sharply. Professionals with a Security+ plus hands-on experience in SIEM tools, vulnerability management, or cloud security regularly land $95,000–$140,000. Adding a CISSP or CEH pushes the upper end of that range significantly.
Senior Level (7+ years)
Senior security engineers and architects sit in the $150,000–$230,000 range at established companies. At FAANG-tier employers, total compensation (base + RSUs + bonus) can reach $300,000+ for staff-level security engineers.
Management / Executive
Security managers average around $160,000–$190,000. CISOs at Fortune 500 companies are among the highest-paid IT executives, with median total comp above $300,000 and top earners exceeding $500,000 at financial institutions and healthcare systems.
How Location Affects Your Cybersecurity Salary
Geography still matters — even with remote work expanding options. The cybersecurity salary gap between San Francisco and rural markets remains over 40%:
- San Francisco / Bay Area: $145,000–$195,000 median
- New York City: $130,000–$175,000
- Washington D.C. / Northern Virginia: $120,000–$165,000 (government + defense contractors inflate demand)
- Seattle: $135,000–$180,000
- Austin: $110,000–$150,000
- Chicago: $105,000–$145,000
- National Average (all markets): $112,000
Northern Virginia deserves a callout: it's the global hub for defense and intelligence cybersecurity work. Cleared professionals (Secret or TS/SCI clearance) command a 15–25% premium on top of already-high regional salaries, making DoD-adjacent cyber one of the highest-paying niches in the field.
Which Certifications Actually Raise Your Cybersecurity Salary
Not all certifications are equal. Here's an honest breakdown of credential ROI based on job posting data and reported salary premiums:
CompTIA Security+ (~$5,000–$10,000 salary bump)
The entry-level standard. Required by many government contractor roles under DoD 8570 regulations. Gets your resume past screening at large employers, but won't differentiate you at mid-senior levels.
CISSP — Certified Information Systems Security Professional (~$15,000–$25,000 premium)
The gold standard for mid-career professionals. Consistently appears as the highest-salary-correlated certification in industry surveys. Requires 5 years of experience to qualify, so it's not an entry-level play — but it's the single most effective credential for pushing past the $130K floor.
CEH — Certified Ethical Hacker (~$8,000–$15,000 bump)
Valued for penetration testing and red team roles. Less universally respected than CISSP among security practitioners, but still opens doors in offensive security.
AWS Security Specialty / Google Professional Cloud Security Engineer (~$20,000+ premium)
Cloud security is the fastest-growing segment of the field. Adding a cloud security certification to a base cybersecurity background pushes you into the $140,000+ tier quickly. This is the highest ROI credential combination right now given cloud adoption rates.
OSCP — Offensive Security Certified Professional (variable, often $20,000+)
The hardest and most respected certification for penetration testers. Hands-on exam, no multiple choice. If you want to break into offensive security or bug bounty work, OSCP signals genuine skill in a way that theory-based certs don't.
Top Courses to Build Cybersecurity Skills (and Earning Power)
Whether you're starting from scratch or upskilling toward a higher-paying specialty, these courses have the clearest path from enrollment to job-ready skills:
Foundations of Cybersecurity (Coursera / Google)
Google's entry-level cybersecurity certificate is the most employer-recognized fast-track into the field. It covers core security frameworks, threat identification, and SIEM tools — exactly what SOC analyst job postings ask for. Best starting point for career changers targeting that $65,000–$80,000 entry-level range.
Cybersecurity Assessment: CompTIA Security+ & CySA+ (Coursera)
Directly prepares you for the two most important certifications for mid-level security analysts. If your goal is to cross the $90,000 threshold, combining Security+ and CySA+ credentials is one of the most direct paths — this course does both.
IBM and ISC2 Cybersecurity Specialist Professional Certificate (Coursera)
ISC2 co-authorship gives this program unusually strong credentialing relevance. The CC (Certified in Cybersecurity) entry-level ISC2 credential is earned alongside this course, giving you a recognized certification plus practical IBM Security tooling experience — a strong combination for analyst roles.
Computer Science for Cybersecurity (edX)
For people who want to understand the underlying systems, not just the security layer on top. Covers networking, OS fundamentals, and cryptography from a CS perspective. Worth it if you're targeting security engineering roles rather than analyst positions — engineers earn $20,000–$40,000 more on average.
Generative AI Cybersecurity & Privacy for Leaders (Coursera)
AI-specific security is an emerging specialty with premium pay. This specialization positions you for the intersection of AI governance and security — a niche that barely existed two years ago but is now a dedicated hiring category at major enterprises.
Cybersecurity for Business Specialization (Coursera)
Targets the management and strategy side of security rather than hands-on technical skills. If you're aiming at security manager, vCISO, or compliance roles — which pay $140,000–$190,000 — this business-oriented framing accelerates that track more than another technical cert would.
FAQ
What is the starting salary for cybersecurity jobs?
Entry-level cybersecurity roles — typically SOC Tier 1 analyst, junior security analyst, or IT security specialist — pay between $55,000 and $80,000 nationally. In major tech hubs like San Francisco, DC, or New York, entry salaries can start closer to $70,000–$90,000. Having a recognized certification like CompTIA Security+ or the Google Cybersecurity Certificate significantly improves both your hiring odds and starting offer.
Can you make $100K in cybersecurity without a degree?
Yes — and it's increasingly common. Many mid-level security analysts and junior penetration testers cross $100,000 with 3–5 years of experience plus certifications (CISSP, CEH, or cloud security certs), regardless of whether they hold a formal degree. Employers in this field are notably more credential- and skills-focused than degree-focused compared to other industries. Bootcamp graduates and self-taught professionals regularly reach six figures within 4–6 years.
Which cybersecurity job pays the most?
Cloud Security Engineer and Security Architect are the highest-paying individual contributor roles, with medians of $148,000–$158,000 and top earners above $230,000. At the executive level, CISO pay at large enterprises regularly exceeds $300,000 in total compensation. If maximizing salary is the goal, the path is: foundational certs → hands-on experience → cloud security specialization → senior engineering or architecture track.
Is cybersecurity a good career in terms of job security?
The global cybersecurity talent shortfall is estimated at 3.4 million unfilled positions as of 2025 (ISC2 Cybersecurity Workforce Study). Layoffs in this sector are significantly rarer than in software engineering generally — security headcount is often treated as non-discretionary in regulated industries. Job security is genuinely strong.
How long does it take to get a cybersecurity job from scratch?
Realistically, 12–24 months from zero IT background to first cybersecurity role if you pursue structured training. The fastest path: complete a Google or IBM cybersecurity certificate (3–6 months), pass CompTIA Security+ (~2–3 months of prep), and apply specifically for SOC Tier 1 roles while building a home lab and CTF (capture-the-flag) portfolio. Some career changers land roles in under a year; others with no tech background take closer to two.
Does a cybersecurity degree pay more than certifications alone?
At the senior level, degrees matter less than experience and certifications. At the entry level and for government/defense roles, a bachelor's in cybersecurity, computer science, or IT can accelerate hiring. For federal positions and DoD contractors, a degree plus clearance eligibility is often explicitly required. For private sector roles, CISSP + experience typically outperforms a degree without certs in salary negotiations.
Bottom Line
The cybersecurity salary market is genuinely strong — but "cybersecurity" is a broad label covering roles that pay $65,000 and roles that pay $230,000. The gap comes down to specialization and credentials, not just years of experience.
If you're starting out: focus on the Google Cybersecurity Certificate and CompTIA Security+ as your fastest path to an employable baseline. If you're mid-career looking to push past $120,000: the CISSP or a cloud security certification (AWS or GCP) has the clearest salary data supporting the investment. If you're aiming at the $150,000+ range: cloud security engineering or security architecture — supported by hands-on experience and the CS fundamentals background to back it up — is where the ceiling sits.
The field rewards people who can actually do the work, not just name the frameworks. Build the skills, earn the credentials that prove them, and the salary numbers here are very achievable.