Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
In the United States, the clearest federal pay benchmark for cybersecurity is $124,910 a year: that was the median annual wage for information security analysts in May 2024. But cybersecurity is a broad field, not one occupation, and that figure does not describe every security job or experience level. Specialized roles, management, and executive work may pay more; some entry-level and adjacent IT roles pay less.
The figures below distinguish government occupational wages from survey and job-board estimates. Compare duties, seniority, location, and what a number includes—not just the job title.
How to read cybersecurity salary figures
Job titles are not standardized. A security analyst might monitor alerts in a security operations center (SOC), manage vulnerabilities, assess risk, or investigate incidents, depending on the employer. Cybersecurity work also overlaps with IT operations, networking, cloud engineering, software development, privacy, compliance, audit, investigations, and executive leadership.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11The U.S. Bureau of Labor Statistics (BLS) provides the strongest government benchmark in this comparison, but its information security analyst occupation is broader than any one company’s title. Other figures here come from a Glassdoor-based compilation or from ISC2 compensation reports. Those measures have different populations and methods, so they are not a single ranking.
#1 Best Overall
| Job | Compensation figure | Measure and scope |
|---|---|---|
| Information security analyst | $124,910 median; below $69,660 for the lowest 10%; above $186,420 for the highest 10% | U.S. BLS annual occupational wages, May 2024 |
| Cybersecurity analyst | About $111,000 | Glassdoor-based median total pay in Coursera’s April 2026 compilation |
| Cybersecurity engineer | About $119,000 | Glassdoor-based median total pay in Coursera’s April 2026 compilation |
| Cloud security engineer or architect | No comparable role-specific figure established here | ISC2’s 2025 global median for CCSP holders was $118,840; it is credential-holder compensation, not a job-title salary |
| Penetration tester | About $154,000 | Glassdoor-based median total pay in Coursera’s April 2026 compilation |
| Incident responder or digital forensics analyst | No comparable role-specific figure established here | Pay varies by seniority, on-call work, and employer; CyberSeek demand data is not a salary table |
| GRC, risk, or compliance analyst | No comparable role-specific figure established here | ISC2’s 2025 global median for CGRC holders was $134,500; it is credential-holder compensation, not a GRC-role median |
| Security architect | No comparable role-specific figure established here | ISC2’s 2025 global median for ISSAP holders was $140,620; it is credential-holder compensation, not a general architect salary |
| Security manager | About $159,000 | Glassdoor-based median total pay in Coursera’s April 2026 compilation; leadership scope varies widely |
For the BLS figures, see its information security analyst profile. The role-specific Glassdoor-based estimates are from Coursera’s April 2026 salary compilation. Total pay can include additional compensation on top of base pay; it is not a guaranteed salary or necessarily a typical offer for an entry-level candidate.
What eight cybersecurity jobs pay—and what the work involves
1. Information security analyst
Analysts monitor systems, investigate alerts, assess vulnerabilities, and help put security controls in place. BLS reported a U.S. median annual wage of $124,910 in May 2024. The lowest 10% earned below $69,660, while the highest 10% earned above $186,420. These are occupational percentiles, not a promise that a new hire will reach the median.
Entry points may include SOC analyst, junior security analyst, vulnerability-management analyst, or security administrator. Analysts may progress into engineering, incident response, threat hunting, or management as they take ownership of more complex work.
2. Cybersecurity engineer
Engineers build, configure, automate, and maintain security controls and platforms, including identity systems, network protections, detection tooling, and infrastructure. The work typically calls for a stronger engineering focus than alert triage alone: scripting, systems knowledge, automation, and the ability to make controls work reliably at scale.
Coursera’s April 2026 compilation puts the Glassdoor-based median total pay for cybersecurity engineers at about $119,000. Treat it as a survey-derived estimate that may include additional compensation, not a U.S. government wage median.
3. Cloud security engineer or architect
Cloud security work protects identities, workloads, data, configurations, and cloud-native applications. Responsibilities can include cloud access management, logging, secure architecture, configuration controls, and data protection. The title may sit within a security team, platform engineering, infrastructure, DevOps, or enterprise architecture, so compare the actual scope of the role.
Rank #2
No role-specific salary benchmark for cloud security is established here. ISC2 reported a 2025 global median of $118,840 for CCSP holders, but that describes people with a credential, not all cloud security engineers or architects. Cloud expertise may be valuable to employers, but the credential figure should not be read as a salary guarantee.
Recommended Free Tools
4. Penetration tester or ethical hacker
Penetration testers conduct authorized tests of applications, networks, cloud environments, and other systems to identify exploitable weaknesses. The job also involves documenting evidence, explaining risk, and recommending fixes. Testing is performed under defined permission and rules of engagement; it is not the same as unauthorized hacking.
Coursera’s April 2026 compilation reports about $154,000 in Glassdoor-based median total pay for penetration testers. That estimate may reflect experienced workers and additional compensation. A penetration tester, a red-team operator, and a vulnerability-management analyst are different roles, so their titles and pay are not interchangeable.
5. Incident responder or digital forensics analyst
Responders help contain and investigate security incidents, establish what happened, preserve evidence, identify root causes, and support recovery. Digital forensics work may involve careful evidence handling and technical analysis; incident-response roles can also require rapid coordination across security, IT, legal, and business teams.
A single authoritative salary median for these titles is not established here. Junior SOC or response work can differ substantially from senior digital forensics and incident response (DFIR), incident command, or consulting work. Rotating shifts, on-call duties, and crisis demands can affect both compensation and quality of life.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →6. GRC, risk, or compliance analyst
Governance, risk, and compliance (GRC) professionals translate business, regulatory, and contractual requirements into controls, policies, assessments, audit evidence, and risk decisions. The work is security-related even when it is less hands-on with technical tools. Regulated industries, privacy responsibilities, third-party risk, and senior advisory work can change the role’s scope and compensation.
No general GRC job-title median is established here. ISC2’s 2025 global median of $134,500 for CGRC holders is compensation reported by credential holders, not a salary figure for every GRC analyst. GRC experience can also lead toward risk leadership, audit, privacy, or broader security management.
7. Security architect
Security architects design how protections fit together across systems: identity models, network segmentation, cloud controls, application security, and enterprise patterns. Some focus on a particular domain, such as applications or cloud; others set standards across a large organization. The work depends on technical depth as well as the ability to influence teams that build and operate systems.
There is no general security-architect salary median established here. ISC2’s 2025 global median of $140,620 for ISSAP holders is a credential-holder figure, not a direct estimate for everyone with an architect title. Architecture roles usually require substantial prior experience, but the required depth and organizational reach vary.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →8. Security manager or CISO
Security managers may lead a team, program, or function. A chief information security officer (CISO) may be accountable for enterprise strategy, budgets, risk acceptance, incident leadership, governance, and communication with executives or a board. A CISO title at a small business can involve a narrower scope than a security director role at a global organization.
Coursera’s April 2026 compilation reports about $159,000 in Glassdoor-based median total pay for information security managers. It is not a CISO-specific figure. ISC2 separately reported a 2025 global median of $130,000 for ISSMP holders and $127,000 for CISSP holders; those are credential-holder measures, not executive salary estimates. ISC2’s U.S. salary research reported an overall average cybersecurity base salary of $157,583, excluding bonuses and additional compensation, for its surveyed population. These different figures are not directly comparable.
Why cybersecurity pay varies
Skills and responsibility
Pay often follows the scope and consequences of the work more than the word “cybersecurity” in a title. A role that owns cloud controls, application security, detection engineering, or incident command may carry different responsibility from one focused on routine ticket handling. People management, budget ownership, enterprise-wide design, and executive risk decisions can also affect compensation. Technical specialization does not automatically pay more than management; the comparison depends on the employer and role scope.
ISC2’s 2025 workforce study identified AI, cloud security, risk assessment, application security, security engineering, and GRC among important skills needs. CyberSeek reported 514,359 U.S. cybersecurity job listings during May 2024–April 2025 and said 10% of listings specifically referenced AI skills. These are demand indicators for that reporting period, not proof of a particular salary premium or a guarantee of future hiring.
- Blue team: SIEM, endpoint detection, identity, incident response, and detection engineering.
- Security engineering: automation, scripting, network security, secrets management, and infrastructure controls.
- Cloud and application security: cloud identity and logging, threat modeling, secure development, code review, and software supply-chain security.
- Offensive security: web applications and APIs, privilege escalation, adversary emulation, and clear test reporting.
- GRC: control frameworks, audit evidence, risk assessment, third-party risk, and regulatory interpretation.
- Leadership: budgets, metrics, governance, crisis communication, and sound business judgment.
Location, industry, and employer
Higher-cost technology hubs may offer higher nominal pay, while a remote employer may use national, regional, or location-adjusted salary bands. Public-sector and defense roles may be affected by locality pay and clearance requirements. A lower salary in a lower-cost area may provide more purchasing power, so compare local opportunities using the same pay measure.
Financial services, healthcare, defense, technology, consulting, retail, manufacturing, energy, and critical infrastructure have different regulatory, safety, financial, and reputational risks. Those differences can shape security budgets and job duties. Startups may offer equity alongside cash, but equity may not be liquid or ultimately valuable; government work may trade some cash compensation for stability, benefits, pension eligibility, or mission.
Experience and working conditions
Early-career jobs often emphasize alert triage, ticket handling, and implementing established controls. Mid-career practitioners may own investigations, engineering systems, cloud or application specialties, or projects. Senior and principal staff often handle architecture, threat modeling, incident command, or complex cross-functional risk. Managers and executives take on staffing, budgets, governance, regulatory exposure, and business accountability. Years worked alone do not determine pay; the complexity and ownership of the work matter.
Higher compensation can also reflect difficult schedules or constraints. SOC and response roles may require nights, weekends, or rotating on-call. Consulting may bring travel, billable-hour targets, and client deadlines. Penetration tests involve formal rules of engagement and substantial reporting; GRC can be documentation- and meeting-heavy; CISO work carries crisis and accountability exposure. Contractors may receive higher hourly rates without equivalent benefits or job security.
Do certifications increase cybersecurity pay?
Certifications can signal baseline knowledge, meet an employer’s requirements, or support a move into a new specialty. Their value depends on the target role, employer, geography, and what experience a candidate already has. A certification alone does not guarantee a security job, and compensation reported by certificate holders does not show that the certification caused higher pay.
ISC2’s 2025 global figures below are self-reported medians for certification holders, not U.S.-only job-title salaries. They vary with role, region, and experience.
| ISC2 certification | 2025 global median compensation among holders |
|---|---|
| SSCP | $95,200 |
| CGRC | $134,500 |
| CSSLP | $125,000 |
| CCSP | $118,840 |
| CISSP | $127,000 |
| ISSAP | $140,620 |
| ISSEP | $136,800 |
| ISSMP | $130,000 |
Match a credential to the work you want to do: cloud credentials for cloud environments, GRC credentials for governance and risk work, and leadership credentials alongside demonstrated program or management experience. Practical work remains essential—such as labs, documented projects, incident experience, or ownership of real controls.
How to compare a cybersecurity offer
Compare offers on the same basis: annual base pay against annual base pay, or total compensation against total compensation. Ask the employer to define any bonus, equity, overtime, on-call, or clearance-related amounts rather than treating them as guaranteed cash.
Free tools Windows power users keep installed
One-click scans. No signup required.
- Base salary and pay range for the role’s location
- Bonus target, eligibility, and how payouts are determined
- Equity type, vesting schedule, and liquidity limits
- On-call expectations, incident rotation, and any compensation for that work
- Overtime eligibility and travel or billable-hour expectations
- Clearance requirements and whether the employer supports obtaining or maintaining one
- Training, certification, and professional-development budget
- Remote-work or relocation policy and location-based salary adjustments
- Reporting line, team size, turnover, and decision-making authority
- Incident-response responsibilities, including nights and weekends
- Promotion criteria, benefits, and retirement contributions
What the market figures do—and do not—show
BLS projects 29% employment growth for information security analysts from 2024 to 2034 and approximately 16,000 openings per year over that decade. These projections apply to that occupation, not every cybersecurity title. ISC2’s 2025 workforce study surveyed 16,029 cybersecurity practitioners and decision-makers globally; it found 20% received no salary increase in the prior year, 57% received an increase of 1%–9%, and 20% received an increase above 10%. The reported shares do not establish a guaranteed raise for an individual worker.
For demand context, CyberSeek tracks U.S. job listings and pathways; listings are not the same as hires, unique vacancies, or pay offers. BLS wage data, Glassdoor-based total-pay estimates, and ISC2 survey results answer different questions. Use the measure that matches the decision you are making.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

