Quick Answer
Cyber security jobs in the USA pay a median of roughly $124,910 a year for information security analysts as of May 2024, according to the U.S. Bureau of Labor Statistics, with most roles ranging from about $95,000 for entry-level analysts to well over $200,000 for senior security engineers, architects, and CISOs. Pay varies significantly by role, years of experience, certifications held (CISSP, CEH, Security+, CISM), and location, with tech hubs like the San Francisco Bay Area, Seattle, and Washington D.C. paying 20 to 40 percent above the national average. Certifications and specialized skills such as cloud security and penetration testing consistently command the largest pay premiums.
Key Highlights of Cyber Security Jobs Salary USA
- The U.S. Bureau of Labor Statistics puts the median annual wage for information security analysts at $124,910 (May 2024), with the field projected to grow 29 percent from 2024 to 2034, far faster than the average occupation.
- Entry-level cybersecurity salaries typically start between $70,000 and $95,000, while senior individual contributors and architects often earn $150,000 to $200,000 or more.
- CISO and other executive security leadership roles report median base pay near $286,000, with total compensation at large enterprises frequently exceeding $400,000 to $500,000 once bonus and equity are included.
- Certifications carry real, measurable pay premiums: CISSP holders report some of the highest averages in the field, CCSP holders in cloud-heavy roles report similarly strong pay, and even foundational credentials like CompTIA Security+ correlate with a meaningful bump over non-certified peers.
- Location still matters a great deal: states such as Washington, New York, California, Colorado, and Maryland, along with metro areas like San Jose and Washington D.C., pay well above the national median because of concentrated tech and federal/defense employment.
- CyberSeek reports well over 500,000 open cybersecurity positions in the US in the past year, yet 2025 industry research shows the hiring gap is increasingly driven by budget constraints rather than a true shortage of qualified candidates.
The US Cybersecurity Job Market in 2026
Cybersecurity has remained one of the most resilient corners of the US tech job market through 2025 and into 2026. Ransomware, supply-chain attacks, cloud misconfigurations, and AI-driven phishing have kept board-level attention, and therefore budget, on security hiring even as some other IT categories saw slower growth. That said, the market has matured. A few years ago, headlines focused almost entirely on a raw "talent shortage." Today, the picture is more nuanced: industry surveys increasingly point to budget constraints, not a lack of qualified people, as the leading reason organizations report unfilled security roles. For job seekers and employers alike, that shift matters because it means compensation, role clarity, and demonstrable, certified skills increasingly decide who gets hired and how much they are paid, rather than sheer scarcity of applicants.
Against that backdrop, understanding what cyber security jobs actually pay in the USA, broken down by role, experience, certification, and geography, is more useful than a single average number. This guide pulls together the most current and reliable public data available, led by the U.S. Bureau of Labor Statistics Occupational Outlook Handbook and the CyberSeek cybersecurity supply and demand heat map, supplemented with role-level and certification-level data from established salary-tracking platforms.
National Average Cyber Security Salary in the USA
The single most authoritative number available is the Bureau of Labor Statistics figure for the occupation it formally tracks, "Information Security Analysts." As of the most recent BLS Occupational Outlook Handbook update, the median annual wage for this occupation was $124,910 in May 2024, meaning half of all information security analysts in the country earned more than that and half earned less. This BLS figure is the government's standardized measure and is generally considered the most defensible single data point for the field, though it covers one specific occupational classification rather than every job title that falls under the broader "cybersecurity" umbrella.
CyberSeek, a workforce data project developed with support from the National Initiative for Cybersecurity Education (NICE) at the National Institute of Standards and Technology (NIST), reports a closely aligned median salary figure for information security analysts and adds valuable context on demand: US employers posted several hundred thousand cybersecurity job openings over the trailing 12 months, with a supply-to-demand ratio indicating there are meaningfully fewer available qualified workers than open requisitions in most states. Commercial salary aggregators such as Glassdoor and ZipRecruiter, which draw from broader self-reported and job-posting data across many more job titles than the single BLS occupational code, tend to report a somewhat wider range, commonly citing an overall US cybersecurity average in the neighborhood of $130,000 to $140,000 a year once higher-paying specialist and leadership titles are folded in. The takeaway for anyone researching pay in this field is that no single number tells the whole story. The realistic range for a working cybersecurity professional in the US in 2026 runs from roughly $70,000 at the entry level to well over $250,000 for senior architects and executives, and the sections below break that range down by the variables that actually drive it.
Cyber Security Salary by Experience Level
Experience is one of the strongest predictors of cybersecurity pay, often more influential than job title alone, because responsibilities and decision-making authority expand quickly once someone has three to five years of hands-on incident response, engineering, or risk-management experience.
- Entry-level (0 to 2 years): Analysts, junior SOC (Security Operations Center) staff, and IT-security generalists typically earn between $70,000 and $95,000 a year. This tier often includes recent graduates and career-changers who hold a foundational certification such as CompTIA Security+ but limited hands-on experience.
- Mid-level (3 to 7 years): Security analysts, engineers, and SOC Tier 2/3 staff with real incident-response and tooling experience typically see $105,000 to $150,000, with cloud security and penetration-testing specialists frequently landing at the higher end of that band.
- Senior-level (8 to 15 years): Senior security engineers, security architects, and lead penetration testers commonly report $150,000 to $200,000 in base salary, with total compensation (including bonus and equity at larger companies) often pushing higher.
- Executive/leadership (15+ years): Directors of security, VPs of Information Security, and Chief Information Security Officers (CISOs) report the widest range of any tier, with base pay commonly between $180,000 and $300,000, and total compensation at large enterprises and financial institutions frequently exceeding $400,000 once bonus and equity are included.
It is worth noting that the jump from mid-level to senior-level compensation in cybersecurity tends to track closely with the acquisition of an advanced, vendor-neutral certification such as CISSP or CISM, a pattern covered in more detail in the certification section below.
Cyber Security Salary by Role
Job titles in cybersecurity are notoriously inconsistent between employers, but the roles below represent the most commonly recruited positions in the US market, along with the salary ranges reported across multiple current 2026 industry salary trackers, including Glassdoor, ZipRecruiter, and specialized cybersecurity career sites.
| Role | Typical US Salary Range (Base) | Reported Average | Notes
|
| SOC Analyst (Tier 1/2) | $65,000 to $105,000 | ~$90,000 | Entry point for many careers; shift and on-call work common |
| Information Security Analyst | $85,000 to $150,000 | ~$124,910 (BLS median) | Official BLS occupational classification; broadest data set |
| Penetration Tester / Ethical Hacker | $90,000 to $170,000 | ~$120,000 | CEH and OSCP strongly influence upper range |
| Security Engineer | $110,000 to $175,000 | ~$135,000 | Builds and hardens security infrastructure; cloud skills add premium |
| Cloud Security Engineer | $120,000 to $185,000 | ~$150,000 | CCSP and AWS/Azure security certifications in high demand |
| Security Architect | $140,000 to $200,000 | ~$165,000 | Senior design authority; usually requires CISSP or equivalent |
| Security Manager / Director | $130,000 to $210,000 | ~$160,000 | People management plus technical oversight |
| Chief Information Security Officer (CISO) | $161,000 to $420,000+ | ~$286,000 median base | Total comp at Fortune 500 firms often exceeds $500,000 with equity/bonus |
Professionals researching how to move from a role like SOC analyst into higher-paying engineering or architecture positions typically combine hands-on project experience with an advanced certification. Simpliaxis offers a CISSP certification training course designed for professionals aiming at senior security analyst, architect, and leadership tracks, and a Microsoft Azure Security Technologies (AZ-500) course for those targeting the growing cloud-security specialization that now commands some of the highest premiums in the field.
Cyber Security Salary by Certification
Certifications remain one of the clearest, most measurable levers for increasing cybersecurity pay in the USA. Multiple independent salary surveys converge on a consistent pattern: advanced, vendor-neutral, management-adjacent certifications like CISSP and CCSP correlate with the strongest premiums, while foundational certifications like CompTIA Security+ correlate with a smaller but still meaningful bump, mostly by making a candidate eligible for roles they otherwise could not access.
| Certification | Typical Reported Average Salary | Approximate Premium Over Non-Certified Peers | Best Fit For
|
| CompTIA Security+ | $90,000 to $105,000 | ~$5,000 to $10,000 | Entry-level analysts, IT-to-security career changers |
| Certified Ethical Hacker (CEH) | $95,000 to $130,000 | ~$12,000 to $18,000 (for pentest roles) | Penetration testers, red-team analysts |
| Certified Information Security Manager (CISM) | $120,000 to $165,000 | ~$15,000 to $25,000 | Security managers moving toward governance and risk leadership |
| Certified Information Systems Security Professional (CISSP) | $130,000 to $170,000+ | ~$25,000 to $35,000 | Senior analysts, architects, and managers with 5+ years experience |
| Certified Cloud Security Professional (CCSP) | $145,000 to $168,000 | ~$20,000 to $30,000 | Cloud security engineers and architects |
These figures are drawn from a range of current industry salary trackers and certifying-body data rather than a single source, since no government agency publishes certification-specific wage data. They should be read as directional evidence of a real, consistent pattern (advanced and specialized certifications pay more) rather than as precise, audited figures. Professionals evaluating which credential to pursue next often start with a Certified Information Security Manager (CISM) course if they are moving toward governance and leadership, or a foundational DevSecOps Foundation certification if they are coming from a software development background and want to build security skills into an existing engineering career.
Cyber Security Salary by State and Metro Area
Location remains one of the largest single swing factors in cybersecurity compensation, driven mainly by concentration of tech employers, federal and defense contracting, and regional cost of living. Multiple 2026 salary datasets consistently place the following states at or near the top of the national ranking:
- Washington: reported average near $150,000, driven by a dense concentration of major cloud and technology employers around Seattle.
- New York: reported average in the $133,000 to $147,000 range, driven by financial-services security demand.
- Colorado: reported average around $132,000, boosted by a growing federal and aerospace-defense security cluster.
- Maryland and Virginia: both consistently rank near the top of the national list because of their proximity to federal agencies and defense contractors; Virginia's average is commonly reported near $131,000.
- California: reported average around $131,000 to $135,000 statewide, with the San Jose-Sunnyvale-Santa Clara metro area reporting some of the highest metro-level averages in the country, commonly cited above $175,000, reflecting Silicon Valley's concentration of big tech security teams.
Remote and hybrid work has narrowed, but not eliminated, these geographic gaps. Multiple salary trackers report that fully remote cybersecurity roles now pay close to, and in some cases above, in-office roles in the same metro tier, since employers increasingly benchmark remote pay against national or regional tech-hub bands rather than the employee's home-state cost of living.
Cyber Security Salary by Industry
Industry sector also has a measurable effect on cybersecurity pay, largely reflecting how much regulatory pressure, data sensitivity, and security-budget maturity a sector carries. Recent 2026 industry-pay data consistently ranks the following sectors among the highest payers for cybersecurity talent:
- Telecommunications: among the highest-paying sectors, with median total pay reported above $150,000, reflecting critical-infrastructure security requirements.
- Information Technology: median total pay commonly reported in the high $130,000s, reflecting both the volume and sophistication of security roles at software and cloud companies.
- Financial Services: median total pay commonly reported in the mid-$130,000s, driven by heavy regulatory compliance obligations (PCI-DSS, SOX, GLBA) and the high cost of a breach.
- Aerospace and Defense: median total pay commonly reported around $125,000, reflecting government clearance requirements and specialized skill premiums.
- Healthcare: increasingly competitive on pay as HIPAA enforcement and ransomware targeting of hospital systems have pushed security budgets up significantly since 2023.
Factors That Influence Cyber Security Pay
Beyond role, certification, and location, several other variables consistently move the needle on cybersecurity compensation in the USA:
- Years of hands-on experience: particularly experience that includes live incident response, red-team/blue-team exercises, or building security programs from scratch, tends to matter more to hiring managers than years of tenure alone.
- Specialized technical skills: cloud security (AWS, Azure, GCP), identity and access management, application security/DevSecOps, and threat intelligence are consistently reported as the highest-premium specializations in 2025 to 2026 hiring data.
- Security clearance: for roles supporting US federal agencies or defense contractors, an active security clearance (Secret or Top Secret) can add a substantial premium because of the limited pool of eligible candidates.
- Company size and funding stage: large, well-funded enterprises and late-stage tech companies generally pay above median, while early-stage startups may offer lower base pay offset by equity.
- Formal education: the BLS notes that information security analysts typically need a bachelor's degree in a computer science-related field, and that employers increasingly prefer candidates who combine a degree with professional certification, especially for senior and architecture-level roles.
- Union and public-sector pay scales: government cybersecurity roles often sit on fixed General Schedule (GS) pay bands, which can be lower than private-sector equivalents at the individual-contributor level but offer more predictable long-term progression and benefits.
The Gender Pay Gap in Cybersecurity
Pay equity remains an unresolved issue in the field. The 2025 ISC2 Cybersecurity Workforce Study, which surveyed more than 16,000 cybersecurity professionals globally, found a persistent gap between what men and women in the field report earning, with men in the study reporting average pay meaningfully higher than women in comparable roles. Industry groups, including (ISC)2, have flagged this as an area requiring continued attention from employers, since the underlying skills and certification requirements for a given role do not differ by gender. Organizations that want to close this gap are increasingly turning to structured, transparent pay bands tied to certification level and demonstrated skill rather than negotiated starting offers, which research has repeatedly shown tend to disadvantage women entering technical fields.
Job Outlook and Demand Through 2034
The long-term outlook for cybersecurity employment in the US remains among the strongest of any occupation tracked by the federal government. The Bureau of Labor Statistics projects that employment of information security analysts will grow 29 percent from 2024 to 2034, a rate the agency classifies as "much faster than the average for all occupations," with about 16,000 openings projected each year on average over the decade, driven mostly by the need to replace workers who transfer to other occupations or retire, on top of new positions created by growing demand for cyber defense.
CyberSeek's supply-and-demand heat map, built using real-time job posting data, shows a similarly strong demand signal, with well over 500,000 cybersecurity job postings recorded across the US in the trailing 12 months and a national supply-to-demand ratio indicating that the available pool of qualified, actively job-seeking cybersecurity workers remains smaller than the number of open roles in most states, particularly those with heavy federal and defense presence such as Virginia, Maryland, and the District of Columbia.
That said, the narrative around the field's often-cited "workforce gap" has shifted meaningfully. Earlier ISC2 workforce studies popularized a headline figure of roughly 4.8 million unfilled cybersecurity jobs globally, but that number measured perceived organizational need rather than actual open, funded requisitions, and ISC2's more recent research has moved away from leading with that figure. Instead, the 2025 study and related 2025-2026 industry reporting increasingly identify budget constraints, not a lack of qualified candidates, as the top reason organizations report unfilled security positions, with a notable share of organizations also reporting cybersecurity budget cuts, hiring freezes, or layoffs over the prior year. For job seekers, the practical implication is that demand for cybersecurity skills remains genuinely strong, but landing the best-paying roles increasingly requires demonstrable, certified skills and a clear specialization rather than simply the existence of open headcount.
How to Increase Your Cybersecurity Salary
Based on the patterns in the data above, a few strategies consistently correlate with faster salary growth for cybersecurity professionals in the USA:
- Earn an advanced, respected certification. CISSP shows the strongest and most consistent premium of any widely held credential in the field, particularly once a professional has the five years of experience required to hold the certification without needing an associate waiver. Simpliaxis's CISSP certification training is built around the exam's eight domains, including security and risk management, security architecture and engineering, and security operations.
- Specialize in cloud security. As more enterprise infrastructure moves to AWS, Azure, and Google Cloud, cloud security skills are consistently among the highest-paying specializations. A credential like the Microsoft Azure Security Technologies (AZ-500) certification signals verified cloud-specific security skill to employers who are actively competing for this talent.
- Move toward governance, risk, and leadership. Professionals who combine technical credibility with governance and risk management knowledge, often via a certification like CISM, tend to move into management and eventually CISO-track roles faster, and those roles carry the highest ceiling in the field.
- Build application security skills early in a development career. Developers who add security skills, rather than security professionals who try to learn development from scratch, are increasingly valuable in DevSecOps-oriented organizations. A foundational credential such as DevSecOps Foundation is a common entry point for this path.
- Target high-paying industries and metros deliberately. Because industry and location together can swing total compensation by 30 percent or more, professionals with location flexibility should weigh remote roles at companies headquartered in high-paying metros or regulated industries like financial services and telecommunications.
- Pursue a security clearance where relevant. For candidates open to defense, intelligence, or federal contracting work, an active clearance remains one of the fastest ways to access above-market pay because of the restricted candidate pool.
Key Takeaways
- The BLS median for information security analysts is $124,910 (May 2024), with the broader cybersecurity job market realistically ranging from about $70,000 at entry level to $250,000+ for senior architects and executives.
- CISO and senior security-leadership roles carry the highest ceiling, with median base pay near $286,000 and total compensation often exceeding $400,000 at large enterprises.
- Certifications produce measurable, consistent pay premiums, with CISSP and CCSP showing the strongest impact and CompTIA Security+ serving as a valuable entry point.
- Location and industry both swing total compensation by 20 to 40 percent, with Washington, New York, California, Colorado, Maryland, and Virginia consistently at the top, and telecommunications, IT, and financial services leading among industries.
- Cybersecurity employment is projected to grow 29 percent from 2024 to 2034 per the BLS, and CyberSeek shows well over 500,000 open US positions, though recent ISC2 research shows budget constraints, not a pure talent shortage, increasingly explain unfilled roles.
- A gender pay gap persists in the field according to the 2025 ISC2 Cybersecurity Workforce Study, an issue employers are increasingly addressing through structured, certification-linked pay bands.
- The fastest documented paths to higher pay are an advanced certification (CISSP or CISM), a cloud-security specialization, or a move into governance, risk, and leadership tracks.
Schema Recommendation and Source Notes
Recommended schema markup: Article schema combined with FAQPage schema for the Frequently Asked Questions section above, which should improve eligibility for rich results and AI answer-engine citation.
Facts that could not be independently verified in this session: Direct, real-time retrieval of BLS.gov, CyberSeek.org, and ISC2.org was not possible during research for this article due to a network access restriction in the research environment. The BLS median wage figure ($124,910, May 2024) and the BLS 29 percent growth projection are drawn from search-engine-indexed summaries of the official BLS Occupational Outlook Handbook page rather than a direct page fetch, as are the CyberSeek job-opening and supply/demand figures and the ISC2 Cybersecurity Workforce Study gender-pay findings. All role-level and certification-level salary ranges (SOC analyst, penetration tester, CISO, CISSP, CEH, Security+, CISM, CCSP premiums, and state/industry breakdowns) are aggregated from multiple current third-party salary-tracking sources rather than a single audited dataset, and individual figures can vary meaningfully by methodology, sample size, and reporting period. Before publishing, these figures should be spot-checked against a live pull of the BLS Occupational Outlook Handbook page, the CyberSeek heat map, and the current ISC2 Cybersecurity Workforce Study report.


























