Key Takeaways
- The average US cybersecurity salary is approximately $115,000, with entry-level roles starting around $60,000 and senior/executive positions exceeding $200,000.
- CISSP holders command the highest certification-driven salary premium, averaging $135,000–$165,000 depending on role and location.
- Geographic location creates a 20–40% swing in compensation — San Francisco, NYC, and the DC/NoVA corridor lead, though remote work is compressing the gap.
- Security clearances add $15,000–$30,000 to base salary, and the premium increases with clearance level (Secret vs. TS/SCI).
- The 4-million-position global workforce gap gives candidates unusually strong negotiating leverage compared to other IT disciplines.
Why Cybersecurity Compensation Matters
Cybersecurity is one of the few fields where demand so consistently outpaces supply that compensation has become a primary competitive lever for employers. With over 4 million unfilled positions worldwide and a BLS-projected growth rate of 32% through 2032, the economics overwhelmingly favor candidates. But "cybersecurity" is not a monolith — a SOC Analyst I in Des Moines earns a fundamentally different salary than a Cloud Security Architect in San Francisco, even though both carry "cybersecurity professional" on their LinkedIn profiles.
This guide breaks down compensation across the dimensions that actually determine your paycheck: role, certifications, years of experience, industry vertical, and geography. Whether you are evaluating a first offer, negotiating a raise, or planning a multi-year career arc, the data below gives you the leverage of specificity rather than vague averages. For a broader view of market dynamics, workforce gap data, and growth projections, see our companion piece on Cybersecurity Job Trends & Salary Data.
Average Salaries by Role
The cybersecurity field encompasses dozens of specialized roles, each with its own compensation band. The table below reflects US salary data aggregated from BLS, Glassdoor, Levels.fyi, and ISC2's Cybersecurity Workforce Study. Ranges account for company size, location, and total compensation (base + bonus, excluding equity).
| Role | Entry-Level (0–2 yrs) | Mid-Career (3–5 yrs) | Senior (6+ yrs) |
|---|---|---|---|
| SOC Analyst | $55,000 – $75,000 | $75,000 – $100,000 | $100,000 – $130,000 |
| Security Engineer | $80,000 – $105,000 | $110,000 – $145,000 | $145,000 – $190,000 |
| Penetration Tester | $70,000 – $95,000 | $100,000 – $140,000 | $140,000 – $185,000 |
| Security Architect | $100,000 – $130,000 | $135,000 – $175,000 | $175,000 – $230,000 |
| Cloud Security Engineer | $90,000 – $120,000 | $125,000 – $165,000 | $165,000 – $210,000 |
| GRC Analyst | $60,000 – $80,000 | $85,000 – $115,000 | $115,000 – $150,000 |
| Incident Responder | $65,000 – $90,000 | $95,000 – $130,000 | $130,000 – $170,000 |
| CISO | Typically requires 8–15 years of experience | $200,000 – $420,000+ | |
Notable observations: Security Architect and Cloud Security Engineer consistently rank among the highest-paid individual contributor (IC) roles, often matching or exceeding front-line management compensation. SOC Analyst remains the most common entry point, but the ceiling is lower without transitioning to engineering, architecture, or offensive security tracks. Penetration testers see a wide mid-career range because compensation diverges sharply between consultancy roles (lower base, higher travel) and in-house red team positions (higher base, better benefits). For a complete map of progression paths, see our Cybersecurity Career Paths guide.
CISO compensation deserves special attention. At Fortune 500 companies, total compensation (base + bonus + equity) regularly exceeds $400,000 and can reach seven figures at the largest tech firms. However, CISO is not an entry-level role — most arrive after 10–15 years of progressive responsibility across multiple security domains, and the position carries board-level accountability and personal liability exposure that justifies the premium.
Salary by Certification
Certifications are the most controllable salary lever in cybersecurity. Unlike experience (which takes time) or location (which involves relocation), you can earn a certification in weeks to months and see an immediate compensation bump. The premiums below represent the average salary uplift for holders of each certification compared to peers with equivalent experience but without the credential.
| Certification | Avg Salary Premium | Common Roles |
|---|---|---|
| CISSP | +$25,000 – $35,000 | Security Architect, Security Manager, CISO, GRC Director |
| OSCP | +$20,000 – $30,000 | Penetration Tester, Red Team Operator, AppSec Engineer |
| CompTIA Security+ | +$8,000 – $15,000 | SOC Analyst, Systems Administrator, IT Security Specialist |
| AWS Security Specialty | +$18,000 – $28,000 | Cloud Security Engineer, DevSecOps Engineer, Cloud Architect |
| CompTIA CySA+ | +$10,000 – $18,000 | SOC Analyst II/III, Threat Analyst, Security Operations Lead |
| CISM | +$22,000 – $32,000 | Security Manager, IT Risk Manager, GRC Director, CISO |
| CCNP Security | +$15,000 – $22,000 | Network Security Engineer, Firewall Engineer, Security Architect |
Cert stacking multiplies premiums. A professional holding both CISSP and AWS Security Specialty does not simply add the two premiums together, but they do compound meaningfully. The market increasingly values hybrid skill sets — someone who can design a secure architecture (CISSP) and implement it in a specific cloud platform (AWS) commands a premium that neither certification achieves alone. For a broader survey of which certifications align with which career trajectories, see our Best Cybersecurity Certifications guide.
Two important caveats about certification premiums. First, Security+ shows a modest premium in raw dollar terms, but its ROI is exceptional for early-career professionals because it is relatively inexpensive, widely recognized, and meets DoD 8570/8140 baseline requirements for government and defense contractor roles. Second, OSCP's premium is somewhat understated by averages because it disproportionately benefits consultants and bug bounty hunters whose variable income is harder to capture in salary surveys.
Salary by Experience Level
Experience remains the strongest single predictor of cybersecurity compensation. Each tier below reflects not just years of service but the qualitative shift in responsibilities, scope, and organizational impact expected at each stage.
Entry-Level (0–2 Years): $55,000 – $95,000
Typical titles: SOC Analyst I, Junior Security Engineer, IT Security Specialist, Security Operations Associate, Junior Penetration Tester.
Entry-level cybersecurity salaries start well above the US median household income, which is a significant draw for career changers. At this stage, employers value demonstrated interest over deep expertise: a Security+ certification, a home lab, participation in CTF competitions, or contributions to open-source security tools can differentiate you from the pool. Many entry-level hires come from adjacent IT roles — help desk, network administration, systems administration — where they developed foundational skills. The key to accelerating out of this tier is building both breadth (exposure to multiple security domains) and a single area of depth that you can point to in interviews.
The $55,000 floor typically represents small-company SOC roles in lower-cost-of-living areas. The $95,000 ceiling is achievable in major metros (especially with a relevant degree and certification) or at well-funded startups and large enterprises that pay competitively for junior talent to prevent poaching.
Mid-Career (3–5 Years): $95,000 – $150,000
Typical titles: Security Engineer II, Penetration Tester, Threat Intelligence Analyst, Cloud Security Engineer, GRC Analyst II, Incident Response Lead.
The mid-career band is where specialization begins to drive meaningful salary divergence. A generalist security engineer at this level earns solidly in the $110,000–$130,000 range, while someone who has specialized in cloud security, application security, or offensive security pushes toward $140,000–$150,000. This is also the stage where certifications like CISSP, OSCP, or AWS Security Specialty deliver their highest marginal return, because they validate the specialization employers are paying a premium for.
At this level, you are no longer simply executing playbooks — you are designing detection logic, scoping penetration tests, building security automation, or leading small teams. The shift from "doer" to "doer who also mentors and designs" is what unlocks the upper end of this range. Professionals who stall in the mid-career band usually have not committed to a specialization or have not taken on scope beyond their immediate task list.
Senior (6–10 Years): $140,000 – $210,000
Typical titles: Senior Security Engineer, Security Architect, Principal Penetration Tester, Senior Cloud Security Architect, Security Engineering Manager, Director of Security Operations.
Senior professionals either occupy high-impact IC roles (architect, principal engineer, staff security researcher) or have transitioned into management. Both tracks pay comparably at this level, though management tends to offer slightly higher base compensation while IC roles may include more equity or bonus upside. The defining characteristic of this tier is organizational influence — you are setting security strategy for a product line, a business unit, or the company overall, and your decisions have budget and headcount implications.
The $200,000+ end of this range is readily achievable at mid-to-large tech companies, financial services firms, and healthcare organizations in major metros. At this level, employers are evaluating your track record (incidents you handled, programs you built, teams you scaled) more than your certification portfolio, though certifications like CISSP and CISM are often minimum requirements for architect and director-level roles.
Executive (10+ Years): $200,000 – $420,000+
Typical titles: CISO, VP of Security, VP of Engineering (Security), Chief Trust Officer, Head of Product Security.
Executive cybersecurity compensation is driven by company size, industry, and board-level accountability. A CISO at a mid-market company ($500M–$2B revenue) typically earns $200,000–$300,000 in total compensation. At Fortune 500 enterprises, $350,000–$500,000 is standard, and at the largest tech companies, total compensation (including equity) can exceed $1 million. The CISO role has also become significantly more visible and accountable — SEC disclosure rules, personal liability precedents (e.g., the SolarWinds SEC case), and board reporting requirements mean the compensation reflects real professional risk.
Highest-Paying Industries
Industry selection can shift your salary by $20,000–$50,000 even when role and experience are held constant. The industries below are ranked by their typical premium over the cross-industry average for comparable cybersecurity roles.
Financial Services: +15–25% Premium
Banks, hedge funds, insurance companies, and fintech firms consistently pay the highest cybersecurity salaries in the private sector. The reasons are structural: financial services face aggressive regulatory requirements (PCI DSS, SOX, FFIEC, GLBA), handle the most sensitive consumer data, and are targeted by the most sophisticated threat actors (nation-state APTs, organized crime). A Security Engineer III at a major bank earns $160,000–$190,000, and senior architects regularly exceed $200,000. Bonuses in financial services are also substantially higher than other industries, often adding 15–30% to base compensation.
Technology: +10–20% Premium (+ Equity)
Large tech companies (FAANG/MANGA and equivalents) offer competitive base salaries, but the real differentiator is equity compensation. A senior security engineer at a major tech company might have a base salary of $180,000, but total compensation (base + bonus + RSUs) of $300,000–$400,000. Startups offer lower base salaries but larger equity grants, which creates high variance — the equity is life-changing if the company succeeds and worthless if it does not. Product security, application security, and cloud security roles are particularly well-compensated at tech companies because they directly protect revenue-generating products.
Government & Defense: +10–20% Premium (Cleared Roles)
Government cybersecurity salaries are paradoxical. Uncleared federal civilian roles (GS scale) often pay 10–20% below private sector equivalents, especially at senior levels where the GS-15 cap constrains compensation. However, defense contractors pay a substantial premium for security clearance holders, particularly at TS/SCI and above. A cleared penetration tester or threat intelligence analyst at a defense contractor earns $130,000–$170,000, and cleared security architects frequently exceed $200,000. The clearance itself functions as a salary multiplier — the bottleneck is the 6–18 month investigation timeline, which creates artificial scarcity. If you hold or can obtain a clearance, the Washington D.C./Northern Virginia/Maryland corridor is the most lucrative market in cybersecurity, particularly at the intersection of cloud security and cleared work (cleared AWS/Azure architects are in extreme demand).
Healthcare: +5–15% Premium
Healthcare cybersecurity salaries have risen sharply in recent years, driven by ransomware attacks on hospital systems, HIPAA enforcement actions, and the digitization of patient records. Large hospital networks and health insurance companies pay competitively for security engineers and architects, particularly those with experience in medical device security, healthcare interoperability standards (HL7 FHIR), or HIPAA compliance automation. The premium is highest for incident response and security operations roles, reflecting the sector's acute exposure to ransomware and the life-safety implications of a breach.
Consulting: Variable (−5% to +20%)
Consulting (Big Four, boutique security firms, MSSPs) offers wide salary variance. Junior consultants may earn less than their in-house counterparts because consulting firms amortize training costs across billable hours. Senior consultants and principals, however, can earn significantly more, especially at firms where compensation includes a share of engagement revenue. The real value of consulting is often career acceleration — you gain exposure to dozens of environments, tools, and threat models in a few years, which compresses the experience curve and makes you more marketable for higher-paying in-house roles later. Travel burden is the primary trade-off.
Geographic Salary Differences
Geography remains a significant (though shrinking) factor in cybersecurity compensation. The table below compares approximate salary adjustments relative to the US national average for mid-career cybersecurity roles.
San Francisco / Bay Area: +25–40% Above National Average
The Bay Area commands the highest raw salaries in cybersecurity, driven by competition from tech companies and the highest cost of living in the US. A mid-career Security Engineer earns $145,000–$185,000 base, with total compensation often exceeding $250,000 at established tech companies. However, the cost-of-living-adjusted premium is smaller than the raw numbers suggest — housing costs alone can consume the entire premium. The Bay Area is most financially advantageous for candidates who can secure FAANG-tier total compensation while managing housing costs (e.g., living in the East Bay or South Bay).
New York City: +20–35% Above National Average
NYC's cybersecurity premium is driven by financial services and media companies. Banks headquartered in Manhattan pay aggressively for security talent, and the concentration of fintech startups creates additional demand. A mid-career Security Engineer earns $135,000–$175,000 base. Like the Bay Area, the cost-of-living offset is significant, but NYC offers more diversity of employer type (finance, media, healthcare, government) than any other single market.
Washington D.C. / Northern Virginia: +15–30% Above National Average
The DC/NoVA corridor is the epicenter of government and defense cybersecurity. The premium here is driven primarily by security clearance requirements — cleared professionals earn 15–30% more than their uncleared counterparts in the same role. The region is home to the NSA, CISA, DISA, and dozens of defense contractors (Booz Allen, Leidos, SAIC, Raytheon, Northrop Grumman) that compete fiercely for cleared talent. For Security+ holders seeking government roles, this is the most target-rich market in the country.
Austin / Denver / Raleigh: +5–15% Above National Average
These secondary tech hubs offer a compelling value proposition: salaries that are 5–15% above the national average but cost-of-living that is 30–50% below the Bay Area. Austin in particular has seen a surge of security hiring as tech companies established major presences there. For professionals optimizing for purchasing power rather than raw salary, these markets often deliver the best financial outcome.
Remote Work: Narrowing the Gap
The post-2020 normalization of remote work has been the single largest disruption to cybersecurity salary geography. Many companies now offer location-adjusted remote salaries, which typically means paying 85–95% of headquarters-location rates regardless of where the employee lives. This creates a significant premium for remote workers in low-cost-of-living areas. A Security Architect earning $180,000 "remote, adjusted for Midwest" achieves greater purchasing power than the same role at $210,000 in San Francisco. However, some companies (particularly in government contracting) still require on-site presence for classified work, which preserves the geographic premium for cleared roles.
International Context
US cybersecurity salaries are the highest globally in absolute terms. UK equivalents run approximately 20–30% lower (a Senior Security Engineer in London earns approximately £70,000–£95,000, roughly $90,000–$120,000). Germany and the Netherlands pay similarly to the UK. Australia's cybersecurity salaries are comparable to the US when adjusted for purchasing power. Emerging markets (India, Eastern Europe, Latin America) pay significantly less in local terms but remote US-based roles are increasingly available to international candidates, creating new arbitrage opportunities.
How to Maximize Your Earning Potential
Compensation in cybersecurity is not random. The professionals who earn at the top of their band consistently execute on a set of identifiable strategies. Below are the highest-ROI approaches, ordered by impact.
1. Stack Certifications Strategically
Not all certification combinations are equally valuable. The highest-premium stacks pair a broad governance certification with a deep technical specialization. CISSP + AWS Security Specialty signals that you can both design security programs and implement them in cloud infrastructure. CISM + OSCP is unusual but extremely compelling — it tells employers you understand both the management framework and the attacker's perspective. Avoid stacking too many same-tier certifications (e.g., Security+ and CySA+ and CASP+ all from CompTIA) — the diminishing returns set in quickly when certifications overlap.
For guidance on selecting certifications based on your target role, explore our practice quizzes to gauge your readiness before investing in exam fees.
2. Specialize in a High-Demand Niche
Generalist security professionals earn well, but specialists earn more. The highest-premium specializations shift over time, but currently the leaders are:
- Cloud Security (AWS/Azure/GCP): Demand exceeds supply by the widest margin of any security specialization. Cloud security engineers and architects consistently earn $150,000–$210,000 at the mid-to-senior level.
- Application Security / DevSecOps: As organizations shift security left into the development pipeline, professionals who can secure CI/CD pipelines, perform code review, and implement SAST/DAST tooling are in extreme demand.
- AI/ML Security: The newest high-premium niche. Organizations deploying large language models and ML pipelines need security professionals who understand prompt injection, model poisoning, and AI governance. Salaries are still calibrating but the premium is significant.
- OT/ICS Security: Industrial control system security is a small but lucrative niche, particularly in energy, manufacturing, and critical infrastructure sectors. The combination of IT security knowledge and OT protocol expertise (Modbus, DNP3, BACnet) is rare.
3. Obtain a Security Clearance
For US-based professionals, a security clearance is one of the most impactful salary levers available. The clearance premium ranges from $15,000–$30,000 at the Secret level to $25,000–$50,000 at TS/SCI, and the premium is even higher for polygraphed positions. The catch: you cannot self-sponsor a clearance — an employer must sponsor you, and the investigation takes 6–18 months. The most common path is to start at a defense contractor or government agency that sponsors your clearance, then leverage the cleared status in subsequent roles. Once you hold a clearance, you have access to a parallel job market that uncleared candidates cannot compete in.
4. Choose Your Track: Management vs. Technical
Cybersecurity is one of the few fields where the technical IC track pays comparably to management at senior levels. A Principal Security Engineer or Staff Security Architect at a tech company can earn $250,000–$400,000 in total compensation, rivaling a Director or VP of Security. The choice between tracks should be based on your strengths and preferences, not on compensation assumptions. Management offers broader organizational influence and a path to CISO; the IC track offers deeper technical work and freedom from people management. Both are financially rewarding, and the best organizations provide transparent dual-track ladders.
5. Negotiate With Data
The cybersecurity talent shortage gives candidates leverage, but leverage only converts to compensation if you negotiate. Specific actions: research salary bands on Levels.fyi, Glassdoor, and Blind before interviews; always negotiate on total compensation (base + bonus + equity + signing bonus), not just base; use competing offers as leverage if available; and quantify your impact in previous roles (e.g., "I reduced mean time to detect by 40%" is more compelling than "I managed the SIEM"). The workforce gap means employers are more afraid of losing you than you are of losing the offer.
6. Invest in Soft Skills
This advice appears in every career guide, but in cybersecurity it carries particular weight. Security professionals who can present risk to a non-technical board, write clear incident reports, and collaborate with engineering teams without creating adversarial friction earn more and promote faster than technically equivalent peers who cannot. The CISO career path is especially dependent on communication skills — the technical hurdle to becoming a CISO is lower than the communication and leadership hurdle.
← Career Paths ← Job Trends & Market Data ← What Is Cybersecurity? ← How to Get Into CybersecurityFixTheVuln Store
Certification Study Planners
Fillable PDF planners for 60+ certifications. Domain trackers, weekly schedules, and progress tracking. Standard, ADHD-Friendly, Dark Mode, and 4-Format Bundle.
From $5.99 per planner