Cybersecurity Salary Statistics [2026]: Pay by Role & Cert
Cybersecurity is one of the highest-paying technology fields — and demand continues to outstrip supply. With 87% unfilled positions globally and a 33% job growth outlook, salaries remain strong across every experience level and specialisation.
This article consolidates salary data from 30+ authoritative sources including BLS, ISC2, Glassdoor, and Fortinet to give you the most comprehensive view of cybersecurity compensation in 2026. Whether you're entering the field, planning a certification, or negotiating a raise — the data below will inform your decisions.
💰 Key Cybersecurity Salary Numbers
The Bureau of Labor Statistics reports the median annual salary for information security analysts at $120,360 as of May 2024. This represents the midpoint — half of cybersecurity professionals earn more, half earn less. The range spans from $63,410 at the 10th percentile to $179,950 at the 90th percentile (BLS OEWS 2024).
At this median salary, cybersecurity professionals earn approximately $463/day — a 23.7% premium over general IT roles. With 33% projected job growth through 2033, this premium is likely to increase as the workforce gap widens.
| Finding | Value | Source |
|---|---|---|
| Median cybersecurity salary (US) | $120,360 | BLS Occupational Outlook Handbook |
| 10th percentile salary (US) | $63,410 | BLS Occupational Employment & Wage Statistics |
| 90th percentile salary (US) | $179,950 | BLS Occupational Employment & Wage Statistics |
| CISO salary range | $220,000-$420,000 | SentinelOne / Industry Reports |
| Entry-level salary range | $74,000-$110,000 | SentinelOne / Industry Reports |
| Mid-level salary range | $115,000-$212,000 | SentinelOne / Industry Reports |
| Cyber premium over general IT | $39,000 | Redbud Cyber |
| Global unfilled positions | 4.8 million | ISC2 Cybersecurity Workforce Study 2025 |
| CISSP certification salary premium | $25K-$35K | EC-Council |
Why Cybersecurity Salaries Stay High
The fundamental economics are simple: demand vastly exceeds supply. With 4.8 million unfilled positions globally and only 5.5 million active professionals, organisations must pay premium salaries to attract and retain talent. Every major data breach and ransomware attack reinforces executive commitment to cybersecurity investment — and that investment flows directly into salaries.
📊 Cybersecurity Salary by Role
Cybersecurity salaries vary dramatically by role and specialisation. Roles range from $192,840 → $90,462, based on Glassdoor 2026 averages. Architecture and engineering roles command the highest salaries, while analyst positions offer strong entry points with clear advancement paths.
| Finding | Value | Source |
|---|---|---|
| Security Architect | $192,840 | Glassdoor |
| Security Engineer | $168,767 | Glassdoor |
| Cloud Security Engineer | $155,000 | Glassdoor |
| DevSecOps Engineer | $148,000 | Glassdoor |
| Penetration Tester | $120,090 | Glassdoor |
| Incident Response Analyst | $105,000 | Glassdoor |
| GRC Analyst | $95,380 | Glassdoor |
| SOC Analyst | $90,462 | Glassdoor |
Salary Explorer by Role
Select a role to see salary data, recommended certifications, and career level.
The salary hierarchy reflects both technical depth and business impact. Security Architects design enterprise-wide security strategies and influence multi-million-dollar decisions — hence the $192K+ average. SOC Analysts are the front line of defence, monitoring alerts and triaging incidents — an essential role that serves as the most common entry point into cybersecurity.
Which Role Should You Target?
If you're entering cybersecurity, SOC Analyst and GRC Analyst offer the most accessible entry points ($90K-$95K). For experienced IT professionals, Penetration Testing ($120K) and Incident Response ($105K) leverage existing technical skills. Cloud Security ($155K) and DevSecOps ($148K) are the fastest-growing specialisations as cloud adoption accelerates.
📋 Complete Cybersecurity Salary Directory (28 Roles)
Below is a comprehensive directory of 28 cybersecurity roles ranked by median salary. Filter by career level, search for specific roles, or click any role name to explore it in detail on JobZone — including AI automation risk scores and career path data.
| # | Role | Avg Salary | Range | Level |
|---|---|---|---|---|
| 1 | Chief Information Security Officer (CISO) | $243K | $190K–$420K | executive |
| 2 | AI Governance Lead | $221K | $150K–$260K | executive |
| 3 | Cybersecurity Lawyer | $220K | $160K–$350K | executive |
| 4 | AI Solutions Architect | $185K | $155K–$260K | senior |
| 5 | Cloud Security Architect | $170K | $170K–$220K | senior |
| 6 | ML/AI Engineer | $165K | $98K–$250K | senior |
| 7 | AI/ML Engineer (Cybersecurity) | $165K | $98K–$250K | senior |
| 8 | Cloud Security Engineer | $161K | $140K–$220K | senior |
| 9 | Cybersecurity Architect | $158K | $130K–$180K | senior |
| 10 | Principal Cybersecurity Specialist | $158K | $130K–$234K | senior |
| 11 | Applied AI Engineer | $155K | $95K–$220K | senior |
| 12 | Data Protection Officer | $152K | $100K–$200K | senior |
| 13 | Principal Cybersecurity Sales Engineer | $150K | $120K–$500K | senior |
| 14 | AI Safety Researcher | $150K | $120K–$300K | specialist |
| 15 | DevSecOps Engineer | $140K | $75K–$170K | senior |
Explore Any Role
Use the search below to explore detailed salary data, career outlook, and AI risk assessments for any cybersecurity role.
🌟 Entry-Level Cybersecurity Salaries
Entry-level cybersecurity salaries range from $74,000 to $110,000 (SentinelOne 2026), depending on location, certifications, and prior IT experience. The BLS 10th percentile of $63,410 represents the very bottom of the market — typically rural areas or roles with no certifications. The realistic entry range for someone with CompTIA Security+ or equivalent and some IT background is $74K-$90K.
| Finding | Value | Source |
|---|---|---|
| Entry-level salary range (US) | $74,000-$110,000 | SentinelOne / Industry Reports |
| SOC Analyst (common entry role) | $90,462 | Glassdoor |
| Security+ holder average salary | $88,000 | CompTIA |
| 10th percentile (BLS) | $63,410 | BLS Occupational Employment & Wage Statistics |
The most common entry-level path is SOC Analyst, averaging $90,462 (Glassdoor 2026). This role provides exposure to security monitoring tools, incident triage, and threat analysis — building the foundation for specialisation into penetration testing, incident response, or security engineering. GRC Analyst ($95K) is another strong entry point for those with compliance or audit backgrounds.
How to Maximise Your Entry-Level Salary
Three factors most influence entry-level compensation: certifications (Security+ adds ~$5K-$10K), location (San Francisco and NYC pay 20-30% above national average), and demonstrable project work (labs, CTFs, and portfolio projects). Career changers from IT can leverage existing experience to enter at the higher end of the entry range.
Higher Entry Salary ($90K+)
- CompTIA Security+ or CySA+ certified
- Major metro area (SF, NYC, DC, London)
- Prior IT experience (helpdesk, sysadmin)
- Portfolio of hands-on projects
- Relevant degree or bootcamp
Lower Entry Salary ($60K-$74K)
- No certifications
- Rural or low cost-of-living area
- No prior IT experience
- No portfolio or practical work
- Theoretical knowledge only
👑 Senior & Executive Cybersecurity Salaries
Senior cybersecurity roles command salaries well into six figures, with CISOs earning $220,000-$420,000+ in base compensation (SentinelOne 2026). A CISO earns approximately 2.7x an entry-level professional — reflecting the immense responsibility of the role. CISO compensation grew 6.7% in 2025 (IANS Research), even as broader tech compensation flattened.
| Finding | Value | Source |
|---|---|---|
| CISO salary range | $220,000-$420,000 | SentinelOne / Industry Reports |
| CISO average salary | $243,000 | Glassdoor |
| Security Architect average | $192,840 | Glassdoor |
| Security Engineer average | $168,767 | Glassdoor |
| CISO compensation growth (2025) | 6.7% | IANS Research & Artico Search |
| Average CISO tenure | 39 months | Hitch Partners 2025 CISO Survey |
| 90th percentile (BLS) | $179,950 | BLS Occupational Employment & Wage Statistics |
The average CISO tenure is 39 months (Hitch Partners 2025), reflecting the high-pressure nature of the role. CISOs face board-level accountability, regulatory scrutiny, and the constant threat of career-defining breaches. Total compensation packages for Fortune 500 CISOs regularly exceed $500K when including equity, bonuses, and retention incentives.
Security Architects ($192,840) and Security Engineers ($168,767) represent the highest-earning individual contributor roles. These positions combine deep technical expertise with business strategy — designing security architectures that protect multi-billion-dollar enterprises. Unlike management tracks, these roles maintain hands-on technical depth.
🌍 Cybersecurity Salary by Country
Cybersecurity salaries vary significantly across countries, reflecting local demand, cost of living, and market maturity. UK cyber salaries are 42% less than US salaries when converted at current exchange rates, though the UK offers a 12% premium over wider IT roles domestically.
| Finding | Value | Source |
|---|---|---|
| United States (median) | $120,360 | BLS Occupational Outlook Handbook |
| United Kingdom (median) | £55,000 | UK DCMS Cyber Security Skills in the UK Labour Market 2025 |
| UK — London (median) | £69,800 | UK DCMS Cyber Security Skills in the UK Labour Market 2025 |
| Canada (average) | CA$85,000 | Glassdoor |
| Australia (average) | A$110,000 | Glassdoor |
| Germany (average) | €65,000 | Glassdoor |
| India (average) | ₹7,50,000 | Glassdoor |
| UK cyber premium over wider IT | 12% | UK DCMS Cyber Security Skills 2025 |
Purchasing Power Context
Raw salary comparisons across currencies are misleading without cost-of-living context. India's ₹7,50,000 (~$9,000 USD) may seem low, but represents a strong middle-class salary in tier-1 Indian cities. UK salaries appear lower than US in dollar terms, but NHS healthcare, pension contributions, and lower healthcare costs offset some of the gap. The real measure is purchasing power relative to local cost of living — and cybersecurity ranks among the highest-paying professions in every country listed.
London commands a significant UK premium — £69,800 vs the national median of £55,000 — reflecting the concentration of financial services, government, and technology firms. Similar metro premiums apply globally: San Francisco and New York pay 20-30% above US national average, Sydney exceeds Australian national figures, and Bangalore outpaces Indian national medians.
Cybersecurity & Ethical Hacker Salary in India
India is one of the fastest-growing cybersecurity markets, with over 40,000 unfilled positions and salaries rising 15-20% annually for skilled professionals. The ethical hacker salary in India ranges from ₹8,00,000 to ₹25,00,000 (Glassdoor 2026), depending on experience, certifications, and employer type. Freshers with CEH or CompTIA Security+ typically start at ₹4,00,000–₹6,00,000, while experienced penetration testers at MNCs and big-4 consultancies command ₹15,00,000–₹25,00,000+.
Salary by City
Bangalore leads India's cybersecurity salaries due to its concentration of global security operations centres and MNC headquarters. MNCs (Cisco, IBM, Deloitte) pay 30-50% premiums over Indian-founded companies for equivalent roles. OSCP and CISSP certifications can increase Indian cybersecurity salaries by 40-60%, making them the highest-ROI investments for Indian professionals targeting ₹15L+ compensation.
📈 Cybersecurity vs IT & Other Fields
Cybersecurity
- Median: $120,000 (US)
- 23.7% premium over IT
- 33% growth outlook
- 4.8M unfilled positions
- Strong remote options
General IT
- Median: $97,000 (US)
- Baseline comparison
- Moderate growth outlook
- Competitive market
- Standard remote availability
Cybersecurity professionals earn a 23.7% premium over general IT roles — $120,000 vs $97,000 median (Redbud Cyber 2025). That's $1,917 more per month, or $88 more per working day. The premium exists because cybersecurity requires specialised knowledge in an undersupplied market, while general IT skills are more widely available.
| Finding | Value | Source |
|---|---|---|
| Cybersecurity median (US) | $120,000 | Redbud Cyber |
| General IT median (US) | $97,000 | Redbud Cyber |
| Absolute salary premium | $39,000 | Redbud Cyber |
| UK cyber premium over IT | 12% | UK DCMS Cyber Security Skills 2025 |
Beyond IT, cybersecurity salaries compare favourably with most professional fields. The $120K median exceeds accountants ($79K), marketing managers ($140K median but broader range), and most healthcare roles outside physicians. Only software engineering ($132K), data science ($108K), and AI/ML engineering ($165K) consistently match or exceed cybersecurity compensation in the technology sector.
📉 Workforce Demand & Job Growth
The cybersecurity workforce gap drives the salary premium. The 87% gap ratio means the industry needs nearly as many new professionals as currently exist. ISC2 reports 4.8 million unfilled positions globally alongside 5.5 million active professionals (ISC2 2024/2025). The BLS projects 33% job growth for information security analysts from 2023-2033 — far exceeding the 4% average for all occupations.
| Finding | Value | Source |
|---|---|---|
| Global unfilled cybersecurity positions | 4.8 million | ISC2 Cybersecurity Workforce Study 2025 |
| Active cybersecurity workforce | 5.5 million | ISC2 Cybersecurity Workforce Study 2024 |
Kaspersky reports it takes over 6 months to fill cybersecurity positions on average (Kaspersky 2024), and 67% of organisations report significant talent shortages (WEF 2025). This supply-demand imbalance is structural — it cannot be solved quickly because cybersecurity requires years of experience to develop expertise. For professionals, this means strong job security and continued salary growth.
What This Means for Your Career
The workforce gap is your opportunity. Unlike most professions where competition is fierce, cybersecurity has more open positions than qualified candidates. This gives you negotiating leverage from day one — multiple job offers, faster promotions, and the ability to choose employers based on culture and growth opportunities rather than desperation.
🧠 Skills Gap & Its Salary Impact
The skills gap isn't just about quantity — it's about specific capabilities. AI/ML security, cloud security, and zero trust are the most in-demand skills (ISC2 2025), and professionals with these specialisations command the highest premiums. Fortinet reports 70% of organisations attribute at least one breach to the cybersecurity skills gap (Fortinet 2025).
| Finding | Value | Source |
|---|---|---|
| Demand for cloud security skills | 36% | ISC2 Cybersecurity Workforce Study 2025 |
The salary implication is clear: specialise in high-demand, low-supply skills and your earning potential increases dramatically. AI security specialists command $155K-$200K+ (emerging field premiums), cloud security engineers average $155K (Glassdoor 2026), and zero trust architects are among the fastest-growing roles in enterprise security.
🏠 Remote & Hybrid Cyber Salaries
72% of cybersecurity professionals now work in remote or hybrid arrangements (ISC2 2025), significantly above the general workforce average. Remote cybersecurity workers earn 5-10% more than on-site peers — reversing the "remote discount" seen in other fields. This premium reflects the highly specialised nature of the work and the global competition for talent.
| Finding | Value | Source |
|---|---|---|
| Working remote or hybrid | 72% | ISC2 Cybersecurity Workforce Study 2025 |
| Remote salary premium | 5-10% more | ISC2 Cybersecurity Workforce Study 2025 |
Cybersecurity is particularly well-suited to remote work because much of the role involves digital tools — SIEM platforms, vulnerability scanners, code review, and incident response coordination can all be performed remotely. SOC operations that once required physical presence are increasingly managed through cloud-based security platforms and virtual SOC models.
The remote work availability also creates geographic arbitrage opportunities. A professional in a low cost-of-living area can earn a salary benchmarked to San Francisco or New York standards while maintaining significantly lower expenses — effectively increasing real purchasing power by 30-50%.
🤝 Gender, Diversity & Pay Equity
Women comprise 22% of the cybersecurity workforce (ISC2 2025), up from 11% in 2013 but still dramatically underrepresented. The gender pay gap in cybersecurity is 5.2% (ISC2 2024) — smaller than many industries but still present. Women in cybersecurity earn an average of $109,000 vs $115,000 for men in comparable US roles.
| Finding | Value | Source |
|---|---|---|
| Women's average salary (US) | $109,000 | ISC2 Cybersecurity Workforce Study 2024 |
| Men's average salary (US) | $115,000 | ISC2 Cybersecurity Workforce Study 2024 |
| Gender pay gap | 5.2% | ISC2 Cybersecurity Workforce Study 2024 |
The 5.2% pay gap in cybersecurity is notably smaller than the general technology industry gap (~8-10%) and the overall US workforce gap (~16%). However, the gap persists particularly at senior levels. Organisations with formal pay equity audits and transparent salary bands show the smallest gaps. The industry-wide talent shortage creates strong incentives for employers to offer competitive salaries regardless of gender — but conscious bias in negotiation and promotion still affects outcomes.
🔥 Burnout, Satisfaction & Retention
High salaries come with high pressure. 66% of cybersecurity professionals report experiencing burnout (Sophos 2025), with 18% annual attrition rates (ISACA 2024). Yet 74% remain satisfied with their career choice (Bitsight 2025) — suggesting that the work is fulfilling despite the stress. The key tension is between meaningful, well-compensated work and unsustainable workloads.
| Finding | Value | Source |
|---|---|---|
| Experiencing burnout | 66% | Sophos Addressing Cybersecurity Burnout 2025 |
| Annual attrition rate | 18% | ISACA State of Cybersecurity 2024 |
| Satisfied with their career | 74% | Bitsight |
The Challenge
- 66% experiencing burnout (Sophos)
- 18% annual attrition rate (ISACA)
- Overwork cited as primary burnout cause
- Alert fatigue from security tool sprawl
- 24/7 on-call expectations
The Upside
- 74% career satisfaction (Bitsight)
- Salaries rising 5-7% annually
- Remote/hybrid work widely available
- Meaningful work defending organisations
- Strong job security and mobility
Burnout isn't inevitable — organisations that invest in team sizing, automation (AI-assisted SOC), rotational on-call schedules, and mental health support see significantly lower attrition. For individuals, setting boundaries, investing in automation skills to reduce toil, and choosing employers with healthy security cultures are the most effective defences against burnout.
📈 Career Path: Entry to CISO
Cybersecurity offers one of the clearest salary progression paths in technology. From entry-level analyst to CISO, each step brings meaningful salary increases and new responsibilities. The typical timeline is 8-15 years from entry to director-level, with CISO roles accessible after 15-20+ years of combined experience.
What Could You Earn in Cybersecurity?
Adjust role, location, experience, and certifications to estimate your potential salary.
The Two Career Tracks
Technical Track (IC)
- SOC Analyst → Security Engineer → Security Architect
- Peak: $192K+ (Security Architect)
- Deep technical expertise
- Hands-on work throughout career
- Key certs: OSCP, CISSP, cloud certs
Management Track
- Analyst → Team Lead → Director → CISO
- Peak: $220K-$420K+ (CISO)
- Strategy and business focus
- People management and board reporting
- Key certs: CISSP, CISM, MBA
Both tracks are viable and well-compensated. The technical track peaks at Security Architect ($192K+) but avoids management responsibilities. The management track leads to CISO ($220K-$420K+) but requires business acumen, board-level communication, and people management skills. Many professionals switch between tracks or combine elements of both.
✅ Key Takeaways
1. Median salary is $120,360
The BLS median for information security analysts puts cybersecurity among the highest-paying technology fields. The full range spans $63K-$180K+ depending on role and experience.
2. The salary range is enormous
From SOC Analyst ($90K) to CISO ($420K+), the field offers continuous salary growth. Security Architects ($193K) and Cloud Security Engineers ($155K) represent the highest-earning specialisations.
3. Certifications deliver immediate ROI
CISSP adds $25K-$35K annually. OSCP unlocks the $120K+ pentester bracket. Even Security+ at $400 adds $5K-$10K — paying for itself in weeks.
4. Demand guarantees salary growth
4.8M unfilled positions, 33% job growth, and 6+ months to fill roles means the salary premium is structural — not a bubble. This shortage won't resolve quickly.
5. Specialise in AI, cloud, or zero trust
The highest-demand skills command the largest premiums. AI security, cloud security ($155K avg), and zero trust architecture are the fastest paths to top-tier compensation.
Frequently Asked Questions
What is the average cybersecurity salary?
The median cybersecurity salary in the US is $120,360 (BLS 2024). The range spans from $63,410 at the 10th percentile to $179,950 at the 90th percentile. Entry-level positions start at $74K-$110K, while CISOs earn $220K-$420K+.
How much do entry-level cybersecurity jobs pay?
Entry-level cybersecurity positions pay $74,000-$110,000 (SentinelOne 2026). The most common entry role, SOC Analyst, averages $90,462 (Glassdoor 2026). Certifications like CompTIA Security+ ($88K average) and prior IT experience can push entry salaries above $90K.
How much does a CISSP certification increase salary?
CISSP holders earn $25K-$35K more than non-certified peers (EC-Council 2025), with an average salary of $136,000 (ISC2 2025). This makes CISSP the highest-value certification in cybersecurity, with ROI within the first month of holding the certification.
What is the highest paying cybersecurity role?
The CISO (Chief Information Security Officer) is the highest-paying role at $220,000-$420,000+ base salary. For individual contributors, Security Architect leads at $192,840 average (Glassdoor 2026). Cloud Security Engineers ($155K) and DevSecOps Engineers ($148K) are the highest-paying specialist roles.
How many unfilled cybersecurity jobs are there?
There are 4.8 million unfilled cybersecurity positions globally (ISC2 2025), alongside 5.5 million active professionals. The BLS projects 33% job growth for information security analysts through 2033, with approximately 17,300 annual job openings in the US alone.
What is the ethical hacker salary in India?
The ethical hacker salary in India ranges from ₹4,00,000 for freshers to ₹25,00,000+ for experienced penetration testers (Glassdoor 2026). CEH-certified professionals average ₹7,00,000–₹12,00,000. MNC employers (Deloitte, IBM, Cisco) pay 30-50% premiums over Indian-founded firms. Bangalore offers the highest salaries at ₹10,00,000–₹15,00,000 for mid-level roles. CISOs in India earn ₹35,00,000–₹50,00,000.
About This Data
This article draws from 185 statistics aggregated from 50+ authoritative sources including IBM Cost of a Data Breach, Verizon DBIR, CrowdStrike Global Threat Report, WEF Global Cybersecurity Outlook, FBI IC3, ISC2 Cybersecurity Workforce Study, Sophos, Gartner, Mandiant M-Trends, and Ponemon Institute reports.
Derived statistics (marked "Nathan House's Analysis") are computed by cross-referencing data from multiple sources — for example, comparing breach costs across industries using IBM data, or validating ransomware trends across Verizon, Sophos, and HIPAA Journal findings.
All statistics include inline source citations with links to primary sources. Data spans 2023-2026, with preference given to the most recent available figures. Last updated: March 2026.
About the Author
Nathan House, StationX
Nathan House is a cybersecurity expert with 30 years of hands-on experience. He holds OSCP, CISSP, and CEH certifications, has secured £71 billion in UK mobile banking transactions, and has worked with clients including Microsoft, Cisco, BP, Vodafone, and VISA. Named Cyber Security Educator of the Year 2020 and a UK Top 25 Security Influencer 2025, Nathan is a featured expert on CNN, Fox News, and NBC. He founded StationX, which has trained over 500,000 students in cybersecurity.