Which Cyber Security Job Fits Your Tech Background?

12 min readBy Nathan House

If you already work in tech and you're thinking about cyber security, you've probably asked the same question most of us ask at that point: which cyber security job is right for me?

It's a fair question, and the usual answers don't help much. Most guides give you a list of 20 job titles and a personality quiz. So people pick the role that sounds most exciting, then spend a couple of years learning skills that have nothing to do with the work they already do.

I think there's a better starting point, and it's the job you have now. In this article I'll walk through five real job ads, from Jefferies, Gusto, Pinterest, Notion and Anthropic, and show which security role each tech background points at, what the employer actually asked for, and where the gap is. Then I'll show you what 661 AI-driven security job ads say about your background.

Let's start with why "cyber security" is the wrong thing to aim for.

TL;DR if you've only got 30 seconds

Pick the security role that sits next to the job you already do: network to network security, cloud to cloud security, operations to detection and response, development to application security.

Five real ads show it. A lot of what they asked for is work people in tech already do. The gap was the security specialism, plus using AI well.

The advertised ranges ran from $123,696 at Pinterest to $485,000 at Anthropic, for US roles from mid-level to Staff+. Three of the five required 6 to 10 or more years.

Learn in this order: security fundamentals, then your specialism, then the AI-driven layer on top.

Cyber Security Isn't One Job: 50 to 60 Roles in 12 Domains

Saying you want "a job in cyber security" is a bit like saying you want "a job in medicine". A surgeon, a radiographer and a GP all work in medicine, but nobody trains for all three at once.

Cyber security works the same way. Depending on how you count, there are 50 to 60 distinct cyber security roles, and they group into about 12 domains. Any list of cybersecurity job roles you find online is really a list of these domains. A few you'll recognise:

Network security. Controlling who and what can reach which parts of a network.

Cloud security. Setting the rules for cloud accounts, so a mistake in one place can't expose everything.

Application security (AppSec). Finding the weak spots in software before attackers do.

Detection and response. Spotting signs of an attack in logs and alerts, then dealing with it.

Penetration testing, or offensive security. Being paid to break in, so the holes get fixed first.

GRC (governance, risk and compliance). The policies, audits and risk decisions that sit above the technical work.

The common mistake is choosing from this list by excitement. For a lot of people that means penetration testing, because it's the one they've seen in films. But excitement tells you nothing about how far you are from the job. Your current work does.

Map of four tech jobs and the security role next to each: network engineer to network security engineer, cloud or systems engineer to cloud security engineer, support or operations to detection and response engineer, developer to application security engineer

So how do you use your current work to choose?

The Cyber Security Career Path That Starts With Your Current Job

If you're moving from IT to cyber security, my advice is simple: pick the security role that sits next to the job you already do. Keep your foundation, and build the security depth you're missing on top of it.

Think of it like moving house within the same town. You keep your local knowledge, your friends and your routes. Moving to another country might sound more exciting, but you start from zero on everything.

When I lined up the job ads for this article, the same three-layer pattern came up in every one:

1

The technical background you already have. Networking, cloud, operations or development.

2

A security specialism on top of it. Network security, cloud security, detection, AppSec.

3

The AI-driven layer. Using AI tools to do the work faster, while you stay in charge of what's right.

Three stacked layers: your tech background at the bottom, a security specialism in the middle, and the AI-driven layer on top, with the caption you can't supervise what you don't understand

That third layer is newer, and the highest-paid ad here was the one built most around it. But it only works on top of the first two, because you can't supervise what you don't understand. If an AI tool writes a firewall rule, someone still has to know whether that rule is safe.

⚠️ A note on the evidence. These were real ads, captured and archived by us between July and August 2026. Four were senior roles and one mid-level, all in US dollars, and four of the five have since closed. In my view the same skills apply at junior level too. These ads show the senior bar, so the salaries and years of experience belong to them, not to a first move.

Let's start with networking.

Network Engineer to Network Security Engineer

If you keep networks running, the natural move is network security.

Jefferies, the investment bank, advertised a VP, Network Security Engineer in Jersey City with a posted salary range of $185,000 to $200,000. Read the requirements and a lot of it is your day job:

"Working knowledge of the OSI model, subnetting, including CIDR notation"

Jefferies, VP, Network Security Engineer (the ad)

The OSI model is the standard way of describing how network traffic moves, layer by layer, from the cable up to the app. If you've ever split a network into subnets, or worked out why traffic isn't reaching a server, you already have that. The ad also asked for depth in Palo Alto firewalls and Illumio, a segmentation tool (segmentation means keeping parts of a network apart, so one compromised laptop can't reach the payroll servers). And it asked for:

"Experience with Automation, Python, LLM’s"

Jefferies, VP, Network Security Engineer (the ad)

So where's the gap? Security work asks a different question of the same network. You know how traffic gets from A to B. A network security engineer asks who should be allowed to reach B, how you would spot someone getting in who shouldn't, and what you'd do in the first ten minutes if they did. The ad also expected you to use AI and automation to test and audit those rules, which means knowing what a safe result looks like before you trust the script's output.

It was also a senior role. It asked for "10+ years of technical experience in networking, network security." Your networking years count towards that. The security half is the part to build.

Requirement card from the archived Jefferies VP, Network Security Engineer ad: working knowledge of the OSI model and subnetting, experience with automation, Python and LLMs, and 10+ years of experience

The formula: networking + network security + the AI-driven layer.

Cloud people, you're next, and your ad paid more.

Cloud or Systems Engineer to Cloud Security Engineer

If you build cloud or systems infrastructure, look at cloud security.

Gusto, the payroll and HR software company, advertised a Senior Staff Security Engineer, Cloud and Network Security. Its cash compensation went up to $270,000 in its San Francisco, New York and Seattle band ($210,000 to $230,000 in Denver and most remote locations, with stock on top).

The line that matters for you:

"Fluency with policy-as-code, Terraform, and CI/CD-first delivery of security controls"

Gusto, Senior Staff Security Engineer (the ad)

In plain terms, that means writing security rules as code and shipping them through CI/CD, the automated pipeline that tests and releases every change. Terraform is a tool for describing cloud infrastructure in code, so if you already write it, you've done the "as code" part many times. Picture a rule that says no storage bucket can ever be made public. Writing that as code is your existing skill. Knowing that it's the rule you need is the security skill.

That's the gap: knowing which rules to set. Who can reach what? Which systems should be kept apart? What data is allowed to leave? Gusto also expected an "AI-native working style with daily use of Claude Code or equivalent agentic tooling". Agentic tools are AI tools that can take actions, like editing files or running commands, instead of only answering questions. So the AI-driven layer was a requirement here, not a nice-to-have.

Requirement card from the archived Gusto Senior Staff Security Engineer ad: fluency with policy-as-code, Terraform and CI/CD, daily use of Claude Code or equivalent agentic tooling, and 10+ years of experience

The formula: cloud skills + cloud security + the AI-driven layer.

Support and operations people often assume none of this applies to them. The next ad says otherwise.

Support or Operations to Detection and Response Engineer

If you work in support, operations or on-call, look at detection and response.

Pinterest advertised a Security Software Engineer II, Detection and Response, remote across the US, with a base salary range of $123,696 to $254,667. Look at what the job involved:

"Respond to alerts generated from our tooling and run incidents as part of an on-call rotation"

Pinterest, Security Software Engineer II, Detection and Response (captured 31 August 2026)

Alerts, on-call shifts, finding out what went wrong under pressure. That will sound familiar. An outage isn't the same as a break-in, but the habits carry over: reading logs, tracing a fault back to its cause, and writing up clear findings.

That overlap depends on what your support work involves. If it includes alerts, on-call incidents and reading logs, you're close. If it's mostly password resets and tickets, those are skills to build first. And notice the title: this was a Security Software Engineer role, so some scripting and query writing came with it.

The gap is learning to read those logs for attacks instead of faults. The ad required:

"Hands on experience with writing SIEM queries for alerting, response, and threat hunting"

Pinterest, Security Software Engineer II, Detection and Response

A SIEM is the system that collects logs from across a company in one place. A SIEM query is a search, such as "show me every login from a new country, followed within an hour by a password change". Writing those searches well is the core skill of the role. Pinterest also wanted AI in the daily work:

"Demonstrated ability to use AI to improve speed and quality in your day-to-day workflow for relevant outputs."

Pinterest, Security Software Engineer II, Detection and Response

Another line asked for a track record of checking AI-assisted work, so your findings still had to match the logs.

One thing made this ad unusual: it set no minimum number of years, though it still required the hands-on SIEM query skills above. By comparison, Jefferies and Gusto required 10 or more years and Notion 6 or more, while Anthropic listed 7 or more as preferred.

The formula: operations experience + detection and response + the AI-driven layer.

Developers, AppSec builds directly on the code you already write.

Developer to Application Security Engineer

If you write software, look at application security. If you lean towards pipelines and operations, look at DevSecOps, which builds security checks into the pipeline itself, so insecure code gets caught before it ships.

Notion advertised an Application Security Engineer, AI Security in San Francisco, with a base salary range of $230,000 to $280,000. The core requirement was:

"working with product teams to design and/or build secure software"

Notion, Application Security Engineer, AI Security (the ad)

You already know how code gets built. AppSec asks you to look at the same code the way an attacker would. Take a search box on a web page. A developer makes sure it returns the right results. An AppSec engineer asks what happens if someone types a database command into it instead of a search term. Then they find the weak spots, test them, and explain to the team what needs to change and why.

At Notion that included the product's AI features, with work on risks like prompt injection, which is tricking an AI feature into ignoring its instructions. But the ad was clear that you didn't need to be an AI expert already:

"You don’t need to be an AI expert, but you’re curious and willing to adopt AI tools to work smarter and deliver better results"

Notion, Application Security Engineer, AI Security (the ad)

That's a part you can learn. If you're a developer, I'm also making a dedicated developer-to-security video that goes deeper on this route.

The formula: development skills + application security (or DevSecOps) + the AI-driven layer.

So what sits at the top of these ladders?

The Ceiling: Anthropic's $485,000 Role and the AI-Driven Layer

Anthropic, the AI company behind Claude, advertised a Staff+ Application Security Engineer at an annual salary of $320,000 to $485,000. Staff+ is the level above senior: someone who sets direction for a whole area, not just their own work. Unlike the others, this ad was still live when I checked on 1 October 2026, at the same range.

The ad described a team that runs security through its own AI:

"We use Claude as our primary tool across every part of the job"

Anthropic, Staff+ Application Security Engineer (the ad)

That covered code analysis, drafting fixes for vulnerabilities, first-line triage of bug reports and help with threat modelling (thinking through how a new feature could be attacked before it's built).

This is what the AI-driven layer looks like at the top end. The employer was paying for the combination: a deep technical base, real security skill, and the ability to direct AI to do the work. Take away the first two and the third is worthless, because you can't check an AI's security fix if you don't understand the code it's fixing.

Posted pay ranges for the five ads, drawn to scale: Pinterest $124K to $255K base, Jefferies $185K to $200K base, Gusto $230K to $270K cash compensation, Notion $230K to $280K base, Anthropic $320K to $485K annual salary

Five ads are a good illustration, but they're five. So what does a bigger sample say?

What 661 AI-Driven Job Ads Say About Your Background

We keep an archive of AI-driven security job ads, each read in full, archived and checked. When I wrote this, it held 661 of them. We tag each one with the backgrounds its required text names, so you can see how often your background comes up. An ad can name more than one, so the rows overlap, and the tags only catch backgrounds an ad names outright, so they undercount routes where the ad describes the tasks instead:

Your backgroundAds that ask for itOf those, no years-of-experience gate
Developer37699
Sysadmin / cloud34287
Network engineer11726
Support / helpdesk21
Bar chart of 661 AI-driven security job ads by the background their required text asks for: developer 376, sysadmin or cloud 342, network engineer 117, support or helpdesk 2

A few things stand out. Developers and cloud or systems people are named far more often than anyone else. Network engineers come up less often, but over a hundred ads still asked for that background directly.

Support and helpdesk almost never appears as a named requirement. That doesn't mean the route is closed. The Pinterest ad above is an example of the overlap: it asked for on-call and alert work, not the words "support background". But it was still a software engineering role that needed SIEM queries and some scripting, so you'll need to build those skills and show the overlap yourself, in your CV and in interviews, rather than expect the ad to spell it out.

Some honest caveats. These are advertised salary bands, not what anyone was paid. The archive leans senior, because senior roles are where employers have written AI into the job first. And an archive is not a list of open vacancies. You can browse every ad for your area here:

Cloud and infrastructure security ads. For network and cloud backgrounds.

Detection and SOC ads. For support and operations backgrounds.

AppSec and product security ads. For developers.

That leaves one practical question. What if more than one route fits you?

If Two Roles Fit, How to Choose

"Which cyber security job is right for me?" gets harder to answer when two of them fit. Plenty of people sit between two backgrounds. A DevOps engineer touches both cloud and code. A network engineer who runs the on-call rota has a foot in detection too.

My rule is simple: if two roles fit, pick the one closer to the work you want to do more of. Your background decides which doors are close. Your interest decides which one you'll still enjoy walking through in five years.

Then take three steps:

1

Read ten real ads for that role, start to finish, and mark every requirement you already meet. Our AI-driven jobs board is a good place to start, and the salary statistics give you the wider pay picture.

2

List the gaps honestly. For most people it's the security specialism plus the AI-driven layer.

3

Learn in that order. Security fundamentals first, then your specialism, then the AI-driven layer on top. My free web-book, Become the Cyber Security Expert the AI Era Demands, covers how to add those last two to the skills you already have.

If you want to see why so many of these jobs are changing shape, my article on tech jobs evolving into $900K roles goes through more of the ads, and the cybersecurity roadmap lays out the learning order step by step.

Frequently Asked Questions

How do I know which cyber security job is right for me?

Start with the work you already do, not the job title that sounds best. Match your background to the role next to it (network to network security, cloud to cloud security, operations to detection and response, development to application security), then read real ads for that role and count how many requirements you already meet.

Can I move into cyber security from IT without a security job first?

Yes. Your IT experience is a strong foundation for the security role next to yours. The ads in this article required the networking, cloud, operations or development skills people already use, plus security depth on top.

Which cyber security role pays the most?

In the five ads covered here, the top of the range was Anthropic's Staff+ Application Security Engineer at up to $485,000 a year. Those are advertised ranges for senior US roles, not typical pay.

Do I need to code to work in cyber security?

Not for every role, but it helps in most of the ones here. Network and cloud security increasingly use code to set rules (Python, Terraform), and application security is built on reading code.

Do these cyber security jobs need years of experience?

Most did. Jefferies and Gusto required 10 or more years, and Notion 6 or more. Anthropic listed 7 or more as preferred, and Pinterest set no number. Your existing tech years count towards that experience. The security specialism is what most people need to add.

Is support or helpdesk a real route into cyber security?

It can be, through detection and response, if your support work includes alerts, on-call incidents and reading logs. Those tasks overlap directly. You'll still need SIEM query writing and some scripting, and very few ads name support as a background, so you'll need to spell out the overlap yourself.

About the Author

Nathan House

Nathan House, Founder & CEO of StationX

Nathan House has 30 years of hands-on cybersecurity experience and is Cambridge-educated, holding CISSP, CISA, CISM, OSCP, CEH, and SABSA. He founded StationX in 1999 — one of the UK’s first cybersecurity companies — and has secured £71 billion in UK mobile banking transactions and the London 2012 Olympics, advising clients including Microsoft, Cisco, BP, Vodafone, and VISA. He authored the world’s most popular cybersecurity course — a #1 Udemy bestseller taken by over 500,000 students — and was named Cyber Security Educator of the Year 2020, AI Security Educator of the Year, and a UK Top 25 Security Influencer 2025. A DEF CON speaker and featured expert on CNN, Fox News, NBC, and the BBC, Nathan leads StationX’s training of more than half a million students worldwide.