Salary ranges vary widely by role, location, and experience, but entry-level positions typically start between $50,000 and $70,000 annually, while senior roles can reach $150,000 or more
Cybersecurity salaries depend on what you actually do. A security analyst watching for breaches earns differently than a penetration tester hired to break into systems, who earns differently than a chief information security officer managing an entire program. Your location matters too — a security engineer in San Francisco takes home more than one in rural Ohio, though the cost of living difference is significant. Years of experience and specific certifications (like CISSP or CEH) also shift the number.
The U.S. Bureau of Labor Statistics tracks "information security analysts" as a category, but that's broad. Within that umbrella sit dozens of specialties with their own pay bands. This guide walks through what different roles actually earn, what affects those numbers, and what the job market looks like right now.
Key Takeaways
- Entry-level security analysts and junior penetration testers typically earn $50,000 to $75,000 per year, while senior roles in the same specialties reach $120,000 to $180,000.
- Location significantly affects salary — major tech hubs and cities with high costs of living pay 20 to 40 percent more than smaller markets for the same role.
- Certifications like CISSP, CEH, and Security+ often correlate with higher pay, though some employers value experience over credentials.
- Government and defense contractor positions often pay more than private sector roles but may require security clearances that take months to obtain.
- Remote work has expanded the job market, allowing people in lower-cost areas to earn rates closer to major city salaries.
Entry-level positions and what they pay
If you're starting out in cybersecurity, you're typically looking at security analyst, junior penetration tester, or security operations center (SOC) analyst roles. These positions usually require a relevant degree or bootcamp certification, sometimes a Security+ or CompTIA Network+ certification, and zero to two years of hands-on experience.
Entry-level security analysts in smaller cities or less competitive markets earn around $50,000 to $60,000 annually. In major tech hubs like San Francisco, Seattle, or New York, the same role pays $65,000 to $80,000. SOC analysts, who monitor networks for suspicious activity, typically fall in the $55,000 to $75,000 range depending on location and employer size. Junior penetration testers (who test systems for vulnerabilities) often start at $60,000 to $75,000, though some smaller firms pay less.
These numbers don't always include bonuses, stock options, or benefits. A job offering $60,000 plus 15 percent annual bonus and full health coverage is materially different from one offering $65,000 with no bonus and high deductibles. Ask about the full package, not just base salary.
Mid-career roles and salary jumps
After three to seven years, you move into mid-career positions: senior security analyst, security engineer, incident response specialist, or mid-level penetration tester. These roles typically require demonstrated experience solving real problems, often a relevant certification, and sometimes a degree (though not always).
A senior security analyst in a mid-sized city earns $80,000 to $110,000. In expensive markets, that same role reaches $110,000 to $140,000. Security engineers — who design and build security systems rather than just monitoring them — typically earn $90,000 to $130,000 depending on location. Incident response specialists, who handle active breaches and attacks, often earn $85,000 to $125,000 because the work is high-pressure and requires fast decision-making.
The jump from entry to mid-career is usually 40 to 60 percent, not a small bump. This is where certifications start to matter more visibly — a CISSP (Certified Information Systems Security Professional) or CEH (Certified Ethical Hacker) often correlates with being on the higher end of the range for your role and location.
Senior and leadership positions
Senior roles include principal security engineer, security architect, and chief information security officer (CISO). These positions require seven or more years of experience, often multiple certifications, and the ability to make decisions that affect the entire organization's security posture.
A principal security engineer or security architect typically earns $120,000 to $160,000 in most markets, with top-tier tech companies and expensive cities pushing toward $180,000 to $220,000. A CISO — the executive responsible for all security at a company — earns $150,000 to $250,000 at mid-sized companies, and $250,000 to $400,000 or more at large enterprises. CISO pay varies dramatically by company size and industry; a CISO at a regional bank earns less than one at a Fortune 500 tech company.
At this level, compensation often includes significant bonuses (20 to 50 percent of base salary), stock options, and executive benefits. The total package matters more than the base number.
How location and company size affect pay
A security analyst role pays differently in Austin, Texas than in San Jose, California, even though the work is identical. San Jose typically pays 30 to 40 percent more. Washington D.C. and Northern Virginia (where many government contractors operate) pay well above average for security roles. Seattle, Boston, and New York also command premium salaries. Smaller cities and rural areas pay 20 to 35 percent less for the same role.
Company size matters too. A startup with 50 employees might pay $65,000 for a security analyst because it has limited budget, but offer equity that could become valuable. A mid-sized company (500 to 5,000 employees) typically pays $75,000 to $90,000 for the same role. A large enterprise (10,000+ employees) often pays $85,000 to $100,000 because it has established salary bands and budget.
Government agencies and defense contractors often pay more than private companies for the same role — sometimes 15 to 25 percent more — but the hiring process is slower and may require a security clearance, which takes three to twelve months to obtain. The trade-off is job stability; government positions rarely lay off staff during downturns.
Certifications and their salary impact
Certain certifications correlate with higher pay, though the relationship isn't automatic. A Security+ certification (CompTIA) is often required for government contractor roles and is associated with entry-level positions earning $55,000 to $75,000. A CISSP (Certified Information Systems Security Professional) typically correlates with mid-career or senior roles and is associated with salaries $100,000 and up. A CEH (Certified Ethical Hacker) is common for penetration testers and is associated with $70,000 to $130,000 depending on experience level.
The catch: certifications alone don't may provide higher pay. An employer hiring a junior analyst won't pay senior analyst rates just because the candidate has a CISSP. But certifications do make you competitive for higher-paying roles and can help you move up faster. Some employers explicitly tie raises or promotions to earning specific certifications.
Certifications also require maintenance — renewing every few years and earning continuing education credits — which costs time and money. Factor that into the decision to pursue one.
Remote work and salary negotiation
Remote positions have shifted the salary landscape. A company in San Francisco can now hire a security engineer in a lower-cost area and pay them 70 to 85 percent of what they'd pay someone local, which is still well above local market rates. This has benefited people in smaller cities and rural areas, who can now earn closer to major-city salaries without relocating.
However, some companies explicitly adjust salaries by location even for remote workers — they'll pay less for someone in a cheaper area. Ask directly: "Is this salary adjusted by location, or is it the same regardless of where I work?" Some companies have moved to location-agnostic pay, meaning everyone doing the same job earns the same base salary.
Salary negotiation in cybersecurity is more common than in some fields because demand is high and employers know they're competing for talent. If you have a job offer, research what others in your role earn in your location using Glassdoor, Levels.fyi, or by asking people in your network. Most employers expect negotiation and have room in their budget.
Job market demand and growth
Cybersecurity roles are in high demand and have been for years. The U.S. Bureau of Labor Statistics projects growth in information security analyst positions, though the exact percentage varies by year and economic conditions. This demand means employers are actively recruiting and willing to pay to fill positions. It also means salaries have been rising faster than inflation in many specialties.
Certain specialties are hotter than others right now. Cloud security engineers, zero-trust architects, and incident response specialists are in particularly high demand and often command premium salaries. Roles that are becoming automated or less critical (like basic network monitoring) may see slower salary growth.
The market is also shifting toward experience and demonstrated skills over credentials. Some employers now hire people without degrees or certifications if they can show they've actually done the work — through portfolios, bug bounties, or capture-the-flag competitions. This has opened paths to higher-paying roles for people who don't follow the traditional degree-plus-certification route.
Frequently Asked Questions
Do you need a degree to earn good money in cybersecurity?
No. Many cybersecurity roles don't require a degree, especially at mid-career and senior levels where experience matters more. Entry-level positions are more likely to require a degree or bootcamp certification, but even that is changing. Some employers will hire based on certifications, portfolios, or demonstrated skills alone. A degree can help you land your first job, but it's not the only path to six-figure security roles.
What's the difference between what a penetration tester and a security analyst earn?
Penetration testers typically earn 10 to 20 percent more than security analysts at the same experience level because the work requires specialized skills and is often project-based (allowing for higher hourly rates). A junior penetration tester might earn $65,000 to $80,000, while a junior analyst earns $55,000 to $70,000. At senior levels, the gap narrows because both roles command high salaries.
How much does a security clearance affect salary?
Having an active security clearance (Secret, Top Secret, or higher) can increase your salary by 10 to 25 percent because it qualifies you for government and defense contractor roles that pay premiums and require cleared employees. However, obtaining a clearance takes time and involves background investigation. If you're starting out, it's usually not worth delaying your career to get one — you can obtain it on the job if an employer needs it.
Do cybersecurity salaries vary by industry?
Yes. Finance and healthcare typically pay more for security roles than retail or nonprofits because they handle sensitive data and face strict regulations. A security engineer at a bank might earn $120,000, while the same role at a nonprofit earns $85,000. Government and defense contractors also pay above-average salaries. Choose your industry partly based on what you want to work on, but know it affects your earning potential.
Is it worth getting a master's degree in cybersecurity for higher pay?
Usually not for salary alone. A master's degree takes two years and costs $20,000 to $60,000, but it typically increases salary by 5 to 15 percent — less than the time and money invested. A master's is more valuable if you want to move into management or research, or if your employer requires it for promotion. For pure earning potential, certifications and experience usually deliver better returns.