21% projected job growth — BLS, 2025–2035

Find your next cyber security job — and the path to get there.

Open security roles, honest US pay data, certification routes that actually pay off, and a step‑by‑step way in for career changers. No fluff, no paywall, no recruiter spam.

Hiring right now for SOC Analyst|

192,900US information security analyst jobs (BLS, 2025)
$129,180Median annual pay for the role (BLS, May 2025)
+21%Projected growth 2025–2035, vs ~4% all jobs
14,100Openings projected per year through 2035

Source: U.S. Bureau of Labor Statistics, Occupational Outlook Handbook. Figures cover the “information security analyst” occupation, which is narrower than the whole security field.

The state of hiring

The shortage is real — but it is a skills shortage, not a headcount one

The 2025 ISC2 Cybersecurity Workforce Study surveyed 16,029 practitioners. The headline finding matters if you are job hunting: teams are not short of applicants, they are short of specific, demonstrable skills.

59% report critical skills gaps

Up from 44% a year earlier. Hiring managers are not lowering the bar — they are raising it on capability while budgets stay flat.

AI/ML and cloud lead demand

AI and machine learning (41%) and cloud security (36%) top the list of needed skills, ahead of risk assessment (29%) and application security (28%).

Soft skills decide offers

Hiring managers consistently rank problem‑solving and communication alongside technical depth. Being able to explain risk to a non‑technical exec is a differentiator.

What this means for you: a generic “cyber security” résumé competes with thousands. A résumé that says “I detect and respond to identity attacks in Entra ID and can prove it” competes with a handful. Pick a lane on the career paths page, then go deep.

Source: 2025 ISC2 Cybersecurity Workforce Study.

Pay, roughly

What security roles pay in the US

Typical total base ranges seen in US job ads. Location, clearance and industry move these a lot — the full salary guide breaks down why.

Three of thirteen roles — see the full salary guide for the rest, with sources.
RoleEntryMidSenior
SOC analyst$60k–$85k$85k–$115k$115k–$130k
Security engineer$90k–$115k$110k–$150k$150k–$185k
Penetration tester$95k–$120k$120k–$150k$150k–$185k
Security architect$140k–$180k$180k–$228k

Common questions

Getting into cyber security, answered

Do I need a degree to work in cyber security?

Not universally. The BLS lists a bachelor’s degree as the typical entry-level education for information security analysts, and many large employers and federal contractors still filter on it. But a large share of practitioners came in through IT support, networking, the military, or self-study plus a certification. If you do not have a degree, the substitute is demonstrable skill: a home lab, a public write-up portfolio, a relevant certification, and adjacent experience like help desk or sysadmin work.

What is the fastest realistic route into a first security job?

For most career changers it is 9–18 months: build core IT and networking fundamentals, earn CompTIA Security+ (or ISC2 CC first if budget is tight), run a home lab you can talk about in detail, then target SOC analyst, IT support with security duties, or GRC analyst roles. Anyone promising a six-figure security job in eight weeks with no IT background is selling something. Our getting started roadmap lays out the whole sequence.

Is cyber security still hiring, or has the market cooled?

Both things are true at once. ISC2’s 2025 study found hiring freezes flat at 39% and layoffs affecting 24% of organisations — conditions stabilised rather than improved. At the same time the BLS projects 21% growth for information security analysts from 2025 to 2035, far above the average occupation. The practical read: entry-level is competitive and unglamorous, mid-level specialists with cloud, identity or detection engineering skills are in genuine demand.

Which certification should I get first?

CompTIA Security+ is the default first certification for most people — it is vendor-neutral, widely recognised by HR filters, and satisfies US DoD 8140 baseline requirements for several job categories. If cost is the blocker, ISC2’s Certified in Cybersecurity (CC) is a cheaper entry point. Save CISSP for when you have the five years of experience it requires; taking it early only earns you Associate status. Full breakdown on the certifications page.

Can I get a remote cyber security job as a beginner?

It is possible but it is the hard mode. Remote-first security roles skew mid to senior, because juniors need supervision, shadowing and access to physical environments. Many SOC roles are shift-based and on-site or hybrid by design. A pragmatic plan: take a hybrid or on-site first role, build two years of real incident experience, then move remote where the market is genuinely open.

Do I need a security clearance?

Only for US federal, defence and intelligence work — but in those markets it is decisive, and an active clearance commands a meaningful premium because employers avoid a months-long sponsorship process. You cannot get one on your own; a sponsoring employer or the military must initiate it. If you are near a defence hub, targeting a cleared-adjacent employer who sponsors is a legitimate career strategy.

Ready to find your next security role?

Browse open roles with published pay bands, or start with the twelve-month plan if you are coming in from outside the field.