21% projected job growth — BLS, 2025–2035
Find your next cyber security job — and the path to get there.
Open security roles, honest US pay data, certification routes that actually pay off, and a step‑by‑step way in for career changers. No fluff, no paywall, no recruiter spam.
Hiring right now for SOC Analyst|
Source: U.S. Bureau of Labor Statistics, Occupational Outlook Handbook. Figures cover the “information security analyst” occupation, which is narrower than the whole security field.
Start here
Four ways people actually break into security
Nobody walks into this field the same way. Pick the lane that matches where you are today — each one is a full guide, not a landing page.
Browse open roles
Filter live security jobs by discipline, seniority and whether they are remote, hybrid or on‑site.
See the boardCompare career paths
Ten security disciplines side by side — day‑to‑day work, skills, pay band and what each one burns you out with.
Compare rolesPick the right cert
What Security+, CISSP, OSCP, CCSP and CISM actually cost, who they are for, and the order to take them in.
Read the guideCheck the pay
Realistic US ranges by role and seniority, plus the four things that genuinely move a security salary.
See salariesThe state of hiring
The shortage is real — but it is a skills shortage, not a headcount one
The 2025 ISC2 Cybersecurity Workforce Study surveyed 16,029 practitioners. The headline finding matters if you are job hunting: teams are not short of applicants, they are short of specific, demonstrable skills.
59% report critical skills gaps
Up from 44% a year earlier. Hiring managers are not lowering the bar — they are raising it on capability while budgets stay flat.
AI/ML and cloud lead demand
AI and machine learning (41%) and cloud security (36%) top the list of needed skills, ahead of risk assessment (29%) and application security (28%).
Soft skills decide offers
Hiring managers consistently rank problem‑solving and communication alongside technical depth. Being able to explain risk to a non‑technical exec is a differentiator.
What this means for you: a generic “cyber security” résumé competes with thousands. A résumé that says “I detect and respond to identity attacks in Entra ID and can prove it” competes with a handful. Pick a lane on the career paths page, then go deep.
Pay, roughly
What security roles pay in the US
Typical total base ranges seen in US job ads. Location, clearance and industry move these a lot — the full salary guide breaks down why.
| Role | Entry | Mid | Senior |
|---|---|---|---|
| SOC analyst | $60k–$85k | $85k–$115k | $115k–$130k |
| Security engineer | $90k–$115k | $110k–$150k | $150k–$185k |
| Penetration tester | $95k–$120k | $120k–$150k | $150k–$185k |
| Security architect | — | $140k–$180k | $180k–$228k |
Common questions
Getting into cyber security, answered
Do I need a degree to work in cyber security?
Not universally. The BLS lists a bachelor’s degree as the typical entry-level education for information security analysts, and many large employers and federal contractors still filter on it. But a large share of practitioners came in through IT support, networking, the military, or self-study plus a certification. If you do not have a degree, the substitute is demonstrable skill: a home lab, a public write-up portfolio, a relevant certification, and adjacent experience like help desk or sysadmin work.
What is the fastest realistic route into a first security job?
For most career changers it is 9–18 months: build core IT and networking fundamentals, earn CompTIA Security+ (or ISC2 CC first if budget is tight), run a home lab you can talk about in detail, then target SOC analyst, IT support with security duties, or GRC analyst roles. Anyone promising a six-figure security job in eight weeks with no IT background is selling something. Our getting started roadmap lays out the whole sequence.
Is cyber security still hiring, or has the market cooled?
Both things are true at once. ISC2’s 2025 study found hiring freezes flat at 39% and layoffs affecting 24% of organisations — conditions stabilised rather than improved. At the same time the BLS projects 21% growth for information security analysts from 2025 to 2035, far above the average occupation. The practical read: entry-level is competitive and unglamorous, mid-level specialists with cloud, identity or detection engineering skills are in genuine demand.
Which certification should I get first?
CompTIA Security+ is the default first certification for most people — it is vendor-neutral, widely recognised by HR filters, and satisfies US DoD 8140 baseline requirements for several job categories. If cost is the blocker, ISC2’s Certified in Cybersecurity (CC) is a cheaper entry point. Save CISSP for when you have the five years of experience it requires; taking it early only earns you Associate status. Full breakdown on the certifications page.
Can I get a remote cyber security job as a beginner?
It is possible but it is the hard mode. Remote-first security roles skew mid to senior, because juniors need supervision, shadowing and access to physical environments. Many SOC roles are shift-based and on-site or hybrid by design. A pragmatic plan: take a hybrid or on-site first role, build two years of real incident experience, then move remote where the market is genuinely open.
Do I need a security clearance?
Only for US federal, defence and intelligence work — but in those markets it is decisive, and an active clearance commands a meaningful premium because employers avoid a months-long sponsorship process. You cannot get one on your own; a sponsoring employer or the military must initiate it. If you are near a defence hub, targeting a cleared-adjacent employer who sponsors is a legitimate career strategy.
Ready to find your next security role?
Browse open roles with published pay bands, or start with the twelve-month plan if you are coming in from outside the field.