Ten disciplines

Cyber security career paths, compared

“Cyber security” is not one job. It is a dozen professions that happen to share a budget line. Here is what each one actually involves, what it pays, how people get in — and the part the recruiter leaves out.

How to use this page. Read for the day-to-day description, not the job title. Most people who are unhappy in security chose a title that sounded impressive and a daily reality they hate. Pay ranges are US base salary bands from entry to senior — the salary guide shows the sources.

The ten disciplines

SOC Analyst

$60k – $130k

Watch the alerts, decide which ones are real, and start the response. Tier 1 triages, Tier 2 investigates, Tier 3 hunts and tunes.

A typical day
Alert queues, EDR timelines, phishing reports from staff, shift handovers. Volume is relentless and the work is genuinely time-pressured.
Core skills
Networking fundamentals, log analysis, SIEM query languages (KQL, SPL), Windows and Linux internals, MITRE ATT&CK literacy.
How people get in
The most common first security job, and the best general-purpose training ground in the field.
What nobody tells you
Shift work is normal and rota-based burnout is real. Set a two-year plan to specialise out of Tier 1.

Security Engineer

$90k – $185k

Build and run the controls: EDR, email security, network segmentation, logging pipelines, automation. Less alert-watching, more building.

A typical day
Deployments, integrations, breaking things in staging, writing the automation that removes the manual step you did last week.
Core skills
Scripting (Python, PowerShell), infrastructure knowledge, CI/CD, at least one cloud, an engineer's instinct for what will page you at 3am.
How people get in
A natural move from IT/sysadmin or from a SOC role where you kept building tooling to make your own job easier.
What nobody tells you
You inherit everyone else's technical debt. Insist on time budgeted for maintenance, not just new tooling.

Penetration Tester

$95k – $185k

Attack systems with permission and document exactly how you got in, so it can be fixed. Web, network, mobile, cloud, physical, social.

A typical day
Scoping calls, hands-on testing windows, and — more than people expect — report writing. The report is the deliverable.
Core skills
Web app security, Active Directory attack paths, scripting, Burp Suite, and the ability to write clearly for a non-technical reader.
How people get in
Hardest entry point in the field. Most testers arrive via a lab-heavy self-study route plus OSCP, or from development.
What nobody tells you
Consultancy means utilisation targets and travel. Also: the job is 40% writing. If you hate writing, you will hate this job.

Cloud Security Engineer

$95k – $260k

Secure the cloud estate: identity, network boundaries, workload protection, and the guardrails that stop misconfiguration at source.

A typical day
Terraform reviews, IAM policy archaeology, CSPM findings, and persuading platform teams that the secure path is also the fast path.
Core skills
Deep AWS/Azure/GCP, infrastructure as code, container and Kubernetes security, identity federation, policy-as-code.
How people get in
Usually a lateral from cloud/DevOps engineering, or from a security engineer who went deep on one provider.
What nobody tells you
Currently one of the best-paid, most in-demand lanes — ISC2 ranks cloud security the #2 most-needed skill. Expect fast change.

Application Security Engineer

$95k – $250k

Stop vulnerabilities before they ship. Threat modelling, secure design review, code review, and running the scanning that developers tolerate.

A typical day
Design reviews with product teams, triaging scanner output, writing secure-by-default libraries, teaching developers.
Core skills
Real programming ability in at least one language, OWASP depth, threat modelling, and the diplomacy to influence teams you do not manage.
How people get in
Overwhelmingly from software engineering. If you can already write and read production code, this is the shortest path in.
What nobody tells you
You have responsibility without authority. Influence is the actual skill; the scanner is just a tool.

Incident Responder / DFIR

$95k – $198k

When something has already gone wrong, scope it, contain it, evict the attacker, and reconstruct what happened.

A typical day
Forensic images, memory analysis, timeline building, and the war-room call where a room of executives wants an answer you do not have yet.
Core skills
Forensics tooling, memory and disk analysis, log correlation, malware triage, and calm written communication under pressure.
How people get in
Typically from a strong SOC Tier 2/3 background, or from law enforcement digital forensics.
What nobody tells you
On-call is real and incidents do not respect weekends. Consulting IR pays well and travels hard.

GRC / Risk Analyst

$65k – $180k

Translate regulation and risk into controls the business will actually adopt, then evidence that they work.

A typical day
Control testing, evidence collection, policy drafting, audit prep, risk register reviews, vendor questionnaires.
Core skills
NIST CSF/800-53, ISO 27001, SOC 2, sector rules (HIPAA, PCI DSS, FFIEC), and unusually strong writing.
How people get in
The most accessible entry point for career changers from audit, compliance, legal, project management or operations.
What nobody tells you
Dismissed as “not real security” by some technical folk. Ignore them — GRC leads to CISO more often than pen testing does.

IAM Engineer

$95k – $180k

Own who can access what, how that is proven, and how access ends when someone leaves. Identity is the modern perimeter.

A typical day
SSO integrations, joiner-mover-leaver automation, entitlement reviews, conditional access policy, killing standing privilege.
Core skills
Entra ID / Okta, SAML and OIDC, directory services, privileged access management, lifecycle automation.
How people get in
Common from IT systems administration — if you have run Active Directory, you are most of the way there.
What nobody tells you
Deeply unglamorous and enormously consequential. Most major breaches are identity failures at some point in the chain.

Threat Intelligence Analyst

$85k – $185k

Track who is attacking your sector, how they operate, and turn that into something defenders and executives can act on.

A typical day
Source collection, actor tracking, writing finished intelligence, briefing stakeholders, feeding detection engineering.
Core skills
Analytic tradecraft, structured writing, OSINT, malware familiarity, and often a language or regional specialism.
How people get in
Frequently from military or government intelligence backgrounds, or from a SOC analyst who kept doing the research nobody asked for.
What nobody tells you
Intelligence that nobody acts on is a newsletter. The job is only valuable if it changes a decision.

Security Leadership (Manager → CISO)

$140k – $700k+

Set strategy, own the budget, build the team, and carry the risk conversation to the board in language it accepts.

A typical day
Hiring, budget defence, vendor negotiation, incident escalations, board decks, and considerably more meetings than you want.
Core skills
Risk framing in business terms, financial literacy, people leadership, regulatory awareness, executive communication.
How people get in
Usually 10–15 years in, most often via security engineering leadership or GRC rather than a purely offensive background.
What nobody tells you
CISO pay ranges enormously with company size and scope. It is also the role most likely to carry personal liability.

Choosing

A blunt way to pick your lane

Answer these honestly. They predict job satisfaction in security better than any aptitude test.

Do you want to build or break?

Builders belong in security engineering, cloud security, IAM and appsec. Breakers belong in pen testing and red teaming. Most people assume they are breakers because it looks better on television, and there are roughly ten builder jobs for every breaker job.

How do you handle interruption?

SOC and IR are interrupt-driven: your plan for the day dies at 09:15. Appsec, GRC and architecture are project-driven with deadlines you can see coming. Neither is better; picking the wrong one is miserable.

Do you like writing?

Pen test reports, intelligence products, policies, risk assessments, incident write-ups — almost every senior security role is 30–50% writing. If that appeals, GRC, threat intel and consulting reward it heavily.

Can you code, honestly?

If you can write and read production code, appsec and detection engineering are open to you at a level and salary that most people take five years to reach. If you cannot yet, IAM, GRC and SOC do not require it on day one.

How do you feel about being on call?

SOC, IR and security engineering carry pagers. GRC, awareness, architecture and most appsec roles do not. This single factor drives more career changes within security than pay does.

Do you want to persuade or to decide?

Individual contributors influence; leaders decide and then own the outcome. If you find yourself more interested in why the business said no than in the technical fix, GRC and the leadership track are calling.

Moving up

The typical progression

Nothing here is a rule — but this is the shape most US security careers take, and knowing it helps you name the next step.

  1. Adjacent start (0–2 years)

    Help desk, sysadmin, network technician, developer, military signals, audit or compliance. Almost nobody starts in security; nearly everybody starts next to it. Use this time to accumulate the fundamentals that security assumes you already have.

  2. First security role (years 1–3)

    SOC Tier 1, GRC analyst, junior security engineer or IT security administrator. The goal is not the title, it is exposure: you now see real incidents, real audits and real production systems.

  3. Specialise (years 3–6)

    Pick one lane and go deliberately deep — cloud, identity, detection, appsec, offensive or risk. This is the step that separates a $95k generalist from a $160k specialist, and it is where most people stall by staying broad.

  4. Senior / lead (years 6–10)

    You set technical direction, review others' work, and own an area outright. Two forks appear: staff/principal engineer, or people management. Try the second before committing — it is a different job, not a promotion.

  5. Leadership (years 10+)

    Manager, director, then CISO or a principal/distinguished IC track. Budget, headcount and board reporting replace hands-on work. Many people discover here that they miss the keyboard — the IC track exists for a reason.

Picked a lane? Find the role.

Filter open security jobs by discipline and seniority — every listing shows its pay band.