How to use this page. Read for the day-to-day description, not the job title. Most people who are unhappy in security chose a title that sounded impressive and a daily reality they hate. Pay ranges are US base salary bands from entry to senior — the salary guide shows the sources.
SOC Analyst
$60k – $130k
Watch the alerts, decide which ones are real, and start the response. Tier 1 triages, Tier 2 investigates, Tier 3 hunts and tunes.
- A typical day
- Alert queues, EDR timelines, phishing reports from staff, shift handovers. Volume is relentless and the work is genuinely time-pressured.
- Core skills
- Networking fundamentals, log analysis, SIEM query languages (KQL, SPL), Windows and Linux internals, MITRE ATT&CK literacy.
- How people get in
- The most common first security job, and the best general-purpose training ground in the field.
- What nobody tells you
- Shift work is normal and rota-based burnout is real. Set a two-year plan to specialise out of Tier 1.
Security Engineer
$90k – $185k
Build and run the controls: EDR, email security, network segmentation, logging pipelines, automation. Less alert-watching, more building.
- A typical day
- Deployments, integrations, breaking things in staging, writing the automation that removes the manual step you did last week.
- Core skills
- Scripting (Python, PowerShell), infrastructure knowledge, CI/CD, at least one cloud, an engineer's instinct for what will page you at 3am.
- How people get in
- A natural move from IT/sysadmin or from a SOC role where you kept building tooling to make your own job easier.
- What nobody tells you
- You inherit everyone else's technical debt. Insist on time budgeted for maintenance, not just new tooling.
Penetration Tester
$95k – $185k
Attack systems with permission and document exactly how you got in, so it can be fixed. Web, network, mobile, cloud, physical, social.
- A typical day
- Scoping calls, hands-on testing windows, and — more than people expect — report writing. The report is the deliverable.
- Core skills
- Web app security, Active Directory attack paths, scripting, Burp Suite, and the ability to write clearly for a non-technical reader.
- How people get in
- Hardest entry point in the field. Most testers arrive via a lab-heavy self-study route plus OSCP, or from development.
- What nobody tells you
- Consultancy means utilisation targets and travel. Also: the job is 40% writing. If you hate writing, you will hate this job.
Cloud Security Engineer
$95k – $260k
Secure the cloud estate: identity, network boundaries, workload protection, and the guardrails that stop misconfiguration at source.
- A typical day
- Terraform reviews, IAM policy archaeology, CSPM findings, and persuading platform teams that the secure path is also the fast path.
- Core skills
- Deep AWS/Azure/GCP, infrastructure as code, container and Kubernetes security, identity federation, policy-as-code.
- How people get in
- Usually a lateral from cloud/DevOps engineering, or from a security engineer who went deep on one provider.
- What nobody tells you
- Currently one of the best-paid, most in-demand lanes — ISC2 ranks cloud security the #2 most-needed skill. Expect fast change.
Application Security Engineer
$95k – $250k
Stop vulnerabilities before they ship. Threat modelling, secure design review, code review, and running the scanning that developers tolerate.
- A typical day
- Design reviews with product teams, triaging scanner output, writing secure-by-default libraries, teaching developers.
- Core skills
- Real programming ability in at least one language, OWASP depth, threat modelling, and the diplomacy to influence teams you do not manage.
- How people get in
- Overwhelmingly from software engineering. If you can already write and read production code, this is the shortest path in.
- What nobody tells you
- You have responsibility without authority. Influence is the actual skill; the scanner is just a tool.
Incident Responder / DFIR
$95k – $198k
When something has already gone wrong, scope it, contain it, evict the attacker, and reconstruct what happened.
- A typical day
- Forensic images, memory analysis, timeline building, and the war-room call where a room of executives wants an answer you do not have yet.
- Core skills
- Forensics tooling, memory and disk analysis, log correlation, malware triage, and calm written communication under pressure.
- How people get in
- Typically from a strong SOC Tier 2/3 background, or from law enforcement digital forensics.
- What nobody tells you
- On-call is real and incidents do not respect weekends. Consulting IR pays well and travels hard.
GRC / Risk Analyst
$65k – $180k
Translate regulation and risk into controls the business will actually adopt, then evidence that they work.
- A typical day
- Control testing, evidence collection, policy drafting, audit prep, risk register reviews, vendor questionnaires.
- Core skills
- NIST CSF/800-53, ISO 27001, SOC 2, sector rules (HIPAA, PCI DSS, FFIEC), and unusually strong writing.
- How people get in
- The most accessible entry point for career changers from audit, compliance, legal, project management or operations.
- What nobody tells you
- Dismissed as “not real security” by some technical folk. Ignore them — GRC leads to CISO more often than pen testing does.
IAM Engineer
$95k – $180k
Own who can access what, how that is proven, and how access ends when someone leaves. Identity is the modern perimeter.
- A typical day
- SSO integrations, joiner-mover-leaver automation, entitlement reviews, conditional access policy, killing standing privilege.
- Core skills
- Entra ID / Okta, SAML and OIDC, directory services, privileged access management, lifecycle automation.
- How people get in
- Common from IT systems administration — if you have run Active Directory, you are most of the way there.
- What nobody tells you
- Deeply unglamorous and enormously consequential. Most major breaches are identity failures at some point in the chain.
Threat Intelligence Analyst
$85k – $185k
Track who is attacking your sector, how they operate, and turn that into something defenders and executives can act on.
- A typical day
- Source collection, actor tracking, writing finished intelligence, briefing stakeholders, feeding detection engineering.
- Core skills
- Analytic tradecraft, structured writing, OSINT, malware familiarity, and often a language or regional specialism.
- How people get in
- Frequently from military or government intelligence backgrounds, or from a SOC analyst who kept doing the research nobody asked for.
- What nobody tells you
- Intelligence that nobody acts on is a newsletter. The job is only valuable if it changes a decision.
Security Leadership (Manager → CISO)
$140k – $700k+
Set strategy, own the budget, build the team, and carry the risk conversation to the board in language it accepts.
- A typical day
- Hiring, budget defence, vendor negotiation, incident escalations, board decks, and considerably more meetings than you want.
- Core skills
- Risk framing in business terms, financial literacy, people leadership, regulatory awareness, executive communication.
- How people get in
- Usually 10–15 years in, most often via security engineering leadership or GRC rather than a purely offensive background.
- What nobody tells you
- CISO pay ranges enormously with company size and scope. It is also the role most likely to carry personal liability.