The board
Cyber security jobs
Where security roles actually get posted, how to read a job advert properly, and a board that only ever lists roles with a published salary band.
Open security roles
Board opening
We are not carrying live listings yet.
Rather than pad the board out, we would rather it be worth checking. Until employers are onboarded, the sources below are where the roles genuinely are — and the section after that will help you read what you find.
Hiring? Listings are free while we build the board out. Send the title, location, work setup, salary band and application link to contact@jobsincybersecurity.com. One rule: no published pay range, no listing.
Real sources
Where live cyber security jobs actually get posted
No single board has everything. These are the sources worth a weekly pass, and what each is genuinely good for.
ClearanceJobs
The default for US roles requiring an active security clearance. If you hold one, this is where employers who will pay for it are looking.
USAJOBS
Every US federal civilian vacancy, including CISA, NSA civilian roles and agency SOC positions. Slow process, real stability, published pay grades.
LinkedIn Jobs
Broadest volume and the best signal on who is hiring in your city. Set alerts on specific titles rather than the word “cyber”.
Dice
Long-standing US tech board with strong contract and contract-to-hire coverage, which is a legitimate way into a first security role.
Indeed
Highest raw volume, lowest signal-to-noise. Useful for spotting the smaller regional employers that never post anywhere else.
Company career pages
The underrated one. Build a list of 30 employers in your area, check their careers page fortnightly, and apply within 48 hours of a posting going up.
Direct applications, no aggregator lag.
Read the ad properly
How to decode a cyber security job posting
“5+ years” is a wish, not a gate
Requirement lists are written by committee and are routinely aspirational. If you meet roughly 60% of the technical asks and can evidence the core two or three, apply. The people who get hired are frequently not the ones who ticked every box.
Watch for the “one-person security team”
A posting that wants SIEM tuning, pen testing, compliance, awareness training and vendor risk from one person is describing five jobs. That can be a superb learning role early on and a fast route to burnout later. Ask who else is on the team.
Shift patterns hide in the fine print
“24/7 operations” and “follow-the-sun coverage” mean nights and weekends. Ask what the rotation actually looks like, whether there is a shift differential, and how on-call is compensated — before the offer stage.
Clearance language tells you the timeline
“Active clearance required” means they will not sponsor. “Must be able to obtain” means they will, and that your start-to-productive timeline may be six months or more. Both are fine — just know which one you are reading.
A missing salary band is information
Several US states now require a pay range in the advert. Where it is absent and not legally required, it usually means the band is wide, the employer wants your number first, or internal equity is a mess. Ask for the range in the first call, every time.
No legitimate employer charges you
Nobody real asks a candidate to pay for training, buy their own equipment upfront, process payments, or send identity documents before a written offer. Every one of those is a recruitment scam signature. Walk away and report it.
Not sure which discipline fits you?
Ten security career paths compared side by side — the day-to-day work, the skills, the pay and the parts nobody advertises.