US salary guide
Cyber security salaries in 2026
What security roles pay in the United States, where the numbers come from, and the four factors that move a security salary more than the job title does.
Last reviewed: 30 August 2026
The BLS occupation code covers analyst-type roles. Engineering, offensive and leadership positions frequently sit outside it and pay differently — which is why the ranges below are wider.
By role
Base salary ranges by discipline and seniority
Annual base salary in USD, excluding bonus, equity and shift differentials. These are typical advertised bands for the continental US — a role in the Bay Area or New York sits at or above the top of each range, and much of the Midwest and South sits below it.
| Role | Entry (0–2 yrs) | Mid (3–6 yrs) | Senior (7+ yrs) | Notes |
|---|---|---|---|---|
| SOC analyst | $60k–$85k | $85k–$115k | $115k–$130k | Shift differentials can add 5–15% |
| Detection engineer | — | $120k–$150k | $150k–$180k | Rarely an entry-level title |
| Security engineer | $90k–$115k | $110k–$150k | $150k–$185k | The broadest, most portable band |
| Penetration tester | $95k–$120k | $120k–$150k | $150k–$185k | Consultancies pay less base, more travel |
| Cloud security engineer | $95k–$130k | $130k–$180k | $180k–$260k | Currently the strongest premium |
| Application security engineer | $95k–$130k | $130k–$180k | $180k–$250k | Tracks software engineering pay |
| Incident responder / DFIR | $85k–$110k | $110k–$150k | $150k–$198k | On-call premiums common |
| GRC / compliance analyst | $65k–$90k | $90k–$130k | $130k–$180k | Highest in banking and healthcare |
| IAM engineer | $85k–$110k | $110k–$155k | $155k–$180k | PAM specialists at the top |
| Threat intelligence analyst | $85k–$105k | $105k–$150k | $150k–$185k | Clearance adds materially |
| Security architect | — | $140k–$180k | $180k–$228k | Senior-only role in practice |
| Security manager / director | — | $150k–$190k | $160k–$220k | Scope and headcount drive the number |
| CISO | — | — | $250k–$700k+ | Enormous spread by company size |
Compiled from published US salary guides and job-ad bands, cross-checked against BLS occupational data. Ranges describe advertised base pay and will not match any individual offer. Sources: BLS Occupational Outlook Handbook, Kore1 cyber security salary guide, CertCompass salary guide. More on how we source and review this data.
What moves the number
Four things that change a security salary more than your title
1. Where the job is — and where you are
The same senior cloud security role can differ by $60,000 between a Bay Area headquarters and a Midwest insurer. Remote roles have partially decoupled pay from geography, but many employers still band by your location, not theirs. Ask which model applies before you name a number.
2. An active security clearance
For US defence, intelligence and federal contracting work, an active clearance is the single largest lever available to most practitioners. Employers pay a premium because sponsoring a new investigation costs them months of unproductive headcount. You cannot self-fund one — it must be sponsored.
3. Cloud and AI skills, specifically
ISC2’s 2025 workforce study puts AI/ML (41%) and cloud security (36%) at the top of what security teams say they need. Demonstrable depth in one cloud provider’s security stack is currently the most reliable way to move up a band without changing job title.
4. The industry, not the company size
Financial services, defence contracting and large technology firms consistently pay above healthcare, higher education, non-profits and state government for the identical job description. If pay is your priority, changing sector beats changing title.
The negotiation point most people miss: security salaries are usually banded internally, and the band is far wider than the offer. Asking “what is the full range for this level, and where does this offer sit in it?” is a normal, professional question — and the answer is frequently more useful than the counter-offer itself.
FAQ
Salary questions, answered plainly
What does an entry-level cyber security job actually pay?
For a genuine first security role in the US — SOC Tier 1, junior GRC analyst, IT security administrator — expect roughly $60,000 to $90,000 depending on city and sector. Postings advertising six figures for a true entry-level role with no prior IT experience are rare, and are usually either mislabelled mid-level roles or require a clearance.
Why is the BLS median so much higher than entry-level pay?
Because the $129,180 median covers the whole occupation, weighted toward experienced practitioners, and the BLS category excludes many junior support roles that people actually start in. It is an accurate picture of the mid-career centre of the field, not of your first year in it.
Does a certification directly increase my salary?
Rarely on its own, and beware of guides that claim a specific dollar uplift per certification — that correlation is mostly driven by the experience of the people who hold them. What certifications reliably do is widen the set of jobs you can apply to, and job changes are where most security salary increases actually happen.
How much does switching employers raise pay compared to a promotion?
In security, external moves have consistently outpaced internal raises, because internal increases are constrained by merit-increase budgets while external offers are set by the market. That said, changing jobs every 12 months reads badly to hiring managers — roughly two to three years per role is the pattern that gets both the raises and the credibility.
Should I take a pay cut to get into security?
Sometimes it is the fastest route, particularly from a well-paid non-technical career. If you do, treat it as a defined 18–24 month investment with a written plan for what you will learn and what you will target next. An open-ended pay cut with no plan tends to become permanent.
See what employers are paying right now
Every role on our board publishes its salary band. No “competitive salary”, no guessing.