Cybersecurity Salary Benchmarks
Market ranges by role, level, and location. Based on BLS OES, CyberSeek, and ISC2 data.
Experience Level
Location Market
Sort By
Filter Roles (click to filter, empty = show all)
Bar widths are relative to the current filtered set. 19 roles shown.
CISO
Typical entry: 12+ yrs
Security Architect
Typical entry: 7+ yrs
Cloud Security Engineer
Typical entry: 3+ yrs
Security Program Manager
Typical entry: 5+ yrs
Application Security Engineer
Typical entry: 2+ yrs
DevSecOps Engineer
Typical entry: 3+ yrs
Security Engineer
Typical entry: 2+ yrs
OT/ICS Security Engineer
Typical entry: 3+ yrs
IAM Engineer
Typical entry: 2+ yrs
Penetration Tester
Typical entry: 1+ yrs
Malware Analyst
Typical entry: 2+ yrs
Network Security Engineer
Typical entry: 2+ yrs
Incident Response Analyst
Typical entry: 1+ yrs
Threat Intelligence Analyst
Typical entry: 1+ yrs
Data Security Analyst
Typical entry: 1+ yrs
Vulnerability Management Analyst
Entry-accessible
GRC Analyst
Entry-accessible
SOC Analyst
Entry-accessible
Security Awareness Specialist
Entry-accessible
Current Market
National Average
+0% vs. national average
National baseline — everything not in High Cost or Above Average metros.
What Moves the Number
Pushes comp up
- Security clearance (TS/SCI can add 20–40% at defense contractors)
- Niche specialization — OT/ICS, malware reversing, CISO-track
- Certs aligned to the role (OSCP for pentest, CISSP for architect)
- FAANG or defense contractor employer vs. mid-market
- Remote with High Cost market anchor
Pushes comp down
- Strictly on-site in a low-tier metro
- Compliance-only GRC vs. hands-on technical work
- Nonprofit, government, or education sector (10–20% below private)
- Under-credentialed for the stated level
- Years-of-experience proxies that aren't skill-based
Data: BLS OES (May 2024), CyberSeek 2025, ISC2 Workforce Study 2025, Glassdoor, PayScale. Ranges = 25th–75th percentile. Updated annually.