Cybersecurity salaries range from $60,000 to $165,000 depending on your role, location, and experience level
A junior security analyst in a smaller city might earn $60,000 to $75,000 per year. A senior security architect in a major tech hub like San Francisco or New York could make $130,000 to $165,000. The middle ground — a mid-level security engineer with five to ten years of experience — typically earns $85,000 to $120,000. These numbers shift based on whether you work for a bank, a tech company, a government agency, or a consulting firm, and they vary significantly by state and region.
The reason the range is so wide is that cybersecurity isn't one job. It's dozens of different roles, each with different entry points and earning trajectories. A penetration tester (someone who tests systems for vulnerabilities) earns differently than a security operations center analyst (someone who monitors networks for attacks in real time). Understanding which path leads where helps you decide whether the field makes sense for your situation.
Key Takeaways
- Entry-level security roles start around $60,000 to $75,000 per year, while senior positions reach $130,000 to $165,000, with location and employer type making a significant difference.
- The most common entry point is a security operations center analyst role, which requires basic certifications like CompTIA Security+ but no prior IT experience.
- Certifications matter more than a four-year degree in cybersecurity — employers often care more about CompTIA Security+, Certified Ethical Hacker, or CISSP than about formal education.
- Government and financial services jobs typically pay 10 to 20 percent more than private tech companies for the same role, but often require security clearances.
- Salary growth accelerates after your first three years; jumping from one company to another usually increases pay faster than staying in one role.
The most common entry-level role: security operations center analyst
If you're starting from scratch — no IT background, no certifications — the security operations center (SOC) analyst job is the standard entry point. You monitor networks and systems for suspicious activity, respond to alerts, and escalate serious incidents to senior staff. It's the job that teaches you how attacks actually happen, which is why it's valuable even though the pay is lower than specialized roles.
A SOC analyst in their first year typically earns $55,000 to $70,000. After two or three years in the role, that grows to $70,000 to $85,000. The job requires you to be on call sometimes, work irregular hours, and handle a lot of false alarms — but it's the fastest way into the field if you don't have a computer science degree. Most employers want a CompTIA Security+ certification, which costs around $400 to test for and takes two to four months of study to prepare for.
Specialized roles that pay more: penetration testing and architecture
Once you have two to four years of SOC experience, you can move into more specialized work. A penetration tester (often called a "pen tester") simulates attacks on systems to find vulnerabilities before real attackers do. These roles pay $85,000 to $130,000 depending on experience and location. You need deeper technical skills and usually a certification like the Certified Ethical Hacker (CEH) or Offensive Security Certified Professional (OSCP).
Security architects design the systems and policies that protect entire networks. They earn $110,000 to $160,000 because they're responsible for preventing breaches across whole organizations. These roles typically require five to ten years of experience and certifications like the CISSP (Certified Information Systems Security Professional), which costs $749 to test for and requires documented work experience before you can sit for the exam.
The jump from SOC analyst to penetration tester or architect isn't automatic. You have to build skills in networking, system administration, and coding — often by taking on side projects or moving to a mid-level role like security engineer first. That intermediate step usually pays $75,000 to $95,000 and takes one to three years.
How location and employer type change what you earn
A SOC analyst in Austin, Texas might earn $68,000, while the same role in San Francisco pays $85,000 to $95,000. New York, Seattle, and Boston also command higher salaries. Rural areas and smaller cities pay 15 to 25 percent less for the same work. Cost of living explains some of this, but not all — tech companies in expensive cities straightforward have larger budgets for security staff.
Your employer type matters just as much. A bank or insurance company typically pays 10 to 20 percent more than a tech startup for the same role, because financial institutions have strict regulatory requirements and larger security budgets. Government agencies (federal, state, and local) also pay well, often matching or exceeding private sector salaries, but they usually require a security clearance, which takes months to obtain and limits where you can work afterward.
Consulting firms — companies that sell security services to other businesses — often pay less than in-house security teams but offer faster skill growth because you work on many different systems and problems. That experience can lead to higher-paying in-house roles later.
Certifications matter more than a degree in this field
Most cybersecurity jobs don't require a four-year degree. Employers care far more about certifications that prove you can do the work. CompTIA Security+ is the baseline — it costs $400 to test for and shows you understand networks, encryption, and threat response. Many employers will hire you without it if you have relevant experience, but having it speeds up the hiring process and can add $3,000 to $5,000 to your starting salary.
The next tier of certifications — CEH, OSCP, or CISSP — cost more ($500 to $750 per exam) and take longer to prepare for, but they unlock higher-paying roles. CISSP is the most expensive and prestigious; it requires you to have worked in security for at least five years before you can even sit for the exam, but it's often a requirement for senior roles and can add $15,000 to $30,000 to your annual salary.
If you do have a four-year degree in computer science, information technology, or cybersecurity, it can help you skip the SOC analyst role and start as a junior security engineer ($70,000 to $85,000), but it's not required. Many people enter the field through bootcamps, online courses, or self-study, then get hired based on certifications and demonstrated skills.
How salary grows as you move up
Your first three years in cybersecurity are the steepest learning curve. A SOC analyst might earn $60,000 in year one, $70,000 in year two, and $80,000 in year three. After that, growth slows unless you change roles or companies. Staying in the same job at the same company typically means 2 to 4 percent annual raises, which barely keeps pace with inflation.
The faster path is to move to a new company every three to four years. Switching from a SOC analyst role to a security engineer role at a different company might jump your salary from $80,000 to $95,000 or $100,000. Switching again from security engineer to senior engineer or architect can add another $20,000 to $40,000. This is how people reach $130,000 to $165,000 salaries — not by staying in one place, but by building skills and moving strategically.
Remote work and contract positions change the pay structure
Remote cybersecurity jobs exist but are less common than in-office roles, especially for entry-level positions. When companies do hire remote security staff, they often pay the same as local roles but sometimes adjust for location — a remote SOC analyst hired by a San Francisco company but living in Ohio might earn $75,000 instead of $90,000. Some companies pay the same regardless of location, so remote work can be a way to earn big-city salaries from a lower cost-of-living area.
Contract and freelance security work — penetration testing, security audits, incident response — can pay higher hourly rates ($75 to $200 per hour depending on specialization) but comes without benefits, job security, or steady income. Most people do contract work after building a reputation in full-time roles, not as an entry point.
Frequently Asked Questions
Do I need a college degree to get a cybersecurity job?
No. Most employers care about certifications and demonstrated skills more than a degree. CompTIA Security+ is the standard entry requirement, and you can prepare for it through online courses or bootcamps in two to four months. A degree can help you skip the entry-level SOC analyst role and start higher, but it's not required to enter the field.
What's the fastest way to reach $100,000 in cybersecurity?
Get CompTIA Security+ certified, work as a SOC analyst for two to three years, then move to a security engineer or specialized role at a new company. This path typically takes five to seven years. Alternatively, if you already have IT or networking experience, you can skip the SOC role and start as a junior security engineer, cutting one to two years off the timeline.
Do government cybersecurity jobs pay more than private sector jobs?
Government jobs often match or slightly exceed private sector pay for the same role, but they require a security clearance, which takes months to obtain. The real difference is stability — government jobs rarely lay off staff, while tech companies do. The tradeoff is less flexibility and slower salary growth.
What certifications should I get first?
Start with CompTIA Security+ if you have no IT background. If you already work in IT or networking, you can skip it and go straight to CEH or OSCP for penetration testing roles, or CISSP if you're aiming for architecture. Each certification costs $400 to $750 and takes two to six months to prepare for.
Can I earn more as a freelance penetration tester than as a full-time employee?
Freelance pen testers can charge $75 to $200 per hour, which sounds higher than a $100,000 salary, but you only bill for hours worked, have no benefits, and spend time finding clients. Most people do freelance work after building a reputation in full-time roles, not as a starting point.