Cybersecurity Salaries by Role and Certification
⚡ Quick Answer
Cybersecurity salary ranges compared by role tier and certification — Security+, CEH, and OSCP — from SOC analyst through security architect.
Get more content like this on Telegram!
Daily AI tips, notes & resources — free
Advertisement
Cybersecurity Salaries by Role and Certification
Cybersecurity salary ranges from roughly $55,000-$85,000 for entry-level SOC and GRC roles up to $130,000-$190,000+ for senior security architects and principal engineers in the US, with certification value (Security+, CEH, OSCP) depending heavily on which specialty track you're actually pursuing.
Updated for 2026. Salary figures are indicative ranges and move quarterly — always cross-check against a current source before negotiating.
The Question Behind the Question
Nobody asking "what does cybersecurity pay" actually means one number, because cybersecurity is a cluster of genuinely different jobs sharing one loose title — SOC analyst, GRC analyst, IAM engineer, cloud security engineer, application security engineer, penetration tester — with meaningfully different pay bands, skill requirements, and certification value at each tier.
This article compares salary by role tier and lines up the three certifications most beginners ask about — CompTIA Security+, Certified Ethical Hacker (CEH), and OSCP — against what they actually do for pay, since the honest answer is "it depends on the specialty" far more than any single number.
Cybersecurity Salary by Role Tier (US, Indicative)
| Tier | Example titles | Typical range (USD, base) |
|---|---|---|
| Entry | SOC Analyst Tier 1, Junior GRC Analyst | $55,000 – $85,000 |
| Mid (2–5 yrs) | Security Analyst, SOC Analyst Tier 2/3, IAM Engineer | $85,000 – $130,000 |
| Senior (5–9 yrs) | Senior Security Engineer, Security Architect, Senior Penetration Tester | $125,000 – $175,000 |
| Staff / Principal | Principal Security Engineer, Red Team Lead | $170,000 – $220,000+ |
| Management | Security Manager, Director of Security | $160,000 – $250,000+ |
Roles requiring an active US government security clearance often carry a premium of roughly ten to twenty-five percent over equivalent figures without a clearance requirement, reflecting the smaller eligible candidate pool. These figures are drawn from data patterns reflected in Levels.fyi, Glassdoor and Indeed aggregates, and US Bureau of Labor Statistics occupational data for information security analysts, and they move quarterly.
Security+ vs CEH vs OSCP, Compared
| Certification | Provider | Difficulty | Best for | Salary impact |
|---|---|---|---|---|
| Security+ | CompTIA | Entry-level, no exploitation required | Any entry-level security role, general baseline | Opens doors to entry roles; limited standalone salary lift beyond that |
| CEH (Certified Ethical Hacker) | EC-Council | Moderate, mostly knowledge-based | Resume keyword for offensive-security-adjacent roles | Recognized by name, weighted less by practitioners than by automated resume filters |
| OSCP | OffSec | Difficult, fully hands-on exam | Penetration testing / red team specialty specifically | Meaningful pay signal within offensive security; limited relevance outside that track |
The practical read: Security+ is close to a universal entry requirement across the field and worth getting regardless of specialty. CEH functions mostly as a keyword that gets you past an applicant tracking system rather than a skill-proving credential practitioners weight heavily in interviews. OSCP is a genuine, difficult, respected proof of offensive capability, but it is specialty-specific — it does little for a GRC or IAM career track and shouldn't be treated as a general cybersecurity salary lever.
Role Tier Combined With Certification: A Realistic Path
| Career stage | Typical certification held | Typical role | Typical salary range |
|---|---|---|---|
| Entering the field | Security+ in progress or freshly earned | SOC Analyst Tier 1 | $55,000 – $80,000 |
| 1–3 years in | Security+ held, CySA+ or cloud cert in progress | SOC Analyst Tier 2, Junior Security Engineer | $75,000 – $110,000 |
| Offensive track, 2–4 years in | OSCP in progress or freshly earned | Junior Penetration Tester | $80,000 – $120,000 |
| Offensive track, 4+ years in | OSCP held, possibly OSCE/OSWE | Senior Penetration Tester, Red Team | $120,000 – $175,000+ |
| Cloud/architecture track, 5+ years in | AWS/Azure security specialty certs | Security Architect | $135,000 – $190,000+ |
This table illustrates a plausible progression, not a guarantee — actual timelines and pay depend heavily on company, region, and individual performance.
Why Source Figures Vary So Much
Ask Levels.fyi, the Stack Overflow Developer Survey, Glassdoor, and the Bureau of Labor Statistics the same question about cybersecurity pay and you'll get meaningfully different numbers, and this reflects real methodological differences, not sloppy data.
Levels.fyi relies on self-reported offers concentrated at large, often well-known tech companies, which skews figures upward relative to the broader market that includes smaller companies, government contractors, and traditional industries hiring security staff. The Stack Overflow Developer Survey captures a large, global, self-selected group of practitioners — useful for directional trends across specialties but not a precise, regionally-specific figure. Glassdoor and Indeed aggregates blend self-reported salaries with job-posting data, and posted ranges sometimes reflect base salary only, undercounting total compensation that might include a security clearance premium or shift differential. The US Bureau of Labor Statistics is the most rigorous source for the broad "information security analyst" occupational category, but its category groups together roles with genuinely different pay bands — a BLS median blends SOC analysts with security architects in ways a specific job-title search would not.
Always cross-reference at least two source types, and weight heavily by your specific region, industry, and whether a clearance is involved, before treating any figure as reliable for a real negotiation.
What These Numbers Do Not Include
Bonuses. Some cybersecurity roles, particularly at larger companies or in consulting, include annual bonus structures on top of base salary that are not reflected in the ranges above.
Equity. Security roles at venture-backed or public tech companies sometimes include equity compensation; this varies enormously and is not part of the base-salary figures here.
Benefits value. Health insurance, retirement matching, and paid time off differ significantly between employers and are not captured in a base salary comparison.
Cost of living. A $95,000 salary in a lower cost-of-living region can represent more real purchasing power than a $120,000 salary in an expensive metro area — never compare raw figures across cities without adjusting.
Taxes. All ranges above are gross, pre-tax figures; actual take-home pay varies by state and local tax structure.
Clearance and industry variance. The clearance premium cited above is a rough, commonly discussed range, not a guaranteed figure — defense contractors, government agencies, and private industry price clearance requirements differently, and this should be checked against current defense-sector-specific data.
How Specialty Choice Interacts With Pay Growth
Picking a specialty early feels like a pay decision, but the honest picture is that specialty matters less to lifetime earnings than depth within whichever specialty you choose, at least past the first few years.
Security operations (SOC) work starts among the more accessible entry points but has a real ceiling for generalist Tier 1 analysts who never move beyond alert triage — the meaningful pay growth in this track comes from moving into detection engineering, threat hunting, or incident response leadership, not from simply accumulating years in a Tier 1 seat.
Governance, risk, and compliance (GRC) work is often underestimated on pay potential because it's seen as less technical, but senior GRC professionals who can credibly bridge security and business risk — particularly those who understand frameworks like ISO 27001 or SOC 2 deeply enough to lead an audit rather than just support one — command salaries comparable to technical senior engineers at many companies, especially in regulated industries like finance and healthcare.
Offensive security (penetration testing, red team) has real ceiling potential at the senior end, reflected in the higher end of the ranges in this article's tables, but the entry funnel is narrower and more competitive than other tracks, and the path in almost always runs through a SOC or sysadmin role first rather than directly, which extends realistic time-to-specialty considerably.
Cloud security engineering has grown into one of the higher-paying tracks specifically because it sits at the intersection of two in-demand skill sets — cloud infrastructure and security — and professionals who came from a cloud/DevOps background moving into security, or vice versa, often command a premium over specialists who only have one half of that combination.
The practical takeaway: don't choose a specialty purely by the headline salary range in a table like the ones above. Choose based on genuine interest in the daily work, since depth and longevity within a track drives pay growth more reliably than the specialty label itself, and burning out on work you don't enjoy caps your growth more than any specialty choice would.
Regional and Industry Variance Worth Knowing
The US national ranges in this article compress considerable regional variance that matters in practice. Major tech hub metros and the Washington D.C. area — the latter heavily influenced by government and defense contracting demand — tend to sit toward the higher end of these ranges, sometimes meaningfully above them for clearance-holding roles specifically. Smaller metros and non-tech-heavy regions tend to sit toward the lower end, though remote work has narrowed this gap somewhat for companies willing to hire nationally at a single pay band.
Industry also shifts these numbers independent of role or region. Financial services and healthcare, both heavily regulated, tend to invest more heavily in GRC and compliance-adjacent security roles specifically, sometimes paying a premium for candidates with industry-specific regulatory knowledge layered on top of general security skill. Government contracting, as discussed, layers a clearance premium on top of otherwise-comparable private-sector figures. Smaller companies and startups, meanwhile, sometimes pay below the ranges in this article for security roles specifically, since security is often one of the later functions built out as a company matures, and early security hires at small companies may be asked to cover a broader, less specialized scope for a correspondingly broader — but not necessarily higher — pay band.
Building a Salary Negotiation Case in Security Roles
Turning the ranges in this article into an actual negotiation requires more than citing a number, since a hiring manager who has seen candidates quote Levels.fyi figures out of context will discount a bare number cited without support far more than one backed by a specific, well-reasoned case.
A stronger negotiation approach starts with triangulating at least two source types — for instance, a BLS occupational figure for information security analysts in your metro area alongside a Levels.fyi or Glassdoor range for the specific title you're being offered — rather than anchoring to a single source's number, since this shows you understand the data landscape rather than having simply screenshotted one favorable figure.
It continues with being specific about what you bring beyond the baseline for the role tier, since two candidates for the same "Security Engineer" title with genuinely different depth — one with a documented incident-response portfolio and relevant certifications, another fresh out of a bootcamp with a certification alone — have real grounds for a different offer, and articulating that difference explicitly, rather than assuming the title alone determines pay, is where real negotiating leverage comes from.
It's also worth directly asking what's included beyond base salary — bonus structure, on-call compensation if applicable, security clearance processing time and any associated retention bonus, and professional development or certification reimbursement budget — since these vary enormously by employer in this field specifically and are easy to overlook when focused only on the base salary figure a table like this one provides.
Finally, timing matters: security hiring, like most tech hiring, has some cyclicality tied to broader company budget cycles and, in the public and defense sector specifically, government fiscal year budget timing, and being aware of these patterns for your specific target sector can meaningfully affect how much negotiating room actually exists at a given moment, independent of your own qualifications.
Certifications Beyond the Big Three
Security+, CEH, and OSCP dominate beginner discussions, but several other certifications matter meaningfully once you're past the entry level and worth knowing about even in an article centered on the big three.
CySA+ (CompTIA Cybersecurity Analyst) sits between Security+ and more advanced SOC-focused credentials, and is commonly cited as a reasonable next step for SOC analysts looking to formalize detection and analysis skill without jumping straight to a fully offensive-security-focused credential like OSCP.
Cloud-specific security certifications — AWS Certified Security – Specialty and comparable Azure and Google Cloud security credentials — have grown in relevance as cloud security engineering has become one of the higher-paying specialty tracks discussed above, and are increasingly weighted by employers hiring specifically for cloud security roles, sometimes more heavily than a generalist credential like CEH.
CISSP (Certified Information Systems Security Professional) is generally a mid-to-senior-career credential rather than an entry one, since it has a work-experience prerequisite, and it tends to matter more for security management and architecture roles than for hands-on technical tracks, functioning partly as a signal of broad security management knowledge rather than deep technical specialty skill.
None of these substitute for the practical, hands-on skill this article and its companion roadmap emphasize throughout — they're best treated as supporting evidence alongside a real portfolio and demonstrated experience, not a replacement for either.
Government, Defense, and Clearance-Adjacent Pay Dynamics
The clearance premium mentioned earlier deserves more texture, since "ten to twenty-five percent" understates how differently this segment of the market behaves compared to purely private-sector security hiring.
Clearance level itself matters — a Secret clearance is far more common and carries a smaller premium than a Top Secret or Top Secret/SCI clearance, since the pool of eligible, cleared candidates shrinks considerably at higher clearance tiers, and employers needing to fill roles requiring the highest clearance levels sometimes struggle enough with candidate scarcity that the effective premium moves well above the general range cited earlier for a specific hard-to-fill role.
Whether you're employed directly by a government agency versus a defense contractor also changes the picture, not just the premium size. Direct government employment often comes with a different total compensation structure entirely — sometimes a lower base salary than an equivalent contractor role but a strong, defined-benefit-adjacent retirement structure and job stability that a contractor role doesn't carry, which makes a pure base-salary comparison between the two even less complete than usual without pricing in those structural differences explicitly.
Contract-to-hire and contractor "body shop" arrangements are also common in this specific niche, where a candidate's cleared status is the primary asset, and rates can be quoted per-hour, per-contract, or as a full-time contractor salary depending on the specific arrangement, making this one of the more genuinely confusing corners of cybersecurity compensation to research without a strong understanding of exactly what arrangement you're being quoted for.
What to Actually Do With This Data Before an Interview
Concretely, before walking into a compensation conversation for any specific security role, it's worth doing three things this article's data alone can't do for you.
Search the specific job title plus your specific metro area across at least two of the source types discussed — a Levels.fyi or Glassdoor search alongside a BLS regional occupational wage lookup — rather than relying on this article's national figures alone, since regional variance can be substantial, as discussed above.
Ask the recruiter directly, early, what the budgeted range for the role actually is, rather than only disclosing your own expectation first. Many recruiters will share a range if asked directly, and this is often more accurate for that specific opening than any aggregate public data source, since it reflects the actual budget rather than a market average.
Weigh the full package, not just base salary, using the "what these numbers do not include" section above as a checklist — bonus structure, clearance-related pay, benefits value, and cost of living all meaningfully affect what a given base salary figure actually represents in real terms for your specific situation.
The Four Mistakes
1. Chasing OSCP or CEH before Security+ and real fundamentals. Advanced certifications assume foundations most beginners skip, and pursuing them out of order rarely translates into the pay bump beginners expect.
2. Assuming a certification alone drives salary independent of specialty. OSCP means little to a GRC hiring manager, and a cloud security certification means little to a pure penetration testing role. Match the certification to the specific track you're pursuing.
3. Comparing your offer to a single source's number. Levels.fyi, BLS, and Glassdoor figures diverge meaningfully for the same title — cross-check at least two before treating any number as a negotiating anchor.
4. Ignoring the clearance premium when it applies, or assuming it always applies when it doesn't. Clearance-driven pay premiums are real but specific to certain government and defense-adjacent roles — don't assume it's baked into a private-sector offer, and don't ignore it if you do hold a clearance.
🔗 Read next: the Cybersecurity Career Roadmap for the full entry-path breakdown, or see the full picture at the pillar — Tech Salaries Ranked.
Advertisement
💬 DiscussionPowered by GitHub Discussions
Frequently Asked Questions

AI & Software Engineering Editorial Team
The AiTechWorlds editorial team writes and reviews in-depth guides on artificial intelligence, machine learning, prompt engineering, programming, and developer tools. Every article is fact-checked against primary sources and kept up to date for working developers and CS students.
Not sure yet? Ask AI about this article
Get an instant, unbiased AI summary of “Cybersecurity Salaries by Role and Certification”.
Advertisement
Related Articles
AI Engineer vs Data Scientist: Salary and Role Comparison
AI engineer vs data scientist salary compared by level, with role differences, sources, and honest ranges you can actually use for 2026.
Career Moves That Raised Pay the Most (And the Ones That Didn't)
How to increase your tech salary: a ranked, honest look at which career moves raise pay the most, and which carry real hidden tradeoffs.
Cloud and DevOps Salaries: AWS vs Azure vs GCP
Cloud engineer salary data compared across AWS, Azure, and GCP roles, with honest ranges, source types, and the mistakes that cost people real money.
Contractor vs Full-Time: The Real Take-Home Comparison
Contractor vs full time salary compared with the real math: benefits, self-employment tax, and PTO factored in, not just the headline hourly rate.