Cybersecurity Salary Guide

Cybersecurity salaries range from $40,000 to over $300,000 annually, with top experts earning up to $600,000. This guide breaks down what people in cybersecurity roles actually earn across levels, regions, and company types, based on 2024 survey data and our own executive search work.

Overview of Cybersecurity Salaries in 2024

The U.S. still has roughly 265,000 unfilled cybersecurity positions according to NIST's 2024 workforce data. That shortage, combined with rising breach costs and expanding compliance mandates, keeps pay elevated across the field. Cybersecurity salaries have trended upward over the past decade; the median annual wage for information security analysts was $99,730 in 2019, and ISC²'s 2024 study now puts the national average salary for cybersecurity at about $107,000 per year, with a median across all levels at $147,138.

Chief Information Security Officers can earn between $200,000 and $600,000 in total compensation, and at large technology firms that number often crosses $800,000 or more when equity is included. The IANS & Artico 2024 CISO Compensation Survey of 755 CISOs reported an average total compensation of $565,000 and a median of $403,000.

At Christian & Timbers, our perspective on these numbers comes from ongoing cybersecurity executive search work with technology and cybersecurity clients, particularly in hubs like San Jose, Austin, and Washington, D.C. Here is a quick view of where the market sits for core roles:

  • Information Security Analyst: $80,000 to $150,000 total comp (entry through experienced)
  • Security Engineer: $110,000 to $220,000+ total comp (mid through senior)
  • Security Architect: $190,000 to $320,000+ total comp (enterprise and cloud)
  • CISO / VP Security: $400,000 to $1,000,000+ total comp (base, bonus, equity combined)
The image depicts a professional working in a modern security operations center in San Jose, surrounded by multiple monitors that display various network data crucial for cybersecurity roles. The setting emphasizes the importance of technology and collaboration among colleagues in maintaining security compliance and addressing potential threats.

Key Factors That Drive Cybersecurity Pay

No single number captures what a cybersecurity job pays. The salary for any position depends on role level, geography, company type, and the candidate's own profile. A cybersecurity professional's salary often increases with experience and specialization, sometimes by multiples rather than increments.

  • Role seniority: Each step up from analyst to engineer to architect to director can add 30–70% to the compensation band. An entry-level SOC analyst at $85,000 and a director of security at $230,000 work in the same field but occupy different markets.
  • Geography: High-cost tech hubs like San Jose, New York, Seattle, and Boston pay 20–50% more than smaller metros for equivalent roles. Geographic location influences cybersecurity salaries across every level.
  • Company stage and sector: Venture-backed technology firms, cybersecurity vendors, AI startups, and aerospace and defense companies pay premiums, especially for candidates with security clearances or niche skills. High-paying sectors for cybersecurity professionals also include finance, healthcare, and government.
  • Skill specialization: Deep expertise in cloud security (AWS, GCP, Azure), incident response, application security, DevSecOps, OT/ICS, or AI security pushes salaries to the top of their range.
  • Credentials and track record: Recognized certifications can lead to noticeable salary increases in cybersecurity roles. CISSP, OSCP, CCSP, and a history of leading programs or reducing risk at scale often justify higher offers. The IANS survey found top-quartile CISOs had over eight years of tenure and multi-company leadership experience.

Typical Salary Ranges by Cybersecurity Role

These ranges are approximate U.S. 2024 figures based on data from Stott & May, CyberSN, ESP IT, and ISC². Christian & Timbers focuses on the upper mid to executive end of these bands when advising hiring companies and candidates.

  • Security / Information Security Analyst: Entry-level cybersecurity roles typically start between $55,000 and $85,000. Experienced analysts with 5+ years earn $110,000 to $145,000+. The lowest 10 percent of cybersecurity salaries earned less than $57,810; the highest 10 percent earned more than $158,860.
  • SOC Analyst / Junior Incident Responder: $80,000 to $115,000 base, often supplemented by shift differentials and on-call pay.
  • Security Engineer: Mid-level cybersecurity professionals earn between $107,000 to $148,000. Senior and specialized engineers (cloud, IAM, threat hunting) reach $180,000 to $220,000+ total comp.
  • Application Security Engineer: Around $185,000 median for roles combining offensive security and development work.
  • Cloud Security Engineer: Median base near $190,000; high end over $240,000 at large technology firms.
  • Security Architect (Enterprise / Cloud / Product): Low end around $190,000; median $220,000 to $260,000; high end $300,000 to $350,000 for chief architects at major companies.
  • Security Manager / Director: Base salaries from $170,000 to $230,000; total comp in technology firms reaches $250,000 to $400,000+ with bonus and equity. Senior cybersecurity positions command salaries from $130,000 to over $260,000 at this tier.
  • CISO / VP Security / Head of Security: Average total comp around $565,000; top 10% exceed $1,000,000. Heidrick & Struggles' 2024 survey found U.S. CISOs averaged $468,000 cash base, $304,000 bonus, and $1,057,000 in equity or long-term incentives. For more on this, read our breakdown of cybersecurity executive pay.
  • Adjacent roles (Product Security Leader, Head of GRC, Security Sales Engineering): These carry different comp mixes. Sales engineering roles at cybersecurity vendors add commission; GRC leaders in regulated industries often see base-heavy packages with compliance-tied bonuses.

Regional Variations: Cybersecurity Pay in San Jose and Other Hubs

Where you land a cybersecurity role matters as much as what you do. Geography shifts salary expectations by tens of thousands of dollars, particularly in California and other tech-heavy states.

  • San Jose / Silicon Valley: One of the top-paying markets in the world for security talent. Senior security engineers and architects see $200,000 to $350,000+ total comp. CISOs at large tech firms in this region can exceed $700,000 to $1,200,000+ with equity. Public data from Levels.fyi shows a Google Security Architect at staff level (L6) earning roughly $594,000 total comp, with $263,000 base, $296,000 in stock, and $34,000 bonus.
  • San Francisco, Seattle, New York, Boston: Total compensation is often comparable to San Jose, but the cost of living and cash-versus-equity mix differ. New York financial services firms lean heavier on cash bonus; Seattle tech companies lean into RSUs.
  • Austin, Raleigh-Durham, Denver: Strong hiring demand with base salaries 10–25% below coastal hubs. Net purchasing power can be comparable or better. Indianapolis saw cybersecurity wage growth of 17.2% year-over-year in 2024 according to CyberSN's job index, though absolute pay remained below coastal levels.
  • Remote roles: Some employers pay based on HQ location; others adjust to the employee's site. A remote security engineer in Ohio may earn 10–25% less than a colleague with the same title in San Jose.
An aerial view of a modern technology campus in Silicon Valley showcases sleek buildings surrounded by a suburban landscape, reflecting the dynamic environment where cybersecurity roles and tech companies thrive in San Jose, California. This vibrant site is a hub for innovation, attracting candidates seeking to understand the evolving job market and salary ranges in the cybersecurity field.

Understanding Total Compensation in Cybersecurity Roles

Base salary alone does not tell the full picture. Total compensation for a cybersecurity position includes several components, and the mix changes as you move up.

  • Base salary: Fixed cash before taxes. For most cybersecurity roles, this is the largest single component.
  • Annual bonus: Typically 5–15% of base for non-executives; 20–50%+ for directors, VPs, and CISOs. Some firms use profit sharing instead.
  • Equity (RSUs / stock options): In public tech companies and late-stage startups, equity can account for 20–40% of total comp at mid and senior levels. For CISOs, equity or long-term incentives averaged $1,057,000 in Heidrick & Struggles' 2024 data.
  • Sign-on bonus: Common when a candidate is leaving unvested equity at a current employer.
  • Benefits: 401(k) match, health coverage, training budgets, and conference attendance add real value that does not appear in salary number comparisons.

A concrete example: a "$220,000 security engineer role" in San Jose might break down as $170,000 base + 10% bonus ($17,000) + $30,000 to $60,000 in equity per year. That matters when you compare it to a "$200,000 base" offer elsewhere with no equity and a 5% bonus.

How to Research and Benchmark Cybersecurity Salaries

Online salary data can be noisy. Job sites often mix contractor rates with full-time pay, or blend outdated numbers with current ones. Triangulating multiple sources gives you a more accurate view.

  • Bureau of Labor Statistics (BLS): Start here for baseline medians and percentiles by region and role. The BLS Information Security Analyst category provides a reliable floor.
  • Levels.fyi and Blind: Best for technology company compensation with verified, recent data points broken down by level, base, stock, and bonus.
  • Glassdoor, LinkedIn Salary, Payscale: Useful for broader market snapshots. Remove clear outliers and filter by year, region, and company size.
  • Colleagues and mentors: Talk to people in the specific cybersecurity role and region you are studying. A senior security engineer in San Jose and one in Chicago operate in different markets, and no algorithm captures that difference as well as a direct conversation.
  • Public pay data: Government security roles and public university IT security positions post salary bands openly, providing a concrete check on GRC or SOC position ranges.
  • Executive search firms: For C-suite and board-level cybersecurity roles, firms like Christian & Timbers provide confidential comp benchmarking across comparable companies. Our CISO executive search practice gives hiring organizations and candidates data that public sites do not capture.

Negotiating Your Cybersecurity Offer

Strong demand for cybersecurity talent gives candidates room to negotiate, particularly at mid-level and senior positions. The IANS 2024 report found that CISOs who changed employers gained 20–30%+ in total comp, while those who stayed saw average merit increases of only 5.6% on base.

  • Prepare a data-backed range: Use the research steps above to build a target for your specific role, region, and level. A security architect in San Jose has a different market than one who is remote in the Midwest.
  • Frame around business value: Cite incidents mitigated, compliance milestones achieved, or security products shipped. "I reduced mean-time-to-detect by 40% and led the SOC through two major incidents with zero data loss" is a stronger point than "the market pays more."
  • Negotiate beyond base: Sign-on bonuses, performance bonus targets, equity refresh cadence, title level (Senior vs. Staff), and support for certs and conferences are all on the table.
  • Executives should focus on long-term incentives: If you are interviewing for a CISO or VP Security role, prioritize equity terms, severance, and reporting line (to CEO vs. CIO). An experienced executive recruiter or legal counsel can add value in this process. For context on why cybersecurity talent searches are complex, read our recent analysis.

Choosing the Right Cybersecurity Job: Beyond Salary

A person entering or advancing in cybersecurity should remember that compensation is one input in a larger equation. Job satisfaction often outweighs salary in career decisions, and learning opportunities can be more valuable than higher pay over a five- or ten-year journey.

  • Leadership quality: Does the CISO have board support? Is security created as a strategic function or treated as a cost center? These things matter for your day-to-day work and career trajectory.
  • Learning environment: Training budgets, rotation across cybersecurity roles, and access to good colleagues accelerate skill growth. Smaller companies may offer better learning environments because you play multiple roles and see more of the problem space.
  • Company culture: Culture impacts job happiness; accept that a $15,000 salary bump at a company with high turnover and poor community among the security team is a bad trade.
  • Work-life balance: On-call expectations, incident frequency, and burnout risk are worth investigating before you send an accept. Work-life balance is crucial for long-term career satisfaction in a field where 2 a.m. pages are a real cost.
  • Mission and impact: Securing AI platforms, aerospace and defense systems, or critical infrastructure can be more career-defining than a bit more pay at a less interesting company. Read how Acronis grew 188% and blocked 7.5M cyberattacks after hiring the right CISO for an example of what the right match produces.

Organizations seeking to build or upgrade their security leadership, and executives exploring next-step roles, can partner with Christian & Timbers to align compensation, role scope, and long-term trajectory.

Recent Articles