The median cybersecurity analyst salary in the United States is $129,180 per year (Source: BLS OEWS May 2025, SOC 15-1212). Top earners make $199,850+ (90th percentile). Senior cloud security architects and incident response leads at major employers clear $180,000 to $250,000. The field has been growing 28% to 33% per year through 2034 per BLS Employment Projections, double or triple the average for all occupations.
Federal cyber hiring has expanded under the National Cyber Strategy, and private-sector breach notification laws (now in all 50 states) have created sustained demand for senior incident-response talent. The market remains tight, with compensation rising well above the broader IT category.
Data last verified September 2026 from BLS Occupational Employment and Wage Statistics (OEWS), May 2025 release, for Information Security Analysts (SOC 15-1212).
At a glance
- National median cybersecurity analyst wage is $129,180 (BLS OEWS, May 2025).
- Washington leads at $154,940; Maryland $139,640; California $138,570.
- San Jose-Sunnyvale-Santa Clara pays the highest metro median at $176,120.
- 4% to 8% annual wage growth forecast through 2027.
Top 10 highest-paying states for cybersecurity analysts
The highest-paying markets cluster around defence contractors, federal agencies, financial-services firms, and technology employers. Washington state tops the list because of Seattle-area tech demand and government contractors in the region.
| Rank | State | Median analyst wage (USD) |
|---|---|---|
| 1 | Washington | $154,940 |
| 2 | Maryland | $139,640 |
| 3 | California | $138,570 |
| 4 | Delaware | $137,030 |
| 5 | Massachusetts | $136,550 |
| 6 | Colorado | $135,220 |
| 7 | District of Columbia | $135,090 |
| 8 | Virginia | $134,900 |
| 9 | New Jersey | $134,820 |
| 10 | New York | $134,660 |
Top-paying metros
Tech hubs combine the largest talent pools with the highest-paying employers. Defense-and-government metros offer slightly lower cash compensation but substantially better benefits and pension structures.
| Metro area | Median wage (USD) | Notes |
|---|---|---|
| San Jose-Sunnyvale-Santa Clara, CA | $176,120 | Highest median, dense tech cluster |
| San Francisco-Oakland-Fremont, CA | $162,310 | Tech and SaaS |
| Seattle-Tacoma-Bellevue, WA | $161,780 | Tech + government contractors |
Industry premiums and certifications
Banking and financial services pay the highest premiums (10% to 20% above the median). Federal government and defence contractors (Booz Allen Hamilton, Leidos, CACI, SAIC) absorb roughly a third of senior talent at competitive rates plus benefits and clearances. Big Four consulting firms (Deloitte Cyber, PwC, EY, KPMG) hire hundreds of cybersecurity specialists per year. Tech (Microsoft, Google, Amazon) pays premium total compensation including equity that can clear $300,000 to $500,000 at senior levels.
Certification premium impact on pay
CompTIA Security+ clears entry roles at most employers and is achievable within 1 to 2 years of study. CISSP requires 5 years of relevant work experience and is the dominant mid-career gate. AWS Security Specialty and Azure Security Engineer certifications carry premium weight at cloud-first employers. CREST CRT and CCT certifications are required for penetration testing and incident response roles at MSSPs. OSCP carries premium rates for offensive security roles. Most senior roles require a combination of CISSP plus one or two specialisations.
Frequently asked questions
(See FAQs above for the questions and answers.)
Methodology
Salary figures drawn from BLS Occupational Employment and Wage Statistics (OEWS), May 2025 release, for Information Security Analysts (SOC 15-1212). State and metro medians reflect published BLS estimates. Annual figures assume full-time work hours (2,080 hours/year). Total compensation estimates include employer retirement contributions and exclude equity grants at public-listed employers.
Compensation data reflects full-time wage-and-salary employment. Verify current postings on employer career sites.
Cybersecurity analyst career trajectories typically follow three tracks: technical depth (cybersecurity engineer, penetration tester, malware analyst), leadership (cybersecurity manager, CISO over time), and adjacent commercial (cybersecurity sales engineer, product marketing, advisory consulting). The technical depth track typically passes through 6 to 10 years of specialist experience before opening up to senior management. CISO roles at the largest enterprises require 15 to 20 years of experience plus industry visibility through conference speaking, published research, or recognised thought leadership.
The US cybersecurity talent pool is supported by federal programmes like the NICE Framework (National Initiative for Cybersecurity Education), CISA's workforce development programmes, and Department of Defense SkillBridge transition programmes. Most senior practitioners enter the field via IT support, systems administration, or software engineering roles and transition into cybersecurity over 2 to 5 years. The CompTIA Security+ certification represents the typical entry gate.
Specific high-demand sub-specialties include cloud security architects (AWS, Azure, GCP), application security engineers, OT/ICS (operational technology / industrial control systems) cybersecurity for critical infrastructure, and AI/ML security specialists. Each sub-specialty carries a premium of 15% to 25% above general cybersecurity roles.
Cybersecurity certification paths worth considering include: CompTIA Security+ (entry), CompTIA CySA+ (intermediate), (ISC)2 CISSP (mid-career gate), (ISC)2 CCSP (cloud security), ISACA CISM (management), CREST CRT/CCT (offensive security), and the AWS, Azure, or GCP security specialty certifications for cloud roles. Many employers fund certification and continuing professional development.
Major US employers of cybersecurity analysts in 2026 include the federal government and defence primes (Booz Allen Hamilton, Leidos, CACI, SAIC, ManTech, Parsons, Northrop Grumman, Lockheed Martin, General Dynamics, Raytheon, Booz Allen Cyber, GDIT, MAXAR), financial-services firms (JPMorgan Chase, Bank of America, Wells Fargo, Citi, Capital One, American Express, US Bank, PNC, Capital One, Discover, MasterCard, Visa), tech giants (Microsoft, Google, Amazon, Meta, Apple, IBM, Oracle, Salesforce, ServiceNow), and consulting firms (Deloitte, PwC, EY, KPMG, Accenture, Booz Allen Cyber, Capgemini, Cognizant, Slalom). Federal cybersecurity hiring expanded under the National Cyber Strategy and the Cybersecurity and Infrastructure Security Agency (CISA) workforce development programmes.
For candidates entering the field, typical preparation includes a bachelor's degree in computer science, cybersecurity, or information systems, plus one or more entry-level certifications (CompTIA Security+, CompTIA CySA+, AWS Cloud Practitioner plus AWS Security Specialty, Microsoft SC-900). Many practitioners enter the field through IT support, network administration, or software development roles before specialising in cybersecurity over 2 to 5 years.






