CybersecurityMarket report2026 data· USA· 2026-07-31

USA Cybersecurity Salary Report 2026

The short answer
In 2026 the median US cybersecurity salary is $141,440 across 8,093 analyzed job postings, with 44.2% disclosing pay. AI and ML security engineers lead roles at $171,700 and San Francisco tops cities at $218,000. Glozo measures a pool of 119,998 people, about 15 for every active opening. Postings clear in 9.5 days and AI security skills add 18.6%.
Supply / demand
15.3×
candidates per vacancy
Median salary
$141,440
all roles, disclosed
Vacancies
8,093
postings analyzed
Pay transparency
44.2%
show a range
Pay by roledirectional, no per-role n

Where the bands sit

Median pay by security specialization runs from $105,000 for cyber risk analysts to $171,700 for AI and machine-learning security engineers, a spread of about 64%. The ordering is not random. All four of the highest medians sit on the engineering and research side: AI and ML security at $171,700, security research and malware analysis at $162,700, application and product security at $161,100 and cryptography engineering at $160,000. Core security engineering follows at $153,000 and security architecture at $151,175. Cloud security ($145,145), DevSecOps ($144,500), identity and access management ($142,900) and penetration testing ($140,200) sit just above the overall median. The bottom of the table is where assessment and reporting work sits: GRC analysis at $120,900, vulnerability management at $118,700, security analysis at $112,120, threat intelligence at $110,000 and cyber risk analysis at $105,000. Roles that build and break systems pay more than roles that assess and document them, and the gap runs to about $67,000 at the extremes. The skill premiums further down reach the same conclusion from a different cut of the same postings. The feed carries no posting count per role, so treat the exact ordering as directional.

AI/ML Security Engineer
$171,700
Security Researcher / Malware Analyst
$162,700
Application Security (appsec) / Product Security Engineer
$161,100
Cryptography Engineer
$160,000
Security Engineer
$153,000
Security Architect
$151,175
Cloud Security Engineer
$145,145
Devsecops / Security Platform Engineer
$144,500
Identity & Access Management (iam) Engineer
$142,900
Red Team Operator
$142,500
Penetration Tester
$140,200
Incident Responder / Dfir
$139,000
Security Consultant
$137,500
Detection / Security Automation Engineer
$133,450
Soc / Security Operations Analyst
$130,000
Grc Analyst (governance, Risk, Compliance)
$120,900
Vulnerability Management Analyst / Engineer
$118,700
Security Analyst
$112,120
Information Security Analyst / Specialist
$110,120
Threat Intelligence Analyst
$110,000
Cyber Risk Analyst
$105,000
Median annual salary by role, disclosed postings
Data table
Median annual salary by role, disclosed postings
RoleMedian
AI/ML Security Engineer$171,700
Security Researcher / Malware Analyst$162,700
Application Security (appsec) / Product Security Engineer$161,100
Cryptography Engineer$160,000
Security Engineer$153,000
Security Architect$151,175
Cloud Security Engineer$145,145
Devsecops / Security Platform Engineer$144,500
Identity & Access Management (iam) Engineer$142,900
Red Team Operator$142,500
Penetration Tester$140,200
Incident Responder / Dfir$139,000
Security Consultant$137,500
Detection / Security Automation Engineer$133,450
Soc / Security Operations Analyst$130,000
Grc Analyst (governance, Risk, Compliance)$120,900
Vulnerability Management Analyst / Engineer$118,700
Security Analyst$112,120
Information Security Analyst / Specialist$110,120
Threat Intelligence Analyst$110,000
Cyber Risk Analyst$105,000
Pay by seniority

The seniority curve

Entry
$83,000
Specialist
$141,000
Expert
$194,000
Leader
$277,000
Median annual salary by seniority tier
Data table
Median annual salary by seniority tier
TierMedian
Entry$83,000
Specialist$141,000
Expert$194,000
Leader$277,000
Geographydirectional, no per-state n

Pay by state

California leads states at $159,000, only 3.2% ahead of Washington at $154,000. New York follows at $143,000, Illinois at $140,000, Colorado at $135,000, Texas at $133,000 and Georgia at $131,000, with Florida lowest at $121,000. That is a spread of about 31%, tighter than the spread across specializations. City medians tell a different story. San Francisco sits at $218,000, which is 27.5% above New York at $171,000 and 68% above Miami at $130,000. Boston is at $156,000, Seattle and Los Angeles both at $155,000, Austin at $152,000, Denver at $146,000, Chicago at $145,000 and Atlanta at $135,000. The $59,000 gap between San Francisco and California as a whole is the figure to keep in mind when reading any state-level pay table, including this one. State medians pool metro and non-metro postings in proportions that differ from one state to the next. Neither cut carries a posting count per item, so read both as directional.

California
$159,000
Washington
$154,000
New York
$143,000
Illinois
$140,000
Colorado
$135,000
Texas
$133,000
Georgia
$131,000
Florida
$121,000
Median annual salary by state, disclosed postings
Data table
Median annual salary by state, disclosed postings
StateMedian
California$159,000
Washington$154,000
New York$143,000
Illinois$140,000
Colorado$135,000
Texas$133,000
Georgia$131,000
Florida$121,000
San Francisco
$218,000
New York
$171,000
Boston
$156,000
Seattle
$155,000
Los Angeles
$155,000
Austin
$152,000
Denver
$146,000
Chicago
$145,000
Atlanta
$135,000
Miami
$130,000
Median annual salary by city, disclosed postings
Data table
Median annual salary by city, disclosed postings
CityMedian
San Francisco$218,000
New York$171,000
Boston$156,000
Seattle$155,000
Los Angeles$155,000
Austin$152,000
Denver$146,000
Chicago$145,000
Atlanta$135,000
Miami$130,000
Monthly posted pay

Month to month

Across the months with enough disclosed pay to report, the posted median moves from $159,140 in February to $135,000 in July, a shift of about 15%. Read that as a change in what was posted, not as a change in what security professionals are paid. Only 44.2% of postings disclose a range, so every monthly point rests on that disclosed slice, and the mix of roles posted moves from month to month. A month heavy in security operations postings shows a lower median than a month heavy in application security, with no underlying pay movement at all. We suppress January, where roughly 85 postings disclosed a range, below the floor we use before publishing a monthly point. May clears that floor at about 198 disclosed, but its volume of 448 postings sits far below the 1,711 in April and the 1,946 in June, and the same shape appears in every industry we have pulled this year. July, at 737 postings, is also thin next to June. Read the overall level rather than any single month.

Median posted salary by monthInline SVG line chart of 7 monthly median salaries. Hollow dashed points are suppressed for thin data.$155,000*$159,140$149,800$145,500$130,350$135,000$135,00001020304050607
Median posted salary by month. * = suppressed (too few disclosed salaries)
Data table
Median posted salary by month
MonthMedianPostingsStatus
2026-01 (Jan)$155,000192suppressed
2026-02 (Feb)$159,1401,028ok
2026-03 (Mar)$149,8001,803ok
2026-04 (Apr)$145,5001,711ok
2026-05 (May)$130,350448ok
2026-06 (Jun)$135,0001,946ok
2026-07 (Jul)$135,000737ok
Market dynamics

What job boards do not show

Two figures in this section come from Glozo data that public salary sources do not publish. Against 7,865 active postings, the field carries a measured talent pool of 119,998 security professionals in the United States. Divide one by the other and there are about 15 available professionals for every open security role. For scale, our recruiting report measures 327,487 people against 6,836 active postings, which is roughly 48 per opening. Security draws on about a third of the people for slightly more open work, and that gap is the central fact about hiring in this field. Postings clear in 9.5 days on average, and the range is narrow. Incident response and forensics roles stay open longest at 12.1 days, followed by security research and malware analysis at 12.0 days and AI and ML security engineering at 11.2 days. Security consulting closes fastest at 7.5 days, with identity and access management at 8.1 days and security architecture at 8.3 days. It is tempting to read that as pay tracking scarcity, and at the top of the table it looks that way. Across all 21 roles the relationship is weak, and security architecture at $151,175 closing in 8.3 days breaks it. What the lifespan cut supports is narrower: the roles that stay open longest are the ones where the work is investigative or new, not simply the ones that pay most.

15.3×
Candidates per vacancy
Deep supply, thin for specialized roles.
9.5 days
Average listing lifespan
How long a posting stays live.
119,998
Candidate pool
In Glozo's data.
Employment mix

Full-time dominates

Full-time work accounts for 91.7% of postings. Contract roles are 6.8%, internships 0.9%, part-time 0.5% and temporary work 0.1%. That full-time share is high for a technical field. Our recruiting report shows 82.0% full-time and 12.3% contract on the same feed and period, so security is close to ten points more permanent. The reading consistent with the rest of this data is that employers treat security as standing in-house capability rather than project work, which matches an employer list led by banks, defense primes and hyperscalers rather than by agencies. The 0.9% internship share is the smallest formal entry route in this report, and it is the posting-side counterpart to the thin entry tier in the talent pool below.

91.7% Full-time
Full-time 91.7%Contract 6.8%Internship 0.9%Part-time 0.5%Temporary 0.1%
Skills premium

What a skill adds to pay

Skill premiums are where this market states its direction most plainly, and they fall off a cliff. AI security carries an 18.6% premium and Kubernetes security 13.1%. Then the table drops: threat modeling is at 4.9%, NIST 800-53 at 3.3% and cloud security at 3.0%. The distance between the top two and the rest is the finding. Employers pay a real premium for security skills that are also engineering skills, applied to systems new enough that few people have done the work before. They pay very little extra for knowledge of an established control framework. NIST 800-53 at 3.3% is the clearest example, and cloud security at 3.0% shows how fast a premium erodes once a skill becomes standard equipment. The role table agrees. AI and ML security engineering is the highest-paid specialization at $171,700, while GRC analysis sits at $120,900 and cyber risk analysis at $105,000. Two independent cuts of the same postings, one by role and one by skill, put engineering-side and AI-adjacent work at the top and assessment work at the bottom. That agreement is worth more than either cut alone.

AI Security
+18.6%
Kubernetes Security
+13.1%
Threat Modeling
+4.9%
NIST 800-53
+3.3%
Cloud Security
+3.0%
Salary uplift vs the industry median
Data table
Salary uplift vs the industry median
SkillUplift
AI Security+18.6%
Kubernetes Security+13.1%
Threat Modeling+4.9%
NIST 800-53+3.3%
Cloud Security+3.0%
Talent pool

Where the candidates are

The pool of 119,998 security professionals concentrates in the middle and upper middle of the ladder. Specialists are 67.1% of it and experts 25.2%, so more than nine in ten measured professionals sit in those two tiers. Leaders are 5.5%. Entry level is 2.1%. That entry share is the number to sit with. It is the thinnest tier in the pool by a wide margin, and the shape is more senior than recruiting's, at 25.2% expert against 20.3% there. For anyone hiring, the consequence is that the tier most employers write job descriptions for, the mid-to-senior specialist, is also the tier every other employer draws from, with very little measured supply underneath it.

Entry2,549 candidates
2.1%
Specialist80,554 candidates
67.1%
Expert30,246 candidates
25.2%
Leader6,649 candidates
5.5%
Share of the candidate pool by seniority
Data table
Share of the candidate pool by seniority
TierShare
Entry2.1%
Specialist67.1%
Expert25.2%
Leader5.5%
Gender payBLS, not Glozo data

Occupation group versus national

The gender pay figures here come from the US Bureau of Labor Statistics, not from Glozo postings. For the computer occupations group that contains security roles, BLS reports a median of $102,752 for men against $84,656 for women, a gap of 17.6%. The national gap across all occupations is 19.4%. Both figures come from the same BLS series, so the comparison holds: the gap in this occupation group is narrower than the national one, though narrower is not the same as small. Two limits are worth stating. The BLS group is far broader than cybersecurity and its medians run well below the posted security medians elsewhere here, so the two sets of numbers are not comparable. And Glozo does not collect gender data on candidates or postings, so no figure in this report is broken out by gender.

BLS · management, business, financial
-17.60%
women $84,656 vs men $102,752
BLS · all occupations (national)
-19.40%
same release, like-for-like
Source: U.S. Bureau of Labor Statistics
FAQ

Common questions

What is the median cybersecurity salary in the US in 2026?

The median is about $141,440 a year, based on 8,093 analyzed United States security job postings. Around 44.2% of those postings disclose a salary range, so the figure reflects the disclosed subset rather than every role in the market. It is a posted base figure and does not include bonus, equity or on-call compensation.

Which cybersecurity role pays the most?

AI and machine-learning security engineers have the highest median at $171,700, followed by security researchers and malware analysts at $162,700, application security engineers at $161,100 and cryptography engineers at $160,000. Cyber risk analysts sit lowest at $105,000. The postings feed carries no count per role, so treat the ordering as directional rather than exact.

How does cybersecurity pay progress with seniority?

Median posted pay runs $83,000 at entry level, $141,000 for specialists, $194,000 for experts and $277,000 for leaders. The specialist tier matches the overall market median almost exactly. The leader tier exceeds every individual-contributor specialization because it includes security leadership roles, which the role breakdown does not cover.

How many security professionals are available for each open cybersecurity job?

About 15. Glozo measures a talent pool of 119,998 security professionals in the United States against 7,865 active postings. Our recruiting report measures roughly 48 per opening on the same feed, so security is a markedly tighter market. The pool is also weighted to the middle and upper middle, with only 2.1% at entry level.

Which skills raise cybersecurity pay the most in 2026?

AI security carries the largest premium at 18.6%, followed by Kubernetes security at 13.1%. The rest of the table is much flatter: threat modeling adds 4.9%, NIST 800-53 3.3% and cloud security 3.0%. The pattern favors engineering-side and emerging-systems skills over familiarity with an established control framework.

How long does a cybersecurity job posting stay open?

The average is 9.5 days. Incident response and forensics roles take longest at 12.1 days, followed by security research and malware analysis at 12.0 days and AI and ML security engineering at 11.2 days. Security consulting closes fastest at 7.5 days, with identity and access management at 8.1 days.

Where does cybersecurity pay best in the United States?

San Francisco leads cities at $218,000, ahead of New York at $171,000 and Boston at $156,000. Among states California is highest at $159,000, then Washington at $154,000 and New York at $143,000. Florida is lowest at $121,000. State figures pool metro and non-metro postings unevenly, so both cuts are directional.