USA Cybersecurity Salary Report 2026
Where the bands sit
Median pay by security specialization runs from $105,000 for cyber risk analysts to $171,700 for AI and machine-learning security engineers, a spread of about 64%. The ordering is not random. All four of the highest medians sit on the engineering and research side: AI and ML security at $171,700, security research and malware analysis at $162,700, application and product security at $161,100 and cryptography engineering at $160,000. Core security engineering follows at $153,000 and security architecture at $151,175. Cloud security ($145,145), DevSecOps ($144,500), identity and access management ($142,900) and penetration testing ($140,200) sit just above the overall median. The bottom of the table is where assessment and reporting work sits: GRC analysis at $120,900, vulnerability management at $118,700, security analysis at $112,120, threat intelligence at $110,000 and cyber risk analysis at $105,000. Roles that build and break systems pay more than roles that assess and document them, and the gap runs to about $67,000 at the extremes. The skill premiums further down reach the same conclusion from a different cut of the same postings. The feed carries no posting count per role, so treat the exact ordering as directional.
Data table
| Role | Median |
|---|---|
| AI/ML Security Engineer | $171,700 |
| Security Researcher / Malware Analyst | $162,700 |
| Application Security (appsec) / Product Security Engineer | $161,100 |
| Cryptography Engineer | $160,000 |
| Security Engineer | $153,000 |
| Security Architect | $151,175 |
| Cloud Security Engineer | $145,145 |
| Devsecops / Security Platform Engineer | $144,500 |
| Identity & Access Management (iam) Engineer | $142,900 |
| Red Team Operator | $142,500 |
| Penetration Tester | $140,200 |
| Incident Responder / Dfir | $139,000 |
| Security Consultant | $137,500 |
| Detection / Security Automation Engineer | $133,450 |
| Soc / Security Operations Analyst | $130,000 |
| Grc Analyst (governance, Risk, Compliance) | $120,900 |
| Vulnerability Management Analyst / Engineer | $118,700 |
| Security Analyst | $112,120 |
| Information Security Analyst / Specialist | $110,120 |
| Threat Intelligence Analyst | $110,000 |
| Cyber Risk Analyst | $105,000 |
The seniority curve
Data table
| Tier | Median |
|---|---|
| Entry | $83,000 |
| Specialist | $141,000 |
| Expert | $194,000 |
| Leader | $277,000 |
Pay by state
California leads states at $159,000, only 3.2% ahead of Washington at $154,000. New York follows at $143,000, Illinois at $140,000, Colorado at $135,000, Texas at $133,000 and Georgia at $131,000, with Florida lowest at $121,000. That is a spread of about 31%, tighter than the spread across specializations. City medians tell a different story. San Francisco sits at $218,000, which is 27.5% above New York at $171,000 and 68% above Miami at $130,000. Boston is at $156,000, Seattle and Los Angeles both at $155,000, Austin at $152,000, Denver at $146,000, Chicago at $145,000 and Atlanta at $135,000. The $59,000 gap between San Francisco and California as a whole is the figure to keep in mind when reading any state-level pay table, including this one. State medians pool metro and non-metro postings in proportions that differ from one state to the next. Neither cut carries a posting count per item, so read both as directional.
Data table
| State | Median |
|---|---|
| California | $159,000 |
| Washington | $154,000 |
| New York | $143,000 |
| Illinois | $140,000 |
| Colorado | $135,000 |
| Texas | $133,000 |
| Georgia | $131,000 |
| Florida | $121,000 |
Data table
| City | Median |
|---|---|
| San Francisco | $218,000 |
| New York | $171,000 |
| Boston | $156,000 |
| Seattle | $155,000 |
| Los Angeles | $155,000 |
| Austin | $152,000 |
| Denver | $146,000 |
| Chicago | $145,000 |
| Atlanta | $135,000 |
| Miami | $130,000 |
Month to month
Across the months with enough disclosed pay to report, the posted median moves from $159,140 in February to $135,000 in July, a shift of about 15%. Read that as a change in what was posted, not as a change in what security professionals are paid. Only 44.2% of postings disclose a range, so every monthly point rests on that disclosed slice, and the mix of roles posted moves from month to month. A month heavy in security operations postings shows a lower median than a month heavy in application security, with no underlying pay movement at all. We suppress January, where roughly 85 postings disclosed a range, below the floor we use before publishing a monthly point. May clears that floor at about 198 disclosed, but its volume of 448 postings sits far below the 1,711 in April and the 1,946 in June, and the same shape appears in every industry we have pulled this year. July, at 737 postings, is also thin next to June. Read the overall level rather than any single month.
Data table
| Month | Median | Postings | Status |
|---|---|---|---|
| 2026-01 (Jan) | $155,000 | 192 | suppressed |
| 2026-02 (Feb) | $159,140 | 1,028 | ok |
| 2026-03 (Mar) | $149,800 | 1,803 | ok |
| 2026-04 (Apr) | $145,500 | 1,711 | ok |
| 2026-05 (May) | $130,350 | 448 | ok |
| 2026-06 (Jun) | $135,000 | 1,946 | ok |
| 2026-07 (Jul) | $135,000 | 737 | ok |
What job boards do not show
Two figures in this section come from Glozo data that public salary sources do not publish. Against 7,865 active postings, the field carries a measured talent pool of 119,998 security professionals in the United States. Divide one by the other and there are about 15 available professionals for every open security role. For scale, our recruiting report measures 327,487 people against 6,836 active postings, which is roughly 48 per opening. Security draws on about a third of the people for slightly more open work, and that gap is the central fact about hiring in this field. Postings clear in 9.5 days on average, and the range is narrow. Incident response and forensics roles stay open longest at 12.1 days, followed by security research and malware analysis at 12.0 days and AI and ML security engineering at 11.2 days. Security consulting closes fastest at 7.5 days, with identity and access management at 8.1 days and security architecture at 8.3 days. It is tempting to read that as pay tracking scarcity, and at the top of the table it looks that way. Across all 21 roles the relationship is weak, and security architecture at $151,175 closing in 8.3 days breaks it. What the lifespan cut supports is narrower: the roles that stay open longest are the ones where the work is investigative or new, not simply the ones that pay most.
Full-time dominates
Full-time work accounts for 91.7% of postings. Contract roles are 6.8%, internships 0.9%, part-time 0.5% and temporary work 0.1%. That full-time share is high for a technical field. Our recruiting report shows 82.0% full-time and 12.3% contract on the same feed and period, so security is close to ten points more permanent. The reading consistent with the rest of this data is that employers treat security as standing in-house capability rather than project work, which matches an employer list led by banks, defense primes and hyperscalers rather than by agencies. The 0.9% internship share is the smallest formal entry route in this report, and it is the posting-side counterpart to the thin entry tier in the talent pool below.
What a skill adds to pay
Skill premiums are where this market states its direction most plainly, and they fall off a cliff. AI security carries an 18.6% premium and Kubernetes security 13.1%. Then the table drops: threat modeling is at 4.9%, NIST 800-53 at 3.3% and cloud security at 3.0%. The distance between the top two and the rest is the finding. Employers pay a real premium for security skills that are also engineering skills, applied to systems new enough that few people have done the work before. They pay very little extra for knowledge of an established control framework. NIST 800-53 at 3.3% is the clearest example, and cloud security at 3.0% shows how fast a premium erodes once a skill becomes standard equipment. The role table agrees. AI and ML security engineering is the highest-paid specialization at $171,700, while GRC analysis sits at $120,900 and cyber risk analysis at $105,000. Two independent cuts of the same postings, one by role and one by skill, put engineering-side and AI-adjacent work at the top and assessment work at the bottom. That agreement is worth more than either cut alone.
Data table
| Skill | Uplift |
|---|---|
| AI Security | +18.6% |
| Kubernetes Security | +13.1% |
| Threat Modeling | +4.9% |
| NIST 800-53 | +3.3% |
| Cloud Security | +3.0% |
Where the candidates are
The pool of 119,998 security professionals concentrates in the middle and upper middle of the ladder. Specialists are 67.1% of it and experts 25.2%, so more than nine in ten measured professionals sit in those two tiers. Leaders are 5.5%. Entry level is 2.1%. That entry share is the number to sit with. It is the thinnest tier in the pool by a wide margin, and the shape is more senior than recruiting's, at 25.2% expert against 20.3% there. For anyone hiring, the consequence is that the tier most employers write job descriptions for, the mid-to-senior specialist, is also the tier every other employer draws from, with very little measured supply underneath it.
Data table
| Tier | Share |
|---|---|
| Entry | 2.1% |
| Specialist | 67.1% |
| Expert | 25.2% |
| Leader | 5.5% |
Occupation group versus national
The gender pay figures here come from the US Bureau of Labor Statistics, not from Glozo postings. For the computer occupations group that contains security roles, BLS reports a median of $102,752 for men against $84,656 for women, a gap of 17.6%. The national gap across all occupations is 19.4%. Both figures come from the same BLS series, so the comparison holds: the gap in this occupation group is narrower than the national one, though narrower is not the same as small. Two limits are worth stating. The BLS group is far broader than cybersecurity and its medians run well below the posted security medians elsewhere here, so the two sets of numbers are not comparable. And Glozo does not collect gender data on candidates or postings, so no figure in this report is broken out by gender.
Common questions
What is the median cybersecurity salary in the US in 2026?
The median is about $141,440 a year, based on 8,093 analyzed United States security job postings. Around 44.2% of those postings disclose a salary range, so the figure reflects the disclosed subset rather than every role in the market. It is a posted base figure and does not include bonus, equity or on-call compensation.
Which cybersecurity role pays the most?
AI and machine-learning security engineers have the highest median at $171,700, followed by security researchers and malware analysts at $162,700, application security engineers at $161,100 and cryptography engineers at $160,000. Cyber risk analysts sit lowest at $105,000. The postings feed carries no count per role, so treat the ordering as directional rather than exact.
How does cybersecurity pay progress with seniority?
Median posted pay runs $83,000 at entry level, $141,000 for specialists, $194,000 for experts and $277,000 for leaders. The specialist tier matches the overall market median almost exactly. The leader tier exceeds every individual-contributor specialization because it includes security leadership roles, which the role breakdown does not cover.
How many security professionals are available for each open cybersecurity job?
About 15. Glozo measures a talent pool of 119,998 security professionals in the United States against 7,865 active postings. Our recruiting report measures roughly 48 per opening on the same feed, so security is a markedly tighter market. The pool is also weighted to the middle and upper middle, with only 2.1% at entry level.
Which skills raise cybersecurity pay the most in 2026?
AI security carries the largest premium at 18.6%, followed by Kubernetes security at 13.1%. The rest of the table is much flatter: threat modeling adds 4.9%, NIST 800-53 3.3% and cloud security 3.0%. The pattern favors engineering-side and emerging-systems skills over familiarity with an established control framework.
How long does a cybersecurity job posting stay open?
The average is 9.5 days. Incident response and forensics roles take longest at 12.1 days, followed by security research and malware analysis at 12.0 days and AI and ML security engineering at 11.2 days. Security consulting closes fastest at 7.5 days, with identity and access management at 8.1 days.
Where does cybersecurity pay best in the United States?
San Francisco leads cities at $218,000, ahead of New York at $171,000 and Boston at $156,000. Among states California is highest at $159,000, then Washington at $154,000 and New York at $143,000. Florida is lowest at $121,000. State figures pool metro and non-metro postings unevenly, so both cuts are directional.