Career & Salary
How Much Can You Actually Make in Cybersecurity?
The headline numbers circulate constantly: "cybersecurity professionals earn $120,000 on average." What those headlines rarely explain is what level, what role, what geography, and what experience level produces that figure — and what the journey from entry point to that salary actually looks like.
The honest picture is more nuanced, and more achievable, than the promotional framing suggests.
Entry Level: The First Two Years
Most people entering cybersecurity without prior IT experience can realistically expect roles in the $45,000–$70,000 range in Western markets, depending on location and whether they are entering through a help desk, IT support, or directly into a junior security analyst position. In African markets, figures vary significantly by country and sector.
These roles — SOC analyst tier 1, IT support with a security rotation, junior GRC analyst — are not glamorous. They are the foundation. The professionals who build genuine expertise during these years consistently outperform peers who spent the same period chasing titles.
Mid-Level: Where the Earnings Accelerate
Two to five years of substantive experience begins to unlock a different category of opportunity. Penetration testers, security engineers, incident responders, and cloud security specialists in this bracket typically earn between $85,000 and $130,000 in competitive markets.
The critical factor at this stage is specificity. Generalists plateau. Specialists — those who can demonstrate deep competency in a defined domain — command significantly higher compensation and have considerably more leverage in salary negotiations.
Senior and Leadership Roles
Senior security engineers, red team leads, detection engineers, and threat intelligence analysts with five or more years of focused experience routinely command $130,000–$180,000 in US markets. CISOs at enterprise organisations often earn considerably more, with total compensation packages including equity and bonuses that can push into the $300,000+ range.
The Variables That Move the Number Most
- Sector: Finance, defence, and critical infrastructure pay meaningfully more than retail or non-profit
- Geography: San Francisco, New York, London, and Singapore have significant salary premiums over smaller markets
- Clearance: Government security clearances, particularly in Five Eyes countries, add substantial premium
- Specialisation: Cloud security, OT/ICS security, and offensive security command higher rates than general roles
- Consulting vs. in-house: Independent consultants and contractors frequently earn more per hour, with the trade-off of no benefits and variable income
What the Numbers Do Not Tell You
Salary data aggregated from job boards and surveys has well-known limitations. It tends to skew towards roles that are publicly posted and fills the data set with mid-market positions. The highest-earning individuals in this field — senior independent consultants, fractional CISOs, and those working in private client security — rarely appear in those datasets at all.
The path to the upper end of the compensation range is not a straight line. It is built through deliberate specialisation, demonstrated results, and a professional network that puts you in the room for opportunities that never reach a job board.
Related Insights
Concerned about your executive digital exposure? Begin a confidential conversation.