Updated by
Hi, I'm Jack, the owner of Cybersecurity Jobs List, and co-founder of Himalayas (himalayas.app) and Cavuno (cavuno.com). Across all my platforms, I work with application security daily: dependency vulnerability scanning, secure authentication, API security, and data protection across hundreds of thousands of users. My technical background is in computer science (UNSW), where he studied security engineering and computer networks, and worked as a research assistant on VR experiments that were published in the Journal of Experimental Psychology. I also work with cybersecurity hiring data every day, tracking which companies are posting, what certifications actually appear in listings, how salaries differ by sub-discipline and clearance level, and where the talent gaps are widest. That combination of security practice, engineering at scale, and daily immersion in the hiring data is what shapes the content on this site. I'm currently based in Sydney, Australia.

Information security protects information in any form, including paper records, conversations and digital files. Cybersecurity focuses on protecting digital systems, networks and the information they handle. The two overlap wherever information depends on technology. ISO's information security overview and NIST's cybersecurity definitions support that distinction.
For your career, the job description matters more than which label an employer uses. An information security role can involve investigating attacks, while a cybersecurity role can involve assessing risk and writing policy. Read the responsibilities before deciding which jobs or courses fit you.
What is the difference between cybersecurity and information security?
The most useful distinction is the scope of what you're protecting. Information security, often shortened to InfoSec, starts with information and its supporting systems. Cybersecurity starts with digital environments, including systems that control physical equipment.
| Comparison | Information security | Cybersecurity |
|---|---|---|
| Main focus | Information in any form and the systems supporting it | Digital systems, networks and their information |
| Example problem | Confidential project plans shared with someone who shouldn't receive them | A compromised account used to access a project workspace |
| Example safeguards | Access rules, secure handling of documents, encryption, staff training | Account protection, secure configuration, monitoring, incident response |
| Overlapping work | Risk assessment, access management, recovery planning and technical security | Risk assessment, access management, recovery planning and technical security |
| Career implication | The title can cover technical or assurance work | The title can cover technical or assurance work |
The examples describe different starting points, rather than exclusive responsibilities. Protecting a cloud folder containing client plans is both an information security task and a cybersecurity task. The access rule and the software enforcing it are parts of the same problem.
Information security includes digital security
NIST defines information security around protecting information and information systems. It isn't limited to policies, document handling or compliance. A security engineer configuring access to a database is protecting information even if their job title never uses the word InfoSec.
ISO's public overview of ISO/IEC 27001 describes an information security management system that brings people, policies and technology together. It explicitly includes information held on paper, digitally or in the cloud. That's a useful reminder when a job advert makes information security sound entirely administrative. Read the ISO overview.
Cybersecurity includes governance
Cybersecurity work also includes deciding which risks matter, who owns them and how the organization will respond. The NIST Cybersecurity Framework 2.0 includes Govern alongside Identify, Protect, Detect, Respond and Recover. Governance is part of managing cyber risk, even when the work doesn't involve writing code.
Digital security can also affect physical operations. NIST's operational technology guidance covers systems that interact with the physical environment, including industrial controls and building automation, where reliability and safety matter. Cybersecurity therefore reaches beyond keeping files private or stopping internet attacks. NIST's OT security overview explains that scope.
Examples: Protecting the same information in different forms
Imagine a small architecture practice called Alder Studio. This is a fictional example. Its team keeps signed client agreements on paper, shares building plans through an online workspace and takes laptops to construction sites.
Three security goals help explain what could go wrong. Confidentiality concerns appropriate access and disclosure; integrity concerns protection against improper changes or destruction; availability concerns reliable access when needed. These are commonly called the CIA triad, and they appear in NIST's information security definition.
A printed agreement goes to the wrong person
A team member leaves a signed agreement in a meeting room used by another business. Someone outside the project can read the client's contact details and fees. The immediate concern is confidentiality, even though no computer has been compromised.
For this scenario, useful questions include who needs access to the paper copy, where it should be stored and how staff handle it when a meeting ends. The information security problem exists because information has reached an unintended reader.
A shared account exposes project files
A former contractor still has access to the online workspace and downloads drawings after their engagement ends. The same confidentiality concern now involves a digital account. Reviewing access, removing permissions that are no longer needed and investigating the download would address the overlapping information security and cybersecurity problem.
The team would need to establish what happened before describing the incident more broadly. An access record can help show activity; it doesn't, by itself, explain someone's intent or every consequence.
Someone changes an approved drawing
An unauthorized person changes a measurement in the digital plan. Everyone can still open the file, but the team can no longer trust that it matches the approved version. This illustrates an integrity problem.
In this example, the review would consider edit permissions, the change history and how approved versions are identified. It would also need to establish whether anyone used the changed drawing. A security problem can matter without information being stolen.
The project workspace becomes unavailable
An outage stops the team opening drawings before a site meeting. The files may remain confidential and unchanged, but they're unavailable when needed. A recovery plan would have to consider how the team resumes work and confirms it's using the right versions.
These examples aren't a security plan for an architecture business. They're a way to practice describing an asset, a failure and its consequence. When reading a job description, look for the kinds of failures that role is expected to help prevent, investigate or recover from.
How the terminology affects your job search
Search both cybersecurity and information security when you're exploring roles. Then narrow your shortlist using the work described, the level of responsibility and the evidence an employer expects from applicants.
The US Bureau of Labor Statistics describes information security analysts as protecting computer networks and systems. Its duties include investigating breaches, using protective software and checking for vulnerabilities, as well as developing standards and contributing to recovery plans. That's a technical occupation under an information security title. BLS occupational profile.
NIST's NICE Framework makes another useful distinction: a work role isn't the same thing as a job title. One job can combine several work roles or parts of them. You therefore need the responsibilities to understand what an employer means by a title. NICE explanation of occupations, jobs and work roles.
Example A: Information security analyst, investigation work
Consider this fictional job description:
Review identity and endpoint alerts, investigate suspicious activity, document findings and improve detection rules with the security operations team.
You'd prepare for this role by practicing how to move from an alert to a supported conclusion. For example, use sample sign-in records in a permitted lab to build a timeline, identify what needs checking and write a short escalation note. Explain what the evidence supports and where you're uncertain.
A useful work sample could show the initial alert, the records you examined, alternative explanations and your recommendation. For a fuller look at this kind of work, read our SOC analyst career guide.
Example B: Information security analyst, supplier assurance
A second fictional employer uses the same title for this description:
Review the security of proposed suppliers, assess evidence against internal requirements, document gaps and follow up on agreed actions.
The central task here is making and explaining a risk judgment. You'd need to understand the supplier's service, what information it handles and whether the evidence answers the questions being asked. A technical claim such as “all customer data is encrypted” still needs careful interpretation of scope.
For practice, create a fictional supplier review with a short service description and a few sample documents. Write down the information still missing, explain why it matters and propose a follow-up question. Label the exercise clearly as fictional; don't present it as a real supplier assessment. Our GRC analyst guide develops this kind of evidence-based work further.
Both example jobs protect information. They call for different preparation because their day-to-day outputs differ. Neither title alone tells you which work you'll spend most of your time doing.
A five-question checklist for comparing security jobs
Copy these questions into your notes and answer them for two adverts that interest you. Use the employer's wording where it is specific, and mark missing information as unknown.
- What would I protect? Identify the service, system or information involved. “Security” is broad; customer accounts, manufacturing equipment and supplier-held documents give you more to work with.
- What would I produce? Look for outputs such as an investigation report, a configured control, a supplier assessment or a tested recovery procedure. These help you choose relevant practice work.
- What decisions would I own? Separate supporting a review from approving it, and escalating an incident from leading the response. Similar task wording can hide very different responsibility levels.
- What evidence must I bring? Record the stated experience, technical skills and qualifications. Keep required and preferred criteria separate, and note which you can demonstrate with a specific example.
- What needs clarifying before I commit? Note unclear duties, supervision, shift or on-call expectations, and the balance between project work and routine operations. Turn each gap into a concrete interview question.
For the fictional roles above, a strong clarification would be: “Could you walk me through a recent task someone in this role completed and what they delivered?” That invites an example you can compare with the advert. “Is this role technical?” can leave you with another ambiguous label.
The checklist also helps you adapt your application. An investigation timeline is relevant evidence for Example A; a carefully reasoned supplier review is more directly relevant to Example B. Describe your contribution accurately, including whether it came from employment, study or a personal project.
Choosing skills, courses and certifications
Build enough shared foundation to explain how information moves through a system, who can access it and what happens when something fails. Accounts and permissions, basic networking, operating systems and clear written reasoning are useful areas to investigate against your target adverts. The depth you need should follow the role's tasks.
For a course, compare the syllabus and assessed work with the outputs on your shortlist. A module called “security operations” could involve a practical investigation, a written overview or both. Ask to see the learning outcomes and assessment format before assuming the course prepares you for the work you want.
Use a small exercise to test your preference before committing to a long program. Spend one session explaining a sample alert and another reviewing evidence for a fictional business requirement. Notice which parts you enjoy and which knowledge gaps stop you making progress. This won't tell you everything about a career, but it gives you something more concrete than a degree title to compare.
Certification names also cross the terminology boundary. The ISC2 CISSP exam outline, for example, spans risk management, security architecture, networks, identity, operations and software security. Its scope illustrates the overlap; mentioning it here isn't a recommendation to take it as your first qualification.
Before choosing any credential, check its official prerequisites and exam outline, then compare them with current adverts for the specific role and market you're targeting. Separate a course completion certificate from a professional certification, and check what each requires. Completing a qualification doesn't by itself establish that you can perform every duty in a job description.
Common questions
Is cybersecurity a subset of information security?
Treating digital information protection as part of information security is a useful introductory model. It becomes less useful as a rigid organizational chart: cybersecurity also deals with the operation of digital systems and their physical effects, while employers use titles in different ways. Use the distinction to explain scope, then check the context in which someone is using the terms.
Which pays more: cybersecurity or information security?
The labels alone don't give you a reliable comparison. Compare roles with similar responsibilities, seniority, location and working arrangements, and distinguish base salary from the rest of the offer. A senior engineering role and a junior assurance role aren't evidence of a pay difference between two whole fields. Search for pay attached to the specific work you want to do.
Does information security require coding?
It depends on the job. An advert involving application code review or security automation calls for different coding preparation from one centered on supplier assessments. Check what you'll need to read, write or troubleshoot, rather than assuming an information security title means no code. Our SOC analyst vs security engineer comparison explores how technical work varies between those roles.
Can I move between cybersecurity and information security roles?
You may already be working across both. For a move between specialties, compare the work you can demonstrate with the destination role's requirements. An analyst moving from supplier reviews into investigations will need evidence of investigation skills; familiarity with security terminology alone won't show that. Use the job checklist to identify the gaps you need to address.
Is IT security the same as information security?
IT security generally points to protecting an organization's information technology. Information security can also include information outside those systems. In a job search, treat IT security as another term worth checking, then read the responsibilities. Employers' use of the label doesn't guarantee a particular scope or level.
Choose the work you want to explore
Pick two current security job listings and complete the checklist for each. Choose them because their duties interest you, even if one says cybersecurity and the other says information security.
Then select one small piece of work to practice from the role you prefer. An explained investigation, a reasoned assessment or a documented configuration gives you a concrete next step and a better basis for choosing what to learn.


