Aktualisiert von
Hi, I'm Jack, the owner of Cybersecurity Jobs List, and co-founder of Himalayas (himalayas.app) and Cavuno (cavuno.com). Across all my platforms, I work with application security daily: dependency vulnerability scanning, secure authentication, API security, and data protection across hundreds of thousands of users. My technical background is in computer science (UNSW), where he studied security engineering and computer networks, and worked as a research assistant on VR experiments that were published in the Journal of Experimental Psychology. I also work with cybersecurity hiring data every day, tracking which companies are posting, what certifications actually appear in listings, how salaries differ by sub-discipline and clearance level, and where the talent gaps are widest. That combination of security practice, engineering at scale, and daily immersion in the hiring data is what shapes the content on this site. I'm currently based in Sydney, Australia.

Most cybersecurity salary pages recycle the same BLS median and a handful of Glassdoor averages. Useful context. Not enough if you are deciding between SOC, engineering, GRC, or a career change this quarter.
Start here while you read: All live cybersecurity jobs · US cybersecurity jobs · SOC analyst jobs · US SOC roles · Entry-level cyber jobs · Cybersecurity category · IT infrastructure / security ops · Risk analysis · GRC jobs
Open any list, then use the page alert/subscribe control so new matching roles reach you without re-searching.
This snapshot is different: posted pay bands and role volume from 5,181 live cybersecurity listings on Cybersecurity Jobs List as of 31 July 2026. Real job ads. Not a self-report survey. Not a promise of what you will clear after negotiation, bonus, or clearance pay.
About the data: USD yearly ranges only, with extreme outliers removed. Role groups come from job titles. When a salary sample is thin, treat the band as directional. Sales and go-to-market titles that hitch a ride on security product postings are not treated as core practitioner demand.
What the board looked like in late July
| Metric | Value |
|---|---|
| Open cybersecurity roles | 5,181 |
| Roles with a usable USD yearly range | 1,180 |
| Remote | 596 |
| Hybrid | 1,314 |
| On-site | 3,261 |
| Senior-labeled roles | 2,893 |
| Mid-level | 1,488 |
| Entry / junior labels | 310 |
The shape of the market in one paragraph: plenty of openings, mostly on-site or hybrid, heavily senior-labeled, with only about 6% carrying an entry or junior tag (310 of 5,181). If your plan depends on a flood of true junior titles, this inventory will frustrate you. If your plan targets analyst, SOC, engineer, and GRC filters with eyes open, there is work here.
For a national backdrop, U.S. BLS data still puts information security analysts at a $124,910 median (May 2024) with faster-than-average long-run growth. That answers whether the field exists. This page answers what employers were asking for on this board at the end of July.
Role volume and posted USD ranges
Averages below are means of the posted minimum and maximum when both exist. Read the salary sample size before treating a band as typical.
| Role group | Open jobs | With USD/yr | Avg posted min | Avg posted max |
|---|---|---|---|---|
| Security engineer | 870 | 278 | $118,998 | $178,891 |
| Security analyst | 524 | 138 | $93,001 | $137,754 |
| GRC / compliance / risk | 445 | 90 | $112,049 | $168,105 |
| SOC / cyber ops | 369 | 67 | $112,891 | $165,822 |
| Pentest / red team | 51 | 4 | $118,340 | $170,468 |
| IR / threat hunt / detection | 43 | 7 | $117,657 | $217,400 |
| Cloud security / DevSecOps | 15 | 5 | $119,820 | $163,900 |
| AppSec / product security | 12 | 2 | $101,450 | $154,175 |
| Other (uncategorized titles) | 2,852 | 589 | $136,359 | $200,450 |
How to read this without fooling yourself:
- Security engineer was the thickest named IC path: 870 roles, 278 with usable USD yearly bands, average posted span roughly $119k-$179k.
- Security analyst carried high volume at a lower posted band (about $93k-$138k average min/max). That is often the practical on-ramp next to SOC.
- GRC was not a side quest. 445 roles, with posted averages near six figures when salary was disclosed. If you prefer frameworks, audits, and risk language to alert queues, the market was already voting with listings.
- SOC / cyber ops held solid volume (369). Where yearly USD appeared, posted averages still clustered in six-figure territory. For tier ladders and tool stacks, use the SOC Analyst career guide.
- Pentest, IR, cloud, and AppSec matter strategically, but July salary samples here were small. Do not build a life plan off n=2 to n=7.
- Other is large on purpose: architects, executives, OT, geo-specific strings, and odd title variants. Its high average max is pulled by senior and leadership packages, not a typical mid-level IC offer.
Who showed up most in the inventory
Largest employers by open-role count on this board at snapshot time. Counts measure listing volume here, not prestige and not a recommendation to apply blindly.
| Company | Open roles | Domain |
|---|---|---|
| EY Global Services | 89 | ey.com |
| PricewaterhouseCoopers LLP | 80 | pwc.com |
| Softtest Pays | 69 | softtestpays.com |
| Booz Allen Hamilton | 61 | boozallen.com |
| TheHiveCareers | 39 | thehivecareers.co |
| CACI | 38 | caci.com |
| Sopra Steria | 33 | soprasteria.com |
| Thales Group | 31 | thalesgroup.com |
| Leidos | 28 | leidos.com |
| GDIT | 27 | gdit.com |
Consulting and federal-adjacent names appear often in high-volume cybersecurity boards. That is a signal about where listings cluster, not a claim that every role is equivalent in pay, clearance, or quality.
What this means if you are hunting
- Volume is not the same as entry access. Senior labels dominate. Pair skill-building with analyst and SOC filters, not only the entry-level tag.
- Engineer and analyst still pay the bills in listing count. If you want options, build toward one of those titles or a clean adjacent path into them.
- GRC is a real lane with both volume and disclosed pay, especially if offensive or deep detection work is not your interest.
- Remote is minority inventory. Fully remote roles exist; on-site and hybrid still own the bulk of July's board.
- Use two salary lenses. BLS-style national medians for the broad field. These posted bands for role-specific asks on live ads.
For the next month's cut of demand and medians, see the August 2026 role demand snapshot.
Career depth:
How we built this snapshot
- Source: live published cybersecurity listings on Cybersecurity Jobs List, 31 July 2026.
- Role groups from job titles; each listing counted in one primary group for the specialty table.
- Salary figures use employer-posted USD yearly minimums and maximums only.
- Board inventory snapshot, not a government labor survey and not accepted-offer data.
Hiring cybersecurity talent?
If you hire practitioners and want a niche board instead of a general marketplace, post a free moderated 30-day listing or use the $49 Featured Launch Special for priority placement. Introductory pricing. No performance guarantees.
Browse live cybersecurity roles
Pick a filter that matches the path you want. On any jobs page, use the built-in alert/subscribe control so fresh roles come to you. Check back weekly.
Keep reading

