Zum Hauptinhalt springen

Cybersecurity Salary & Role Snapshot (July 2026)

Posted pay bands from 5,181 live cyber listings. Engineer, analyst, SOC, and GRC volume, plus what the numbers mean if you are job hunting.

Aktualisiert von

JW
Jack Walsh31.07.2026 · 6 Min. Lesezeit

Hi, I'm Jack, the owner of Cybersecurity Jobs List, and co-founder of Himalayas (himalayas.app) and Cavuno (cavuno.com). Across all my platforms, I work with application security daily: dependency vulnerability scanning, secure authentication, API security, and data protection across hundreds of thousands of users. My technical background is in computer science (UNSW), where he studied security engineering and computer networks, and worked as a research assistant on VR experiments that were published in the Journal of Experimental Psychology. I also work with cybersecurity hiring data every day, tracking which companies are posting, what certifications actually appear in listings, how salaries differ by sub-discipline and clearance level, and where the talent gaps are widest. That combination of security practice, engineering at scale, and daily immersion in the hiring data is what shapes the content on this site. I'm currently based in Sydney, Australia.

Diesen Beitrag teilen

Abstract cybersecurity data visualization with role-volume bars, network lines, and salary-analysis motifs in blue and green
Editorial visualization for the July 2026 Cybersecurity Salary and Role Snapshot.

Most cybersecurity salary pages recycle the same BLS median and a handful of Glassdoor averages. Useful context. Not enough if you are deciding between SOC, engineering, GRC, or a career change this quarter.

Start here while you read: All live cybersecurity jobs · US cybersecurity jobs · SOC analyst jobs · US SOC roles · Entry-level cyber jobs · Cybersecurity category · IT infrastructure / security ops · Risk analysis · GRC jobs

Open any list, then use the page alert/subscribe control so new matching roles reach you without re-searching.

This snapshot is different: posted pay bands and role volume from 5,181 live cybersecurity listings on Cybersecurity Jobs List as of 31 July 2026. Real job ads. Not a self-report survey. Not a promise of what you will clear after negotiation, bonus, or clearance pay.

About the data: USD yearly ranges only, with extreme outliers removed. Role groups come from job titles. When a salary sample is thin, treat the band as directional. Sales and go-to-market titles that hitch a ride on security product postings are not treated as core practitioner demand.

What the board looked like in late July

MetricValue
Open cybersecurity roles5,181
Roles with a usable USD yearly range1,180
Remote596
Hybrid1,314
On-site3,261
Senior-labeled roles2,893
Mid-level1,488
Entry / junior labels310

The shape of the market in one paragraph: plenty of openings, mostly on-site or hybrid, heavily senior-labeled, with only about 6% carrying an entry or junior tag (310 of 5,181). If your plan depends on a flood of true junior titles, this inventory will frustrate you. If your plan targets analyst, SOC, engineer, and GRC filters with eyes open, there is work here.

For a national backdrop, U.S. BLS data still puts information security analysts at a $124,910 median (May 2024) with faster-than-average long-run growth. That answers whether the field exists. This page answers what employers were asking for on this board at the end of July.

Role volume and posted USD ranges

Averages below are means of the posted minimum and maximum when both exist. Read the salary sample size before treating a band as typical.

Role groupOpen jobsWith USD/yrAvg posted minAvg posted max
Security engineer870278$118,998$178,891
Security analyst524138$93,001$137,754
GRC / compliance / risk44590$112,049$168,105
SOC / cyber ops36967$112,891$165,822
Pentest / red team514$118,340$170,468
IR / threat hunt / detection437$117,657$217,400
Cloud security / DevSecOps155$119,820$163,900
AppSec / product security122$101,450$154,175
Other (uncategorized titles)2,852589$136,359$200,450

How to read this without fooling yourself:

  • Security engineer was the thickest named IC path: 870 roles, 278 with usable USD yearly bands, average posted span roughly $119k-$179k.
  • Security analyst carried high volume at a lower posted band (about $93k-$138k average min/max). That is often the practical on-ramp next to SOC.
  • GRC was not a side quest. 445 roles, with posted averages near six figures when salary was disclosed. If you prefer frameworks, audits, and risk language to alert queues, the market was already voting with listings.
  • SOC / cyber ops held solid volume (369). Where yearly USD appeared, posted averages still clustered in six-figure territory. For tier ladders and tool stacks, use the SOC Analyst career guide.
  • Pentest, IR, cloud, and AppSec matter strategically, but July salary samples here were small. Do not build a life plan off n=2 to n=7.
  • Other is large on purpose: architects, executives, OT, geo-specific strings, and odd title variants. Its high average max is pulled by senior and leadership packages, not a typical mid-level IC offer.

Who showed up most in the inventory

Largest employers by open-role count on this board at snapshot time. Counts measure listing volume here, not prestige and not a recommendation to apply blindly.

CompanyOpen rolesDomain
EY Global Services89ey.com
PricewaterhouseCoopers LLP80pwc.com
Softtest Pays69softtestpays.com
Booz Allen Hamilton61boozallen.com
TheHiveCareers39thehivecareers.co
CACI38caci.com
Sopra Steria33soprasteria.com
Thales Group31thalesgroup.com
Leidos28leidos.com
GDIT27gdit.com

Consulting and federal-adjacent names appear often in high-volume cybersecurity boards. That is a signal about where listings cluster, not a claim that every role is equivalent in pay, clearance, or quality.

What this means if you are hunting

  1. Volume is not the same as entry access. Senior labels dominate. Pair skill-building with analyst and SOC filters, not only the entry-level tag.
  2. Engineer and analyst still pay the bills in listing count. If you want options, build toward one of those titles or a clean adjacent path into them.
  3. GRC is a real lane with both volume and disclosed pay, especially if offensive or deep detection work is not your interest.
  4. Remote is minority inventory. Fully remote roles exist; on-site and hybrid still own the bulk of July's board.
  5. Use two salary lenses. BLS-style national medians for the broad field. These posted bands for role-specific asks on live ads.

For the next month's cut of demand and medians, see the August 2026 role demand snapshot.

Career depth:

How we built this snapshot

  • Source: live published cybersecurity listings on Cybersecurity Jobs List, 31 July 2026.
  • Role groups from job titles; each listing counted in one primary group for the specialty table.
  • Salary figures use employer-posted USD yearly minimums and maximums only.
  • Board inventory snapshot, not a government labor survey and not accepted-offer data.

Hiring cybersecurity talent?

If you hire practitioners and want a niche board instead of a general marketplace, post a free moderated 30-day listing or use the $49 Featured Launch Special for priority placement. Introductory pricing. No performance guarantees.

Post a job · Employer pricing

Browse live cybersecurity roles

Pick a filter that matches the path you want. On any jobs page, use the built-in alert/subscribe control so fresh roles come to you. Check back weekly.

Keep reading

Ähnliche Beiträge

Wir verwenden Cookies

Wir verwenden Cookies, um die Nutzung dieses Boards zu verstehen und es zu verbessern. Analyse-Cookies laufen nur, wenn du zustimmst. Cookie-Richtlinie