Research date: September 14–15, 2026. Salary figures are US ranges composited from BLS, CyberSeek postings data, Salary.com, levels.fyi, and Glassdoor/Indeed norms; treat them as estimates unless marked [measured]. Certification prices are as published or as credibly market-reported at the research date.
1. The market, honestly
This section is where most cybersecurity career content loses credibility, so the site should lead with the uncomfortable version.
Demand is real. CyberSeek recorded 514,359 US cybersecurity job postings between May 2024 and April 2025 [measured]. BLS projects 21% growth for information security analysts from 2025 to 2035, with median pay of $129,180 [measured].
But it is concentrated at mid and senior levels, and the entry level is genuinely hard in 2025–26. ISC2's 2025 workforce study found 39% of organizations under hiring freezes, 24% with layoffs, and 36% with budget cuts, alongside a pivot to hiring for specific skills — AI security at 41%, cloud at 36%, risk at 29% — rather than headcount. The broader post-2022 tech-junior slump, compounded by AI absorbing Tier-1 triage work, hits cybersecurity juniors too. "Entry-level" postings demanding three to five years of experience remain endemic.
The "millions of unfilled jobs" claim deserves scrutiny. ISC2's own 2025 study conspicuously de-emphasized its previous 4.8-million-gap headline and reframed the problem as a skills gap rather than a headcount gap. The gap figure is derived by surveying managers about desired headcount and extrapolating globally — it counts wishes, not funded requisitions, and it is difficult to reconcile with layoffs at a quarter of organizations.
The honest advice: cybersecurity is rarely a true entry-level field. It is most reliably entered from adjacent IT — help desk to sysadmin or network to security, or developer to application security. A realistic timeline to a first security role for a newcomer is one to three years including adjacent-IT time.
Publishing this, rather than the bootcamp pitch, is a differentiator. The audience most likely to link to and recommend a careers page is the audience that has been burned by the other version.
2. Certifications that matter in 2026, with costs
| Certification | Body | 2025–26 US cost | Notes |
|---|---|---|---|
| CC | ISC2 | $199 (exam periodically free through ISC2's certification drive) [measured] | A genuine zero-experience entry certification |
| Security+ (SY0-701) | CompTIA | ~$404 voucher [estimate] | The default HR filter for entry roles; DoD 8140 baseline |
| CySA+ | CompTIA | ~$423 [estimate] | Blue-team and SOC ladder |
| PenTest+ | CompTIA | ~$423 [estimate] | Largely displaced by CPTS and OSCP as a hiring signal |
| SSCP | ISC2 | $249 [measured] | Underrated operations certification |
| CISSP | ISC2 | $749 exam [measured] plus ~$135/yr maintenance | Requires five years' experience; the management and architecture gate |
| CCSP | ISC2 | $599 [measured] | Cloud governance and architecture |
| CGRC | ISC2 | $599 [measured] | Governance, risk, compliance |
| CSSLP | ISC2 | $599 [measured] | Secure software lifecycle |
| OSCP / OSCP+ | OffSec | $1,749 course plus exam; Learn One $2,749/yr [measured] | Still the strongest penetration-testing hiring signal. OSCP+ is the three-year renewable designation introduced late 2024 |
| CPTS | Hack The Box | ~$210 exam plus Academy subscription | Widely regarded as more realistic and rigorous than OSCP for less money; growing recognition, still a weaker HR filter |
| PNPT | TCM Security | $499 all-in including training, exam, report, debrief, and one retake | Excellent value and realism; non-expiring |
| eJPT | INE Security | ~$249 | The standard first offensive certification |
| BTL1 | Security Blue Team | ~$399 | Practical blue-team credential |
| GIAC (GCIH, GCFA, GPEN, GREM, GWAPT) | GIAC/SANS | Exam ~$999; with SANS course ~$8,800+ [estimate] | Gold standard for DFIR depth; usually employer-funded |
| CISA / CISM | ISACA | ~$575 member / ~$760 non-member per exam [estimate] | GRC, audit, and security management staples |
| CIPP/US, CIPM | IAPP | ~$550 exam plus ~$275 first-year maintenance [estimate] | The privacy career gate; AIGP is the fast-growing AI-governance credential |
| CEH | EC-Council | ~$1,199+ [estimate] | HR recognition, weak practitioner respect; pursue only if a specific job requirement demands it |
| CRTO | Zero-Point Security | ~$500 [estimate] | Red-team operations |
The degree question. BLS lists a bachelor's degree as typical but explicitly notes entry with certifications and experience. In practice, degrees matter most for government and cleared work, visa cases, and CISO-track credibility. Portfolios plus certifications plus adjacent experience can substitute in the private sector — but in the oversupplied 2025–26 junior market, a degree functions as a tiebreaker more often than it used to. Cert-embedded degree programs such as WGU's are the common budget path.
3. Seventeen roles
1. SOC Analyst (Tier 1–3)
Skills: log analysis, SIEM (Splunk, Sentinel), Windows and Linux internals, networking, phishing triage, ATT&CK. Certs: Security+, CySA+, BTL1, and GCIA or GCIH at senior level. Salary: entry $55K–$80K, mid $80K–$110K, senior $105K–$140K. Portfolio: a home SIEM lab on Wazuh or a Sentinel free tier, documented detections, TryHackMe SOC paths, CTF writeups. Entry reality: still the widest doorway, but AI triage is compressing Tier-1 hiring — differentiate with automation skills. Progression: Tier 1 to 3, then detection engineering, threat hunting, or incident response. Misconception: "staring at dashboards forever." It is the field's residency program.
2. Security Engineer
Skills: Python scripting, infrastructure as code, identity (Okta, Entra), EDR and SIEM administration, cloud, real software-engineering practice. Certs: Security+, cloud-provider security certifications, CISSP later. Salary: mid $110K–$160K; big tech $200K–$400K+ total compensation. Portfolio: Terraform-hardened environments, detection-as-code repositories, contributions to open-source security tools. Entry: rarely a first job — arrive from sysadmin, software engineering, or the SOC. Misconception: it is an ops-heavy building role, not hacking.
3. Penetration Tester
Skills: web (OWASP), Active Directory, networking, and report writing, which is half the job. Certs: OSCP/OSCP+ or CPTS, then OSEP or OSWE. Salary: entry $80K–$105K, mid $100K–$140K, senior or lead $130K–$180K; boutique consulting bills $250–$450 per hour. Portfolio: HTB Pro Labs, published CVEs, sanitized sample reports, a bug-bounty record. Entry reality: crowded and glamorized. Consultancies hire OSCP holders who can write; expect travel and report grind. Misconception: roughly 30% hacking, 70% scoping, writing, and re-reporting the same findings — clients are paying for the report.
4. Red-Team Operator
Skills: everything in penetration testing plus detection evasion, command-and-control frameworks, tool development in C, C#, or Rust, and physical and social engineering. Certs: OSEP, CRTO, GXPN. Salary: $130K–$200K+; niche and senior-only. Path: penetration testing first, five-plus years. Misconception: not an entry field at all. Operations are tightly scoped, rules-of-engagement-bound, and mostly quiet persistence.
5. Threat Hunter
Skills: hypothesis-driven hunting, ATT&CK, EDR telemetry query languages such as KQL, intelligence consumption, statistics. Certs: GCFA or GCTI; no dedicated gate. Salary: $110K–$170K. Path: a sideways move from senior SOC or DFIR. Portfolio: published hunts, Sigma rules, hunting notebooks. The data hook: the 14-day median dwell time and 122-day espionage dwell time are the hunter's budget justification.
6. Incident Responder
Skills: containment under pressure, forensics fundamentals, ransomware playbooks, and communication with executives, insurers, and counsel. Certs: GCIH, ECIH. Salary: $95K–$150K; IR consulting seniors $150K–$200K+. Reality: on-call and surge-driven; burnout risk is real and should be named. Path: SOC to IR to DFIR, consulting, or the CISO track.
7. DFIR Analyst
Skills: disk, memory, and network forensics (Volatility, Plaso, Velociraptor, KAPE), evidence handling, malware triage, expert-witness writing. Certs: GCFA, GCFE, GNFA; EnCE for legal-heavy work. Salary: $90K–$150K corporate, $120K–$180K consulting or senior; government lower. Portfolio: solve and write up public forensic challenges on CyberDefenders and DFIR CTFs. Misconception: courtroom-grade rigor and chain-of-custody paperwork dominate. It is meticulous, not thrilling.
8. Application Security Engineer
Skills: code review and an actual developer toolchain — you must code — plus SAST, DAST, SCA, threat modeling, secure SDLC, and API security. Certs: OSWE, CSSLP; portfolio matters more than certificates here. Salary: $130K–$190K, senior or staff $180K–$250K+. Consistently among the best-paid individual-contributor roles, because the supply of security people who genuinely write code is thin. Path: usually from software engineering. The data hook: DBIR 2026's finding that 31% of breaches start with software vulnerabilities is AppSec's budget case.
9. Cloud-Security Engineer
Skills: deep AWS, Azure, or GCP; IAM; Kubernetes; IaC scanning; CSPM; detection engineering on cloud logs. Certs: AWS Security Specialty ($300), AZ-500 ($165), CCSP ($599). Salary: $120K–$180K, senior $170K–$230K. Demand hook: ISC2 2025 lists cloud security as the second-highest skills need at 36%. Portfolio: public IaC-hardening repositories, flaws.cloud and CloudGoat writeups.
10. Security Architect
Skills: enterprise architecture, zero trust, M&A due diligence, translating risk into design, breadth across domains. Certs: CISSP effectively mandatory; SABSA or TOGAF optional. Salary: $150K–$220K, principal $200K–$260K+. Path: ten-plus years through engineering. Misconception: it is a communication and diplomacy job as much as a technical one.
11. CISO
Skills: risk governance, budget defense — note that more than half of CISOs had flat or shrinking budgets in 2025 — board communication, regulatory navigation including the SEC's four-day rule, and crisis leadership. Certs: CISSP plus CISM are common. Salary: median $385,811, range roughly $315K–$471K [measured aggregator, September 2026]; large-enterprise total compensation with equity commonly $600K–$1M+. Reality: average tenure of two to four years, and personal legal exposure is now a negotiating point post-Uber and SolarWinds — D&O coverage and indemnification belong in the offer discussion.
12. Privacy Professional
Skills: GDPR, CCPA, and the state-law patchwork; data protection impact assessments; data mapping; vendor contracts. Law-adjacent and low-code. Certs: CIPP/US, CIPM; AIGP for AI governance. Salary: analyst $80K–$120K, manager $120K–$170K, privacy counsel or DPO $170K–$250K+. Entry: genuinely open to non-technical backgrounds from legal and compliance — one of the few real side doors into the field.
13. GRC Analyst
Skills: framework fluency (NIST CSF and 800-53, ISO 27001, SOC 2), risk registers, audit management, vendor risk, and writing. Certs: Security+, CISA or CISM, CRISC, CGRC. Salary: entry $65K–$90K, mid $90K–$130K, senior or manager $125K–$170K. Entry reality: the most realistic entry lane in 2025–26 — compliance-automation growth created steady demand, and the role tolerates career-changers from audit and finance. Misconception: "GRC is paperwork." Good GRC people run the risk conversation that decides budgets.
14. Security Researcher
Skills: vulnerability research, fuzzing, reverse engineering, exploit development, or data-driven threat research — plus publishing. Certs: mostly irrelevant; OSED and OSEE signal exploit-development ability. Salary: $120K–$200K+, with top vendor labs and bug-bounty elites well beyond. Path: demonstrated work — CVEs, conference talks, blog posts — is the entire currency. Reality: a tiny job pool with superstar economics.
15. Malware Analyst / Reverse Engineer
Skills: x86 and ARM assembly, IDA or Ghidra, debuggers, unpacking, C and C++, sandboxing, YARA. Certs: GREM. Salary: $100K–$160K, senior $150K–$200K at AV vendors, major IR firms, FFRDCs, and the intelligence community. Portfolio: published analyses of real families using public sandbox samples. Misconception: AI summarizes strings, but humans still do the hard unpacking. Demand is stable and supply is scarce.
16. Cybercrime Investigator
Skills: OSINT, blockchain tracing, legal process, fraud patterns, forensics fundamentals. Employers: FBI, Secret Service, HSI (roughly GS-10 to GS-14, $60K–$130K [measured federal scales]), state and local agencies, exchanges, and fintech financial-intelligence teams ($90K–$160K). Certs: CFE, GIAC, agency academies. Reality: the government route means academies, clearances, polygraphs, and mobility requirements. Private crypto-investigation demand grew alongside the ransom-tracing economy.
17. Security Awareness Specialist
Skills: instructional design, communications and marketing, behavioral science, phishing-simulation platforms, and metrics beyond click rate. Certs: SANS SSAP; nothing gates the field. Salary: $70K–$120K, program leads $110K–$150K. Entry: open to educators and marketers pivoting in. The data hook: the persistent ~62% human-element share of breaches justifies the function — but so does the honest caveat that behavior-change evidence is mixed, which makes measurement skills the differentiator.
4. Learning paths
The beginner sequence
IT fundamentals → ISC2 CC or CompTIA Security+ → a home lab with public writeups → an adjacent IT, GRC, or SOC job → specialize in years two to four → a senior certification (OSCP, CISSP, or a GIAC) only when it unlocks a specific job.
Free-first resources, in the order they are worth doing
- PortSwigger Web Security Academy — free, and the best structured web-security curriculum that exists.
- OverTheWire — free Linux and command-line fundamentals through wargames.
- TryHackMe — the gentlest guided on-ramp, with free content and roughly $126/year premium.
- picoCTF / CyLab Security Academy — free, and the standard student entry point.
- CyberDefenders and Blue Team Labs Online — free tiers for defensive and DFIR practice.
- Hack The Box — free active machines, with VIP+ around $223/year and Academy from $96/year for students.
- A home lab — virtualization plus deliberately vulnerable targets (Juice Shop, DVWA, VulnHub, Metasploitable) plus a small Active Directory environment plus free detection tooling, all on an isolated host-only network.
A budget path to employable
Roughly $1,500 total: Security+ ($404) plus a year of TryHackMe and HTB ($200) plus CPTS ($210) or CySA+ ($423) plus used lab hardware. Contrast this explicitly with $8,800 SANS courses, which employers — not individuals — should fund.
What employers actually value in 2026
Practical, proctored, report-producing certifications. OSCP and OSCP+ remain the top HR filter, with CPTS and PNPT rising as proof of real skill. Alongside that: lab rankings, CTF results, home-lab writeups, open-source contributions, and bug-bounty acknowledgments. Multiple 2026 guides converge on two findings — hands-on beats multiple-choice, and report-writing and communication are the differentiator between otherwise equivalent candidates. That is exactly why PNPT and CPTS-style exams, which require a professional report and a live debrief, are gaining employer respect.
5. Cross-cutting career advice for the site
- Sequence matters more than credentials. Fundamentals, then one entry certification, then demonstrable work, then a job adjacent to security, then specialization.
- Portfolio beats certificate in a tiebreak. A public repository with detections, IaC, or writeups; a documented home lab; one meetup or conference talk.
- Publish a skepticism module. Any bootcamp promising a six-figure job in six months, citing millions of unfilled roles, is selling against the data in section 1. Saying so builds more trust than any other single page on a careers section.
- Name the side doors. GRC and privacy are the two genuinely accessible entry lanes for career-changers, and almost nobody writes about them well.
- Cover the AI angle without hype. 41% of organizations cite AI security as their top skill need. Every role above now has an AI-adjacent differentiator: AI governance for GRC and privacy, LLM application security for AppSec, AI-assisted detection engineering for the SOC.
- Be honest about burnout. Incident response and SOC work are surge-driven and on-call. Publishing that alongside the salary tables is what separates a credible careers section from a recruiting funnel.