Tech · Updated 16 September 2026

Cybersecurity Analyst salary and career roadmap

Detect, investigate and contain attacks on a company's systems, in an occupation BLS puts at a $129,180 median wage and 21% projected growth to 2035 - the fastest of any major tech role.

Salary data checked · outlook from BLS projections released · by Bilal Tahir

$129,180 a yearMedian wage (BLS, May 2025) source
$124,000 a yearMedian total comp (Levels.fyi, US) source
$90,000 a yearEntry-level median total comp (Levels.fyi) source
$180,000 a yearSenior analyst median (Levels.fyi) source
More than $199,850 a yearTop 10% wage (BLS) source
21% growth, 2025 to 2035Projected growth 2025-2035 source
14,100 US openings a yearOpenings per year source
12-30 monthsTime to first job source
What it is
A Cybersecurity Analyst is the person who watches for and responds to things that should not be happening on a company's systems: triaging security alerts, investigating the real ones, containing incidents, and tuning the detections so the noisy alerts stop arriving.
Salary
A Cybersecurity Analyst in the United States earns a median of $90,000 entering the field, $124,000 at mid-career and $180,000 at senior level; the top end is $227,000. (BLS Occupational Employment and Wage Statistics, May 2025 (SOC 15-1212 Information Security Analysts), widened with Levels.fyi United States security analyst reports, )
Outlook
Employment is projected to grow 21% over the ten years to 2036, with about 14,100 US openings a year. (BLS Occupational Outlook Handbook, 15-1212 Information Security Analysts, )
Time to first job
A career changer starting from zero typically needs 12 to 30 months at 10-15 hours a week to reach a first offer.
Cost to get in
The cheapest verified route in (Compliance and GRC side door) costs about $400; the most expensive costs about $2,200.
Roadmap
Our Cybersecurity Analyst roadmap is 8 steps and about 1,230 study hours; the fastest route in is Managed security service provider (MSSP) at about 9 months.
Degree
The US Bureau of Labor Statistics lists a bachelor's degree as the typical entry-level education for information security analysts and many postings ask for one, but this field has a stronger tradition than most of hiring on demonstrated skill, and CompTIA Security+ plus a public detection lab plus two years of IT experience substitutes effectively outside federal roles and large regulated employers.
Automation exposure
Low. Tooling now handles alert enrichment and first-pass triage, which is exactly the tier-1 work a career changer used to be hired to do, so the automation is compressing the entry layer rather than the occupation. What does not automate is taking responsibility during a live incident: deciding to isolate a production host, judging what an attacker did with the access they had, and explaining to a board why customer data was exposed.

What does a Cybersecurity Analyst do?

A Cybersecurity Analyst is the person who watches for and responds to things that should not be happening on a company's systems: triaging security alerts, investigating the real ones, containing incidents, and tuning the detections so the noisy alerts stop arriving. A cybersecurity analyst is the person watching for, and responding to, things that should not be happening: a login from two countries twenty minutes apart, a server reaching out to an address nobody recognises, a phishing campaign against the finance team. The same work is also posted as SOC Analyst, Security Analyst, Information Security Analyst, Security Operations Analyst, Incident Responder.

A cybersecurity analyst is the person watching for, and responding to, things that should not be happening: a login from two countries twenty minutes apart, a server reaching out to an address nobody recognises, a phishing campaign against the finance team. In a security operations centre (SOC) the work is triage - alerts arrive, you decide within minutes whether each one is noise or an incident, you escalate the real ones and you tune the detection so the noisy ones stop arriving. In a smaller company the same person also does vulnerability management, access reviews, phishing training and the annual compliance audit.

The people who last are pattern-matchers with patience. You need to be comfortable with ambiguity (most alerts resolve to 'probably nothing, here is why I think so'), meticulous about documentation because your notes become evidence, and able to say something uncomfortable to a senior person without making an enemy. Curiosity about how systems break is the core trait; a background in IT support, networking, help desk or even fraud investigation transfers well.

The honest tradeoffs. First, 'entry level' in this field usually means two to four years of IT experience first - the widely repeated claim of a huge talent shortage is true at the mid and senior level and much less true for people with no experience at all, where SOC analyst postings routinely draw hundreds of applicants. Second, shift work: many SOCs run 24/7, and your first role may well be nights or a rotating schedule. Third, the pay distribution is wide and bimodal. BLS puts the information security analyst median at $129,180, but that occupation code includes experienced engineers; Levels.fyi entry-level security analyst reports have a median total compensation of $90,000, and a first tier-1 SOC job outside a major metro is commonly $55,000-$75,000. The ramp from there is steep if you keep specialising.

Why Cybersecurity Analyst pay is high

Security is priced against loss, not against effort. A single breach carries regulatory penalties, litigation, incident-response retainers, customer churn and, for public companies, disclosure obligations, so the expected cost of an undetected intrusion at a mid-sized firm dwarfs a security team's payroll. The work is also non-deferrable and adversarial: unlike most IT projects, you cannot postpone it to next quarter, because there is a human on the other side actively trying to get in. Meanwhile the supply of people who can both operate the tooling and reason about an attacker's next move is thin, and it is thinned further by clearance requirements in the government and defence sectors. BLS projects 21% employment growth for information security analysts between 2025 and 2035, several times the all-occupations average, which keeps upward pressure on wages.

What's good

  • 21% projected growth from 2025 to 2035, the fastest of any large computing occupation (BLS)
  • Certifications carry real screening weight, which helps candidates without a degree
  • Demand in every sector: healthcare, finance, government, retail, manufacturing, not only tech companies
  • Work is genuinely interesting and adversarial; the problem set changes with the threat landscape
  • Clear specialisation ladders into cloud security, detection engineering, IR and architecture, each with a pay step
  • A security clearance, once held, is a durable and portable advantage

What's hard

  • Entry is harder than the 'skills shortage' headlines suggest; tier-1 SOC openings draw very large applicant pools
  • Shift work, nights and weekends are common in the first role
  • Alert fatigue and burnout are endemic; the field's turnover is high for a reason
  • You are judged on the incidents that happen, not the hundreds that did not
  • Constant study outside work hours to keep up, and certifications expire and cost money to renew
  • The pay range at the bottom is much lower than the BLS median implies: Levels.fyi entry-level reports sit at a $90,000 median, and non-metro tier-1 roles are often $55,000-$75,000

What a Cybersecurity Analyst does all day

  • 07:00 Shift handover: read the overnight notes and pick up the two open investigations
  • 07:30 Work the alert queue - phishing reports, impossible-travel logins, endpoint detections, most of which are benign
  • 09:30 A genuine one: a user's token is being used from an unfamiliar ASN. Contain the session, force a reset, check what was accessed
  • 11:00 Write the incident record while it is fresh, because it may be read by legal or an auditor in a year
  • 12:30 Tune the rule that generated forty false positives yesterday and document why the threshold changed
  • 14:00 Vulnerability review with the infrastructure team: which of this month's CVEs actually reach your environment
  • 15:30 Threat-hunt an hour against one ATT&CK technique rather than waiting for an alert
  • 16:30 Answer a security questionnaire from a customer's procurement team, which is more of the job than anyone expects
  • Shift patterns: many SOCs run 24/7, so nights, weekends and rotating schedules are common in the first role

Cybersecurity Analyst salary in 2026: by level

US, annual, USD. Base plus typical bonus where the source reports it.

A US Cybersecurity Analyst earns a median of $90,000 entering the field, $124,000 at two to four years and $180,000 at senior level, with the top end at $227,000. These are base-salary figures in US dollars as of September 2026, synthesised from BLS Occupational Employment and Wage Statistics, May 2025 (SOC 15-1212 Information Security Analysts), widened with Levels.fyi United States security analyst reports. Pay varies about 15-30% by metro.

BLS OEWS (May 2025) gives information security analysts a median annual wage of $129,180 across 192,900 US jobs, with the lowest 10% under $75,090 and the highest 10% over $199,850. That code covers engineers and architects as well as analysts, so it overstates a first job. Levels.fyi US security analyst reports (n=560, retrieved 15 September 2026) run $74,000 (10th pct), $93,000 (25th), $124,000 (median), $180,000 (75th), $227,000 (90th), with a base median of $120,000 - note the small equity component compared with software engineering. Levels.fyi entry-level security analysts (n=83, a thin sample) report $58,000 / $78,100 / $90,000 / $100,000 / $113,000 across those percentiles, and senior analysts (n=241) report $104,000 / $139,240 / $180,000 / $222,000 / $286,250. Three things move pay sharply: a US security clearance (commonly a 10-20% premium with defence contractors), moving from detection into offensive security or cloud security engineering, and geography. Consultancy and managed-security-provider roles pay less than in-house at the same level but compress experience.

21%projected 10-year growth
14,100openings per year
lowautomation exposure

BLS projects information security analyst employment to grow 21% from 2025 to 2035, much faster than average, from a 2025 base of 192,900 jobs, with about 14,100 openings a year including replacement needs. That is the strongest ten-year outlook of any large computing occupation. Automation risk is low: tooling automates enrichment and triage of routine alerts, which raises the bar for tier-1 work but increases demand for people who can investigate, tune detections and respond to a live incident. The realistic caveat is that the growth is concentrated above the entry line - the same pipeline compression affecting junior developers applies here, with tier-1 SOC roles attracting very large applicant pools. The field's stated 'skills gap' is real for people with three or more years of hands-on experience and much softer for those with none, which is why the roadmap below routes through an IT role rather than straight into security.

“Employment of information security analysts is projected to grow 21 percent from 2025 to 2035, much faster than the average for all occupations.”

US Bureau of Labor Statistics, Occupational Outlook Handbook, Information Security Analysts, source,

Cybersecurity Analyst salary by city

National bands scaled by metro wage differentials from the BLS May 2025 OEWS release.

Cybersecurity Analyst pay is highest in San Jose / Silicon Valley (mid-career median about $176,080, ×1.42 the national figure) and lowest among large metros in Salt Lake City (about $117,800). The multiplier moves the offer, not what you keep after rent and state tax.

Cybersecurity Analyst median pay by US metro, 2026, USD per year, derived from the national bands above.
MetroEntryMidSeniorvs national
San Jose / Silicon Valley$127,800$176,080$255,600×1.42
San Francisco Bay Area$121,500$167,400$243,000×1.35
New York City$115,200$158,720$230,400×1.28
Seattle$108,000$148,800$216,000×1.2
Boston$103,500$142,600$207,000×1.15
Washington DC metro$100,800$138,880$201,600×1.12
Los Angeles$97,200$133,920$194,400×1.08
Chicago$94,500$130,200$189,000×1.05
Austin$94,500$130,200$189,000×1.05
San Diego$93,600$128,960$187,200×1.04
Denver$91,800$126,480$183,600×1.02
Philadelphia$91,800$126,480$183,600×1.02
Dallas$90,000$124,000$180,000×1.0
Minneapolis$90,000$124,000$180,000×1.0
Raleigh-Durham$90,000$124,000$180,000×1.0
Houston$89,100$122,760$178,200×0.99
Atlanta$88,200$121,520$176,400×0.98
Phoenix$85,500$117,800$171,000×0.95
Miami$85,500$117,800$171,000×0.95
Salt Lake City$85,500$117,800$171,000×0.95

A multiplier raises the number on the offer letter, not what you keep. San Francisco pays about 35% more than the national median for these roles, but median Bay Area rent and California state income tax eat most of that for anyone below the senior rung. Texas, Florida, Washington, Tennessee and Nevada levy no state income tax, which is worth roughly 4-10% of take-home versus California or New York City, where city tax stacks on top of state tax. Run the comparison on after-tax income minus housing before you move. Fully remote roles are the edge case worth chasing: a national pay band spent in a 0.88 cost market beats a 1.35 salary spent in a 1.6 cost market for most people.

How the multipliers are derived

Anchor: the BLS May 2025 OEWS national mean wage across all occupations is $33.54/hr ($69,770/yr). Metro all-occupation means from the same release: San Jose-Sunnyvale-Santa Clara $57.32 (1.71x national), San Francisco-Oakland-Fremont $48.19 (1.44x), Washington-Arlington-Alexandria $44.20 (1.32x), Seattle-Tacoma-Bellevue $44.13 (1.32x), Boston-Cambridge-Newton $43.09 (1.28x), New York-Newark-Jersey City $41.50 (1.24x), Denver-Aurora-Centennial $39.28 (1.17x), Atlanta-Sandy Springs-Roswell $34.57 (1.03x), Chicago-Naperville-Elgin $34.42 (1.03x, May 2024), Dallas-Fort Worth-Arlington $33.96 (1.01x), Phoenix-Mesa-Chandler $33.48 (1.00x). We damp the top end of those raw ratios. All-occupation means exaggerate the gap for the careers on this site, because national pay bands, remote hiring and company-wide equity grids compress geographic spread for high-skill professional roles more than they do for service and hourly work. Levels.fyi shows the same damping: its Bay Area software engineer average total compensation of about $291k sits roughly 1.3x-1.4x the US median, not 1.7x. Non-US multipliers convert local market rates to USD and are directional, not survey-grade.

How to become a Cybersecurity Analyst

Every route we could verify, with honest time, cost and difficulty.

There are 6 routes we could verify into Cybersecurity Analyst work. The fastest is Managed security service provider (MSSP) at about 9 months; the cheapest is Compliance and GRC side door at about $400. The route that produces most first hires is not the one people plan: a help desk, desktop support, systems administration or managed security service provider job at $45,000 to $65,000 first, owning phishing triage and access reviews from inside, and transferring to the security team in 18 to 30 months, because a tier-1 security operations centre posting can draw hundreds of applicants who all hold the same certificate you do.

Help desk or IT support, then internal move to security

The standard route. Get an IT support or systems role ($45,000-$65,000), earn Security+, volunteer for phishing triage, access reviews and patching, and transfer to the security team in 18-30 months. Employers usually fund the certifications once you are inside.

24 months$600 cost

Certificate-plus-labs into a tier-1 SOC

Google Cybersecurity Professional Certificate plus CompTIA Security+ plus a serious lab record (TryHackMe SOC path, Hack The Box Junior Cybersecurity Analyst path) and a home detection lab. Possible directly, but competitive; expect a long search and be willing to take shift work.

12 months$900 cost

Managed security service provider (MSSP)

MSSPs hire in volume, train in-house and run 24/7 shifts, so they take candidates that in-house SOCs will not. Pay is lower and the pace is relentless, but two years there is worth four elsewhere in exposure.

9 months$600 cost

Government, defence or cleared work

US federal and contractor roles often require Security+ for DoD 8140 compliance and will sponsor a clearance for the right candidate. Slower hiring process, but the degree filter is weaker, training is funded and a clearance is a durable pay premium.

18 months$500 cost

Offensive security / penetration testing

Hack The Box and TryHackMe to a high rank, then OSCP ($1,749 for the course and exam bundle). Harder to enter cold than defensive work and smaller in headcount, but it is the one branch where a portfolio of proven exploitation can outweigh both a degree and prior employment.

18 months$2k cost

Compliance and GRC side door

Governance, risk and compliance roles (audit support, vendor risk, evidence collection) hire people from finance, audit, legal and project management backgrounds with far less technical depth, pay reasonably, and give you a legitimate security title to move from.

9 months$400 cost

Cybersecurity Analyst roadmap: 8 steps, 1,230 hours

Turn it into dates ·

Becoming a Cybersecurity Analyst from zero takes about 1,230 study hours across 8 steps, roughly 12 to 30 months at 10-15 hours a week plus a job search. Step one is IT and networking fundamentals before anything labelled 'hacking'. Networking and operating system fundamentals come before anything labelled hacking because you cannot recognise abnormal traffic without knowing exactly what normal looks like, and this is where self-taught candidates most often fail an interview - naming ten attack techniques but unable to explain a three-way handshake. The home detection lab sits at step three rather than at the end because it is the artefact that separates you from the other applicants with the same certificate.

  1. 1

    How a packet gets from a browser to a server and back: TCP/IP, DNS, DHCP, NAT, HTTP and TLS, ports and firewalls. Windows and Linux administration: users and groups, permissions, services, the event log and journald, the registry, process listings. Build a small home network with a virtual machine or two and break it on purpose.

    Why now: You cannot recognise abnormal traffic without knowing exactly what normal looks like. Every credible security interviewer probes fundamentals first, and this is where self-taught candidates most often fall down - they can name ten attack techniques but cannot explain a three-way handshake.

    120 h this step120 h cumulative
  2. 2

    Threats and attack types, cryptography basics, identity and access management, secure network design, risk and governance, and incident response terminology. Study the SY0-701 objectives directly rather than only watching videos, and do the performance-based question practice.

    Why now: Security+ is the most-screened entry credential in the field and it is the DoD 8140 baseline, which matters for any government or defence-adjacent employer. It will not by itself get you hired, but its absence will get you filtered out of a large share of postings.

    100 h this step220 h cumulative
  3. 3

    Stand up a small environment: a Windows machine with Sysmon, a Linux server, and a free SIEM (Wazuh, Security Onion or a Splunk free licence). Ship the logs in, generate real activity including some malicious simulation, then write detection rules that catch it. Document every detection with the ATT&CK technique it maps to.

    Why now: This is the artefact that separates you from the other three hundred applicants with the same certificate. Being able to say 'here is my repo of twelve detection rules, here is what each catches and here is the false-positive rate I measured' is a completely different conversation from 'I have Security+'.

    140 h this step360 h cumulative
  4. 4

    Work the defensive paths properly: TryHackMe's SOC Level 1 and Cyber Defence content, and Hack The Box Academy's Junior Cybersecurity Analyst and SOC Analyst job-role paths. Do the offensive basics too, because you cannot detect what you do not understand, but keep the centre of gravity defensive if you want a first job faster.

    Why now: Employers want hours at a keyboard, and these platforms produce a public, verifiable record of them. HTB Academy's SOC Analyst path also terminates in the CDSA certification ($490 including the exam), which is hands-on rather than multiple-choice and is increasingly recognised by SOC hiring managers.

    200 h this step560 h cumulative
  5. 5

    Python for parsing logs, calling APIs and automating enrichment; PowerShell for Windows investigation. Then get fluent in one query language - SPL for Splunk, KQL for Microsoft Sentinel and Defender - to the point where you can write a detection and a hunt from a blank editor.

    Why now: Query fluency is the single most testable skill in a SOC interview and the one that most distinguishes a tier-2 analyst from a tier-1 one. Automation skill is what stops you from being replaced by the automation.

    120 h this step680 h cumulative
  6. 6

    Apply to help desk, desktop support, systems administration, NOC and MSSP roles as well as tier-1 SOC openings. Once inside: own phishing triage, run the vulnerability scan report, do the quarterly access review, write the incident notes nobody else wants to write, and tell the security team you want in.

    Why now: This is the step people try hardest to skip and regret skipping. A tier-1 SOC posting can attract hundreds of applicants, most of whom have the same certificate you do; almost none of them have two years of demonstrated production troubleshooting. Internal transfer conversion rates dwarf cold applications, and your employer will usually pay for the next certification.

    100 h this step780 h cumulative
  7. 7

    After 18-24 months in a security seat, pick a lane. Cloud security (AWS/Azure security services, identity, posture management) has the strongest demand and pay. Detection engineering suits people who like building. Incident response and forensics suits people who like the crisis. Offensive security is the smallest branch and the hardest to enter, but OSCP is the credential that opens it.

    Why now: Generalist analysts plateau around the BLS median. The jump from roughly $100,000 to $180,000 (the Levels.fyi senior analyst median) comes from a specialism plus a track record, not from another broad certificate.

    250 h this step1,030 h cumulative
  8. 8

    Once you have five years of paid experience across at least two of the eight CISSP domains (or four years plus a qualifying degree or credential), sit CISSP. Before you qualify, the Associate of ISC2 route lets you pass the exam and hold the credential in waiting.

    Why now: CISSP is a management and architecture credential, not an analyst one, and it is the single most common requirement in senior and lead security postings - including many that pay above the BLS 90th percentile of $199,850. Budget $749 for the exam plus a $135 annual maintenance fee. Do not take it early; without the experience it signals a candidate who studies rather than one who has responded to an incident.

    200 h this step1,230 h cumulative

Best certifications for a Cybersecurity Analyst

Which ones matter, what they cost, and how often people pass.

No certification is legally required, but CompTIA Security+ is close to mandatory in practice: it is the most-screened entry credential and an approved Department of Defense 8140 IAT Level II baseline, so its absence filters you out of a large share of federal and defence-contractor postings. The voucher is $439 direct from CompTIA, raised from $425 on 1 June 2026, or about $373 to $395 through authorised resellers, on 80 to 150 hours of study. The Google Cybersecurity Professional Certificate at roughly $147 to $294 over three to six months is a curriculum rather than a credential - useful because it maps to the Security+ objectives and comes with a discounted voucher, but no employer screens on it. Leave CISSP ($749 plus a $135 annual maintenance fee) until you have the five years of experience it requires.

high value

CompTIA Security+ (SY0-701, V7)

CompTIA

Cost
$439 exam voucher from the CompTIA store (raised from $425 in June 2026); authorised resellers discount to roughly $373, and academic vouchers run 40-50% lower
Study
80-120
Pass rate
Not published; maximum 90 multiple-choice and performance-based questions in 90 minutes, pass mark 750 on a 100-900 scale, three-year renewal via continuing education
medium value

Google Cybersecurity Professional Certificate

Google (on Coursera)

Cost
$49/month after a 7-day free trial, or included in Coursera Plus ($59/month or $399/year); most learners finish for under $300
Study
About 170 (Coursera lists 6 months at 7 hours a week across 9 courses)
Pass rate
n/a - completion-based; rated 4.8 from 69,190 reviews with 1,615,669 enrolled
medium value

HTB Certified Defensive Security Analyst (CDSA)

Hack The Box

Cost
$490 including the exam and the 15-module SOC Analyst path
Study
150-250
Pass rate
Not published; hands-on defensive exam with a report deliverable
high value

CISSP (Certified Information Systems Security Professional)

ISC2

Cost
$749 exam fee plus a $135 annual maintenance fee
Study
150-250
Pass rate
Not published by ISC2; requires five years of paid experience in at least two of the eight domains, or the Associate of ISC2 route while you accrue it
high value

OSCP+ / PEN-200 (Offensive Security Certified Professional)

OffSec

Cost
$1,749 Course + Cert bundle (90 days of lab access and one exam attempt); $2,749/year Learn One (one year of access and two attempts); $1,699 exam only
Study
300-600
Pass rate
Not published; notoriously low on first attempt. 24-hour proctored practical exam: 60% standalone machines, 40% an Active Directory breach simulation, plus a report
low value

CEH (Certified Ethical Hacker)

EC-Council

Cost
$950 voucher for EC-Council remote proctoring or $1,199 at a Pearson VUE centre, plus a $100 eligibility application fee if you self-study; $499 retake; $80/year renewal
Study
80-120
Pass rate
Not published
medium value

HTB Certified Penetration Testing Specialist (CPTS)

Hack The Box

Cost
$490 including the exam and the 28-module Penetration Tester path
Study
250-400
Pass rate
Not published; practical exam with a professional report

Skills employers screen for

Networking: TCP/IP, DNS, HTTP/S, TLS, proxies, firewalls, packet analysisOperating system internals for Windows and Linux, including logging and processesSIEM query writing and alert triageLog analysis and correlation across sourcesIdentity and access management, MFA and privilege escalation pathsVulnerability management and CVSS prioritisationThe MITRE ATT&CK framework and mapping detections to itIncident response process: detect, contain, eradicate, recover, reportPhishing and malware triage, including basic static analysisScripting in Python and PowerShellCloud security fundamentals in at least one providerRegulatory basics: SOC 2, PCI DSS, HIPAA, GDPR as relevant to your sectorSplunk or Microsoft SentinelCrowdStrike, Defender for Endpoint or SentinelOneWiresharkNmapBurp SuiteElastic StackWazuh or OSSECSysinternals and SysmonNessus or OpenVASPython and PowerShellVirusTotal and OSINT toolingA ticketing system such as Jira or ServiceNow

Soft skills that decide offers: Writing incident reports that a non-technical executive can act on, Calm escalation under time pressure, Scepticism without paranoia; most alerts are benign, Explaining a risk decision to someone whose project you are slowing down, Discretion with sensitive information, Sustaining attention through long stretches of routine triage.

Best courses for a Cybersecurity Analyst

Checked on the provider's page on 16 September 2026. Some links are affiliate links.

We list 6 courses for Cybersecurity Analyst work, checked on the provider's page. Take the Google Cybersecurity Professional Certificate only if you need structured teaching to begin with, then stop paying for video and buy keyboard hours instead: a TryHackMe or Hack The Box Academy subscription at roughly $130 to $220 a year produces a public, verifiable record of practice that hiring managers can check, which no completion certificate does.

edX · Harvard University CS50's Introduction to Computer Science 110 h · Free to audit; verified certificate from $199 The single best free CS foundation: about two-thirds of CS50 students have never taken a CS course, and the C-first approach builds the mental model bootcamps skip. Coursera · Google Google IT Support Professional Certificate 122 h · Free to enroll; $49/mo for certificate; included in Coursera Plus ($59/mo or $399/yr) · ★ 4.8 The standard first rung into tech with no degree: 2.2M enrollments, aligned to CompTIA A+, and ACE-approved for up to 15 college credits. Coursera · Google Google Cybersecurity Professional Certificate 170 h · $49/mo after 7-day free trial (most finish under $300); included in Coursera Plus ($59/mo or $399/yr) · ★ 4.8 The largest entry-level security program by a wide margin (1.6M learners, 4.8 rating) and it targets the SOC analyst role specifically rather than generic security theory. Coursera · IBM IBM Cybersecurity Analyst Professional Certificate 152 h · Free to enroll; certificate included in Coursera Plus ($59/mo or $399/yr) · ★ 4.6 Fourteen courses that explicitly prepare for CompTIA Security+, the certification most US security job postings name, plus ACE credit for up to 10 credits. Coursera · Microsoft Microsoft Cybersecurity Analyst Professional Certificate 190 h · Free to enroll; includes 50% discount voucher for the SC-900 exam; included in Coursera Plus ($59/mo or $399/yr) · ★ 4.7 Most corporate security teams run on Microsoft tooling; this is the only major cert built around Azure AD and Defender with an SC-900 exam discount included. Coursera · Google Cloud Google Cloud Cybersecurity Professional Certificate 94 h · Free to enroll; included in Coursera Plus ($59/mo or $399/yr) · ★ 4.5 Cloud security analysts out-earn on-prem SOC analysts; this 94-hour cert is the shortest bridge between the two if you already hold a general security cert.

Cybersecurity Analyst interview questions and format

A Cybersecurity Analyst loop is typically three to five stages over two to six weeks: a recruiter screen, a fundamentals technical screen on networking, operating systems and common attacks, a scenario or tabletop round where you are handed alert data or a log excerpt and asked to investigate aloud, sometimes a practical lab or take-home, and a behavioural round on escalation under pressure. The stage that filters most candidates is the scenario round, because reciting the incident response phases is easy and reasoning through real log data is not.

Typically three to five stages: recruiter screen, a fundamentals technical screen (networking, operating systems, common attacks), a scenario or tabletop round where you are handed alert data or a log excerpt and asked to investigate aloud, sometimes a practical lab or take-home, and a behavioural round on escalation and handling pressure. Government and defence roles add clearance checks and a longer timeline. Offensive roles substitute a practical exploitation exam and a written report.

Questions that come up

  • Walk me through what happens when you type a URL into a browser, and where an attacker could interfere.
  • You get an alert for a successful login from a new country twenty minutes after a login from home. What do you do, in order?
  • What is the difference between symmetric and asymmetric encryption, and where is each used?
  • Explain a recent CVE that mattered and why it mattered.
  • How do you tell a false positive from a real detection, and what do you do with a rule producing too many?
  • Describe the phases of incident response and who you notify at each.
  • What is lateral movement, and which log sources would show it?
  • How would you investigate a suspected phishing email end to end?
  • Explain least privilege and how you would audit an over-permissioned account.
  • Tell me about a time you had to tell someone senior that they could not do what they wanted.

Prep

Cybersecurity Analyst FAQ

Can I become a Cybersecurity Analyst with no IT experience at all?

It happens, but it is the exception. Most people who get hired into a first security role came from help desk, systems administration, networking or software. The fastest realistic plan is to take an IT job now, earn Security+ while you are in it, do the security-adjacent work nobody else wants, and transfer in 18-30 months. If you go straight at tier-1 SOC roles, add a home detection lab and lab-platform hours, be willing to work nights, and expect a long search.

Which cybersecurity certification should I get first as a career changer in 2026?

CompTIA Security+ ($439 from CompTIA, around $373 through authorised resellers). It is the most-screened entry credential and it is the DoD 8140 baseline. Pair it with the Google Cybersecurity Professional Certificate (roughly 170 hours, $49/month on Coursera) if you want structured teaching first. Skip CISSP until you have five years of experience, and treat CEH ($950-$1,199 plus a $100 application fee if self-studying) as optional - it is widely required by HR filters in government contracting and widely disparaged by practitioners elsewhere.

Is a degree necessary to get hired as a Cybersecurity Analyst?

BLS lists a bachelor's degree as the typical entry-level education, and plenty of postings ask for one, but this field has a stronger tradition than most of hiring on demonstrated skill. Certifications, a public lab and prior IT experience substitute effectively. The degree matters most for federal roles, large regulated employers and for eventual management.

Should I aim for red team or blue team work as a Cybersecurity Analyst?

Blue team (defensive: SOC, detection, incident response) has perhaps ten times the headcount and a far more accessible entry point. Red team (penetration testing, offensive) is glamorous, smaller, and usually entered after defensive or development experience plus a hard practical credential such as OSCP ($1,749 for the course and exam bundle) or HTB CPTS ($490). Learn offensive technique either way - it makes you better at defence - but plan your first job as blue.

What does the pay actually look like at the start?

The BLS median of $129,180 covers the whole occupation, including senior engineers. A first tier-1 SOC job is commonly $55,000-$75,000 outside a major metro, and Levels.fyi entry-level security analyst reports have a $90,000 median with a $58,000 tenth percentile. The steep part of the curve comes at years three to six: senior analyst reports on Levels.fyi have a $180,000 median.

How much does the whole path into a Cybersecurity Analyst job cost?

A lean version: Google Cybersecurity Certificate at roughly $150-$250 over three to five months, Security+ at $373-$439, a lab platform subscription at roughly $130-$220 a year, and free tooling (Wazuh, Security Onion, Atomic Red Team) for the home lab. That is under $900 to be credibly employable. Optional later spends - CDSA $490, OSCP $1,749, CISSP $749 plus $135 a year - are best paid for by an employer once you are inside.

Will AI take Cybersecurity Analyst jobs over the next decade?

It is already automating alert enrichment and first-pass triage, which compresses the tier-1 layer. What it does not do is take responsibility for a live incident, decide to isolate a production host, or explain to a board why customer data was exposed. Aim past the layer being automated: learn to write detections, investigate deeply and communicate clearly, and use the tooling to cover more ground.

What does a Cybersecurity Analyst actually do all day in a security operations centre?

Mostly triage, and most of it turns out to be nothing. A shift opens with a handover and the alert queue - phishing reports, impossible-travel logins, endpoint detections - and the skill is deciding within minutes which are noise. When a real one lands, say a token being used from an unfamiliar network, you contain the session, force a reset and work out what was accessed, then write the incident record while it is fresh because legal or an auditor may read it in a year. The rest of the day is rule tuning, vulnerability review, an hour of threat hunting and customer security questionnaires.

Cybersecurity Analyst versus Cloud or DevOps Engineer: which career should I choose?

Choose Cloud or DevOps Engineer for money and stability, Cybersecurity Analyst for growth and variety. Levels.fyi puts the DevOps-focus median total compensation at $170,500 a year against $124,000 for security analysts, and the DevOps path has no shift work. Security has the stronger outlook - BLS projects 21 percent growth for information security analysts to 2035 against 8 percent for computer network architects - and certifications carry weight in both. Both routes run through the same adjacent jobs, help desk and systems administration, so you can defer the decision by 18 months.

How much does a Cybersecurity Analyst make in the Washington DC metro area?

Roughly 10 to 15 percent above the national figure, plus a clearance premium on top. The BLS median for information security analysts is $129,180 a year nationally, so the Washington DC metro sits near $142,000 to $149,000, and a US security clearance commonly adds a further 10 to 20 percent with defence contractors. That combination makes the DC area the best-paid concentration of defensive security work in the country. The trade-offs are a slower federal hiring process, a background investigation, and CompTIA Security+ as a hard requirement for Department of Defense 8140 roles.

Is Cybersecurity Analyst a good career for someone switching at 40?

Yes, with one condition: route through an IT job rather than straight at security. Age is not the filter, but zero production experience is - tier-1 postings draw hundreds of applicants holding the same certificate. Backgrounds that transfer unusually well at 40 include IT support, networking, fraud investigation, audit and compliance, the last of which opens the governance, risk and compliance side door. Expect 12 to 30 months to a first security seat, possible shift work in it, and a Levels.fyi entry-level median of $90,000 a year against a $129,180 BLS median for the whole occupation.

Sources

Every number on this page traces to one of these. Page checked 16 September 2026.

  1. bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm
  2. levels.fyi/t/security-analyst/locations/united-states
  3. levels.fyi/t/security-analyst/levels/entry-level/locations/united-states
  4. levels.fyi/t/security-analyst/levels/senior/locations/united-states
  5. comptia.org/en-us/certifications/security/
  6. isc2.org/certifications/cissp
  7. offsec.com/courses/pen-200/
  8. eccouncil.org/train-certify/certified-ethical-hacker-ceh/
  9. coursera.org/professional-certificates/google-cybersecurity
  10. academy.hackthebox.com/
  11. tryhackme.com/pricing
  12. pluralsight.com/individuals/pricing
  13. attack.mitre.org/
  14. coursera.org/courseraplus