How to Get Into Cybersecurity: Steps & $129,180 Median Pay

If you want to know how to get into cybersecurity without prior experience, this guide gives you a realistic route. You will see what information security analysts earn according to official US wage data, which states pay the most, and a step-by-step plan you can start this month. We also cover typical certification and training costs as ranges, an honest look at the downsides, and how to search for openings. It will not promise a job or a shortcut. It will help you decide whether to spend your time and money on this path.

Data updated October 2026 using official wage statistics and live job listings.

Key facts

  • Occupation: Information Security Analyst (SOC 15-1212)
  • Median annual pay: $129,180 (BLS OEWS, May 2025)
  • Mean annual pay: $132,510
  • Pay range: $75,090 (10th percentile) to $199,850 (90th percentile)
  • Employed nationally: 190,650
  • Highest state median in the data: Washington, at $154,940

What an entry-level cybersecurity job really involves

“Cybersecurity” is a broad field, not a single job. The official occupation closest to what most career changers aim for is Information Security Analyst, which the Bureau of Labor Statistics tracks under SOC code 15-1212. These analysts monitor systems for threats, investigate alerts, help respond to incidents and recommend ways to protect an organization’s data.

Almost nobody starts as a senior analyst. The usual doors for beginners are narrower roles, such as:

  • Security operations (SOC) analyst, tier 1: watching alerts, triaging them and escalating real problems.
  • IT help desk or systems administration: the most common stepping stone, because you learn how networks, accounts and devices work.
  • Vulnerability or compliance analyst: scanning systems, tracking fixes and documenting controls against standards.
  • Junior security or GRC (governance, risk and compliance) roles: policy, audits and risk work, often with less hands-on technical depth.

Job titles vary a lot between employers, so read the duties in each posting rather than relying on the title alone.

Cybersecurity salary: what official data shows

The most reliable pay source is the BLS Occupational Employment and Wage Statistics program. For information security analysts, the national median annual wage was $129,180 (BLS OEWS, May 2025), with 190,650 people employed in the occupation.

Be careful reading that number as a starting salary. The median covers all analysts, including experienced ones. The 10th percentile of $75,090 is a better guide to the lower end of the pay scale, and entry-level roles often sit nearer to it than to the median. The 90th percentile is $199,850.

Information Security Analyst annual wages, United States and top-paying states. Source: BLS OEWS, May 2025.
Measure / locationAnnual wage
National 10th percentile$75,090
National median$129,180
National mean$132,510
National 90th percentile$199,850
Washington (state median)$154,940
Maryland (state median)$139,640
California (state median)$138,570
Massachusetts (state median)$136,550
Colorado (state median)$135,220
Virginia (state median)$134,900
New Jersey (state median)$134,820
New York (state median)$134,660
North Carolina (state median)$131,540
Texas (state median)$129,890

State medians in the data run lower in some places too. Indiana’s median is $101,420 and Missouri’s is $103,440. Even so, those figures are well above many other occupations. Remember that higher pay in a state often comes with a higher cost of living, so compare take-home value and not just the headline number.



How to get into cybersecurity: a step-by-step plan



This plan assumes you are starting from zero and working part-time on it. Treat the timelines as rough guides. Your pace, background and local job market will change them.

  1. Pick a target role this week. Choose one or two from the list above, such as SOC analyst or vulnerability analyst. Read ten real job postings and note the repeated skills and certifications. That is your syllabus.
  2. Learn IT fundamentals first (about 1 to 3 months). Cover networking basics (IP addresses, DNS, ports), operating systems (Windows and Linux), and how user accounts and permissions work. Skipping this is the most common reason beginners stall.
  3. Build a home lab (ongoing, often free). Use free virtualization software to run a couple of virtual machines. Practice installing systems, reading logs and changing settings. Write down what you did and learned.
  4. Practice on free training platforms. Beginner-friendly capture-the-flag sites and guided security labs let you practice defensive and offensive skills legally. Keep a short record of what you complete.
  5. Earn one foundational certification (about 2 to 6 months of study). Entry-level employers often recognize CompTIA Security+ or similar credentials. See the next section for costs.
  6. Create proof of skill. Publish two or three write-ups: a lab walkthrough, an incident-analysis exercise, or a short risk assessment of a fictional small business. Hiring managers often care more about evidence than about course names.
  7. Apply broadly, including adjacent roles. Apply to help desk, IT support, junior SOC and compliance roles at once. A first IT job followed by an internal move to security is a common and realistic route.
  8. Network deliberately. Join local security meetups or online communities, ask for informational chats, and tailor your resume to each posting’s wording.

For a full beginner, a realistic window from starting to a first IT or security job offer is often several months to a year or more. A degree can help, since employers commonly list a bachelor’s degree in computer science or a related field, but many people enter through certifications, IT experience and demonstrable skills. Check the BLS Occupational Outlook Handbook for the current education requirements for this occupation.

Certifications, costs and realistic timelines

Costs vary by provider, and prices change often, so the figures below are broad ranges. Check each official site for current fees before you budget.

  • CompTIA (A+, Network+, Security+): exam vouchers typically cost from around a couple of hundred dollars to a few hundred dollars each. Check CompTIA’s official site for current prices and any retake policy.
  • ISC2 Certified in Cybersecurity (CC): an entry-level option from ISC2. Fees and any promotions change, so confirm on ISC2’s site.
  • Higher-level credentials (CISSP, CISM, GIAC): usually require professional experience, cost more, and are not first-job credentials. Look at ISC2, ISACA and GIAC for requirements.
  • Study materials: free videos, library resources and low-cost practice exams can keep spending modest. Paid bootcamps can cost thousands of dollars, so research their outcomes and reviews carefully before committing.
  • Degrees: community college programs and online bachelor’s programs vary widely in cost. Check with accredited institutions and your state’s financial aid office.

A sensible low-budget path is to start with free fundamentals, buy one or two exam vouchers, and add paid training only if you hit a gap. Some employers and workforce agencies offer training funds or tuition help, so ask your local American Job Center about eligibility.

Some federal and defense-related roles also require background checks or security clearances, which an employer must sponsor. You cannot normally obtain one on your own. Check the job posting and the relevant agency’s guidance.

Where the jobs are right now

This edition of the guide does not include a live vacancy feed, so we are not quoting an opening count or naming specific hiring employers. Rather than guess, here is what the official data does tell you about where the work is concentrated.

The 190,650 information security analysts counted by BLS work across the country. The highest median wages in the data are in Washington ($154,940), Maryland ($139,640), California ($138,570), Massachusetts ($136,550) and Colorado ($135,220). Virginia, New Jersey and New York follow closely. These are good places to start searching if you are willing to relocate or work remotely for employers based there.

To find current openings yourself:

  • Search on a mix of titles: “security analyst,” “SOC analyst,” “junior cybersecurity,” “IT support,” “help desk” and “compliance analyst.”
  • Filter by “entry level” but also read the requirements, since some “entry-level” postings still ask for experience. Apply anyway if you meet most of them.
  • Check state and local government job sites, universities, hospitals, banks and managed service providers. Many of these hire for IT roles that lead into security.
  • Set up email alerts so you can apply early, and join our WhatsApp job alerts group above for updates.

Is cybersecurity right for you?

The upsides:

  • Strong pay compared with many fields, with a median of $129,180 (BLS OEWS, May 2025).
  • Many different specialties, so you can move between technical, investigative and policy-focused work.
  • Skills transfer across industries, and many jobs can be done remotely or in a hybrid arrangement.
  • Constant learning keeps the work interesting if you like solving puzzles.

The downsides:

  • The first job is the hardest to land. Many “entry-level” postings still ask for experience, certifications or both.
  • Entry pay is often well below the median, closer to the lower end of the range ($75,090 at the 10th percentile).
  • Some roles involve shift work, on-call duty or high stress during incidents.
  • You must keep learning as threats and tools change, and certifications need renewal.
  • Alert fatigue and repetitive monitoring work are real in first-tier roles.

If you enjoy troubleshooting, are curious about how systems break, and can tolerate a slow first year, it is a reasonable bet. If you want quick results with no technical study, it may not be.

Frequently Asked Questions

Is cybersecurity a high-salary career?

By official data, yes. The national median for information security analysts is $129,180, and the 90th percentile is $199,850 (BLS OEWS, May 2025). Beginners usually earn less than the median, and pay varies by state, employer and role.

Can you make $500,000 a year in cybersecurity?

That is far above what the BLS data shows for analysts, whose 90th percentile is $199,850. Pay at that level, if it happens at all, is typically tied to rare senior or executive positions, equity or consulting income, not a typical career path. Do not plan around it.

Is cybersecurity a 9-to-5 job?

Some roles are standard business hours, especially compliance, policy and many analyst positions. Others, such as security operations centers and incident response, can involve shifts, weekends or on-call duty. Ask about schedules in every interview.

Can I get into cybersecurity without a degree?

Many people do, but it takes deliberate effort. Employers often list a degree, yet they also hire candidates who show IT experience, a foundational certification and proof of hands-on skill. Starting in IT support is a common route. Check the BLS Occupational Outlook Handbook for the typical education level.

What kinds of cybersecurity jobs are there?

Common areas include security operations and monitoring, incident response, vulnerability management, network and cloud security, application security, identity and access management, and governance, risk and compliance. Each has a different skill mix, so pick one to focus on first.

Sources

  • U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics (OEWS), May 2025: https://www.bls.gov/oes/
  • Google search results for “how to get into cybersecurity” (US), October 2026, used to shape the FAQ
  • Official bodies to check for current fees and requirements: CompTIA, ISC2, ISACA, GIAC, the BLS Occupational Outlook Handbook, and your local American Job Center

Cybersecurity rewards steady, practical effort, so pick your first target role today and take the first small step.



Tinashe Motsi
Tinashe Motsi

Career expert and founder of Universal Job Board, dedicated to connecting professionals with top-tier global opportunities.

Articles: 332