PayCrunch Research · The exact AI playbook for your profession, sourced to the U.S. Bureau of Labor Statistics

PayCrunch AI Playbook · Technology

Chief information security officer pay by market and model

$250,590top of the range in Tennessee · middle $129,180 / yr
AI is transforming this role

Chief Information Security Officers in the United States earn a median of $129,180 a year. Pay starts near $75,090. Pay reaches $250,590 at the top of the range in Tennessee, the best-paying state for this work among those with at least 500 people in the job.

Source: U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025 (Information Security Analysts, SOC 15-1212). Last checked 9 September 2026.

Entry level
$75,090
Top of the range · Tennessee
$250,590
Education
Bachelor's or Master's in Cybersecurity
Lower disruption Higher exposure AI is transforming this role
Entry · $75,090 Top of range · $250,590 (Tennessee) Middle $129,180

Wages — U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025 (Information Security Analysts). Top of the range is the highest state-level figure among states with at least 500 people in the job. AI-impact rating is PayCrunch's editorial assessment. Updated September 2026.

🆕 New & Trending AI Tools for Chief Information Security OfficerReviewed September 2026

We track new AI-tool launches every week and refresh this list — here’s what’s gaining traction for Chief Information Security Officer work right now.

Claude CodeNEWFree / usage-based

Terminal coding agent that reads your repo, runs tests, and ships multi-file changes.

How a Chief Information Security Officer uses it: describe a feature and let it implement and test it across the codebase

OpenAI CodexNEWIncl. w/ ChatGPT plans

Agent that runs longer, deterministic multi-step coding jobs on its own.

How a Chief Information Security Officer uses it: delegate a well-defined build or migration and review the finished result

WindsurfNEWFree / $15 mo

Agentic IDE that keeps context across a whole project.

How a Chief Information Security Officer uses it: make large, coordinated changes without losing track of the codebase

AWS KiroNEWPreview / see site

Spec-driven coding agent that turns written specs into working code.

How a Chief Information Security Officer uses it: write the spec first and let it build to that spec

NotebookLMNEWFree / $7.99 mo

Google tool that answers questions grounded only in the documents you give it — with citations.

How a Chief Information Security Officer uses it: load your own manuals, policies, or PDFs and ask questions that stay accurate to the source

CursorFree / $20 mo

AI-native code editor that edits across an entire project.

How a Chief Information Security Officer uses it: describe a change in plain English and let it rewrite and refactor whole files

GitHub Copilot (Agent Mode)$10–19 mo

AI pair-programmer built into VS Code and GitHub that now completes multi-step tasks.

How a Chief Information Security Officer uses it: hand off a task and have it plan, edit multiple files, and open a pull request

ChatGPTFree / $20 mo

The most-used AI assistant — writing, analysis, research, and images from a plain-language chat.

How a Chief Information Security Officer uses it: draft emails and documents, summarize long files, and get instant answers to on-the-job questions

ClaudeFree / $20 mo

AI assistant known for careful writing, long-document analysis, and coding.

How a Chief Information Security Officer uses it: analyze big reports or spreadsheets and turn messy notes into clean, finished writing

A breach, a budget fight, and a board briefing can land on the same afternoon. The chief information security officer is the person who owns all three. You carry security risk for the organization: what happens in an incident, how the money gets spent, and what the board is told. Analysts hunt and harden. You decide what the organization will live with, what it will fix, and when the news leaves the security team.

Incidents, the budget, and the board

On a quiet week you are still making risk decisions. A business unit wants a vendor that cannot meet the control expectations you set. A product team wants to ship with a known weakness because a customer date is close. Insurance wants a clearer picture of how you would survive a ransomware event. You write down what you will accept, what you will fund, and what you will take to the chief executive because it exceeds your authority. The quiet weeks are where the bad weeks are won or lost.

On a bad week the incident channel is your room. You confirm whether customer data, operations, or money are actually at risk. You decide who is in command, when to isolate a system, and when the business impact of shutting something down is worse than the intrusion you are watching. Legal, communications, the technology lead, and the affected business sit with you. You owe them a recommendation they can act on, not a stream of raw alerts. Afterward you owe the board a plain account: what happened, who was affected, what it cost, and what will change.

The budget is the other half of the same job. You argue for people, for the few tools that close real gaps, and for the unglamorous work of identity, logging, backup, and recovery. A board that liked a demo last quarter may not like the bill for fixing the basics. Your skill is tying each dollar to a risk they already agreed matters. You also stop spending on controls that look busy and change nothing. A security chief who cannot say no to a tool is as exposed as one who cannot say no to a risky launch.

Who you face when the risk is real

You deal upward, sideways, and into the workforce. Upward is the chief executive and the board, often through an audit or risk committee. Sideways is the technology leader who owns the systems, the general counsel who owns privilege and disclosure, the finance lead who owns the insurance and the reserves, and the business presidents whose products create the risk. Downward is a team of architects, detection specialists, identity specialists, and security engineers who need priorities they can finish. If you try to be the best analyst in that room, you will abandon the decisions only you can make.

External parties show up more often than a new chief expects. Customers send security questionnaires and then ask for a conversation when the answers worry them. Regulators, depending on your industry, ask how you protect particular kinds of data. Law enforcement may be part of an incident. Insurers send their own reviewers. You decide who speaks for the company and what is said. A careless sentence in those rooms can cost as much as the incident itself. Prepare your leads so the story stays accurate when you are not the one on the call.

You will also spend time on the unglamorous design of the program itself. Who is on call. How an analyst escalates to you. Which systems are crown jewels and which are allowed to fail for a while. How a new product gets a security review early enough to matter. These choices feel like management overhead until the night something breaks. Write them down, practice them on a small event, and fix the parts that confused people. A board will never see that rehearsal, and it is the reason the briefing you eventually give them is coherent.

Keep a written risk appetite you can point to. When a president wants an exception, the conversation is about that appetite, the compensating control, and the date the exception dies. Verbal shrugs create folklore. Folklore is how the next incident starts with the words "we thought that was allowed." Your signature, or your refusal, is part of the control environment. Treat it that way even when the request arrives late and friendly.

CISSP, CISM, and a record of owning risk

There is no government licence for this seat. Companies look for a record of owning security risk, and they often look for credentials that mark that record. The CISSP, the Certified Information Systems Security Professional, comes from ISC2. The CISM, the Certified Information Security Manager, comes from ISACA. Similar marks include the Security+ credential from CompTIA and the Certified Cloud Security Professional, also from ISC2. Each one tells a hiring committee that you studied a recognized body of security practice and that the issuing organization stands behind the designation.

People prepare by doing the work and then completing the issuing body's certification process. Security leadership, incident experience, and time spent explaining risk to non-specialists matter more than a shelf of badges. Hold the credential that matches the story you tell. A CISSP beside a career of hands-on security, or a CISM beside a career of managing a program, supports the interview. A badge with no incident, no budget, and no board conversation will be treated as homework. Skip any description of exams in your letter. Talk about the risk you owned.

What the badge can and cannot carry

CISSP, CISM, and their cousins are professional credentials from ISC2, ISACA, and similar bodies. They help a board trust your vocabulary. The hire still turns on whether you have already run incidents, a budget, and a hard conversation with leadership. Bring both, and lead with the conversation.

How a board picks its security chief

Companies open this search after a scare, a growth spurt, a new regulation, or a board that has decided security can no longer sit as a sub-team inside technology. Read which of those is happening. Your examples should match. A first-time program inside a company that has never had a chief needs a builder. A company recovering from an incident needs someone who has already sat in that chair while the facts were still ugly. A heavily regulated company needs someone who can talk to examiners without hiding behind jargon.

The process usually runs through a search firm, then the chief executive, then a board committee, with peers from technology, legal, and finance along the way. They will ask about an incident you led, a risk you accepted in writing, a control you killed because it was theater, and a time you told a more senior person to stop. Answer with sequence and consequence. Who decided. What you recommended. What the business did. What you would repeat. Vague courage is less persuasive than a specific call you can defend.

Ask blunt structural things before you accept. Do you report to the chief executive, to the board, or to the technology chief. Who owns the incident declaration. Is the budget yours. Which security teams actually report to you, and which stay inside product or infrastructure. A title that reports three layers down, with no budget and no right to stop a launch, is a different job. Name that difference in the interview, while you can still walk away, rather than discovering it in the first incident.

Your materials should be short and specific. One page on the program you ran, the risks you moved, and the way you informed a board. A separate note on the incident you are willing to discuss, with confidential details removed. References from a chief executive, a general counsel, and a technology peer who saw you under pressure. Those three voices tell the committee whether you can hold the room. A reference who only praises your technical depth is describing a principal engineer.

Once you have held the risk

The first year is orientation with a clock on it. You learn the real systems, the crown-jewel data, the identity mess, and the places backups have never been tested. You meet the board on a cadence and give them a risk picture they can remember. You pick a small number of fixes that reduce the worst outcomes, and you fund them. You introduce an incident rhythm the business understands before you need it. You resist the urge to announce a transformation that will take three years to show a single result.

After a full cycle of incidents, budget, and board reporting, the career opens. Some security chiefs move to a larger or more complex organization, where the same muscles face a bigger blast radius. Some add privacy, risk, or resilience to the mandate and become a broader risk executive. Some go to boards as the director who has actually run an incident. Some return to advisory work, selling judgment rather than headcount. The market believes a second tour more easily than a first, provided you can talk about what you changed and what you left alone on purpose.

Stay close enough to the technical work to know when you are being managed by your own staff, and far enough from the console that the program still runs when you are in a board meeting. Hire leaders who are better than you at detection, identity, and product security. Your remaining edge is the call: accept, mitigate, transfer, or stop the business action. If that call gets fuzzy, the title is ornamental and your next employer will notice.

An offer for the security chief, read on a wider chart

Judge a chief information security officer offer against Information Security Analysts pay in Occupational Employment and Wage Statistics for May 2025 (SOC 15-1212), a broader series than the executive who owns incidents, budget, and the board, with a headcount of 190,650 that month counting people in the series rather than salaries. Entry is $75,090. The median is $129,180. Tennessee carries a published high end of $250,590, which is reported because the state's count was sufficient for the Bureau to release a top of range. Entry to median is $54,090. Median to that Tennessee high end is $121,410.

Tennessee's high end and the state medians are different facts. Washington shows the highest state median at $154,940, which is $25,760 above the national median. Maryland's median is $139,640, California's is $138,570, Delaware's is $137,030, and Massachusetts's is $136,550. Puerto Rico's median, $63,740, is the lowest charted. A state median is typical pay in that place for the series. Use Washington's median, or another state's, when the job is there. Use $250,590 only as the high end of the published range in Tennessee, not as the typical paycheck in that state and not as a substitute for a state median you do not have in front of you for Tennessee.

An offer near $75,090 matches the entry of a broad analyst series. A seat that already owns incidents, the budget, and the board belongs in a conversation about the median of $129,180, and about the state median if you will work in Washington, Maryland, California, Delaware, or Massachusetts. Bring the reporting line and the budget authority with the number. If those are missing, the entry-side figure may describe the real job better than the title does. The long gap from the median to the Tennessee high end, $121,410, is a picture of how far the published range extends for the series. Treat it as context for a scarce executive scope, and tie any move in that direction to board exposure, incident authority, and the size of the risk you will personally accept.

Pick one anchor before you talk: the median for a true chief mandate, a state median when geography is the difference, or the entry figure if the role is really a senior analyst job wearing a larger name. Then describe the risk you will own. Boards pay for a person who can sit in the incident, defend the spend, and tell them the truth afterward.

The top of Chief Information Security Officer pay — and how to get there with AI

$250,590what Chief Information Security Officer pay reaches in Tennessee

Highest state-level top-of-range annual wage for Information Security Analysts, among states with at least 500 people in the job. U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025.

And the role it leads to — Computer and Information Systems Managers — reaches $327,300 in Washington.

$75,090entry$129,180middle$250,590top end

Two security leaders with identical skill can sit far apart in this range, because the top of the range here is set by the regulatory pressure on the industry you serve and by whether you are one employer's officer or several organisations' contracted one.

The work itself is portable in a way few executive roles are: performing risk assessments and testing data processing systems, developing plans to safeguard files against unauthorised modification or disclosure, documenting security policies, procedures and tests, reviewing violations of security procedure with the people who caused them, coordinating implementation with staff and outside vendors. Because it is portable, the price varies by where and how it is sold. Banks, healthcare systems, defence suppliers and public agencies pay for the same competence at different rates, and a fractional security officer serving three mid-sized firms is paid on a different basis entirely. What makes either move possible is a documented body of work you can carry with you, which is precisely what a leader who never wrote the policies down cannot do.

Your playbook, by where you are now

Just startingBuild a record that travels

  1. Write the security policies and procedures you operate under, rather than inheriting a set nobody has read since the audit.
  2. Run and document a genuine risk assessment, including the findings that were inconvenient.
  3. Get hands deep enough on access management software and active directory software that you can question an engineer's answer.
  4. Deliver the user awareness training yourself and measure whether behaviour changed, not whether people attended.
  5. Use Claude to draft the first version of a policy document, then rewrite it against the control framework your sector is actually audited on.

What proves it: A policy set and risk assessment you authored that survived an external audit.

Realistic span: the first several years in security

A few years inGet fluent in one regulated sector

  1. Pick a regulated industry and learn its examinations properly, because sector fluency is what a hiring committee pays for.
  2. Own vendor and third-party security review, since coordinating with outside vendors is half of what the role turns out to be.
  3. Run a real incident exercise with the executive team in the room and write the honest debrief afterwards.
  4. Study where the demand sits rather than where the technology press points; Tennessee pays this occupation best, on the strength of healthcare and logistics employers.
  5. Build a portfolio of programme artifacts you are allowed to describe: maturity assessments, board papers, remediation plans.

What proves it: A security programme you took through a regulator or customer examination.

Realistic span: the middle stretch of a security career

ExperiencedSell the role, not the hours

  1. Take a fractional or contracted security officer engagement alongside a stable one, and see what a second organisation pays for the same programme.
  2. Package your programme as a repeatable engagement: assessment, roadmap, board reporting, quarterly review.
  3. Relocate or negotiate remote terms toward the markets and industries that price this role highest, with a written case built on what you delivered.
  4. Keep the technical footing current — encryption, firewall architecture, audit trail analysis — so you are never the officer who cannot follow the incident.
  5. Consider the information systems management track if you would rather hold the whole technology budget than the security part of it.

What proves it: Two organisations paying for your security leadership at the same time, or a negotiated move with the case in writing.

Realistic span: once you have run a full programme

The next 90 days

Over the next ninety days, build the portable version of your programme. Take the risk assessment method, the policy set, the board reporting pack and the incident response plan you use, strip out anything specific to your employer, and rewrite them as a set you could deploy somewhere else in a fortnight. Then price the work: how many days a quarter would a mid-sized firm in your sector need to run this properly. That number is the entire basis of a fractional conversation and of a relocation negotiation, and almost nobody in this role has worked it out. A chief information security officer who has is negotiating from evidence rather than from a job advertisement.

Wage figures: BLS OEWS, May 2025. The playbook is PayCrunch editorial guidance, not a guarantee of pay or placement.

Careers related to Chief Information Security Officer

Similar pay, same field

Where this can lead

Every figure is the national median from the U.S. Bureau of Labor Statistics (OEWS) shown on that role’s own page.

Never used AI before? Start here (2 minutes).

Bring AI into your SOC first, this month. If your stack includes an AI security assistant (Microsoft Security Copilot, CrowdStrike Charlotte AI, or SentinelOne Purple AI), pilot it on alert triage and investigation for one team. It summarizes incidents, speeds investigation, and cuts analyst toil — you keep human approval on every containment action.

In parallel, get ahead of the company's own AI use: shadow AI, prompt injection, and data leakage are now your problem. Use enterprise AI (never secrets or incident data in consumer tools) to draft policy and board materials. You own every security decision; AI accelerates the triage, the analysis, and the writing.

The one rule, forever: In security, an AI mistake is a breach. Never let AI auto-remediate, block, or make access or containment decisions without human approval and change control — validate every AI-flagged threat and every AI-suggested action. Never paste secrets, credentials, incident details, or customer data into a consumer AI tool, and own the security and governance of every AI system the company deploys.
The plays — exact steps, exact prompts

Do these in order. Each one is copy-paste ready. You do not need to know anything about AI going in.

1
Modernize the SOC with AI triage and investigation
Why this pays: A CISO is judged on how fast the team detects and responds while controlling headcount cost. AI that triages alerts, summarizes incidents, and accelerates investigation cuts mean-time-to-respond and analyst burnout — the efficiency and risk-reduction story that earns budget, trust, and a bigger mandate.
Microsoft Security CopilotCrowdStrike Charlotte AISentinelOne Purple AISplunk
1
Pilot an AI SOC assistant (Microsoft Security Copilot, CrowdStrike Charlotte AI, or SentinelOne Purple AI) on alert triage, enrichment, and investigation summaries — with the rule that every containment or remediation action still needs human approval.
2
Measure the impact honestly so you can defend the investment to the board.
Copy-paste this prompt
Act as a security-operations advisor. We piloted [an AI SOC assistant] with a [12]-analyst team. List the metrics to measure real impact (mean-time-to-detect, mean-time-to-respond, alerts triaged per analyst, false-positive rate, analyst toil and burnout), how to baseline them, the traps that make AI-productivity claims misleading, and how to present results to a board in one slide.
Track false-positive and false-negative rates alongside speed — faster triage that misses real threats is not a win.
What you'll haveA faster, leaner SOC with lower response times at controlled headcount — the risk-and-efficiency narrative that wins a CISO budget and mandate.
2
Secure the company's own AI adoption
Why this pays: As every team races to adopt AI, the CISO owns a brand-new attack surface: shadow AI, prompt injection, data leakage, and insecure AI features in the product. The CISO who governs AI adoption safely becomes the enabler of the company's AI strategy rather than its blocker — indispensable to the board.
Palo Alto Prisma AIRSMicrosoft Purview (DLP)LakeraWiz
1
Inventory and govern AI use: discover shadow AI, apply data-loss controls (Microsoft Purview DLP), add AI-specific runtime protection and guardrails (Palo Alto Prisma AIRS, Lakera) against prompt injection and data leakage, and scan AI in your cloud with Wiz.
2
Draft the enforceable AI-security policy that lets the company adopt safely.
Copy-paste this prompt
Act as a CISO. Draft an AI-security policy for a [SaaS] company: approved AI tools and data classes for each use, rules on secrets and customer data, controls for shadow AI, requirements for securing AI features we build (prompt-injection, data-leakage, and model-abuse testing), vendor and data-retention requirements, and an approval path for new AI use. Practical and enforceable, not legalese.
Have legal and privacy review before publishing; pair the policy with technical controls or it will not hold.
What you'll haveCompany-wide AI adoption that is governed and safe — the CISO becomes the enabler of AI strategy, the ownership that anchors the mandate.
3
Defend against AI-powered attacks
Why this pays: Attackers now use AI for hyper-realistic phishing, business email compromise, deepfakes, and faster malware. The CISO who upgrades defenses and training for the AI-threat era prevents the costly breach that defines a security leader's reputation — and protects the company the board holds them accountable for.
Abnormal SecurityKnowBe4DarktraceMicrosoft Defender
1
Upgrade email and identity defenses for AI-era social engineering (Abnormal Security for BEC and phishing, behavioral detection via Darktrace or Microsoft Defender) and modernize security-awareness training (KnowBe4) for deepfakes and AI phishing.
2
Pressure-test your readiness with an AI-built tabletop exercise you run with the team.
Copy-paste this prompt
Act as an incident-response facilitator. Build a tabletop exercise for an [AI-driven business email compromise using a deepfake voice of our CFO to authorize a wire transfer]. Include the scenario timeline, the decision points for security, finance, and comms, the questions to test our controls and playbooks, and the gaps this is likely to expose. General exercise only, no real data.
Use it to find gaps in your real playbooks; validate every control against your actual environment.
What you'll haveDefenses and people hardened against AI-powered attacks — preventing the breach that would define a CISO's tenure the wrong way.
4
Automate compliance and audit evidence
Why this pays: Compliance (SOC 2, ISO 27001, HIPAA, PCI) consumes security-team time and executive attention. AI-automated evidence collection and continuous compliance frees the team for real risk work and lets the CISO show the board a defensible posture — the credibility that supports budget and scope.
VantaDrataMicrosoft Security CopilotServiceNow
1
Automate control monitoring and audit-evidence collection (Vanta or Drata) for your frameworks, and use AI to draft policies, risk assessments, and audit responses for your review.
2
Turn a framework into a concrete program with an AI-structured plan you own.
Copy-paste this prompt
Act as a GRC lead. We need to reach [SOC 2 Type II] readiness in [6 months]. Draft a program plan: the control domains, the evidence each requires, which controls can be continuously monitored versus manually attested, the likely gaps for a [50-person SaaS] company, and a month-by-month milestone plan. Flag decisions that need a human owner.
Automation collects evidence; you still own control design and the accuracy of every attestation.
What you'll haveContinuous, low-effort compliance and a defensible audit posture — freeing the team for real risk work and giving the board confidence.
5
Quantify and communicate risk to the board
Why this pays: At the top of the band, a CISO is an executive who translates cyber risk into business terms the board acts on. Using AI to quantify risk and sharpen board materials builds the executive presence that earns budget, influence, and top-of-band comp — moving the CISO from technician to strategist.
ClaudeChatGPTGamma
1
Draft and pressure-test your board risk narrative, then make it your own.
Copy-paste this prompt
Act as a CISO's advisor. Help me write the security section of a board update. Raw points: [paste bullets on threat landscape, incidents, key risks, control maturity, and investment asks]. Turn it into a crisp one-page narrative for a non-technical board: our risk in business terms, what we are doing, what I need from the board, and the top risks I am managing. Confident, honest, no jargon or fear-mongering.
Never paste real incident specifics or sensitive findings into a consumer tool; keep it high-level or use an enterprise plan.
2
Use AI to help translate technical risk into financial terms — potential loss and risk reduction per dollar — so the board can weigh security like any other investment.
What you'll haveCyber risk expressed in business terms the board funds — the executive presence that earns a CISO influence and top-of-band comp.
6
Build the enterprise security program and command the mandate
Why this pays: CISO comp tracks the scope and criticality of what they protect. Building a mature, AI-augmented security program — and stepping into a larger or higher-risk enterprise mandate, often with equity — is the most direct path from the middle to the top of the band.
ClaudeChatGPTLinkedIn
1
Design the security operating model and hiring plan with an AI-assisted draft you own.
Copy-paste this prompt
Act as a security-org designer. We are scaling security for a company growing from [500 to 1,500] employees while adopting AI broadly. Propose an operating model (SOC, GRC, AppSec, identity, AI security), the first 5 hires in priority order with the reason, the build-versus-outsource calls (MSSP, MDR), and the metrics the board should judge us on. Flag the biggest risks of scaling this fast.
Adapt to your real risk profile and budget; security org design is judgment, not a template.
2
Benchmark and negotiate your scope, budget, and equity deliberately. Top-of-band comp comes from owning security for a larger, higher-risk enterprise — treat your next role or renewal as the lever it is.
What you'll haveA mature, AI-augmented security program and a bigger, board-level mandate — the scope and ownership that carry a CISO's comp toward $250,590.
Your 12-month sequence to the top of the range

How the plays above stack into a path from median pay toward the $250,590 tier.

Month 1
Pilot an AI SOC assistant on alert triage with human approval on all actions; baseline your response metrics.
Months 2-3
Inventory and govern the company's AI use; deploy DLP and AI runtime guardrails; draft the AI-security policy.
Months 3-6
Upgrade defenses and training for AI-powered attacks; run an AI-built tabletop to find gaps.
Months 6-9
Automate compliance and audit evidence; free the team for real risk work.
Months 9-12
Quantify risk in business terms and sharpen the board narrative with AI-built materials.
Year 2
Mature the program and negotiate a larger, board-level mandate — toward $250,590.
Next steps for a Chief Information Security Officer

Some links below are affiliate or partner links. PayCrunch may earn a commission if you enroll or subscribe through them, at no extra cost to you. Wage figures on this page still come from the Bureau of Labor Statistics, not from these programs.

Chief Information Security Officer work is specific enough that a stamped 'check out these courses' block would be noise. BLS files this work as Information Security Analysts (SOC 15-1212). O*NET Job Zone 4 is typical: a bachelor's degree, so the honest next credential is a professional certificate or bachelor's-level coursework — not a random catalog dump.

The occupation's listed knowledge areas include Telecommunications and Engineering and Technology; the links search those subjects, not a generic 'career courses' list.

Chief Information Security Officers in this dataset list AJAX among the tools in use, so a program that names that stack is a better fit than a survey course.

Cybersecurity programs on Coursera for Chief Information Security Officer work

Coursera search for cybersecurity — a professional certificate or bachelor's-level coursework that lines up with computing, not a generic professional-development aisle.

Cybersecurity courses on edX

edX search for cybersecurity, aimed at computing (SOC 15-1212). Same field as the Coursera link, different university catalog.

Screened remote and flexible Chief Information Security Officer listings on FlexJobs

FlexJobs screens remote, hybrid, freelance, and flexible listings so you are not wading through unverified ads. This is a job-board search for Chief Information Security Officer work, not a claim that they list a counted SOC 15-1212 inventory.

Build a Chief Information Security Officer resume on Resume Now

Write a Chief Information Security Officer resume, or one aimed at Computer and Information Systems Managers, instead of a blank template. Resume Now is a resume builder; we are not claiming a counted template set for this SOC.

Build a Chief Information Security Officer resume on Zety

A Chief Information Security Officer resume that names the actual tasks on this page, or the step-up title Computer and Information Systems Managers, beats a blank template when you apply.

What Chief Information Security Officers earn by state

These are the Bureau of Labor Statistics’ own figures for Information Security Analysts, state by state — not a cost-of-living adjustment applied to the national number. Only states employing at least 500 people in the occupation are shown, because a state median drawn from a handful of workers is noise rather than a signal.

Washington
$154,940
highest of them · +20% vs the national median
Puerto Rico
$63,740
lowest of the 42 states and territories that qualify · -51% vs the national median
The same job pays $91,200 more a year at the median in Washington than in Puerto Rico — 143% higher. That gap is what the Bureau measured, before any question of what it costs to live in either place. The top-of-range figure quoted at the head of this page, $250,590, is a different statistic in a different place: it is the 90th-percentile wage in Tennessee. The state that pays the typical worker most and the state where the best-paid go highest are not always the same one.
Washington$154,940Maryland$139,640California$138,570Delaware$137,030Massachusetts$136,550Colorado$135,220District of Columbia$135,090Virginia$134,900

Source: U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025, SOC 11-3021. 42 states and territories clear the 500-employee reporting floor for this occupation; those below it are left out rather than shown with a wide error band.

Free data. Use any of it.

PayCrunch publishes verified, BLS-sourced salary + AI-playbook data on 1,000+ professions — free, no signup.

Frequently asked
Will AI replace CISOs?
No — it is transforming the job. AI cannot own security strategy, carry accountability for a breach to the board, make the judgment call in a live incident, or lead a security organization. What it changes is the terrain: AI runs the modern SOC, and attackers use AI too. CISOs who master AI for defense and govern the company's AI use pull far ahead of those who treat it as someone else's problem.
Is it safe to let AI take security actions automatically?
Rarely, and never without guardrails. Use AI to triage, enrich, and investigate at machine speed, but keep human approval and change control on every containment, blocking, or access decision. An AI acting alone on a false positive can take down production; acting on a false negative can miss a breach. The judgment stays with the human.
How is AI changing the CISO's job specifically?
On defense, AI automates SOC triage and investigation and speeds compliance. On offense, attackers use it for better phishing, deepfakes, and faster malware. And a whole new surface — the company's own AI adoption — becomes the CISO's to secure. The role is expanding, not shrinking.
Is it safe to use ChatGPT in security work?
Not with secrets, credentials, incident details, or customer data — those never go into consumer AI. Use enterprise, purpose-built security AI (Microsoft Security Copilot, CrowdStrike Charlotte AI) for operational work, and reserve general tools for policy drafting and board materials phrased without sensitive specifics.
How does AI actually raise a CISO's pay?
By expanding the mandate. Comp tracks the scope and risk you own. A CISO who runs a modern AI-augmented SOC, secures the company's AI adoption, and quantifies risk for the board becomes the executive the company bets its security on — which earns a bigger, higher-risk mandate, equity, and top-of-band offers.
Methodology & sources
  • Salary (median, 10th, top of the range) — U.S. Bureau of Labor Statistics, OEWS.
  • By state — the Bureau of Labor Statistics’ own state medians, limited to states employing at least 500 people in the occupation. No cost-of-living arithmetic is applied to a wage anywhere on this page.
  • The plays — PayCrunch's own step-by-step guidance using publicly available AI tools. Tool names/URLs are real and current as of August 2026; prompts written to work as-is. Verify any professional output before relying on it.

Sources