PayCrunch Research · The exact AI playbook for your profession, sourced to the U.S. Bureau of Labor Statistics

PayCrunch AI Playbook · Technology

Why teaching lifts a cybersecurity analyst's top end

$250,590top of the range in Tennessee · middle $129,180 / yr
AI is transforming this role

Cybersecurity Analysts in the United States earn a median of $129,180 a year. Pay starts near $75,090. Pay reaches $250,590 at the top of the range in Tennessee, the best-paying state for this work among those with at least 500 people in the job.

Source: U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025 (Information Security Analysts, SOC 15-1212). Last checked 9 September 2026.

Entry level
$75,090
Top of the range · Tennessee
$250,590
Education
Bachelor's in cybersecurity, CS, or IT
Lower disruption Higher exposure AI is transforming this role
Entry · $75,090 Top of range · $250,590 (Tennessee) Middle $129,180

Wages — U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025 (Information Security Analysts). Top of the range is the highest state-level figure among states with at least 500 people in the job. AI-impact rating is PayCrunch's editorial assessment. Updated September 2026.

🆕 New & Trending AI Tools for Cybersecurity AnalystReviewed September 2026

We track new AI-tool launches every week and refresh this list — here’s what’s gaining traction for Cybersecurity Analyst work right now.

Claude CodeNEWFree / usage-based

Terminal coding agent that reads your repo, runs tests, and ships multi-file changes.

How a Cybersecurity Analyst uses it: describe a feature and let it implement and test it across the codebase

OpenAI CodexNEWIncl. w/ ChatGPT plans

Agent that runs longer, deterministic multi-step coding jobs on its own.

How a Cybersecurity Analyst uses it: delegate a well-defined build or migration and review the finished result

WindsurfNEWFree / $15 mo

Agentic IDE that keeps context across a whole project.

How a Cybersecurity Analyst uses it: make large, coordinated changes without losing track of the codebase

AWS KiroNEWPreview / see site

Spec-driven coding agent that turns written specs into working code.

How a Cybersecurity Analyst uses it: write the spec first and let it build to that spec

NotebookLMNEWFree / $7.99 mo

Google tool that answers questions grounded only in the documents you give it — with citations.

How a Cybersecurity Analyst uses it: load your own manuals, policies, or PDFs and ask questions that stay accurate to the source

CursorFree / $20 mo

AI-native code editor that edits across an entire project.

How a Cybersecurity Analyst uses it: describe a change in plain English and let it rewrite and refactor whole files

GitHub Copilot (Agent Mode)$10–19 mo

AI pair-programmer built into VS Code and GitHub that now completes multi-step tasks.

How a Cybersecurity Analyst uses it: hand off a task and have it plan, edit multiple files, and open a pull request

ChatGPTFree / $20 mo

The most-used AI assistant — writing, analysis, research, and images from a plain-language chat.

How a Cybersecurity Analyst uses it: draft emails and documents, summarize long files, and get instant answers to on-the-job questions

ClaudeFree / $20 mo

AI assistant known for careful writing, long-document analysis, and coding.

How a Cybersecurity Analyst uses it: analyze big reports or spreadsheets and turn messy notes into clean, finished writing

The console, the alert, and the call you make

A console fills with alerts, and you decide which ones deserve a real investigation. You are a cybersecurity analyst. Your seat is the analyst seat: you watch the alerts the company already collects, and you investigate the ones that might be a real problem. A chief information security officer directs the security program and speaks for it to leadership. A cloud engineer builds and runs the platform. Those are different chairs. When an offer uses a fuzzy title, match the duties to the queue and the investigations. If the duties are a program budget or a build pipeline, you are looking at a different job wearing a familiar word.

The day is a queue. Tools the company has deployed, often a central logging system and the detectors tied to it, raise alerts about logins, malware warnings the tool already classified, odd data movement, or a system that stopped behaving like its neighbors. You open the alert. You read the fields it already contains: which account, which machine, what time, what the tool thinks happened. You pull the surrounding log context your procedure allows. You decide whether this is something to close, something to watch, or something to escalate as an incident. Then you write that decision so the next analyst, or the incident lead, can follow it.

You deal with the teammates on your shift, with system owners who know whether a server is supposed to talk to the internet, with a manager who cares about the queue’s health, and sometimes with a legal or privacy partner when an investigation touches personal data. You deal with the person who will be woken up if you escalate, so your escalation has to be worth their time. You also deal with the noise. Most alerts are benign. The craft is telling those apart from the few that are not, without inventing drama and without waving through a pattern you do not understand.

Triage in the morning, a write-up before you leave

A shift usually starts by taking the queue from the previous analyst. You read what they left open. You learn which detections have been noisy all week and which ones the team has decided are still worth a look. You work the highest concern first, the way your team ranks concern, and you keep a short list of alerts you touched so nothing sits unseen because you got absorbed in one hard case. If your company runs around the clock, your handoff note is as important as the investigation. The person coming in should know what is still live.

Investigation, at this seat, is gathering what the logs and the asset owners can tell you and comparing that with the alert. You ask the owner whether the activity was planned. You check whether the account is still supposed to be active. You look at whether the same pattern appeared yesterday. You stop when you have enough to close or to escalate, and you say what you still do not know. A write-up names the alert, the systems involved, the evidence you relied on, the decision, and the next action. It stays inside the company’s systems. It is a record for defenders and for auditors, written so a colleague can replay your reasoning.

You will also tune the queue, within the authority you have. A detection that fires on every password reset is hiding the alerts that matter. You document why you think it is noisy, you propose a change, and you let the person who owns the detection decide. You do not silence an alert because it annoyed you on a Friday. The analyst seat includes that restraint. Over a month, the quality of the queue is part of your work product, right beside the incidents you caught. Teams promote people who make the next shift easier, not only people who enjoy a single dramatic case.

Security+ and the write-ups employers believe

There is no single licence that every analyst seat requires. Employers commonly look for CompTIA Security+ or a similar certificate, plus evidence you have done the work. CompTIA grants Security+. It signals that you can speak the defensive vocabulary: alerts, access, and the basics of investigating a suspicious event. Similar certificates from other bodies show up on postings too. Bring the one the posting names. None of them is a substitute for a record of investigations you can discuss. The certificate gets you understood. The write-ups get you hired.

Preparation is study for the certificate the posting wants, plus practice on a range or a lab the training provider or your school supplies, plus any sanctioned work you can describe. A help-desk job that taught you accounts and tickets is a real on-ramp, because analysts spend their lives asking what an account was supposed to do. A degree in cybersecurity, computer science, or a related field helps at larger employers. An internship on a security team helps more than a stack of certificates with no story attached. When you practice, stay on the defensive side of the work: read alerts, write findings, escalate. That is the seat. Keep your notes free of anything you are not allowed to share, and never walk into an interview with someone else’s incident data.

Certificate plus a case you can tell

CompTIA Security+, or a similar certificate the posting names, is a common way to show the vocabulary. Pair it with a write-up of an investigation you were allowed to discuss. See CompTIA for the organization that grants Security+.

If a posting names a different certificate, or a clearance, follow the posting. A clearance is the government’s process, and only an employer who has the work can sponsor it. You cannot buy it on your own and then demand the seat. Security+ remains a widely recognized starting point for commercial analyst jobs. Confirm it is the one they want before you spend a season preparing for a certificate their hiring manager does not use. Then spend at least as much effort on writing a clear finding as you spend on the certificate itself.

Landing the analyst queue

Companies, government contractors, banks, hospitals, and managed security providers all hire this seat. The posting should say whether you watch a queue around the clock, whether you work a business-day investigation team, and which tools you will live in. Apply with a resume that names the environment, the kind of alerts you handled, and the decisions you made. In the interview, walk through one case from alert to decision without turning it into a performance. They are listening for whether you checked with the system owner, whether you wrote it down, and whether you knew when to escalate. A tour of scary vocabulary, with no decision at the end, tells them you want a different conversation.

Ask who owns the detections, who you wake up, and what a closed alert looks like in their tool. Ask how a mistake in a write-up gets corrected. Ask whether the seat includes any on-call and how that on-call is paid, in their words. Ask whether the title on the letter is the analyst queue or a blend that also expects you to build cloud systems or to run the whole program. You want the blend named now, because the pay and the days will follow the blend. A manager who can describe a normal Tuesday is a better sign than a manager who only describes emergencies.

New analysts are often paired with a senior person for the first stretch of shifts. Ask how that pairing works and what “ready for the queue alone” means to them. Bring your certificate if they asked for it, and bring a portfolio piece you have permission to show. References should be someone who saw you investigate, even if the setting was a lab course or a help desk that escalated odd account activity. Honesty about the limit of your experience beats a padded story. Teams would rather teach a careful junior than unteach a reckless one.

From triage to a deeper analyst specialty

The first seat is triage. You learn the company’s noisy detections, its asset list, and its escalation path. You get faster without getting sloppy. You build a habit of write-ups another analyst can trust at 2 a.m. That habit is the promotion. A full analyst owns harder cases and starts to see patterns across a week, not only across a single alert. You might focus on identity alerts, on endpoint warnings, or on the investigations that follow a confirmed incident, still as an analyst rather than as the person who directs the whole program.

A senior analyst coaches the queue, reviews other people’s findings, and helps decide which detections are worth keeping. You may represent the shift in a meeting with system owners. You still investigate. The senior title without the write-ups is just a longer meeting calendar. Some analysts later move toward detection engineering, incident leadership, or a specialist team. A few aim at the chief’s chair or at a cloud engineering role. Those are real careers, and they are different seats from the one this page describes. If you want them, notice the extra work they require and do not assume the analyst ladder drops you into them. If you want to stay an analyst, a senior queue role can be a complete career.

Keep a private list, with sensitive details removed, of the kinds of cases you have closed and the kinds you have escalated. When you ask for the senior seat, that list is your evidence. Ask what the current senior analysts are trusted to decide alone. Match that trust before you ask for the title. Keep any certificate the company values current if they require it for the seat. The work that moves you is still the same work: a queue that gets cleaner, and findings a teammate can follow.

What to say when the analyst offer has a number

For the analyst offer in your hand, the May 2025 Occupational Employment and Wage Statistics figures for information security analysts (SOC 15-1212) are the chart behind these dollars, and they belong to the seat that watches alerts and investigates them. Entry on that national range is $75,090. The national median is $129,180. The gap from entry to the median is $54,090. A first queue job often lives nearer $75,090 than the middle, especially when the company is hiring you to learn its tools. That $54,090 is a concrete way to ask what a year of solid write-ups, an on-call rotation, or a move from junior triage to independent investigations does to the salary. Get the company’s answer in its own bands.

The high end of the published range is $250,590 in Tennessee, among places with enough people in the job for the Bureau to publish it. From the national median to that high end is $121,410. Tennessee’s $250,590 is the high end of the published range there. It is a different kind of figure from a state median. The highest state median is Washington at $154,940, which is typical pay in Washington. The national median sits $25,760 below that Washington median. If you are judging a typical analyst offer in Washington, $154,940 is the comparison. If you are talking about the high end of the published range, $250,590 is a Tennessee figure and a later-career comparison. Keep them apart so a first queue offer is not asked to resemble a range top from somewhere else.

Other state medians, each typical pay in that state, are Maryland at $139,640, California at $138,570, Delaware at $137,030, and Massachusetts at $136,550. Puerto Rico’s median is $63,740. Read a Maryland offer against $139,640, a California offer against $138,570, a Delaware offer against $137,030, and a Massachusetts offer against $136,550. An offer near $75,090 is an entry figure on the national range. An offer near $129,180 is the middle. Mention $250,590 only when the role is scarce and senior and the employer can explain the scope. On-call pay, bonuses, and clearance differentials belong in the employer’s numbers. Bring the certificate they asked for, bring the investigations you can discuss, and accept the seat whose queue matches the analyst work you just described.

The top of Cybersecurity Analyst pay — and how to get there with AI

$250,590what Cybersecurity Analyst pay reaches in Tennessee

Highest state-level top-of-range annual wage for Information Security Analysts, among states with at least 500 people in the job. U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025.

And the role it leads to — Computer and Information Systems Managers — reaches $327,300 in Washington.

$75,090entry$129,180middle$250,590top end

The analyst at the top of the range of this range is rarely the one who tuned the most alerts; it is the one every team calls before adopting something new, because that person taught them the last three things and told them the truth about the risk.

Training users and promoting security awareness sits on this occupation's task list and is usually treated as an annual chore handed to whoever objects least. It is also the only task that puts an analyst in a room with every department in the company. Reviewing violations of computer security procedures with the people who caused them is the same opening in miniature. Meanwhile assistants are arriving inside all of those departments with nobody assigned to say what may be pasted into them, what may not, and how company data ends up somewhere it should not. Whoever owns that answer becomes the person the business consults instead of the person it notifies afterwards.

Your playbook, by where you are now

Just startingLearn it well enough to explain it

  1. Take the awareness sessions nobody wants and rebuild them around real incidents from your own organisation.
  2. When you review a violation with the person who caused it, ask what made the safe path harder than the unsafe one, then fix that.
  3. Get properly hands-on with access management software and active directory software, since access is what most questions are really about.
  4. Document the security policies, procedures and tests you operate, because you cannot teach what nobody has written.
  5. Practise explaining encryption in transit to a non-technical colleague until they can repeat it back correctly.

What proves it: An awareness session people quote afterwards, built on incidents from your own organisation.

Realistic span: the first two years

A few years inOwn the rules for the new tools

  1. Write the assistant usage standard for your company: which data classes may go into ChatGPT, Claude or Microsoft Copilot, which may never, and what gets logged.
  2. Run the risk assessment behind that standard rather than copying somebody else's policy.
  3. Build a short course per department, because the risky habits in engineering, finance and legal are not the same habits.
  4. Point NotebookLM at your own policy set and incident history to generate the questions your training ought to answer.
  5. Coordinate the rollout with the vendors and with the teams adopting the tool, and be present when access is granted.

What proves it: An adopted usage standard plus a course delivered across several departments.

Realistic span: years three through six

ExperiencedBe the reason the company can adopt anything

  1. Own the review path that lets a new tool into the business, so approval becomes a process instead of a favour.
  2. Turn your training into a programme with a curriculum, a measure of changed behaviour, and named owners after you.
  3. Take the plans that safeguard files against unauthorized modification or disclosure and rewrite them for how people work now.
  4. Speak for security in front of executives, because the information systems management track begins in that room.

What proves it: A tool adoption process and a training programme the business genuinely runs on.

Realistic span: seven years in and onward

The next 90 days

In the next ninety days, write the document your company does not have: one page saying which assistants people may use, what may be put into them, and what happens to it afterwards. Do not start from a template. Start by asking twenty colleagues across three departments what they are already using and what they have already pasted in, promising that nobody gets punished for the answer. You will learn more about real exposure in a week than a year of monitoring gave you. Then write the page, run it past legal, and teach it in person to each department rather than emailing it round. A cybersecurity analyst who does this stops being the one who says no afterwards and becomes the one consulted before the decision.

Wage figures: BLS OEWS, May 2025. The playbook is PayCrunch editorial guidance, not a guarantee of pay or placement.

Careers related to Cybersecurity Analyst

Similar pay, same field

Where this can lead

Every figure is the national median from the U.S. Bureau of Labor Statistics (OEWS) shown on that role’s own page.

Never used AI before? Start here (2 minutes).

Open a browser and go to chatgpt.com. Click Sign up and create a free account with your personal email - never a work account, and never anything tied to your employer's systems. This is ChatGPT.

Type a real security question into the box, like: Explain how a MITRE ATT&CK technique like credential dumping (T1003) actually works, and what log sources and detections would catch it. Read the answer, then ask a follow-up about a technique you see at work - described generically, with no real data. That back-and-forth is how analysts use AI to learn faster and think about detections, and keeping every prompt free of real logs, IPs, and credentials is the non-negotiable habit.

The one rule, forever: Never paste production configurations, credentials, API keys, private IP addresses, internal hostnames, or real log data into public AI tools - it is a data-exfiltration risk and can leak sensitive infrastructure into a model. Use only your organization's sanctioned enterprise AI, and always test an AI-suggested fix or detection in a lab before touching production, because AI confidently produces insecure or wrong configurations.
The plays — exact steps, exact prompts

Do these in order. Each one is copy-paste ready. You do not need to know anything about AI going in.

1
Run the AI SOC copilot instead of being replaced by it
Why this pays: The analysts who master AI security copilots become force-multipliers who investigate faster and mentor the tool; the ones who only triage alerts by hand are exactly whose work is being automated. This is the survive-and-climb move.
Microsoft Security CopilotCrowdStrike Charlotte AISentinelOne Purple AI
1
Learn what your SOC's AI copilot can and cannot do, and start using it to accelerate investigations while you own the judgment.
Copy-paste this prompt
Explain how an AI SOC copilot like Microsoft Security Copilot is used in a real investigation workflow: what it automates, what an analyst must still verify, and the mistakes to avoid trusting it on. Give me a checklist for validating its output before I act on it.
2
Use public AI to build the underlying knowledge so you can judge the copilot's output, not just accept it.
Copy-paste this prompt
Quiz me one question at a time on incident investigation fundamentals - log analysis, common attack patterns, and triage decisions - and after each answer, explain what a senior analyst would look at next. Use only generic examples.
What you'll haveYou become the analyst who wields AI to investigate at senior speed - the profile that gets promoted, while pure manual triage gets automated.
2
Specialize in cloud security - the highest-demand niche
Why this pays: Cloud misconfiguration is a leading breach cause, and cloud security engineers command pay at the top of the band. Specializing here is one of the surest routes past $150K.
WizAWS Security toolingMicrosoft Defender for Cloud
1
Have AI build you a cloud-security learning path anchored to the platform your organization uses.
Copy-paste this prompt
I am a cybersecurity analyst who wants to specialize in cloud security on [AWS / Azure / GCP]. Build me a 90-day learning plan covering identity and access management, network security, common misconfigurations, CSPM tools, and the relevant certification. For each topic give one hands-on exercise I can do in a free tier.
2
Learn to read and reason about cloud misconfigurations using generic, sanitized examples.
Copy-paste this prompt
Show me the ten most common cloud security misconfigurations, why each is dangerous, how an attacker exploits it, and how to detect and fix it. Use generic examples with no real account details.
What you'll haveYou become the person who secures the cloud environment every company is moving to - a specialty that pays at the top of the analyst band.
3
Become a detection engineer, not a dashboard watcher
Why this pays: As AI absorbs alert monitoring, the durable value moves to building the detections - detection-as-code. Detection engineers earn well above line analysts and are far harder to automate.
SplunkElastic SecurityGitHub Copilot
1
Learn to write and tune detections, using AI to accelerate the query and rule writing you then validate.
Copy-paste this prompt
Teach me detection engineering fundamentals: how to turn a MITRE ATT&CK technique into a detection rule, how to reduce false positives, and how detection-as-code workflows work. Then walk me through writing a sample Sigma rule for [generic technique], explaining each part.
2
Use an AI coding assistant to build the light scripting and automation the role needs, tested only in a lab.
Copy-paste this prompt
Help me write a Python script that parses generic authentication logs and flags anomalous login patterns. Explain each part so I understand it. Sample log format only, no real data.
Run and test everything in an isolated lab; never point practice scripts at production systems.
What you'll haveYou move from consuming alerts to engineering the detections behind them - higher-paid, harder-to-automate work at the center of a modern SOC.
4
Break into threat hunting and incident response
Why this pays: Proactive threat hunting and DFIR incident response are premium specialties - when an organization is breached, these are the people it pays most to have. Both sit near the top of the band.
CrowdStrike FalconVelociraptorChatGPT
1
Build a hypothesis-driven hunting method and use AI to research adversary behavior you then verify.
Copy-paste this prompt
Teach me structured, hypothesis-driven threat hunting. Given the adversary technique [generic technique], walk me through forming a hypothesis, what data sources to hunt in, what normal versus malicious looks like, and how to document findings. Generic examples only.
2
Rehearse the incident-response decisions and communication that separate senior responders.
Copy-paste this prompt
Act as an incident commander running a tabletop exercise. Present a fictional ransomware scenario and ask me, one decision at a time, what I would do for containment, eradication, and communication, critiquing each choice.
What you'll haveYou add the high-stakes specialties organizations pay a premium for, work AI assists but cannot own - a direct step toward the top of the band.
5
Earn the CISSP to clear the architect and management gate
Why this pays: The CISSP is the credential that gates the higher-paid security architect and management roles. Combined with experience, it is often what unlocks the top of the band.
ChatGPTClaude
1
Study for the CISSP with an AI tutor that adapts to your weak domains.
Copy-paste this prompt
You are a CISSP exam tutor. Explain [domain topic, e.g., security architecture or risk management] the way the exam frames it, using its 'think like a manager' mindset, then quiz me with three CISSP-style questions and explain the reasoning behind each answer.
2
Have AI build a study plan across all eight domains around your work schedule.
Copy-paste this prompt
Build me a 12-week CISSP study plan around a full-time job, ordered by domain weight, with weekly goals and a practice-question target for each week.
What you'll haveYou earn the credential that clears the architect and management pay gate - one of the clearest steps into the top of the security band.
6
Build hands-on offensive skills to defend better and earn more
Why this pays: Understanding how attackers actually operate makes you a far more valuable defender and opens higher-paid penetration-testing and red-team roles. Offensive skill is a durable, hard-to-automate edge.
Hack The BoxTryHackMeChatGPT
1
Train on legal, sandboxed hacking platforms and use AI to explain concepts you get stuck on.
Copy-paste this prompt
I am working through a Hack The Box / TryHackMe machine and I am stuck understanding [generic concept, e.g., privilege escalation on Linux]. Explain the concept and the general methodology without giving me the answer to the specific box, so I learn to find it myself.
2
Map a path toward an offensive certification like the OSCP if red-teaming appeals.
Copy-paste this prompt
Build me a realistic 6-month plan to prepare for the OSCP from my current level, covering the skills, practice platforms, and study rhythm, around a full-time job.
What you'll haveYou gain an attacker's perspective that makes you a stronger defender and qualifies you for premium offensive-security roles - a durable edge as routine defense automates.
Your 12-month sequence to the top of the range

How the plays above stack into a path from median pay toward the $250,590 tier.

This week
Create a free ChatGPT account and use it to learn one MITRE ATT&CK technique and how it is detected - using only generic examples, never real logs.
Weeks 1-2
Learn your SOC's AI copilot and start using it to speed investigations while you own the verification.
Month 1
Pick your climb - cloud security, detection engineering, or threat hunting - and start the AI-built 90-day learning plan for it.
Months 1-3
Practice hands-on in a lab or on Hack The Box / TryHackMe, and start writing or tuning real detections at work.
Months 2-4
Begin studying for the CISSP or a cloud-security certification with an AI tutor.
Months 3-6
Apply for a specialized role - cloud security, detection engineer, threat hunter, or incident responder - with your new skills and credential.
Ongoing
Keep moving up the stack and keep every real log, credential, and config out of public AI - the specialization is what pays and the discipline is what protects you.
Gear for this job

As an Amazon Associate, PayCrunch earns from qualifying purchases. Links to books and tools are for the job on this page; we only recommend what we’d use in the work.

ISC2 CISSP Official Study Guide, 10th

Sybex / Chapple official OSG 10th (ISBN 978-1-39425-469-9) for the earn-the-CISSP play. Official OSG is not the exam. Not OSCP. No leftover CISSP item-count card.

Next steps for a Cybersecurity Analyst

Some links below are affiliate or partner links. PayCrunch may earn a commission if you enroll or subscribe through them, at no extra cost to you. Wage figures on this page still come from the Bureau of Labor Statistics, not from these programs.

Cybersecurity Analyst work is specific enough that a stamped 'check out these courses' block would be noise. BLS files this work as Information Security Analysts (SOC 15-1212). O*NET Job Zone 4 is typical: a bachelor's degree, so the honest next credential is a professional certificate or bachelor's-level coursework — not a random catalog dump.

The occupation's listed knowledge areas include Telecommunications and Engineering and Technology; the links search those subjects, not a generic 'career courses' list.

Cybersecurity Analysts in this dataset list AJAX among the tools in use, so a program that names that stack is a better fit than a survey course.

Cybersecurity programs on Coursera for Cybersecurity Analyst work

Coursera search for cybersecurity — a professional certificate or bachelor's-level coursework that lines up with computing, not a generic professional-development aisle.

Cybersecurity courses on edX

edX search for cybersecurity, aimed at computing (SOC 15-1212). Same field as the Coursera link, different university catalog.

Screened remote and flexible Cybersecurity Analyst listings on FlexJobs

FlexJobs screens remote, hybrid, freelance, and flexible listings so you are not wading through unverified ads. This is a job-board search for Cybersecurity Analyst work, not a claim that they list a counted SOC 15-1212 inventory.

Build a Cybersecurity Analyst resume on Resume Now

Write a Cybersecurity Analyst resume, or one aimed at Computer and Information Systems Managers, instead of a blank template. Resume Now is a resume builder; we are not claiming a counted template set for this SOC.

Build a Cybersecurity Analyst resume on Zety

A Cybersecurity Analyst resume that names the actual tasks on this page, or the step-up title Computer and Information Systems Managers, beats a blank template when you apply.

What Cybersecurity Analysts earn by state

These are the Bureau of Labor Statistics’ own figures for Information Security Analysts, state by state — not a cost-of-living adjustment applied to the national number. Only states employing at least 500 people in the occupation are shown, because a state median drawn from a handful of workers is noise rather than a signal.

Washington
$154,940
highest of them · +20% vs the national median
Puerto Rico
$63,740
lowest of the 42 states and territories that qualify · -51% vs the national median
The same job pays $91,200 more a year at the median in Washington than in Puerto Rico — 143% higher. That gap is what the Bureau measured, before any question of what it costs to live in either place. The top-of-range figure quoted at the head of this page, $250,590, is a different statistic in a different place: it is the 90th-percentile wage in Tennessee. The state that pays the typical worker most and the state where the best-paid go highest are not always the same one.
Washington$154,940Maryland$139,640California$138,570Delaware$137,030Massachusetts$136,550Colorado$135,220District of Columbia$135,090Virginia$134,900

Source: U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025, SOC 15-1212. 42 states and territories clear the 500-employee reporting floor for this occupation; those below it are left out rather than shown with a wide error band.

Free data. Use any of it.

PayCrunch publishes verified, BLS-sourced salary + AI-playbook data on 1,000+ professions — free, no signup.

Frequently asked
Will AI replace cybersecurity analysts?
It is genuinely automating the routine part - Tier-1 alert triage and monitoring - so a job that is only watching a dashboard is exposed. But it is also expanding higher-value work in cloud security, detection engineering, threat hunting, and AI security itself, where demand and pay are rising. The move is to climb up the stack, using AI as a force-multiplier.
Can I paste logs or configs into ChatGPT to get help?
No. Real logs, configurations, credentials, internal IPs, and hostnames must never go into public AI - it is a data-exfiltration risk and can expose your infrastructure. Use generic, sanitized examples for learning, and use only your organization's sanctioned enterprise AI for anything touching real systems.
What actually moves an analyst toward $250,590?
Specializing into cloud security, detection engineering, threat hunting, or incident response, and earning the CISSP to reach architect and management roles. AI accelerates the learning and the daily work, but it is the specialization and the credential that command top pay.
Which certifications matter most?
The CISSP gates architect and management roles; cloud-security certifications (AWS, Azure, GCP) are in high demand; and offensive certs like the OSCP open penetration-testing and red-team work. AI tutors make studying for any of them far more efficient.
Do I need to be a strong coder?
You do not need to be a software engineer, but light scripting - especially Python - is increasingly valuable for detection engineering and automation, and AI coding assistants make it far more approachable. The higher-paid security roles reward the ability to build, not just monitor.
Methodology & sources
  • Salary (median, 10th, top of the range) — U.S. Bureau of Labor Statistics, OEWS.
  • By state — the Bureau of Labor Statistics’ own state medians, limited to states employing at least 500 people in the occupation. No cost-of-living arithmetic is applied to a wage anywhere on this page.
  • The plays — PayCrunch's own step-by-step guidance using publicly available AI tools. Tool names/URLs are real and current as of August 2026; prompts are written to work as-is. Verify any professional output before relying on it.

Sources