The information security analyst who teaches the tooling
$250,590top of the range in Tennessee · middle $129,180 / yr
AI is transforming this role
Information Security Analysts in the United States earn a median of $129,180 a year. Pay starts near $75,090. Pay reaches $250,590 at the top of the range in Tennessee, the best-paying state for this work among those with at least 500 people in the job.
Source: U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025 (Information Security Analysts, SOC 15-1212). Last checked 9 September 2026.
Entry level
$75,090
Top of the range · Tennessee
$250,590
Education
Bachelor's degree in Cybersecurity
Wages — U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025 (Information Security Analysts). Top of the range is the highest state-level figure among states with at least 500 people in the job. AI-impact rating is PayCrunch's editorial assessment. Updated September 2026.
🆕 New & Trending AI Tools for Information Security AnalystReviewed September 2026
We track new AI-tool launches every week and refresh this list — here’s what’s gaining traction for Information Security Analyst work right now.
Claude CodeNEWFree / usage-based
Terminal coding agent that reads your repo, runs tests, and ships multi-file changes.
How an Information Security Analyst uses it: describe a feature and let it implement and test it across the codebase
OpenAI CodexNEWIncl. w/ ChatGPT plans
Agent that runs longer, deterministic multi-step coding jobs on its own.
How an Information Security Analyst uses it: delegate a well-defined build or migration and review the finished result
WindsurfNEWFree / $15 mo
Agentic IDE that keeps context across a whole project.
How an Information Security Analyst uses it: make large, coordinated changes without losing track of the codebase
AWS KiroNEWPreview / see site
Spec-driven coding agent that turns written specs into working code.
How an Information Security Analyst uses it: write the spec first and let it build to that spec
NotebookLMNEWFree / $7.99 mo
Google tool that answers questions grounded only in the documents you give it — with citations.
How an Information Security Analyst uses it: load your own manuals, policies, or PDFs and ask questions that stay accurate to the source
CursorFree / $20 mo
AI-native code editor that edits across an entire project.
How an Information Security Analyst uses it: describe a change in plain English and let it rewrite and refactor whole files
GitHub Copilot (Agent Mode)$10–19 mo
AI pair-programmer built into VS Code and GitHub that now completes multi-step tasks.
How an Information Security Analyst uses it: hand off a task and have it plan, edit multiple files, and open a pull request
ChatGPTFree / $20 mo
The most-used AI assistant — writing, analysis, research, and images from a plain-language chat.
How an Information Security Analyst uses it: draft emails and documents, summarize long files, and get instant answers to on-the-job questions
ClaudeFree / $20 mo
AI assistant known for careful writing, long-document analysis, and coding.
How an Information Security Analyst uses it: analyze big reports or spreadsheets and turn messy notes into clean, finished writing
The queue is already long when the analyst opens it. Overnight alerts sit beside a vendor notice, a ticket an engineer sent back as unclear, and a finding from yesterday that still needs a sentence a manager can read without a meeting. The work is to monitor what the tools are showing, write what the review actually found, and move tickets until the right person can finish them. That is the analyst seat. A chief information security officer sets direction for the whole program and speaks for it to executives. The analyst lives closer to the record.
What hiring managers mean by this seat
When a security team posts for an information security analyst, the hiring manager is usually trying to add someone who can be trusted with three repeating tasks. The first is monitoring: looking at alerts, logs, and notices the company already collects, and deciding which ones deserve a human. The second is a written finding, short enough to read and specific enough to act on. The third is ticket work, which means opening, updating, chasing, and closing the record so a fix does not die in a chat thread. Teams differ in how much of the week is live monitoring and how much is writing and follow-through. The posting that matches this career is the one that wants all three.
A watch role that lives only on a live shift, with no expectation of a written finding, is a narrower assignment. The analyst described here still monitors, and may take a rotation on the queue, but the job is incomplete if nothing is written down and no ticket moves. The chief's job is incomplete in the other direction: strategy, budget, and board conversation without time in the queue. People who want the analyst seat should be glad to do the unglamorous middle. People who want only the live rush, or only the executive table, will be bored or overmatched.
The day has a rhythm that looks ordinary from the outside and is judgment on the inside. Morning often starts with what fired overnight and with any ticket that aged past the team's own deadline. Midday may be a review of access changes, a look at scan results the team already runs, or a conversation with IT about a vendor fix that needs a window. Late day is for writing: what was seen, which system, why it matters to the business, and what should happen next. The analyst does not invent a private method for breaking into systems. The analyst documents concern, routes it, and stays with it until the ticket reflects reality.
Partners are everywhere and none of them report to the analyst at the start. Server and network teams, application owners, a help desk, sometimes a lawyer or a compliance lead, and a manager who has to explain the week upward. The analyst who thrives writes so those partners can act without a second translation. The analyst who struggles either buries the point in tool output or sends a ticket so vague that the receiving team sends it back. Both failures are about communication, and hiring managers listen for them.
Credentials that survive a resume screen
Name the issuer, not a fog of letters
Early in this career, many hiring managers look for CompTIA Security+ because it shows a baseline the industry recognizes. Later, a credential such as CompTIA CySA+ speaks more directly to analysis work, and the CISSP from (ISC)2 is the widely known professional mark people pursue as the job grows. CompTIA's own home is comptia.org.
None of these is a licence to practice, and none of them replaces a record of having monitored, written, and closed work. Security+ is often the first one an employer will pay for or require within a year of hire. It proves a broad foundation. CySA+ is aimed more tightly at people who analyze and respond in a defensive role. CISSP is broader and is often treated as a senior professional credential, useful when you want lead responsibility or a move toward program work. Preparation is study from the issuer's own outline, plus enough job experience that the material attaches to something you have seen. The issuer describes the examination. A career guide should not pretend to.
Degrees help and they are not the only door. Computer science, information technology, cybersecurity, and related majors are common on resumes that reach a hiring manager. So are people who started on a help desk, a systems team, or a network team and learned to read what those teams already see. If your degree is in another field, show the bridge: a credential, a lab you can talk about honestly, and any workplace monitoring you have done with permission. If your degree is in security and you have never owned a ticket, say that plainly and show projects that mimic the three tasks, labeled as practice rather than as employment.
Letters that do not match the seat can hurt. A senior management credential on a junior resume, with no analysis behind it, reads as decoration. A pile of badges with no story about a finding you wrote is the same problem. Pick one or two credentials you can discuss, keep them current the way the issuer requires, and spend the rest of your effort on writing samples. A redacted finding, with customer names and sensitive detail removed, will do more in an interview than a tenth badge.
The first year on a real queue
The first months are about learning what "normal" looks like in that environment. Every company is noisy in its own way. An analyst who escalates everything will exhaust the people who have to respond. An analyst who closes everything as benign will miss the one event that mattered. Calibration comes from sitting with a senior person, reading old findings, and asking why a ticket was pushed or dropped. Take notes in your own words. Build a sense of which systems are precious, which teams answer quickly, and which alerts are famous for crying wolf.
Writing gets scrutinized early. A strong finding names the system, the time, what was observed, what is still unknown, and the next action. It separates observation from guess. It says who was told. It does not wander into a tutorial on how an intrusion would be carried out. Hiring managers and legal reviewers both prefer the plain version. If you cannot explain the concern to an application owner in a few clear sentences, you do not yet understand it well enough to close it.
Ticket hygiene is the part ambitious people skip and then get coached on. Update the record when the status changes. Do not let a thread in chat become the only history. Chase politely and on a schedule. When another team owns the fix, your job is to keep the ticket true, not to seize their keyboards. When the work is done, close it with a sentence the next analyst can trust at 2 in the morning. That habit is what a senior person means by "reliable," and it is how you earn harder findings later.
Expect a mix of urgent and dull. Vendor notices, access reviews, scan output, and policy exceptions fill the dull hours, and they are part of the job rather than a distraction from it. The urgent hours are when something looks wrong and a manager wants a status that is accurate even if it is incomplete. Practice saying what you know, what you have ruled out, and when you will update. People remember the analyst who stayed calm and specific. They also remember the analyst who guessed in public.
Senior analyst, lead, and the fork after that
Senior work is still monitoring, findings, and tickets, with harder judgment and less supervision. You take the ambiguous alert. You review someone else's writing before it leaves the team. You notice when a whole class of tickets is failing for the same reason, and you say so. A lead adds scheduling, coaching, and the relationship with the teams that receive your work. The lead is still close to the queue. A lead who only attends meetings will lose the feel of the tools, and the team will feel it within a month.
After that, people branch. Some move toward security engineering, where the day is building and tuning the controls the analysts rely on. Some move toward security architecture or risk work, where the day is design and tradeoffs across the business. Some aim at management of a security team, and a few eventually want the chief's chair. Those are different crafts. The analyst path does not require you to abandon the queue in year three. It does require you to get better at the three tasks until a harder scope is obvious to the person who would promote you.
Lateral moves are common and they should be honest. An analyst from a bank can move to a hospital, a software company, or a public agency, and the tools will differ more than the habits. What travels is the ability to monitor without panic, to write a finding a stranger can use, and to keep a ticket alive until it is true. What does not travel is insider slang and a resume that lists every product you have logged into. In the interview, walk through one finding from detection to close, including the part where you were wrong and corrected the record.
May 2025 pay for Information Security Analysts
May 2025 Occupational Employment and Wage Statistics describe Information Security Analysts, and that series matches this title. The entry wage is $75,090. The national median is $129,180. The rise from entry to the median is $54,090, which is the published distance from a starting analyst to the middle of the occupation. Use those two figures before you reach for the top of the range. A first role that includes training, a shared queue, and close review belongs nearer entry. An analyst who already owns findings and closes hard tickets without a handler belongs nearer the median.
The high end of the published range in Tennessee is $250,590, in the locations the Bureau could include when it reported a high end. That figure is the top of the range there. It is a different statistic from a state median, and the tables here do not hand you a Tennessee median to confuse with it. The gap from the national median up to that Tennessee high end is $121,410. Treat it as the far end of published pay for scarce senior scope, not as a typical offer in that state and not as a target for a first analyst job.
State medians tell the typical story, and they are not the same story as Tennessee's range top. Washington's median is $154,940, which is $25,760 above the national median and the highest median in this set. Maryland is $139,640, California is $138,570, Delaware is $137,030, and Massachusetts is $136,550. The lowest median is Puerto Rico at $63,740. The gap between Washington and Puerto Rico is $91,200. If you are weighing a move, put the median of the place next to $129,180 and see whether the offer is local-typical, national-typical, or something else entirely.
How to talk about the offer
Bring the statistic that matches the chair. A new analyst quoting $250,590 is having a fantasy. A senior analyst in a high-median state quoting only $75,090 is leaving the published record unused. If the scope is entry, start from $75,090 and ask what performance would justify movement toward $129,180. If you already do the three tasks well, anchor on $129,180 and use the $54,090 step to show how far an "entry" label would undershoot the work. If the role is senior and the package is meant to compete for scarce people, you may mention $250,590 as the high end of the published range in Tennessee, then return quickly to the median that fits the state where you would actually sit.
For a Washington offer, $154,940 is the median to know, and $25,760 is the published lift over the national median. Maryland, California, Delaware, and Massachusetts cluster from $139,640 down to $136,550, all above the national median, none of them a substitute for the Tennessee range top. A Puerto Rico conversation belongs against $63,740, with $91,200 describing the spread from the highest median to the lowest, not a verdict on your skill. On-call rotations, bonus plans, and credential support change the lived package. Discuss them in words. Do not attach a dollar figure the Bureau did not publish. Match each published number to what it measures, and let the monitoring, the findings, and the tickets argue for where you sit inside the band.
The top of Information Security Analyst pay — and how to get there with AI
$250,590what Information Security Analyst pay reaches in Tennessee
Highest state-level top-of-range annual wage for Information Security Analysts, among states with at least 500 people in the job. U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025.
And the role it leads to — Computer and Information Systems Managers — reaches $327,300 in Washington.
$75,090entry$129,180middle$250,590top end
This occupation splits on one thing: whether the business treats you as the person who blocks requests or the person who shows engineering, finance and legal how to use something new without getting hurt.
Two duties sit near the top of this job's list and both are teaching in disguise: training users and promoting security awareness, and reviewing violations of computer security procedures with the people who committed them. Most analysts treat them as overhead and put their hours into firewall rules, virus reports and modifying access status, all of which are steadily being automated. What is not automated is an engineer asking whether a customer table can go into an assistant and getting a straight, technically correct answer inside the hour. Being that answer is a position, and positions are what pay.
Your playbook, by where you are now
Just startingEarn the right to be believed
Do the unglamorous parts well first, risk assessments, access changes and encrypting data in transit, so nobody can dismiss you as a trainer who cannot build.
Hold a monthly drop-in where anyone can bring a tool or a design and ask whether it is safe, and answer every question that same week.
Rebuild one awareness module around a real incident inside your own company, leaving the technical detail in.
Follow current reports of viruses and vulnerabilities daily and be first on your team to describe a new one in plain words.
Learn active directory software and access management software properly, since access is what most questions turn out to be about.
What proves it: A drop-in session engineers actually attend, and one awareness module rebuilt around a real incident.
Realistic span: the first two or three years
A few years inMake the safe path the easy path
Publish a short written pattern for each common risky thing, customer data in a chat assistant, credentials in code, an external file share, saying how to do it safely rather than that it is forbidden.
Stand up a sandbox where a team can try something new against synthetic data before anyone argues about policy.
Run tabletop drills with an actual department instead of with the security team, and write up what broke.
Review GitHub Copilot and comparable developer tooling properly, then give engineering written guidance rather than a verdict.
Document the emergency measures policies and tests you operate, and teach them to the people who will be woken up.
What proves it: A published set of safe-use patterns and a drill report from outside the security team.
Realistic span: years four through seven
ExperiencedOwn how the company learns
Run an internal certification: a short course and an assessment a team must pass before handling a sensitive data class.
Take charge of the review path for new systems and make it fast enough that nobody bothers routing around it.
Coordinate implementation of security plans with outside vendors and with the departments affected, and be present when it lands.
Grow two people who can teach without you, because a programme with a single instructor is not a programme.
Tennessee is where this occupation prices highest, and information systems leadership is the usual next rung after a company-wide programme.
What proves it: An internal certification programme with named graduates, and a review path teams choose to use.
Realistic span: eight years and beyond
The next 90 days
Book a recurring hour once a week, in a room or a call anyone can join, and call it the clinic. Bring nothing. Let people arrive with whatever they are about to do, a vendor, a script, a spreadsheet of customer records, an assistant they have already started pasting into, and answer them properly and in writing within a day. Keep it up for a quarter without being asked to. Two things follow. You uncover exposure no scan would ever have surfaced, because people say things aloud they would never put in a ticket. And you become the default first call, which is the position every senior role in this occupation is really hiring for.
Wage figures: BLS OEWS, May 2025. The playbook is PayCrunch editorial guidance, not a guarantee of pay or placement.
Every figure is the national median from the U.S. Bureau of Labor Statistics (OEWS) shown on that role’s own page.
Never used AI before? Start here (2 minutes).
Start with the security AI wired into your stack. If you have Microsoft Security Copilot, CrowdStrike Charlotte AI, or an AI-enabled SIEM, use it to summarize an incident and draft the investigation queries — then verify every result against the raw logs. It reasons over your telemetry; you make the calls.
For scripting, log parsing, and learning with no sensitive data, use ChatGPT or Claude to write a detection regex, explain an attacker technique, or draft a Python parser. Keep live incident data, IOCs that identify a victim, and credentials inside approved, isolated tools.
The one rule, forever: AI is an analyst's force multiplier, not the decision-maker. Never let AI auto-contain, disable accounts, or push blocks without human approval — a wrong automated action can take down production or tip off an attacker mid-investigation. Never paste live incident data, credentials, customer PII, victim-identifying IOCs, or malware samples into a consumer AI tool; use approved, isolated tooling. Verify every AI-suggested detection for false positives before it fires, and remember you own the containment call, not the model.
The plays — exact steps, exact prompts
Do these in order. Each one is copy-paste ready. You do not need to know anything about AI going in.
1
Turn alert triage from a grind into a fast, judged workflow
Why this pays: Escaping the tier-1 alert treadmill is what frees you to do the specialized work that pays; AI triage summarization is the lever — if you verify it.
Microsoft Security CopilotCrowdStrike Charlotte AISplunk / Sentinel (AI)
1
Use Security Copilot or Charlotte AI to summarize an alert's context — the who/what/where and related events — so you decide true vs. false positive in seconds, then confirm against raw telemetry.
Copy-paste this prompt
Explain this security alert in plain language and tell me what to check to confirm or dismiss it: [paste sanitized alert fields — no customer PII]. List the MITRE ATT&CK techniques it maps to, the log sources I should pull, and the specific indicators that would make this a true positive.
Use on sanitized alert data to structure triage; verify against the actual logs — never close or escalate on the AI's summary alone.
2
Feed your verified dispositions back into tuning so the noisy, low-value alerts stop reaching you.
What you'll haveFaster, better-judged triage and less noise — the reclaimed time that lets you move into higher-paid specialties.
2
Become a detection engineer, not just an alert responder
Why this pays: Detection engineering (writing the rules, not just answering them) is a distinct, better-paid track; AI accelerates writing and testing detections as code.
SigmaSplunk / Sentinel (KQL/SPL)Claude / ChatGPT
1
Write detections as code in Sigma (portable) or native KQL/SPL, using AI to draft the logic from an attacker technique, then test it against known-good and known-bad data.
Copy-paste this prompt
Write a [Sigma] detection rule for [suspicious use of certutil.exe to download a payload on Windows], mapped to the relevant MITRE ATT&CK technique. Explain the logic, the fields it depends on, likely false positives, and how I would test it. Then give the [KQL] equivalent for Microsoft Sentinel.
Use to draft detections; validate against real telemetry and tune out false positives before it goes live — a noisy rule erodes trust.
2
Version your detections in Git with tests, treating detection content like software you maintain.
What you'll haveA portfolio of tuned, tested detections — the detection-engineering skill set that commands the top of the analyst band.
3
Automate response with SOAR, human in the loop
Why this pays: Analysts who automate response cut incident cost and handle more with less — the leverage that gets you promoted into senior and lead roles.
TinesTorqCortex XSOAR
1
Build response playbooks in Tines or Torq for repeatable steps — enrichment, ticketing, evidence gathering — using AI to draft the workflow logic, with human approval gates before any containment.
Copy-paste this prompt
Design a SOAR playbook for [a phishing report]: steps to enrich the sender and URLs against threat intel, detonate the attachment safely, check who else received it, and draft a containment recommendation — but require an analyst to approve before quarantining or blocking. List the integrations needed and the decision points.
Use to design the workflow; keep a human approval gate on every containment or disruptive action — never fully auto-remediate.
2
Start by automating enrichment and evidence-gathering (safe) before automating any action (gated).
What you'll haveFaster, consistent incident handling at lower cost — the automation impact that earns senior and lead pay.
4
Level up threat hunting and intelligence
Why this pays: Proactive threat hunting is senior, well-paid work; AI helps you form hypotheses, query at scale, and digest threat intel faster than manual hunters.
Use MITRE ATT&CK to frame hunts and AI to turn a threat-intel report into concrete, testable hunt hypotheses and the queries to run.
Copy-paste this prompt
Based on this threat-actor TTP summary: [paste public report], generate three specific, testable threat-hunt hypotheses for a [Windows/Active Directory] environment, the data sources and queries to test each, and what a positive finding would look like. Map each to MITRE ATT&CK.
Use public threat intel to design hunts; run the queries in your environment and validate findings before raising an incident.
2
Document hunts and findings so they become new detections — close the loop from hunt to permanent coverage.
What you'll haveA proactive hunting practice that finds what alerts miss — the senior capability behind top-of-range compensation.
5
Own cloud security, where the money is
Why this pays: Cloud security is the highest-demand, best-paid segment of the field; pairing AI with cloud-security tooling makes you the scarce specialist.
WizProwlerAWS / Azure security (with AI)
1
Use Wiz or Prowler to find cloud misconfigurations and attack paths, and AI to explain the risk and prioritize remediation by real exploitability.
Copy-paste this prompt
Given this cloud security finding: [sanitized — e.g., an IAM role with wildcard permissions reachable from the internet], explain the attack path, the blast radius, how an attacker would exploit it, the prioritized fix, and a guardrail to prevent recurrence. Note any legitimate use I should check before remediating.
Use to assess and prioritize on sanitized findings; confirm the real configuration and business use before changing anything.
2
Build preventive guardrails (policy-as-code) so the same misconfiguration cannot come back.
What you'll haveCloud-security expertise in the segment with the most demand — the specialization that pushes pay past $251k.
6
Accelerate certs and write clearer incident reports
Why this pays: Certifications (CISSP, OSCP, cloud security) are direct salary levers, and clear incident and executive communication is what gets analysts promoted into leadership.
NotebookLMClaude / ChatGPTHack The Box / TryHackMe
1
Load cert objectives into NotebookLM and drill with an AI tutor; practice hands-on skills on Hack The Box/TryHackMe; and use AI to turn your incident notes into clear technical and executive reports.
Copy-paste this prompt
Turn these incident notes into two write-ups: a technical timeline for the security team (with MITRE ATT&CK mapping and IOCs) and a plain-language executive summary (impact, actions taken, residual risk, recommendations). Notes: [paste sanitized].
Use to draft reports on sanitized details; you verify the timeline and facts, and never include victim-identifying data in a consumer tool.
2
Publish sanitized write-ups or a blog to build a public reputation — visibility plus certs is the promotion formula.
What you'll haveCerts earned faster and communication that gets you noticed — the credentials and visibility behind lead and architect pay.
Your 12-month sequence to the top of the range
How the plays above stack into a path from median pay toward the $250,590 tier.
Month 1
Use your security AI (Copilot/Charlotte/SIEM) to speed alert triage, verifying every result against the raw logs.
Months 2-3
Start writing detections as code (Sigma/KQL) with AI drafting and rigorous false-positive tuning.
Months 3-6
Automate enrichment and evidence-gathering in a SOAR tool, with human gates on any action.
Months 6-9
Build a threat-hunting practice from intel-driven hypotheses and convert findings into detections.
Months 9-12
Specialize in cloud security and knock out a cert (CISSP/OSCP/cloud) with an AI tutor.
Year 2
Lead detections, hunts, or incident response for your org — the specialist/lead scope at the top of the band.
Gear for this job
As an Amazon Associate, PayCrunch earns from qualifying purchases. Links to books and tools are for the job on this page; we only recommend what we’d use in the work.
Some links below are affiliate or partner links. PayCrunch may earn a commission if you enroll or subscribe through them, at no extra cost to you. Wage figures on this page still come from the Bureau of Labor Statistics, not from these programs.
Information Security Analyst work is specific enough that a stamped 'check out these courses' block would be noise. BLS files this work as Information Security Analysts (SOC 15-1212). O*NET Job Zone 4 is typical: a bachelor's degree, so the honest next credential is a professional certificate or bachelor's-level coursework — not a random catalog dump.
The occupation's listed knowledge areas include Telecommunications and Engineering and Technology; the links search those subjects, not a generic 'career courses' list.
Information Security Analysts in this dataset list AJAX among the tools in use, so a program that names that stack is a better fit than a survey course.
Coursera search for cybersecurity — a professional certificate or bachelor's-level coursework that lines up with computing, not a generic professional-development aisle.
FlexJobs screens remote, hybrid, freelance, and flexible listings so you are not wading through unverified ads. This is a job-board search for Information Security Analyst work, not a claim that they list a counted SOC 15-1212 inventory.
Write an Information Security Analyst resume, or one aimed at Computer and Information Systems Managers, instead of a blank template. Resume Now is a resume builder; we are not claiming a counted template set for this SOC.
An Information Security Analyst resume that names the actual tasks on this page, or the step-up title Computer and Information Systems Managers, beats a blank template when you apply.
What Information Security Analysts earn by state
These are the Bureau of Labor Statistics’ own figures for Information Security Analysts, state by state — not a cost-of-living adjustment applied to the national number. Only states employing at least 500 people in the occupation are shown, because a state median drawn from a handful of workers is noise rather than a signal.
Washington
$154,940
highest of them · +20% vs the national median
Puerto Rico
$63,740
lowest of the 42 states and territories that qualify · -51% vs the national median
The same job pays $91,200 more a year at the median in Washington than in Puerto Rico — 143% higher. That gap is what the Bureau measured, before any question of what it costs to live in either place. The top-of-range figure quoted at the head of this page, $250,590, is a different statistic in a different place: it is the 90th-percentile wage in Tennessee. The state that pays the typical worker most and the state where the best-paid go highest are not always the same one.
Source: U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025, SOC 15-1212. 42 states and territories clear the 500-employee reporting floor for this occupation; those below it are left out rather than shown with a wide error band.
Free data. Use any of it.
PayCrunch publishes verified, BLS-sourced salary + AI-playbook data on 1,000+ professions — free, no signup.
It is transforming the work, not eliminating it — attackers use AI too, which only raises demand for skilled defenders. AI triages alerts and drafts queries, but deciding what is a real threat, running an incident, and owning the containment call (with real consequences if you are wrong) are human responsibilities. Tier-1 alert-clicking shrinks; detection engineering, hunting, cloud security, and IR leadership grow. Move up the value chain.
Is it safe to paste logs or alerts into ChatGPT?
Not live incident data, credentials, customer PII, victim-identifying IOCs, or malware. That can leak sensitive information and expose an active investigation. Sanitize aggressively, or use enterprise security AI (Security Copilot, Charlotte) built with proper data controls. Consumer tools are for abstracted problems and learning.
Can I let AI automatically respond to incidents?
Enrichment and evidence-gathering, yes; containment actions, no — not without a human approval gate. An automated block or account disable can take down production or alert an attacker mid-investigation. Keep a human in the loop for every disruptive action; you own that call.
Can I trust AI-generated detections?
Only after you test and tune them. AI drafts plausible detection logic quickly, but an untuned rule floods you with false positives (and erodes trust) or misses the real thing. Validate against known-good and known-bad data and treat detections like code you maintain.
How do I reach the $251k+ top of the range?
Specialize and lead. Use AI to escape the tier-1 grind, then go deep in a high-demand area — cloud security, detection engineering, threat hunting, or incident response — stack a respected cert (CISSP, OSCP), and build a reputation through clear reporting and public work. Specialization plus leadership, not alert volume, is what the top of the band pays for.
Methodology & sources
Salary (median, 10th, top of the range) — U.S. Bureau of Labor Statistics, OEWS.
By state — the Bureau of Labor Statistics’ own state medians, limited to states employing at least 500 people in the occupation. No cost-of-living arithmetic is applied to a wage anywhere on this page.
The plays — PayCrunch's own step-by-step guidance using publicly available AI tools. Tool names/URLs are real and current as of August 2026; prompts written to work as-is. Verify any professional output before relying on it.