Cybersecurity hiring is strong but harder to enter in 2026
CyberSeek’s count, as reported by Axis Intelligence, reached 514,359 US cybersecurity openings in the 12 months ending March 2026, up 12% year over year. Cybersecurity remains a durable career, while funding, experience requirements, and specialization make entry selective.
The skills-gap headline gives poor career advice because it confuses unmet demand with a funded requisition. So choose a target role before making a 2026 cybersecurity certification list.
Start with a lane that fits your skills. Earn the credential relevant postings ask for. Then build proof you can explain. Search adjacent routes alongside junior security jobs. We’ll examine the market, entry barriers, roles, salaries, certifications, portfolio work, and a 12-month plan.
In this article
- Is cybersecurity still a good career in 2026?
- The shortage story has a budget problem
- Entry-level cybersecurity is the hardest rung to reach
- Pick the work before you pick the certification
- You do not have to start in the SOC
- Salary numbers are useful only when you know what they measure
- Certifications open the interview; practical proof closes it
- Build one proof portfolio around the role you want
- Use a 12-month plan that ends in applications
- The best 2026 path is specific, adjacent, and provable
Is cybersecurity still a good career in 2026?
Yes, with a realistic entry plan.
The US Bureau of Labor Statistics projects 29% growth for information security analyst jobs from 2024 to 2034. In 2024, the occupation had 182,800 jobs. The BLS projects about 52,000 more by 2034 and roughly 16,000 openings each year. The BLS figure is reproduced in DecipherU’s 2026 career report.
Handle the global shortage figure carefully. ISC2’s 2024 Workforce Study estimated a 4.8 million-person global workforce gap, up 19% from 2023. ISC2’s 2025 study did not publish a new gap number. It shifted attention toward critical skills. Treating 4.8 million as a current count of vacant jobs in 2026 is sloppy.
These figures measure postings and surveys. Some also model occupations. They don’t tell you how many openings are funded or open to beginners. Marcus Chen, co-author of the Axis Intelligence research, explains why security hiring can persist during cuts:
“Unlike engineering headcount, which companies cut when quarters get rough, cybersecurity staffing is tethered to compliance obligations. SOC 2, HIPAA, GDPR, the SEC’s 2023 cyber disclosure rules — these don’t shrink when budgets do. Security is often the last team cut and the first approved for new hires. The 514,000 number is sticky in a way that software developer job counts aren’t.”
That persistence still doesn’t guarantee your first offer is funded.
The shortage story has a budget problem
Lack of budget overtook talent availability as the leading reason organizations could not fill security roles. The same workforce research reported 37% of respondents experiencing budget cuts, 25% reporting layoffs, and 38% reporting hiring freezes.
The ISACA State of Cybersecurity 2025 figures show the operational result: 55% of teams were understaffed, 65% had unfilled positions, and 39% took three to six months to fill non-entry roles.
A team can be understaffed while a candidate struggles to find an approved position. The market hires where risk has already won budget approval. It does not promise to train whoever buys a certificate.
CyberSeek reported supply-demand ratio was 74%, meaning roughly 74 qualified candidates for every 100 roles in its measure. That suggests a supply shortfall without establishing that every role is approved, local, or suitable for a beginner.
Search by lane, seniority, location, and salary floor.
Entry-level cybersecurity is the hardest rung to reach
The entry-level problem is measurable. UK Department for Science, Innovation and Technology data reported through Axis Intelligence shows postings asking for less than one year of experience fell from 25% in 2022 to 17%. Another 63% now request two to six years.
ISC2’s 2025 workforce study found that 56% of hiring managers believe training an entry-level hire to full independence takes four to nine months. A separate survey summarized in the research found that 90% of security managers consider prior IT experience and 89% require at least one certification.
Calling this an entry-level market is generous; employers often want a junior title attached to an experienced operator.
Your systems, networking, cloud, compliance, support, or development work is the evidence that can shorten the entry gap. Maya, a systems administrator with four years of Windows, networking, identity, and ticket-escalation experience, wants to move into security without taking a pay cut. She already understands access requests and operating systems. She knows escalation, troubleshooting and production risk too. Her task is translating those skills into security outcomes.
Career changers are not a rare exception. New entrants aged 39 to 49 represented 35% of new entrants in 2024, up from 18% in 2022.
AI adds pressure at the bottom. OccupationPay notes that repetitive entry-level SOC tasks face increasing automation pressure. Alert enrichment and routine triage are easier to automate than investigation, judgment, communication, and remediation. Build toward the latter.
Pick the work before you pick the certification
The SOC is a useful on-ramp, though the neat SOC-to-CISO ladder is convenient for course sellers and incomplete for career changers.
The figures below come from BLS/O*NET data presented in DecipherU’s report. They are approximate 25th-percentile, midpoint, and 90th-percentile estimates across different occupations and titles, rather than predictable promotion stages.
| Role | 25th percentile | Midpoint | 90th percentile |
|---|---|---|---|
| SOC analyst, Tier 1 | $55,000 | $78,000 | $105,000 |
| GRC analyst | $60,000 | $90,000 | $130,000 |
| Threat intelligence analyst | $65,000 | $95,000 | $135,000 |
| Penetration tester | $70,000 | $100,000 | $140,000 |
| Security engineer | $85,000 | $120,360 | $165,000 |
| Cloud security architect | $110,000 | $145,000 | $195,000 |
| Security sales engineer | $100,000 | $150,000 | $220,000 |
| CISO | $150,000 | $210,000 | $340,000+ |
The roles involve different work:
- SOC analyst: Monitor alerts, investigate events, and escalate incidents.
- GRC analyst: Map controls, manage risk, and prepare for audits.
- Threat intelligence analyst: Interpret information about adversaries and campaigns.
- Penetration tester: Assess weaknesses within an agreed scope and report remediation.
- Security engineer: Implement controls across identity, networks, endpoints, and infrastructure.
- Cloud security architect: Design controls for AWS, Azure, or Google Cloud. This generally follows cloud experience.
- Security sales engineer: Translate technical risk into a solution a customer can evaluate.
- CISO: Set strategy, manage risk, and communicate accountability to executives.
Application security, DevSecOps, privacy, and supply-chain security are adjacent lanes. Reported estimates include $152,000–$210,000 for AI security engineers, $160,000–$220,000 for AI red-team specialists, $140,000–$250,000 for zero-trust architects, $120,000–$170,000 for supply-chain security analysts, and $185,000–$290,000 for cybersecurity or privacy attorneys.
Treat those as specialist-market estimates for people with substantial domain experience; they are poor benchmarks for a career changer’s first security job. The available data also doesn’t establish that every listed specialty is growing faster than every traditional role.
For Maya, security engineering or cloud security could preserve more of her systems value than a reset into Tier 1 SOC work. If she prefers investigation and escalation, SOC remains a sensible target.
The salary table covers different occupational datasets, so its security-engineer midpoint should not be ranked directly against the BLS information security analyst median as one promotion ladder.
You do not have to start in the SOC
Map your previous work to the security problem you want to solve:
- IT support or networking: SOC analysis, security engineering, or cloud security.
- Compliance, audit, legal, or policy: GRC, privacy, or security assurance.
- Software development: Application security, product security, or DevSecOps.
- Customer discovery and explanation: Security sales development, account executive work, or sales engineering.
- Offensive-security interest: Penetration testing or red-team work after building fundamentals.
Sales can suit someone who prefers customer problems and quota work. They may also prefer explaining solutions to working incident queues. The following table shows the most relevant entry and technical-sales routes; it isn’t a complete sales-career map.
| Role | Base salary | OTE |
|---|---|---|
| SDR/BDR | $45,000–$60,000 | $70,000–$95,000 |
| Mid-market account executive | $75,000–$110,000 | $130,000–$200,000 |
| Enterprise account executive | $100,000–$140,000 | $180,000–$300,000+ |
| Sales engineer | $110,000–$150,000 | $150,000–$220,000 |
Secondary estimates from DecipherU’s analysis; OTE assumes 100% quota attainment.
OTE means on-target earnings at full quota. Actual pay may be lower. Sales engineering still deserves serious consideration: you evaluate technical products, understand customer risk, and explain why a control matters.
Salary numbers are useful only when you know what they measure
The most useful official benchmark is the BLS median information security analyst salary of $124,910 in May 2024, as reproduced by DecipherU.
The $135,969 US average repeated by Unihackers comes from a secondary aggregator and measures something different. It likely reflects senior-heavy samples, different job titles, or both. Available secondary estimates put entry-level cybersecurity pay roughly between $55,000 and $70,000, with some broader estimates reaching $85,000 depending on role and location.
Regional premiums change the picture too. Use the national median as a rough base:
$124,910 × 1.42 ≈ $177,000
That is the approximate result for a reported 42% Bay Area premium. The premium is itself approximate, so reporting cents would be theater.
Reported premiums also include DC Metro at 35%, New York City at 30%, Seattle and the Pacific Northwest at 28%, Boston and the Northeast at 25%, Austin and Texas at 18%, and US remote roles at 10%.
Virginia has more than 53,000 open roles in the state-level CyberSeek count, supported by federal agencies, defense contractors, and the intelligence ecosystem. That figure is separate from the 68,000-plus roles attributed to the broader DC Metro region; those geographies can overlap, so don’t add them together.
These salary tables help with planning; they do not forecast offers. I haven’t verified every regional estimate against a live posting, so measure your target market before spending money or accepting a pay cut.
Certifications open the interview; practical proof closes it
CybersecurityElite puts the trade-off plainly: “Honestly: yes for getting interviews, no as a substitute for skill. Certs are a filtering mechanism.”
Match the credential to the job you want. Stop when another credential no longer appears in your target postings.
| Target use | Credential | Estimated cost | Format |
|---|---|---|---|
| Foundation | Google Cybersecurity Certificate | About $49/month | Coursework |
| Foundation | ISC2 CC | Free during promotion | Multiple choice |
| General entry filter | CompTIA Security+ | About $400 | Multiple choice plus performance |
| Junior offensive work | eJPT | About $249 | Practical |
| Intermediate offensive work | PNPT | About $400 | Practical plus report |
| SOC and detection | CySA+ | About $400 | Multiple choice plus performance |
| SOC and detection | BTL1 | About $400 | Practical |
| Advanced offensive work | HTB CPTS | About $490 | Practical plus report |
| Advanced offensive work | OSCP | $1,600+ | Practical plus report |
| Cloud security | AZ-500 | About $165 | Multiple choice plus labs |
| Cloud security | AWS Security Specialty | About $300 | Multiple choice |
| Senior security | CISSP | About $749 | Adaptive multiple choice |
Costs are 2026 estimates. Verify current vendor pricing before paying.
For Maya, Security+ makes sense if the cloud, security engineering, or SOC postings she wants list it. Use Google’s certificate only if she needs structured fundamentals; otherwise, begin with Security+ preparation. Her next investment should be a practical cloud or identity project.
CEH is overrated for technical competence. In my view, the standard multiple-choice CEH is chiefly useful as a recruiter-recognized filter. Take it when a target posting names it; CEH Practical gives you stronger technical evidence to discuss.
CISSP belongs later. Full certification requires five years of experience. Candidates who pass before meeting that requirement may hold the official designation Associate of ISC2. Treat CISSP as a senior-role eligibility filter, not as proof of incident-handling ability.
Build one proof portfolio around the role you want
A project earns attention when a hiring manager can inspect the scope, evidence, decision, and limits. Use this compact process:
- Choose one target skill. Pick cloud identity, detection engineering, control mapping, vulnerability reporting, or another recurring requirement in your target postings.
- Define the boundary. State the systems, assumptions, exclusions, and success condition.
- Show evidence and judgment. Include logs and configuration. Add the test results. Explain the recommendation.
- Publish a concise report. Make the work easy to review and easy to question.
Shape the deliverable around the lane:
- SOC: Show alert triage and a detection rule. Add an incident timeline and the escalation decision.
- Penetration testing: A scoped lab report with evidence, remediation, and limitations.
- Cloud security: Identity, logging, network, and storage controls tied to a threat model.
- GRC: Control mapping, a risk register, and an executive recommendation.
- Application or AI security: A threat model, test plan, or safe evaluation of an AI system.
In DecipherU’s analysis of CyberSeek postings, cloud security appeared in 92% of postings. Incident response and forensics appeared in 88%. Threat intelligence and hunting appeared in 85%, GRC in 83%, security architecture in 80%, and AI/ML security in 78% of the analyzed postings.
When a posting says “degree or equivalent experience,” use the project to make that equivalence legible. It won’t guarantee employment. It gives the interviewer something better than a list of course completions: evidence to challenge.
Use a 12-month plan that ends in applications
Use the schedule as an adaptable plan for action.
Months 1–2 — Choose the lane
Audit your current work and identify the security problem it already touches. Fill gaps in networking, identity, operating systems, cloud basics, and security principles.
Months 3–5 — Earn one foundation credential
Choose the credential that appears in your target postings. Use Google’s certificate for structured fundamentals when needed; otherwise, prepare directly for Security+ or the relevant lane-specific exam.
Months 6–8 — Build proof
Complete one substantial project and document it clearly. Use practical labs or an exam when they support the target role.
For Maya, that could mean connecting Windows identity, cloud access, logging, and a small threat model. She would be extending existing systems experience rather than pretending to be a beginner.
Months 9–10 — Add a second credential only if the market asks for it
Use CySA+ or BTL1 for SOC work, eJPT or PNPT for penetration testing, CPTS or OSCP for advanced offensive roles, and AZ-500 or AWS Security Specialty for cloud security. Add CRTP or CRTO later for a specific red-team direction.
Months 11–12 — Apply through several doors
Apply to adjacent roles and apprenticeships. Include contractors, internal transfers and junior security positions. Tailor the project evidence to each posting.
Maya should reject any route whose published entry range falls below her salary floor unless the role offers a documented promotion or internal-transfer path. Cloud security and security engineering may protect her existing value better than a Tier 1 reset.
The best 2026 path is specific, adjacent, and provable
A plan that ends with another course is avoidance wearing a study schedule.
Open 20 target postings this week. Record the skills that recur. Identify one transferable advantage. Choose one useful certification. Build one artifact against the most common requirement. Set your salary and location range before paying for an exam.
The strongest cybersecurity career paths in 2026 may begin in security engineering, GRC, cloud operations, application security, privacy, or sales engineering. Start where your existing competence gives you leverage, then make the security work impossible to miss.