Information Security Analyst Career Guide for 2027
- Median annual pay
- $129,180
- BLS OEWS, May 2025
- Projected growth, 2025-35
- 21%
- BLS Employment Projections
- Typical entry education
- Bachelor’s
- BLS Employment Projections
Key takeaways
- Information security analysts protect an organization’s systems and data: they watch for attacks, find weak points before someone else does, and set the rules that keep files and networks safe. BLS counts 190,650 of them, earning a median of $129,180 in May 2025.
- Few people start here. BLS lists a bachelor’s degree as the typical entry education plus some work experience in a related job, usually network or systems administration, help desk or software work. Plan on a first job in IT before your first security title.
- It is one of the fastest-growing jobs on this site. BLS projects 21% growth from 2025 to 2035, against 3.5% for all occupations, as companies add security staff in response to cyberattacks. That works out to about 14,100 openings a year.
- Computer systems design and related services employs the most, 43,440, and banks and other credit intermediation are among the largest employers too. By share of jobs, Virginia and Maryland lead the country, which tells you how much of this work sits near federal agencies and defense contractors.
- The career runs from analyst to security engineer or architect, and for some to running a security program. BLS publishes no pay by level, so this guide shows the full range instead. Pay by state, metro and industry is in the information security analyst salary report.
What information security analysts do
Counted by BLS as information security analysts.
Information security analysts keep an organization’s systems and data safe. They monitor networks for signs of attack, test defenses to find weak points, investigate incidents when they happen, and set the access rules and policies that keep the next one from working.
BLS counts them as information security analysts; job titles include security analyst, cybersecurity analyst and SOC analyst. The tasks below, from O*NET, show how much of the work is planning and prevention rather than reacting.
The core tasks
- Develop plans to safeguard computer files against accidental or unauthorized modification, destruction, or disclosure and to meet emergency data processing needs.
- Monitor current reports of computer viruses to determine when to update virus protection systems.
- Encrypt data transmissions and erect firewalls to conceal confidential information as it is being transmitted and to keep out tainted digital transfers.
- Perform risk assessments and execute tests of data processing system to ensure functioning of data processing activities and security measures.
- Modify computer security files to incorporate new software, correct errors, or change individual access status.
- Review violations of computer security procedures and discuss procedures with violators to ensure violations are not repeated.
Task statements for information security analysts, quoted from O*NET OnLine, in O*NET’s order of importance.
Job titles you will see
- Information Security Officer
- Information Security Specialist
- Information Systems Security Analyst
- Information Systems Security Officer
- Information Technology Security Analyst
- Network Security Analyst
- Security Analyst
- Systems Analyst
Titles reported by workers in this occupation, O*NET OnLine.
Where information security analysts work
The largest employers of information security analysts among the 24 industries we checked, BLS OEWS, May 2025.
Firms in computer systems design and related services employ the most security analysts, followed by management of companies and enterprises and banks and other credit intermediation. Federal agencies and defense contractors weigh heavily too, which is why Virginia and Maryland have the highest share of these jobs.
Information Security Analysts, national industry-specific estimates, BLS OEWS, May 2025. A candidate list of industries, ranked by employment; not BLS’s complete industry ranking. Share is the industry’s employment divided by the occupation’s national employment, 190,650.
Ways to become an information security analyst
BLS lists a bachelor’s degree as the typical entry education. Lengths are NCES’s definitions of each degree.
-
A bachelor’s in computer scienceusually at least four years of full-time study · median 120 credits
Take electives in networks, operating systems and security, and set up a home lab to practice.
Compare computer science bachelor’s programs → -
A bachelor’s in software engineeringusually at least four years of full-time study · median 121 credits
Secure design and testing are part of the curriculum, which suits application security work.
Compare software engineering bachelor’s programs → -
Experience in IT firstusually at least four years of full-time study, then less than 5 years of related experience
BLS lists less than 5 years of experience in a related occupation as typical for entry. Network or systems administration, technical support and software development all count.
Compare online computer science bachelor’s programs → -
A master’s latergenerally one or two years of full-time study beyond the bachelor’s · median 30 credits
Not required for entry, but it can support a move into security architecture or management.
Compare computer science master’s programs →
Degree lengths: NCES, Digest of Education Statistics 2022, Appendix B: Definitions. Credits: the median of the programs in each ranking that state a credit total on their own page.
What employers expect
BLS’s typical entry requirements for information security analysts, BLS Employment Projections, occupation tables 1.2, 1.10 and 1.12, 2025-35.
- Typical entry education
- Bachelor’s degree
- Work experience in a related occupation
- Less than 5 years
- Typical on-the-job training
- None
What workers say a new hire needs
Share of surveyed workers in the occupation giving each answer, O*NET OnLine. Not a hiring requirement.
Programs to start with
The top two programs in each of our rankings, with the score and rank they carry there.
- California State University-Long Beach #1 in our Computer Science Degrees for Software Engineers Score 94.1 of 100
- California State University-Fullerton #2 in our Computer Science Degrees for Software Engineers Score 93.0 of 100
- San Jose State University #1 in our Bachelor’s in Software Engineering Score 87.0 of 100
- Florida Gulf Coast University #2 in our Bachelor’s in Software Engineering Score 85.2 of 100
- North Carolina State University at Raleigh #1 in our Master’s in Computer Science for Software Engineers Score 96.6 of 100
- Texas A&M University #2 in our Master’s in Computer Science for Software Engineers Score 93.7 of 100
What the degree costs
IPEDS tuition, 2023–24, at the programs in our rankings: in-state undergraduate for bachelor’s, the school’s average graduate rate for master’s.
Tuition is before fees, housing and financial aid, and it is the school-wide IPEDS figure, so the price a student pays can differ widely from the sticker. Public schools charging in-state rates sit at the low end of the bachelor’s range.
For what the job pays once you are in it, the information security analyst salary report shows pay in every state BLS publishes, the largest metro areas and across industries. Software developers, for comparison, earned a median of $135,980.
Information security analyst pay and job outlook
Information Security Analysts, BLS OEWS, May 2025; BLS Employment Projections, 2025-35.
Top-paying factors
Where the highest medians are, against the national median of $129,180. Each is a published median from the same release, not an estimate for any one person.
Information Security Analysts, BLS OEWS, May 2025: state, metropolitan area and national industry-specific medians.
Half of information security analysts earned more than $129,180 in May 2025 and half earned less; the middle half fell between $97,810 and $163,500. Washington has the highest state median, $154,940. BLS publishes no pay by years of experience, so this guide gives the range, not a ladder of salaries. The information security analyst salary report breaks pay down by state, metro and industry.
How the career moves
Typical stages. Titles and scope change by employer; BLS publishes no stages or pay by level.
-
First job in IT
IT Support Specialist · Network Administrator · Systems Administrator · Software Developer
Learn how real systems are built, configured and broken. Most security analysts spend their first years here, and the habits from this work, reading logs and tracing problems, are the ones security uses every day.
-
Security analyst
Information Security Analyst · SOC Analyst · Security Operations Analyst
Watch alerts, investigate what set them off, and decide whether it is an attack. Run vulnerability scans, review access and write up what you found so the fix sticks.
-
Security engineer
Security Engineer · Penetration Tester · Incident Responder
Build and test the defenses instead of only watching them: design firewall and access rules, attack your own systems to find gaps, and lead the response when something gets through.
-
Security leadership
Security Architect · Security Manager · Chief Information Security Officer
Decide how the whole organization is protected: which risks matter most, what to spend, and how to answer to auditors and executives. Some stay technical as architects; others run the security team.
Pros and cons
What people like about being an information security analyst, and what wears on them.
What draws people in
- Pro: Some of the fastest projected growth of any computing job, tied to a problem that is not going away.
- Pro: Pay close to software development, with a median well above most occupations.
- Pro: Employers in almost every industry, from banks and hospitals to government and tech.
- Pro: Work that feels concrete: you stop real attacks and fix real weaknesses.
What to weigh first
- Con: Rarely a first job: most people need a few years in IT or software before a security title.
- Con: Incidents don’t keep office hours, so on-call shifts and late nights come with many roles.
- Con: The threats change constantly, so the learning never stops.
- Con: Much of the work is quiet monitoring and paperwork, not the dramatic hunting the job is known for.
A day in the job
Illustrative: a composite day built from the job’s core tasks, not a record of one person’s day. Real days vary by team and employer.
- MorningReviewing overnight alerts, ruling out the false alarms and digging into the two or three that look real.
- Late morningA team check-in on open incidents and a patch that has to go out before an attacker uses the weakness it fixes.
- AfternoonRunning a vulnerability scan, reviewing who has access to a sensitive system, and removing accounts that shouldn’t be there.
- Late afternoonMeeting with developers about a new application, to build security in before it ships instead of after.
- End of dayWriting up an investigation so the next shift can pick it up, and reading the day’s security advisories.
Five questions before you commit
If most of these get a yes, the job is likely a good match.
- Do you like figuring out how things break?Security means thinking like an attacker and finding the weak point first.
- Are you willing to start in a general IT or software job?Most security analysts get their first security title after a few years of related work.
- Can you stay calm when something goes wrong?During an incident you have to work carefully while everyone else is worried.
- Will you keep learning on your own time?New attacks and tools appear every month, and the job assumes you keep up.
- Can you explain risk to people who aren’t technical?Much of the job is convincing others to change how they work.
Frequently asked questions
What does an information security analyst do?
They protect an organization’s computer systems, networks and data. O*NET’s top task for the occupation is to “Develop plans to safeguard computer files against accidental or unauthorized modification, destruction, or disclosure and to meet emergency data processing needs.” Day to day that means monitoring alerts, testing defenses, investigating incidents and setting access rules.
What degree do you need to be an information security analyst?
BLS lists a bachelor’s degree as the typical entry education, usually in computer science, information technology, software engineering or a related field, along with some work experience in a related occupation.
How much do information security analysts make?
Information security analysts earned a median of $129,180 in May 2025, according to BLS. The 10th percentile was $75,090 and the 90th was $199,850.
Is cybersecurity a growing field?
Yes. BLS projects 21% growth for information security analysts from 2025 to 2035, against 3.5% for all occupations, and ties it to firms adding security staff as cyberattacks increase. That is about 14,100 openings a year.
Can you become a security analyst with a software engineering degree?
Yes. A software engineering or computer science degree covers the programming, networks and operating systems security work builds on. Electives in security, networking and cryptography, plus a first job in IT or software, make the move easier.
Is information security analyst an entry-level job?
Usually not. BLS lists work experience in a related occupation as part of the typical path in, on top of a bachelor’s degree. Many analysts start in network or systems administration, technical support or software development.
Where do information security analysts work?
Computer systems design and related services employs the most, 43,440, followed by management of companies and enterprises and banks and other credit intermediation. Virginia has the most security analysts of any state.
How much does the degree path cost?
At the 75 bachelor’s programs in our software engineering ranking with a figure, median in-state tuition for 2023–24 was $20,696 a year, before fees and aid.
References
Every figure on this page comes from one of these, read by the site’s data scripts and computed at build time, never typed in.
- 1 Information Security Analysts, O*NET OnLine Task statements and reported job titles, quoted verbatim, and the education survey of workers in the occupation. O*NET OnLine, read 2026-10-06.
- 2 BLS Occupational Employment and Wage Statistics, May 2025: national, industry Information security analysts: employment, median and percentiles nationally, and employment and median in the 24 industries we checked. Read .
- 3 BLS Employment Projections, 2025-35 Projected employment change and annual openings, 2025 to 2035, for information security analysts and the related occupations.
- 4 BLS Employment Projections, occupation tables 1.2, 1.10 and 1.12, 2025-35 Table 1.2: BLS’s typical entry education, work experience and on-the-job training.
- 5 NCES, Digest of Education Statistics 2022, Appendix B: Definitions Definitions of the bachelor’s and master’s degree, including their usual length in full-time study.
- 6 NCES IPEDS IC2023_AY, 2023-24: undergraduate tuition for bachelor’s programs; for master’s, the school-wide average graduate tuition, which excludes program fees Tuition for the 75 ranked bachelor’s and 44 ranked master’s programs, the same figures the ranking pages show.
- 7 BLS Employment Projections, occupation tables 1.2, 1.10 and 1.12, 2025-35: tables 1.2 and 1.12 Typical entry education and related work experience for information security analysts, and BLS’s stated factor behind the projection: firms adding security staff as cyberattacks increase.