Cybersecurity Analyst
You’re the detective: you catch the one real attack hiding in a thousand false alarms, and then you prove it. Demand is huge, and the routine first-pass sorting is automated now, so the edge is your judgment about which one is real.
Related: Software Engineer, Data Analyst, AI Application Builder
The day in the life
The pile · emails people sent in
6 sent in by staff this morning
- •every one of them sent in by a real person who thought it looked wrong
- •nobody has opened any of them yet, just the subject and who sent it
the pile, before you read a single one
Six emails, and one of them might be a real trick. Where do you start?
Try a day as a cybersecurity analyst
A short, playful taste of the real work.
One of the fastest-growing kinds of work, but the jobs you would start in are unusually hard to get.
Most people do a job looking after other people’s computers first, then pass one exam to prove they know the basics.
What you’d do all day
The picture is breaking into systems on purpose to test them, but that’s a separate track that’s harder to get into. The common entry job is defending: watching security dashboards, reading logs, and triaging alerts, which means sorting which ones are a real threat and which are false alarms, plus a lot of compliance paperwork.
That first-pass sorting is increasingly automated now. So the durable part is the investigation a tool can’t finish: hunting what it misses and judging what an attacker is trying to do.
- Monitoring & alert triage45%
- Investigation & response20%
- Threat hunting & analysis10%
- Tooling & automation10%
- Reporting, strategy & meetings15%
Almost half the day is watching warnings come in and sorting the real ones from the false ones. That is exactly the part computers are starting to do.
“Cybersecurity” splits into a few very different jobs, from watching alerts to breaking in on purpose.
- Watching for attackssitting on alerts in real time and deciding what’s actually a threat.
- Responding to breachesshowing up after something’s been hacked, to contain it and figure out what happened.
- Checking the rulesmaking sure a company actually follows the security rules it’s supposed to.
- Breaking in on purposetesting a system’s defenses by trying to break into it yourself, with permission.
A typical early-career day
- 9:00Watch the dashboards
Scan the stream of security alerts. Most are noise; the job is spotting the one that isn’t.
- 10:30Investigate a suspicious one
Dig into an alert: real threat or false alarm? This is the core judgment call, made over and over.
- 1:00Document & escalate
Write up what you found and route it to the right people. Careful records are a big part of the job.
- 2:30Trace what happened
When something’s real, dig through the logs to reconstruct it, patient, detailed detective work.
- 4:30The first pass, sorted
The first-pass alert sorting gets done automatically now; you hunt what it misses and make the calls it can’t.
An entry level day on a security operations team, often on call. The attacking side most people picture is a separate track, and it takes experience to get into.
The outlook
Where it’s going
Cybersecurity is one of the fastest-growing fields anywhere: the BLS projects about 29% growth, and there are hundreds of thousands of unfilled US openings. But AI is reshaping it from the bottom: it’s automating tier-1 alert triage, the classic entry job, so some teams are shrinking those roles. The value is moving up to hands-on investigation, threat hunting, and securing the newer systems themselves.
Right now
Here’s the paradox: demand is enormous and the talent gap is famous, yet the junior door is brutally hard. Entry jobs expect experience and certs you can’t easily get without a job, and the exact tier-1 work that used to be the training ground is now automated. The field is booming, but breaking in rewards demonstrated, hands-on skill and a clear specialty over a generic résumé.
Would you like it?
Worth a look if you are patient, you notice small things, and you like working out whether an alarm means someone is really getting into the computers, or it is nothing.
Tap any that sound like you.
In practice, people realize it’s their thing when…
…and it probably isn’t their thing when
How people get in
- 4
- Years it takes on average
- $48K
- Average cost
- 14,100
- Jobs open up each year
Every way in
A cybersecurity degree
About 5 in 10
Four years · About $48K at a state college
Another computer job first, then one exam
About 4 in 10
Four years · About $200 for the first exam
Security+, the certificate most people are told to start with, still recommends two years of doing the work before you sit it.
Those are the two, and plenty of people take both. Employers ask for the certificate whether or not you went to college, so a degree usually ends with you sitting the same exam anyway.
How your first job gets decided
Nobody votes you in. What stands between you and the job is an exam you can sit whenever you are ready, and if the work is for the government, a background check they run on you first.
What employers check
- Not the tools you know. The people hiring say what they are short of is clear thinking, explaining yourself and working a problem out, ahead of anything technical.
- Some kind of school after high school, more often than the stories suggest. About 5 in 10 say a degree, about 2 in 10 an extra course on top of one, and about 1 in 10 a two year degree.
- Patience. Nearly 4 in 10 employers say filling a beginner job takes them up to six months, so a slow answer is not a no.
The first job is usually watching for attacks on somebody else’s network, and most people arrive at it from another computer job rather than straight out of school.
- The middle of this job pays $129,180 a year, and the work is growing about 21% over the next ten years.
- A cybersecurity degree earns about $85,100 four years after you finish, which is high for any degree.
When to apply
Nothing in this job is passed once and finished. All of it runs out.
- Every three yearsSecurity+ and CISSP, the two certificates employers ask for by name, both run out after three years unless you keep doing training to hold on to them. CISSP charges $135 a year on top of that, just to stay on the list.
- June 11 2027The current version of the entry exam stops being offered on that date. After it, you sit whatever replaces it, so the thing you studied for has an end date of its own.
- About four monthsIf the work is for the government they investigate you before you start, and a first check has been taking about 109 days. Once you have been cleared, moving to a different government job takes about a day.
How long it takes
There is no single route into this. About 4 in 10 of the people under 30 doing it came through another computer job first, about the same number came from outside computing entirely, and four years is the usual distance between starting out and being trusted with the work.
Most of this job is deciding whether something odd is an attack when the evidence points both ways, and then saying why you decided that. You can make one of those calls now.
Try deciding if an email is an attackCatch a Phish: Investigate a Suspicious Email
Work a suspicious email the way the job really works: gather the evidence, spot the small things that give a fake away, and decide whether someone is trying to trick you, without being fooled and without scaring everyone over an email that turns out to be fine. Looking at the evidence and deciding, quickly and calmly when you cannot be sure, is what the people who guard a company’s computers do every day.
Where these numbers come from
Written by the Sidequest team, from the sources below.
- Pay: BLS Information Security Analysts (SOC 15-1212, median $124,910, May 2024; +29% 2024-34; that median runs high because the same code covers the senior security engineer and architect roles analysts grow into); PayScale analyst-title experience bands (2026).
- The outlook: BLS OOH Information Security Analysts (SOC 15-1212, May 2024); ISC2 2024/25 Workforce Study (global gap); SANS/GIAC 2026 (AI cutting tier-1 roles); CyberSeek US openings. Dated June 2026.
- Getting in: How many people take each route is our own estimate, rounded. O*NET OnLine 15-1212.00 (Information Security Analysts), Job Zone Four, SVP 7.0 to under 8.0, and the education responses (53% a bachelor degree, 23% a post baccalaureate certificate, 13% a two year degree); site updated August 25 2026, read September 2026, for the four years and for the three answers. Bureau of Labor Statistics Occupational Employment and Wage Statistics, May 2025, SOC 15-1212, for the $129,180 middle wage. BLS Occupational Outlook Handbook, Information Security Analysts, read September 2026, for the 14,100 openings a year and the 21% growth to 2035; this is a newer release than the May 2024 figures this page cites elsewhere. ISC2 2025 Cybersecurity Workforce Study, published December 2025 from 16,029 respondents, for the 38% of people under 30 who came through another computer job and the equal share who came from outside computing entirely. ISACA State of Cybersecurity 2025-2026, published September 2025, for the 38% of employers who take three to six months to fill a beginner job, and for clear thinking, explaining yourself and problem solving being what employers say they are short of. CompTIA Security+ SY0-701 exam and renewal pages, read September 2026, for the recommended two years of experience, the three year renewal, and the June 11 2027 retirement of this version. ISC2 exam pricing, certification requirements and annual maintenance fee pages, read September 2026, for the $199 entry exam, the five years of experience, the six years an Associate has to earn them, and the $135 a year. Security, Suitability, and Credentialing Performance Accountability Council, Trusted Workforce 2.0 quarterly progress report FY25-Q4 and FY26-Q1, for the 109 days on a first high risk investigation and the single day to move an existing clearance. College Board, Trends in College Pricing and Student Aid 2025, public four year in state tuition and fees of $11,950 a year, for the $48K four year total. U.S. Department of Education College Scorecard, field of study data, CIP 11.10 Computer and Information Technology Security at bachelor level, read September 2026, for the $85,100 median four years out. Dated September 2026.