Key Takeaways
- Cybersecurity careers follow a clear pathway. Most people start in entry-level roles such as SOC analyst, then specialize in forensics or penetration testing before moving into leadership.
- Entry-level roles pay roughly $60,000 to $134,000. Specialized and senior positions, including information security officers, earn more.
- The field is growing fastest in specialized roles. The US Bureau of Labor Statistics projects 29% growth for information security analysts through 2034.
- Marshall offers two degree pathways into cybersecurity, both tied to its Institute for Cyber Security.
- Marshall’s students placed 65th of more than 500 teams in the Spring 2026 National Cyber League (first among participating Sun Belt schools).
If you’re considering a career in cybersecurity but not sure where to start, you’re thinking about the right question at the right time. Employers have far more open roles than people to fill them, and the right education can help you secure one of them.
The cybersecurity career pathway offers plenty of room to grow, beginning with entry-level roles that lead into specialties such as digital forensics and penetration testing, then on to leadership as you gain experience. Entering the field takes a mix of education, practical skills and certifications, and Marshall University’s programs are designed to help you develop all three.
Overview of Cybersecurity Job Growth
Cybersecurity is one of the few fields where open jobs still outnumber the people qualified to fill them. CyberSeek, which tracks national workforce data, counts 514,359 cybersecurity job openings over the past year and only about 74 workers available for every 100 of them, which leaves close to 1 in 4 roles unfilled. That shortage also affects hiring timelines, with cybersecurity positions taking 21% longer to fill than other IT jobs.
The U.S. Bureau of Labor Statistics (BLS) projects 29% job growth for information security analysts through 2034, much faster than the average for all occupations. That works out to about 16,000 openings a year and 52,100 new jobs over the decade, with a national median wage of $124,910.
Industries Seeking Cybersecurity Professionals
Cybercriminals often focus on certain industries, but every business is a potential target, which means every industry needs cybersecurity experts. Manufacturing has led all industries in cyberattacks for five years running, accounting for 27.7% of incidents in 2025, according to IBM’s 2026 X-Force Threat Intelligence Index. Financial firms are prime targets as well, since they hold the high-value data attackers want, a pattern documented by a 2025 U.S. Treasury analysis.
Demand reaches well beyond those sectors, though, with employers hiring for cybersecurity roles in:
- Government and defense, the front line for national infrastructure
- Healthcare, a top target for its patient records and connected devices
- Technology and software, built on products the world relies on
- Higher education, home to student data and original research
Wherever sensitive data is stored, someone has to protect it, which means trained cybersecurity professionals can work almost anywhere.
Job Outlook for Cybersecurity Careers
Growth across cybersecurity concentrates in the specialized roles, with the BLS projecting computer and information systems manager positions to grow 15% through 2034 and forensic science technician roles to grow 13% over the same period, both well ahead of the average across occupations.
The more general IT roles are moving in the opposite direction, with BLS projecting network and computer systems administrator positions to decline about 4% and computer support specialist roles about 3% through 2034 as routine tasks become automated. For students deciding where to focus, the pattern points in a clear direction, since the specialties still adding jobs are the ones that call for security-specific skills and credentials, the kind a focused cybersecurity program teaches.
What Is the Cybersecurity Career Pathway?
The cybersecurity career pathway is the typical route professionals follow from entry-level IT and security roles into specialized tracks and, with experience, into senior and leadership roles. Most people start in a foundational job such as help desk, network administration or a junior security operations center (SOC) analyst role, then commit to a specialization such as defensive operations, offensive security or governance before moving up.
Here is how the pathway generally breaks down:
Entry-Level Foundations (zero to two years), where you learn the core skills:
- Help desk or IT support
- Systems or network administrator
- Junior security operations center (SOC) analyst
Core Specialization Tracks (three to seven years), where you commit to a discipline:
- Defensive security, or cyber defense
- Offensive security, or red teaming
- Governance, risk and compliance (GRC)
- Cloud and security engineering
Senior Leadership and Architecture (eight or more years), where you set strategy and design systems:
- Security architect
- Security manager or director
- Chief information security officer (CISO)
It’s common to move between tiers, and no two professionals’ journeys will look alike. For example, a help desk technician who earns a security certification can move into a SOC analyst role, and a SOC analyst who enjoy
Entry-Level Cybersecurity Roles
These positions are where most cybersecurity careers begin, and each one builds skills that apply to more advanced roles, so each role below includes a note on where it commonly leads. Salary figures show typical base pay from Glassdoor, with the closest BLS wage category as a benchmark. Actual pay varies by employer, location and experience.
Cybersecurity Technician
A cybersecurity technician installs and maintains security systems, watches for vulnerabilities and responds when a breach or attack happens.
| Required Skills | Computer systems knowledge, basic coding, problem-solving, organization and clear communication |
| Relevant Certifications | CompTIA Security+, Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH) |
| Average Base Pay | $65,000 to $112,000 (Glassdoor); closest BLS benchmark: computer support specialists, median $61,550 |
| Next Steps | Move into a SOC analyst or security specialist role as you gain experience |
Network Administrator
A network administrator secures, maintains and troubleshoots an organization’s computer networks so they run smoothly and safely.
| Required Skills | Knowledge of local, wide-area and virtual private networks (LANs, WANs and VPNs); firewalls and access control; server fundamentals; teamwork and communication |
| Relevant Certifications | Cisco Certified Network Associate (CCNA), CompTIA Network+ |
| Average Base Pay | $68,000 to $107,000 (Glassdoor); closest BLS benchmark: network and computer systems administrators, median $96,800 |
| Next Steps | Specialize in security engineering or network security, then work toward security architecture |
Systems Administrator
A systems administrator, or sysadmin, sets up and maintains a company’s servers and computer systems, keeps hardware and software current and resolves issues as they surface.
| Required Skills | Knowledge of LANs and WANs, system installation and maintenance, analytical thinking, communication and multitasking |
| Relevant Certifications | CompTIA A+, CompTIA Network+, CompTIA Security+, Red Hat Certified System Administrator (RHCSA) |
| Average Base Pay | $80,000 to $119,000 (Glassdoor); closest BLS benchmark: network and computer systems administrators, median $96,800 |
| Next Steps | Grow into security engineering or systems security, then toward architecture roles |
Security Operations Center (SOC) Analyst
A SOC analyst monitors an organization’s security tools and alerts, flags suspicious activity and helps respond to incidents. Junior analysts focus on monitoring and first-line triage.
| Required Skills | Network security knowledge, incident response, threat analysis, familiarity with security tools, attention to detail and communication |
| Relevant Certifications | CompTIA Security+, CompTIA Cybersecurity Analyst (CySA+), GIAC Security Essentials (GSEC), CEH |
| Average Base Pay | $60,000 to $108,000 (Glassdoor); closest BLS benchmark: information security analysts, median $124,910 |
| Next Steps | Advance into incident management, threat analysis or penetration testing, or move up to senior SOC roles |
Junior Security Engineer
A security engineer designs and maintains the systems that protect an organization’s network. Junior engineers support senior staff, monitor alerts and perform routine assessments.
| Required Skills | Networking, security tools, operating systems, incident response, basic programming and risk assessment |
| Relevant Certifications | CompTIA Security+, CompTIA SecurityX (formerly CASP+), CEH, CISSP |
| Average Base Pay | $72,000 to $129,000 (Glassdoor); closest BLS benchmark: information security analysts, median $124,910 |
| Next Steps | Progress to security engineer, then toward security architecture |
Junior Security Consultant
A security consultant assesses an organization’s defenses and recommends improvements. Junior consultants assist with research, incident analysis and reporting.
| Required Skills | Security principles, penetration testing basics, analytical skills, technical proficiency and communication |
| Relevant Certifications | CompTIA Security+, CEH, Associate of ISC2, Certified Information Systems Auditor (CISA) |
| Average Base Pay | $74,000 to $134,000 (Glassdoor). Closest BLS benchmark: information security analysts, median $124,910 |
| Next Steps | Move into a full security consultant role, then toward lead consulting or governance, risk and compliance (GRC) work |
Compliance Analyst
A compliance analyst makes sure an organization meets the security regulations that apply to its industry.
| Required Skills | Attention to detail, auditing, communication, analytical thinking, data visualization and problem-solving |
| Relevant Certifications | Google Cybersecurity Professional Certificate, CISA, Project Management Professional (PMP) |
| Average Base Pay | $60,000 to $100,000 (Glassdoor). Closest BLS benchmark: information security analysts, median $124,910 |
| Next Steps | Grow into IT auditing or GRC management, then toward an information security officer role |
Vulnerability Asessor
A vulnerability assessor, also called a vulnerability analyst, finds weaknesses in an organization’s networks and software, then helps close them before attackers can exploit them.
| Required Skills | Security fundamentals, vulnerability assessment tools, network and system knowledge, risk assessment, report writing and attention to detail |
| Relevant Certifications | CompTIA Security+, CEH, CISSP |
| Average Base Pay | $53,000 to $87,000 (ZipRecruiter; see note below the chart). Closest BLS benchmark: information security analysts, median $124,910 |
| Next Steps | Specialize in penetration testing or move into a security specialist role |
Where Entry-Level Roles Lead Next
With a few years of experience and the right certifications, entry-level professionals move into specialized and senior work. Here is where the paths above tend to lead.
Penetration Tester (Ethical Hacker), mid-level. Penetration testers are hired to break into systems on purpose and expose the gaps a real attacker could use. Many come up through SOC analyst or vulnerability assessor roles.
> Typical pay: $89,000 to $155,000
Digital Forensic Analyst, mid-level. A digital forensic analyst examines digital evidence after a breach or crime to reconstruct events and spot unusual patterns. This is a signature strength of Marshall’s Cyber Forensics and Security programs.
> Typical pay: $76,000 to $132,000
Digital Forensic Examiner, mid-level. A digital forensic examiner acquires and preserves evidence from devices such as phones, drives and cloud accounts while keeping the chain of custody intact.
> Typical pay: $108,000 to $173,000
Cybercrime Investigator, mid-level. A cybercrime investigator gathers digital evidence used to prosecute crimes, either independently or as part of a team.
> Typical pay: $57,000 to $95,000
IT Auditor, mid-level. An IT auditor checks that an organization’s systems work correctly and securely, and helps surface errors or fraud. Compliance analysts often grow into this role.
> Typical pay: $75,000 to $121,000
Security Specialist, mid-level. A security specialist designs and implements measures to keep networks and systems safe.
> Typical pay: $60,000 to $108,000
Incident Manager, mid-level. An incident manager coordinates the response to security issues and outages to limit damage and restore operations quickly. SOC analysts often move into this role.
> Typical pay: $66,000 to $116,000
Information Security Officer, advanced. An information security officer sets security policy, runs risk assessments and oversees incident response across an organization. It is a leadership position for people who have spent years in analyst, engineering or compliance roles.
> Typical pay: $132,000 to $210,000
How to Start a Career in Cybersecurity With No Experience
Entry-level cybersecurity requirements usually come down to a combination of foundational knowledge, a certification or degree and demonstrated skills. Even with no direct experience, you can get there by following a few clear steps:
- Start with the fundamentals. Learn networks, operating systems and security principles through a degree program, online courses or a combination of the two. A cybersecurity degree gives you structured training and a credential employers recognize.
- Earn an entry-level certification. Credentials such as CompTIA Security+ or the Google Cybersecurity Professional Certificate validate your skills and help your resume get past the first screening.
- Get hands-on practice. Set up a home lab, join capture-the-flag competitions or contribute to open-source security projects. Hands-on experience often matters as much as coursework.
- Create a portfolio. Document your projects, write-ups and competition results so you have proof of your skills for hiring managers.
- Apply strategically. Target true entry-level titles, tailor your resume to each posting and use your network and career services.
At Marshall, those steps are built into the program, and the Institute for Cyber Security connects you with the research projects and industry partners that lead to jobs.
What You Can Do with a Cybersecurity Degree
Wondering what jobs you can get with a cybersecurity degree? Nearly all of the roles on this page start there. A cybersecurity degree qualifies you for work that ranges from entry-level analyst and administrator jobs to specialized forensics and, over time, security leadership.
Here is a rough picture of cybersecurity degree salary ranges as graduates move along the pathway:
- Entry-level roles such as analyst, administrator and technician: roughly $53,000 to $134,000 in base pay
- Mid-level and specialized roles such as forensics, penetration testing and auditing: roughly $57,000 to $154,000
- Senior and leadership roles such as information security officer: $131,000 and up, with computer and information systems managers earning a median of $171,200
Marshall offers two degree pathways into these careers. The Cyber Forensics and Security, B.S. combines security and digital forensics with applied lab work, and the Regents Bachelor of Arts with a Digital Forensics and Information Assurance emphasis gives working adults and transfer students a flexible route into the field. Both connect students to the Institute for Cyber Security, where coursework maps to the roles employers are hiring for.
Cybersecurity Roles: Comparison Chart
Need a quick overview of each position? Here is how the roles compare by career level, typical base pay and common certifications.
| Role | Career Level | Typical Base Pay | Common Certifications |
|---|---|---|---|
| Cybersecurity Technician | Entry | $65,000–$112,000 | CompTIA Security+, CISSP, CEH |
| Network Administrator | Entry | $68,000–$107,000 | CCNA, CompTIA Network+ |
| Systems Administrator | Entry | $80,000–$119,000 | CompTIA A+, Network+, Security+ |
| SOC Analyst | Entry | $60,000–$108,000 | CompTIA Security+, CySA+, CEH |
| Junior Security Engineer | Entry | $72,000–$129,000 | CompTIA Security+, SecurityX, CISSP |
| Junior Security Consultant | Entry | $74,000–$134,000 | CompTIA Security+, CEH, CISA |
| Compliance Analyst | Entry | $60,000–$100,000 | CISA, PMP, Google Cybersecurity Certificate |
| Vulnerability Assessor | Entry | $53,000–$87,000* | CompTIA Security+, CEH, CISSP |
| Penetration Tester | Mid-career | $89,000–$154,000 | CEH, CompTIA PenTest+ |
| Digital Forensic Analyst | Mid-career | $76,000–$132,000 | GCFA, GCFE, CFCE |
| Digital Forensic Examiner | Mid-career | $76,000–$132,000* | EnCE, CFCE, GCFE |
| Cybercrime Investigator | Mid-career | $57,000–$95,000 | CISSP, CEH |
| IT Auditor | Mid-career | $75,000–$121,000 | CISA, CISSP |
| Security Specialist | Mid-career | $60,000–$108,000 | CompTIA Security+, CISSP, CISM |
| Incident Manager | Mid-career | $66,000–$116,000 | GCIH, CISM, CISSP |
| Information Security Officer | Advanced | $131,000–$210,000 | CISSP, CISM, CISA |
A note on two figures: Glassdoor’s digital forensic examiner base range ($108,000 to $173,000) reflects senior and federal examiners, so the table shows the digital forensic analyst range as a truer entry-to-mid picture. Glassdoor’s vulnerability analyst range ($99,000 to $156,000) skews toward experienced staff, so the table uses ZipRecruiter’s entry-to-mid range for that role instead.
Which Cybersecurity Career Is Right for You?
There are many possible careers in cybersecurity for you to pursue. Which one is the right one will depend on your strengths and interests.
If you like investigating and piecing together evidence, digital forensics may fit. If you would rather test defenses and think like an attacker, penetration testing could be your track. People who enjoy policy and organization often do well in compliance and governance, while those drawn to building and maintaining systems tend to lean toward engineering and administration.
Marshall’s programs let you explore each of these directions before you commit.
Explore Marshall’s Institute for Cyber Security
Marshall’s Institute for Cyber Security gives students a place to apply what they learn. The institute connects academic programs, research and industry partners. It also backs up its reputation with results.
In the Spring 2026 National Cyber League competition, Marshall’s student team placed 65th out of more than 500 teams and finished first among participating Sun Belt Conference schools. “The National Cyber League presents challenges that mirror real-world cybersecurity tasks, and our students competed at a very high level against teams from across the country,” said Dr. Paulus Wahjudi, professor of computer science.
Marshall’s faculty bring national experience to the classroom. In May 2026, Dr. Joshua Brunty, a Marshall faculty member, served as head coach of the United States Cyber Team at the International Cybersecurity Challenge in Australia. “Cybersecurity professionals are on the front lines of protecting critical infrastructure, financial systems, businesses and national security in an increasingly connected world,” Brunty said.
The program is expanding, too. A new Institute for Cyber Security building is under construction and expected to open in August 2027, with cyber ranges, digital forensics labs and operational technology environments designed to train students on real systems. Marshall also recently launched a digital identity microcredential covering multi-factor authentication, biometrics and the identity security tools used across the industry.
For students, that combination of applied programs, competitive results and expanding facilities gives them an edge when they enter the job market.
Ready to explore which cybersecurity path fits your goals? At Marshall, small class sizes, hands-on lab work and faculty with real-world experience give you the foundation to launch a career you’ll be proud of. You’ll learn on the same tools and systems employers use, backed by the Institute for Cyber Security and a program built for where the field is headed.
Ready to join the Herd? Request more information or apply today.
FAQs
No, 25 is not too late to start a career in cybersecurity, and neither is 35 or 45. Employers hire on demonstrated skills and current certifications, and career changers often bring useful experience from IT, military, law enforcement or business roles. What you can show an employer is valuable at any age.
A degree is not strictly required for every cybersecurity job, but it helps considerably. Some professionals enter through certifications and self-taught skills, yet many employers prefer or require a bachelor’s degree for analyst and engineering roles, and a degree can speed advancement into senior positions. A program such as Marshall’s gives you the practical experience employers look for.
Advancing in cybersecurity usually comes from a mix of experience, certifications and choosing a specialization. Many professionals spend two to three years in an entry-level role, earn a mid-level certification such as CISSP, then commit to a track such as defensive operations, offensive security or governance. Lateral moves between roles are common and can speed the move into senior positions.
Cybersecurity roles vary in schedule. Many analyst, engineering and compliance jobs follow standard business hours, while security operations center positions often run in shifts to cover nights and weekends. Incident response can bring occasional after-hours work when a breach happens. Remote and hybrid arrangements are common across much of the field.
A two-year cybersecurity degree, or associate degree, can be worth it as an affordable entry point into help desk, support and junior analyst roles. Many graduates then transfer their credits toward a bachelor’s degree, which most employers prefer for analyst and engineering positions. If your goal is specialized or senior work, plan to continue toward a four-year degree.
Yes, $200,000 a year is achievable in cybersecurity, though it usually takes years of experience and a senior or specialized role. Chief information security officers, security architects and seasoned penetration testers can reach that range, especially at large companies or in high-cost markets. Entry-level and mid-level roles typically pay well below that figure.