My cousin rang me last April, about ten at night, which is when he calls if something’s bothering him. He’d finished a six-month course, applied to somewhere north of sixty openings, and had two replies, both automated. What he wanted to know was whether cybersecurity analyst jobs were still worth chasing or whether he’d bought into an industry that was mostly selling shovels.
I didn’t have a clean answer for him and I still don’t. The demand behind cybersecurity analyst jobs is real and it’s published by people with nothing to sell you. The difficulty of getting through the front door is also real, and it’s worse than almost any careers page will admit. Both facts sit next to each other, and most writing on cybersecurity analyst jobs picks whichever one suits the angle. I’d rather give you the version I gave him, including the annoying parts.
What cybersecurity analyst jobs actually consist of, hour by hour
The image most people carry involves dark rooms and scrolling code. The reality is a ticket queue, and how you feel about ticket queues will probably decide how long you last in the field.
Alerts arrive from a SIEM. You open the oldest, look at what fired, gather context about the host and the user, then decide whether it matters. Then you open the next one. The overwhelming majority of what passes through cybersecurity analyst jobs turns out to be nothing, and by nothing I mean a service account behaving oddly because somebody in infrastructure edited a scheduled task at 4pm and told nobody, or a login from a hotel network in Denver because the sales rep is genuinely in Denver. Being good at this means clearing ninety-five boring things quickly enough that you still have concentration left for the ninety-sixth, which is the one that matters.
The official description isn’t far off. BLS lists the duties as monitoring networks for breaches and investigating them, maintaining tools like firewalls and encryption, checking systems for vulnerabilities, and preparing reports on attempted attacks and security metrics for management. What people don’t expect is how much of these cybersecurity analyst jobs is disaster recovery planning, since analysts are heavily involved in writing those plans and then repeatedly testing the steps in them.
Then there’s the part nobody trains you for, which is phoning a stranger in your own company at nine in the evening to ask why their laptop just did something strange. Sometimes they’re lying. Usually they were following a YouTube tutorial. If you want the fuller responsibilities list before committing to a path, this deeper role breakdown goes further into the day-to-day than I can here.
How the detection loop works from end to end
I get asked how the work actually functions, as though there’s a single mechanism. There isn’t, it’s a loop, and every one of the cybersecurity analyst jobs you see advertised sits somewhere along it.
Everything starts with telemetry, meaning logs. Endpoint agents, firewall records, cloud audit trails, identity events, DNS queries. If something isn’t logged it doesn’t exist as far as you’re concerned, which is why investigations so often end with somebody saying there’s no visibility into that system. Then detection logic fires and the alert lands in your queue, which is where most cybersecurity analyst jobs begin their working day.
Triage is where the hours go. You’re sorting into true positive, false positive, and the third category nobody warns you about, benign true positive, meaning yes that happened and no it doesn’t matter. Enrichment follows: who owns the machine, what does this user normally do at this hour, has that file hash appeared elsewhere in the estate. After that comes a containment call, which might mean isolating the host and disabling the account, or leaving it alone and watching, and the second option is scarier than it sounds.
Finally there’s the write-up and the tuning. Tuning separates people going somewhere from people closing tickets, and it’s the habit that turns junior cybersecurity analyst jobs into senior ones. Anybody can close a ticket. Fewer people go back and fix the rule that woke them at 3am for nothing. Most teams map coverage against MITRE ATT&CK, and the useful part isn’t memorising technique IDs, it’s knowing which techniques your environment can’t see at all.
The KnowBe4 case, because abstractions make this sound tidier than it is
In July 2024 a security awareness company called KnowBe4 hired a principal software engineer who turned out to be a North Korean operative using a stolen American identity and a photo AI-modified from stock imagery. He got through video interviews. He got through background checks.
On 15 July 2024, at 9:55pm EST, tooling raised alerts about anomalous activity on the workstation they’d shipped him. The SOC rang the new hire, who said he’d been following a router guide to fix a speed problem. That explanation didn’t survive contact with the evidence. Across roughly twenty-five minutes the operator manipulated session history files, moved suspicious files, and ran unauthorised software, using a Raspberry Pi to pull down the malware. The device was contained about twenty-five minutes after the first alert, and no data was accessed or exfiltrated.
Hiring failed completely. Detection held, and it held because somebody staffing one of those unglamorous cybersecurity analyst jobs was watching the queue at ten at night. It’s the most useful case study available to anyone preparing for interviews, and the full incident write-up reads in one sitting.
Notice what the analysts did, though. No malware reverse engineering. They saw something odd, made a phone call, listened to an answer that didn’t fit, and pulled the plug on a hunch they could partially justify. Judgement under time pressure, which is the actual product of most cybersecurity analyst jobs.
The shortage everyone quotes, and what cybersecurity analyst jobs really show
I’ll be blunt, because the standard framing does harm to beginners. The millions-of-unfilled-roles headline isn’t invented, but it’s misread constantly. Employers are not short of applicants for cybersecurity analyst jobs. They’re short of applicants who can contribute in week one, and short of budget to develop the ones who can’t.
ISC2’s 2025 workforce study surveyed a record 16,029 professionals and gives you the shape of it. Budget cuts were reported by 36% and layoffs by 24%, each down a single percentage point year on year. A third said their organisations lack the resources to staff teams adequately, while 29% said they can’t afford to hire people with the skills they need. That second number is the one to stare at. Not can’t find, can’t afford. A meaningful slice of the gap around cybersecurity analyst jobs is a money problem in costume.
Large organisations wore it worst, with 32% reporting layoffs, 46% budget cuts, 49% hiring freezes and 41% promotion freezes, and the people left behind are tired: 48% said they felt exhausted trying to stay current, and 47% felt overwhelmed by workload. ISC2’s own analysis of those findings argues the crisis is about skills depth rather than headcount.
So who does get through. People who demonstrate rather than assert. Somebody who says they built a lab, shipped Sysmon into Elastic, wrote nine Sigma rules and fixed the one generating constant false positives will beat a stack of certificates every time. If you’re at zero, the sequencing into cybersecurity analyst jobs matters more than application volume, and this guide to starting from scratch sets out the realistic on-ramps.
One unglamorous point. Help desk and sysadmin work still converts into cybersecurity analyst jobs at a better rate than bootcamps do, and BLS notes many analysts arrive with prior IT experience, often as network and computer systems administrators.
Money: the medians, the floor, and the spread
The median annual wage for information security analysts was $129,180 in May 2025, against $109,470 across computer occupations and $50,980 for all US occupations. The lowest 10% earned under $75,090 and the highest 10% earned more than $199,850.
| Segment (BLS, May 2025) | Median annual wage |
| Information (telecom, media, publishing) | $138,650 |
| Computer systems design services | $132,410 |
| Finance and insurance | $130,630 |
| Management of companies and enterprises | $128,950 |
| Scientific and technical consulting | $125,420 |
| All information security analysts | $129,180 |
| Lowest 10% | Under $75,090 |
| Highest 10% | Over $199,850 |
If you’re entering the field, the number to anchor on is $75,090, not the median. Entry-level cybersecurity analyst jobs in a mid-sized American SOC land well below it, and outside the US the range is wider again, sometimes dramatically so.
The percentile spread tells you where money moves inside cybersecurity analyst jobs, and it isn’t purely seniority. Cloud detection engineering, incident response and detection-as-code pay more because fewer people do them properly. Location matters too, and how pay shifts across markets is worth checking before accepting a first offer, since renegotiating later is harder than people assume.
On outlook, BLS projects 21% growth between 2025 and 2035 versus 3% for all occupations, with roughly 14,100 openings a year and employment rising from 192,900 to about 233,400. Strong, but fourteen thousand annual openings should be read carefully rather than triumphantly by anyone counting on cybersecurity analyst jobs to absorb every applicant.
Certifications for cybersecurity analyst jobs: filters, not qualifications
This is where I’d spend least, and I say that having paid for several. Certificates get you past automated screening and past an HR reviewer who doesn’t know the field. They don’t convince a SOC manager, and they don’t substitute for the hands-on evidence cybersecurity analyst jobs are really screened on.
BLS notes that although a bachelor’s degree in a computing field is typical, some analysts enter with a high school diploma plus relevant industry training and certifications. That door into cybersecurity analyst jobs exists. It’s narrower than vendors imply.
The ones I’ve seen earn their cost are Security+, which clears HR filters and satisfies US DoD 8140 requirements for government-adjacent work; CySA+, which sits closer to real triage; and BTL1, respected increasingly because you can’t pass it by memorising a book. Splunk’s Core User and Power User certifications are cheap and specific. What I wouldn’t chase early is CISSP, which expects five years of experience and reads oddly on a junior CV when you’re applying for first-rung cybersecurity analyst jobs.
Plenty of people start with the Google beginner track, which is inexpensive and structured well enough to tell you within weeks whether you enjoy reading logs. Budget properly too, since testing fees add up once you’ve stacked three exams into a year and failed one.
Tools you need hours in
Listing tools on a CV is trivial, and interviewers for cybersecurity analyst jobs now ask follow-ups designed to catch people who’ve only read about them. Get real hours in a SIEM, Splunk or Elastic if you can get access, Wazuh or Security Onion if you’re self-funding, and learn the query language properly. Get an EDR: Defender for Endpoint is most accessible via a developer tenant, while CrowdStrike and SentinelOne dominate postings.
Beyond that, configure Sysmon yourself and learn the important event IDs cold. Run Zeek or Suricata so you develop a sense of what encrypted traffic hides. Write Sigma rules, the most transferable junior skill there is. Try Velociraptor or KAPE for collecting evidence from a live host, and CyberChef, which is unremarkable and which everyone in cybersecurity analyst jobs uses constantly.
Build all of it in one lab rather than separately. A domain controller, two Windows workstations, a Linux box, an attacker VM running Atomic Red Team. Execute a technique, watch what appears in your logs, write a detection, then try to evade your own detection. That loop taught me more in two weekends than a month of courses, and it’s the closest thing to rehearsing cybersecurity analyst jobs before anyone hires you.
Getting hired, in the order I’d actually do it
Pick one lane first, SOC analyst or GRC or vulnerability management, because applying across all three makes every application weaker. Build the lab and document it publicly, with honest write-ups of what didn’t work, since failure documentation reads as experience whereas flawless documentation reads as copied. Take one certificate that clears filters, not four. Write two or three incident reports reconstructing public breaches and noting which detection would have caught things earlier, because that’s literally the writing sample cybersecurity analyst jobs require of you.
Then apply narrowly, twenty tailored applications rather than two hundred generic ones, referencing the stack named in the posting. And take the adjacent role if it arrives first, since moving internally into cybersecurity analyst jobs after eighteen months is a much shorter queue than the external one.
The anecdote I owe you: my first technical screen fell apart in about four minutes. They asked what Sysmon Event ID 1 records and why it matters more than the standard Windows process creation event. I knew it conceptually, fumbled it anyway, because I’d read about it and never configured it. The interviewer said something like “you’ve studied this, you haven’t run it,” which was fair and annoyed me for a week. I built the lab that weekend and passed a comparable interview six weeks later. Same question, as it happens.
That gap, between having read something and having run it, is more or less the entire barrier to entry in cybersecurity analyst jobs.
FAQs
Do I need a degree for cybersecurity analyst jobs?
Usually preferred, not universally required. BLS lists a bachelor’s as typical, but notes some analysts enter with training and certifications instead.
How long does the first role realistically take?
With no IT background, twelve to twenty-four months is fair, often passing through a help desk or sysadmin position on the way.
Will AI remove cybersecurity analyst jobs?
It’s absorbing tier-one triage, which pushes junior work toward tuning, validation and investigation. Alert volume is still growing faster than the automation handling it.
Analyst or penetration tester for pay?
Senior offensive work often pays more, but there are far fewer openings and a less defined ladder.
Can a junior get hired fully remote?
Rarely. Most employers want that first year on-site or hybrid, partly for mentoring and partly because of identity fraud cases like the KnowBe4 one.
Final Thoughts
Cybersecurity analyst jobs remain a strong career bet with a genuinely difficult front door, and you deserve both halves of that. Pay sits well above the national median, growth is projected at seven times the all-occupation average, and none of it guarantees an interview, because what employers lack is proven capability rather than enthusiasm.
So stop polishing the CV and start producing evidence. Build the lab, break something in it, catch yourself doing it, write down what you saw. Then apply to twenty places running the stack you practised on, and keep going after the first fifteen ignore you.
The people who land cybersecurity analyst jobs aren’t the ones who studied hardest. They’re the ones who could show their working.

An IT career coach with 7 years of experience helping beginners map out certification paths that actually lead to interviews, not just another resume line. He’s guided dozens of career-switchers through their first AWS or CompTIA exam and writes for itechnova.io, covering IT certifications, cybersecurity, and the software tools people actually need to know.