Security analyst career path
Security analyst is the most common way into security, and hardly anyone works the alert queue for a whole career. The first real choice comes around Tier 2. You can go deeper on investigation through incident response, threat intel or hunting. You can start building as a security or detection engineer. Or you can head toward risk and compliance. The analysts who move up fastest tend to be the ones who automated part of their own queue.
Updated Pay and job counts from live US job listings
What comes after security analyst?
A common next step for a security analyst is incident responder, usually 2 to 4 years into a SOC. You can also step up to security operations engineer, or move sideways to threat intelligence analyst. Some change careers and become a GRC analyst or a penetration tester.
Security analyst jobs in the US
- Advertised pay
- $67K-$133K
- Open jobs
- 7,271
- Median
- $98K
Jobs are counted by title on US job boards. Pay is the middle half of the 17 listings that state a salary.
Where security analysts go next
5 moves people make from this role. The job counts and pay are for each destination role, so you can see what the market wants right now.
| Move to | Type | Usually when | Open US jobs | Advertised pay |
|---|---|---|---|---|
| Incident responder | Step up | Usually 2 to 4 years into a SOC | 302 | $120K-$151K |
| Security operations engineer | Step up | After 2 to 4 years | 285 | $111K-$180K |
| Threat intelligence analyst | Sideways move | Year 2 or 3 | 99 | $85K-$138K |
| GRC analyst | Career change | Year 1 to 3 | 102 | $108K-$147K |
| Penetration tester | Career change | After 2 to 4 years | 256 | $130K |
Job counts and pay from US listings, September 29, 2026. Pay shows only where at least five listings state it.
What each move takes
Why each move fits, the skills hiring managers look for, and the proof to have on your resume before you apply.
Incident responder
Step up302 open US jobs$120K-$151K advertised
Incident response finishes the cases you escalate, from scoping and containment to forensics and the final report. If you already work cases past triage, you're halfway there.
- Usually when
- Usually 2 to 4 years into a SOC, once you've run an investigation from alert to closure
- Skills to add
- Digital forensics (Velociraptor, KAPE, Volatility)
- EDR investigation in tools such as CrowdStrike Falcon or Microsoft Defender for Endpoint
- Incident documentation and timeline building
- GIAC GCIH or GCFA
- Have this on your resume first
- Investigations you led beyond triage, each with the scope, the containment steps you took and how it ended.
Security operations engineer
Step up285 open US jobs$111K-$180K advertised
You know which alerts waste time and which lookups you keep doing by hand. That's the requirements list for the detections and playbooks security operations engineers build.
- Usually when
- After 2 to 4 years, usually once you've started scripting away repetitive triage
- Skills to add
- Python for automation
- SOAR playbooks (Splunk SOAR, Microsoft Sentinel playbooks or Tines)
- Detection-as-code with Sigma
- SIEM engineering: log onboarding and parsing
- Have this on your resume first
- An automation or detection you built, with the analyst hours saved or false positives removed.
Threat intelligence analyst
Sideways move99 open US jobs$85K-$138K advertised
You see attacker indicators and techniques in alerts every shift. Threat intel asks who's behind them and what they'll do next, and your view of real attacks keeps the research honest.
- Usually when
- Year 2 or 3, usually analysts who'd rather research and write than race the queue
- Skills to add
- MITRE ATT&CK mapping and adversary profiling
- Threat intelligence platforms (MISP, OpenCTI)
- Intelligence writing for technical and executive readers
- GIAC GCTI
- Have this on your resume first
- Intelligence you produced that changed something, like a campaign write-up that led to new detection rules.
GRC analyst
Career change102 open US jobs$108K-$147K advertised
Plenty of GRC (governance, risk and compliance) people know the frameworks but have never watched a control fail. You have, and it makes your control testing hard to argue with.
- Usually when
- Year 1 to 3, often analysts who want regular hours and more time on policy
- Skills to add
- NIST CSF, NIST 800-53 and ISO 27001
- SOC 2 audit preparation
- Risk assessment and vendor risk reviews
- CISA or CRISC over time
- Have this on your resume first
- Control evidence or audit support you contributed, plus documentation or policy you owned.
Penetration tester
Career change256 open US jobs$130K advertised
Every shift shows you what gets caught and what slips through. On offense, that tells you where to push.
- Usually when
- After 2 to 4 years, plus steady hands-on lab time outside work
- Skills to add
- Nmap, Burp Suite and Metasploit
- Active Directory attack techniques
- Hack The Box or TryHackMe lab progression
- OSCP
- Have this on your resume first
- OSCP or equivalent, plus lab write-ups or a public profile of rooms and reports.
Now check your own resume
Your own resume will give you a sharper answer than this page. Your years, tools and wins change which move fits.
The suggested roles and fit scores come from AI. The job counts and pay come from live listings.
Questions security analysts ask
Is security analyst an entry-level job?
Tier 1 SOC analyst is the closest thing security has to an entry-level job. Most postings still expect some IT background, like help desk, networking or sysadmin work, plus a cert such as CompTIA Security+. Senior analyst titles are not entry level.
Should a security analyst move into engineering or incident response?
Pick engineering if you like building and automating, and incident response if the investigation itself is the fun part. Both are common next steps. If you can't decide, automate something in your current queue and notice which part you enjoyed.
Do I need a degree to move past a Tier 2 analyst role?
Usually not. Security hiring leans heavily on proven skills and certifications, and investigations or detections you can walk through in detail count for more. Some government and defense roles do require a degree or a clearance.