Explore Cybersecurity Careers by the Work, Not Just the Title
51 cybersecurity roles across 10 categories: responsibilities, salaries, certifications, and career paths.
Job titles alone do not describe cybersecurity work. The Career Center is built on the CyberSN Taxonomy, which defines each role through its tasks and responsibilities, so you can find where your experience fits, what adjacent roles look like, and where a path can lead.
Functional Roles
Each defined by tasks and responsibilities
Capability Categories
From Defense and Offense to GRC and Research
Framework Aligned
Extends the NIST NICE Framework
Ten Categories, One Shared Language
Every role belongs to one of ten capability categories in the CyberSN Taxonomy. Start with the kind of work that interests you.
Defense
15 rolesProtecting systems, data, and identities through the day-to-day work of securing enterprise environments.
GRC
5 rolesGoverning cyber risk, regulatory compliance, and privacy obligations across the organization.
Manage
6 rolesLeading security teams and owning strategy, budgets, and outcomes at every level of the organization.
Offense
3 rolesTesting defenses by finding and exploiting weaknesses before real adversaries can.
Response
4 rolesInvestigating and containing security incidents and understanding how attacks unfolded.
Plan
5 rolesDesigning security programs, architectures, and the projects that deliver them.
Product Security
4 rolesBuilding security into software and products from design through release.
Research
3 rolesAdvancing security knowledge through cryptography, data science, and vulnerability research.
Educate
3 rolesTeaching, training, and documenting cybersecurity knowledge for teams and the wider field.
Sales
3 rolesConnecting organizations with security products, services, and coverage that fit their needs.
Find Your Role
Search by title or alternate title, or filter by category and career stage. Every role page covers responsibilities, salary, common certifications, and adjacent career paths.
Defense
15 rolesProtecting systems, data, and identities through the day-to-day work of securing enterprise environments.
AI Security Engineer
An AI Security Engineer protects AI and machine learning systems, securing models, training data, and the AI supply chain while evaluating those systems for weaknesses such as prompt injection and data poisoning.
View roleCloud Security Engineer
A Cloud Security Engineer builds, maintains, and improves the protection, detection, and alerting that keep cloud infrastructure, platforms, applications, and networks secure.
View roleCyber Insider Threat Analyst
A Cyber Insider Threat Analyst collects and assesses potential security threats originating from within an organization, whether from employees, business partners, or third-party vendors, and turns that analysis into findings and recommendations leaders can act on.
View roleCyber IT Support Specialist
A Cyber IT Support Specialist handles the security side of IT support, resolving access, account, and endpoint issues, helping employees use security tools correctly, and escalating genuine security events to the security operations team.
View roleCyber Threat Intelligence Analyst
A Cyber Threat Intelligence Analyst researches, collects, and analyzes information about cyber threats, then turns it into intelligence the organization uses to anticipate attacks and counter adversaries.
View roleCybersecurity Administrator
A Cybersecurity Administrator manages the day-to-day security of an organization's systems, networks, applications, and devices, working as part of a team to keep business and customer data protected against cyber threats.
View roleCybersecurity Specialist
A Cybersecurity Specialist maintains the security of an organization's networks and data, strengthening defensive infrastructure and staying current on emerging threats.
View roleData Loss Prevention Engineer
A Data Loss Prevention Engineer administers the systems that keep sensitive data from leaving an organization, operating DLP platforms across endpoints, networks, and cloud services and responding to the alerts they generate.
View roleData Security Engineer
A Data Security Engineer designs, implements, and monitors the controls that protect an organization's data, applying techniques like encryption, hashing, and tokenization while serving as the resident expert on data protection compliance.
View roleIdentity & Access Management Engineer
Identity & Access Management Engineers control who can access an organization's systems and data, designing and operating the identity, authentication, and authorization services that keep access consistent, auditable, and compliant.
View rolePKI Professional
PKI Professionals architect, design, and develop the certificate and key management systems an organization relies on to prove identity, encrypt communications, and prevent fraud.
View roleSecurity Analyst
A Security Analyst monitors networks, systems, and data storage for cybersecurity threats, investigates and responds to alerts, and strengthens an organization's protection and detection capabilities.
View roleSecurity Engineer
A Security Engineer builds, maintains, and improves the protection, detection, and alerting that keep an organization's infrastructure, services, applications, and networks secure.
View roleSOC Analyst
A SOC Analyst staffs an organization's security operations center, triaging alerts from the monitoring queue, escalating confirmed incidents through the tier structure, and keeping detection coverage running across shifts.
View roleVulnerability / Threat Management Analyst
A Vulnerability / Threat Management Analyst identifies weaknesses and cyber threats across an organization's networks and software, then drives the corrective measures that strengthen security within those systems.
View roleGRC
5 rolesGoverning cyber risk, regulatory compliance, and privacy obligations across the organization.
Cyber Risk Analyst
A Cyber Risk Analyst proactively identifies, assesses, and consults on areas of cybersecurity risk, translating technical exposure into business and customer impact and recommending how to mitigate it.
View roleCybersecurity / Privacy Attorney
A Cybersecurity / Privacy Attorney advises organizations on the processes required to meet state, federal, and international legal requirements for personal data, represents clients before regulators, and supports incident response so losses are contained without compromising legal compliance.
View roleData Privacy Officer
A Data Privacy Officer oversees an organization's data privacy and protection program, ensuring that personal data belonging to customers, employees, and partners is processed in line with company policy and regulatory requirements.
View roleGovernance Risk & Compliance Analyst
A Governance Risk & Compliance (GRC) Analyst manages risks related to security, privacy, and regulatory compliance, ensuring that an organization's operations and procedures meet government and industry standards.
View rolePrivacy Analyst
A Privacy Analyst assesses an organization's policies, procedures, and operations to make sure they meet privacy requirements, managing the legal and operational risks that come with handling sensitive data.
View roleManage
6 rolesLeading security teams and owning strategy, budgets, and outcomes at every level of the organization.
C-Suite
The C-suite is an organization's executive leadership team; the "C" stands for chief, as in CEO, CIO, and CTO. Each executive serves as the expert in their domain, driving organizational strategy and departmental direction.
View roleChief Information Security Officer (CISO)
A Chief Information Security Officer (CISO) is the executive who owns an organization's information security program: setting security policy, managing security teams, and directing resources against the risks that matter most.
View roleChief Security Officer (CSO)
A Chief Security Officer (CSO) leads an organization's operational security and risk management across both cyber and physical domains, protecting company assets, systems, intellectual property, and the safety of employees and customers.
View roleCybersecurity Director
A Cybersecurity Director is a senior leader accountable for an organization's overall cybersecurity: supervising security design and implementation, incident response, budgets, and regulatory compliance while managing security personnel and shaping strategy.
View roleCybersecurity Lead
A Cybersecurity Lead heads a security team or department, overseeing service delivery, managing relationships, and keeping the team's work aligned with organizational goals.
View roleCybersecurity Manager
A Cybersecurity Manager runs the security operations of a department, supervising analysts and administrators, owning budgets and policies, and overseeing threat detection and cyber defense so that business data, financial assets, and customer information stay protected.
View roleOffense
3 rolesTesting defenses by finding and exploiting weaknesses before real adversaries can.
Application Security Engineer
An Application Security Engineer identifies risks in software applications and drives improvements: building security components, testing applications from an attacker's perspective, and shaping how engineering teams build securely.
View rolePenetration Tester
A Penetration Tester simulates cyberattacks against an organization's networks, systems, applications, and processes to find and exploit weaknesses before real attackers do, then documents the findings in remediation reports.
View roleRed Teamer
A Red Teamer simulates a real adversary against an organization, pursuing a specific objective quietly to test how well defenders detect and respond to an actual attack.
View roleResponse
4 rolesInvestigating and containing security incidents and understanding how attacks unfolded.
Digital Forensic
A Digital Forensic acquires, recovers, and analyzes data from devices, systems, and networks to investigate cyber breaches, attacks, and company investigations, producing evidence that supports or contests event timelines.
View roleIncident Responder
An Incident Responder manages an organization's response to cybersecurity events such as data loss, ransomware, and system compromise: assessing severity, investigating what happened, and leading containment, eradication, and recovery.
View roleReverse Engineer / Malware Analyst
A Reverse Engineer, also known as a Malware Analyst, decompiles, disassembles, and de-obfuscates malicious software to understand exactly how it operates, then turns that analysis into detection methods and intelligence the organization can act on.
View roleThreat Hunter
A Threat Hunter proactively searches for and tracks advanced cyber threats that evade automated detection, finding hidden adversaries (whether insiders or external groups) before they can attack.
View rolePlan
5 rolesDesigning security programs, architectures, and the projects that deliver them.
Cybersecurity Advisor
A Cybersecurity Advisor is a senior subject matter expert who guides an organization toward the right security solutions, shaping requirements with architects and delivering compliant outcomes that support business growth.
View roleCybersecurity Business Analyst
A Cybersecurity Business Analyst gathers and documents requirements for security initiatives, translating between security teams and business stakeholders so programs address the right problems and their progress can be measured.
View roleCybersecurity Program Manager
A Cybersecurity Program Manager runs multiple security-focused projects that share a common goal, planning and prioritizing complex cybersecurity work across offices, departments, and business entities.
View roleCybersecurity Project Manager
A Cybersecurity Project Manager coordinates the delivery of focused security projects, working with technical specialists to complete initiatives on time and on budget while managing scope, compliance, and deadlines.
View roleSecurity Architect
A Security Architect designs the systems that detect and prevent cyber threats, combining deep hardware and software knowledge with policy development to build defenses into an organization's technology from the start.
View roleProduct Security
4 rolesBuilding security into software and products from design through release.
Cybersecurity Software Engineer
A Cybersecurity Software Engineer designs, builds, and improves software with security as a core requirement, working across the full program lifecycle to meet an organization's cybersecurity needs and business goals.
View roleDevSecOps
A DevSecOps professional automates and integrates cybersecurity at every stage of the software development lifecycle, building protection into code, pipelines, and operations instead of bolting it on after release.
View roleProduct Security Engineer
A Product Security Engineer owns the end-to-end security of an organization's software products, working alongside engineering and product teams to build security into every release.
View roleSite Resiliency Engineer
A Site Resiliency Engineer keeps products and platforms available and recoverable under failure and attack, treating availability as a security property and engineering systems to degrade gracefully and recover quickly.
View roleResearch
3 rolesAdvancing security knowledge through cryptography, data science, and vulnerability research.
Cryptography Professional
Cryptography Professionals create, validate, and implement the ciphers, algorithms, and security protocols that encrypt an organization's data, and analyze existing encryption to find and fix its weaknesses.
View roleCyber Data Scientist
A Cyber Data Scientist gathers and analyzes cybersecurity data from across an organization, uncovers relationships hidden in that data, and connects the resulting insights to executive leadership to inform security decisions.
View roleSecurity Researcher
A Security Researcher investigates current and emerging technologies, proposed standards, and threat actor techniques to uncover how application and system vulnerabilities can be exploited, then demonstrates and communicates those findings.
View roleEducate
3 rolesTeaching, training, and documenting cybersecurity knowledge for teams and the wider field.
Cybersecurity Professor / Instructor
A Cybersecurity Professor / Instructor educates students and professionals in cybersecurity through academic institutions or commercial training programs, designing courses, teaching at the undergraduate and graduate levels, and conducting research in their specialization.
View roleCybersecurity Technical Writer
A Cybersecurity Technical Writer develops and supervises security content, from reports and manuals to policy documentation, converting strategy into actionable steps and digestible copy for organizational audiences.
View roleSecurity Awareness Specialist
A Security Awareness Specialist designs and delivers programs that help employees recognize and resist cyber threats, running phishing simulations, building role-specific training, and measuring how workforce behavior changes over time.
View roleSales
3 rolesConnecting organizations with security products, services, and coverage that fit their needs.
Cyber Insurance Professional
A Cyber Insurance Professional helps organizations anticipate and manage cybersecurity threats to their business by advising on cyber insurance coverage, shaping policies, and overseeing claims.
View roleCyber Sales Professional
A Cyber Sales Professional owns every stage of the cybersecurity sales cycle: generating and qualifying new opportunities, building relationships with technical buyers, and managing deals through the sales process to close.
View roleCybersecurity Sales Engineer
A Cybersecurity Sales Engineer drives the technology evaluation stage of the sales process, acting as the technical advisor who shows prospective clients how a security product solves their problems.
View roleMeet Your Career Where It Is
Whether you are entering the field, changing roles, or moving into leadership, career pathways follow responsibilities: the experience you already have translates into adjacent work.
Early career
Roles that build a hands-on security foundation, often reachable from general IT experience.
Mid career
Roles for professionals with established security experience who are deepening a specialty.
Senior
Deep specializations where design judgment and accumulated experience carry the work.
Leadership
Roles accountable for teams, programs, budgets, and security outcomes.
Keep Exploring
The CyberSN Taxonomy
The shared language behind every role page, aligned with the NICE Framework.
Explore the TaxonomyWorkforce Intelligence Guide
How organizations understand the tasks, responsibilities, and capabilities across their security workforce.
Read the GuideBlogs
Perspectives on cybersecurity careers, retention, and the workforce from the CyberSN team.
Read the BlogPodcasts & Videos
Conversations with security leaders and practitioners on careers and workforce strategy.
Watch and ListenEvents
Upcoming sessions and past recordings from CyberSN and the wider community.
See EventsResources for Women in Cybersecurity
Communities, conferences, podcasts, and training programs supporting women in the field.
Browse the DirectoryMilitary Veteran Resources
Hiring programs, federal resources, and veteran-led communities for service members entering cybersecurity.
Browse the DirectoryThe Same Language Employers Use
The taxonomy behind these role pages is the same one organizations use to understand their own security workforce: which tasks and responsibilities are covered, which capabilities their teams hold, and how people, capabilities, strategy, and outcomes connect.
For professionals, that shared language means your profile and experience describe the work you actually do. For organizations, it means visibility into how responsibilities are distributed across the workforce ecosystem. Learn how the same foundation powers Workforce Intelligence.
Put your experience in front of the right roles
Build a profile on the same taxonomy employers use to describe their openings, and search positions matched to the work you actually do.
Building a security team? Explore CyberSN Talent Solutions