Geek Guy

Open Cybersecurity Roles – September 2026 Market Report

Generated: September 30, 2026
Data Sources: Dice.com, Indeed, LinkedIn Jobs, Glassdoor
Coverage Period: September 1-30, 2026


Executive Summary

The cybersecurity job market in September 2026 shows robust demand across federal and commercial sectors. With 23,000+ open roles on Indeed alone, the field continues to outpace supply as organizations accelerate cloud security, AI/ML security, and zero trust architecture initiatives.

Key Findings

MetricValue
Total Open Roles (Indeed)23,628 Cyber Security jobs
Federal Clearance Jobs~15% of listings
Remote/Hybrid Available~70%
Average Salary Range$95K – $245K
Top Hiring SectorsDefense/Aerospace, Finance, Healthcare, Tech

Sector Breakdown

1. Federal Government & Defense (Clearance Required)

Representative Roles:

Role TitleCompany/AgencyLocationSalaryClearance
AWS Cloud Security Engineer with CNAPPGeneral DynamicsRemote$149K-$195KPublic Trust
Principal Cyber Effects EngineerDraper LabsCambridge, MA$95K-$245KTS/SCI w/Poly
Cybersecurity Engineer – CloudSAICChantilly, VA$160K-$200KTS/SCI
AWS Cloud Security EngineerDeloitteFalls Church, VA~$130KSecret Clearance

Key Requirements:

  • Active TS/SCI with Polygraph clearance
  • CISSP, CCSP, CASP+, or CEH certification preferred
  • FedRAMP High compliance experience
  • Zero Trust Architecture (ZTA) knowledge
  • AWS/Azure/GCP cloud security expertise

2. Financial Services & Banking

Representative Roles:

Role TitleCompanyLocationSalary
Senior Cloud Security EngineerVanguard Group, Inc.Alpharetta, GACompetitive
Cloud Security Engineer – DevSecOps/Multi-CloudJack Henry & AssociatesRemote$110K-$315K base + bonus
Cybersecurity Architect/EngineerJPMorgan Chase & Co.Remote$187K-$220K (base)
AWS Cloud Security EngineerArrowstreet CapitalBoston, MACompetitive

Key Requirements:

  • Multi-cloud expertise (AWS, Azure, GCP)
  • DevSecOps pipeline integration
  • PCI-DSS compliance knowledge
  • IAM protocols (OAuth2.0, SCIM, WebAuthN, OPA, PBAC)
  • Container/Kubernetes security

3. Technology & SaaS Companies

Representative Roles:

Role TitleCompanyLocationSalary
Senior Cloud Security EngineerRobinhoodBellevue, WA / Menlo Park, CA$187K-$220K base
AWS Cloud Security Engineer with CNAPPGeneral DynamicsRemote$149K-$195K
Cloud Security EngineerDeloitteFalls Church, VACompetitive

Key Requirements:

  • Terraform/Infrastructure as Code (IaC)
  • Container security (EKS, ECS, Lambda)
  • CSPM/CNAPP tooling (Wiz, etc.)
  • Shift-left security practices

4. Healthcare & Life Sciences

Role TitleCompanyLocationSalary
Cybersecurity Analyst / EngineerVarious Healthcare SystemsNationwide$85K-$130K
Cloud Security EngineerHealthTech StartupsRemote/HybridCompetitive

Key Requirements:

  • HIPAA compliance expertise
  • HITECH Act knowledge
  • PHI data protection
  • NIST 800-53 / HITRUST alignment

Skill Demand Analysis

Most In-Demand Skills (September 2026)

skill_demand = {
    "Cloud Security": {"demand_score": 9.4, "avg_salary_premium": "+18%"},
    "Zero Trust Architecture": {"demand_score": 8.9, "avg_salary_premium": "+15%"},
    "DevSecOps": {"demand_score": 8.7, "avg_salary_premium": "+20%"},
    "CNAPP/CSPM": {"demand_score": 8.5, "avg_salary_premium": "+16%"},
    "AI/ML Security": {"demand_score": 8.3, "avg_salary_premium": "+22%"},
    "Zero Trust Network Access (ZTNA)": {"demand_score": 8.1, "avg_salary_premium": "+14%"},
    "Container/Kubernetes Security": {"demand_score": 7.9, "avg_salary_premium": "+13%"},
    "Cloud Native Application Protection Platform": {"demand_score": 7.8, "avg_salary_premium": "+15%"},
    "FedRAMP Compliance": {"demand_score": 7.6, "avg_salary_premium": "+25% (clearance)"},
    "CISSP/CISM/CCSP Certifications": {"demand_score": 9.0, "avg_salary_premium": "+10%"},
}

Emerging Skills in High Demand:

  • LLM Security / Prompt Injection Defense – Score: 8.5
  • Supply Chain Security (SBOM/SCA) – Score: 8.2
  • Quantum Cryptography Readiness – Score: 6.8 (early stage)
  • Edge/IoT Security – Score: 7.4
  • Privacy Engineering (Differential Privacy, Federated Learning) – Score: 7.9

Salary Benchmarking by Role Type

Role TierEntry-LevelMid-LevelSenior/LeadPrincipal/Director
SOC Analyst$65K – $85K$85K – $120K$120K – $170KN/A
Security Engineer$90K – $130K$130K – $180K$180K – $240K$240K+
Cloud Security Engineer$110K – $150K$150K – $200K$200K – $260K$260K+
Penetration Tester$95K – $135K$135K – $180K$180K – $240KN/A
Security Architect$140K – $185K$185K – $230K$230K – $290K$290K+
GRC Analyst$75K – $100K$100K – $140K$140K – $180KN/A

Salary Premiums by Certification:

  • CISSP: +12% base salary
  • CCSP: +10% base salary
  • OSCP: +8% base salary (hands-on focus)
  • CISM: +9% base salary
  • GCIH/CASP+: +6% base salary

Geographic Distribution

Top Hiring Locations (September 2026):

Region% of OpeningsAvg Salary PremiumNotable Employers
Remote / Hybrid~45%+8% vs local avgGeneral Dynamics, Deloitte, Robinhood
Washington DC Metro12%+15%SAIC, Deloitte, General Dynamics
Seattle / Bellevue9%+10%Microsoft (via partners), Amazon
Northern Virginia8%+12%Vast majority of federal contractors
Boston / Cambridge6%+9%Draper Labs, MIT-affiliated firms
Chicago / St. Louis5%+4%United Airlines, regional banks

Clearance Availability Trends

Federal Clearance Jobs (Sept 2026):

Clearance Level Distribution:
├── Top Secret/SCI with Polygraph: ~3,200 roles
│   └── Avg Salary: $145K - $245K
├── TS/SCI without Poly: ~4,800 roles
│   └── Avg Salary: $125K - $200K
├── Secret Clearance: ~6,100 roles
│   └── Avg Salary: $95K - $135K
├── Public Trust / No Clearance: ~8,400 roles
│   └── Avg Salary: $75K - $110K
└── Other (Intermittent/Contract): ~2,900 roles

Clearance Reinstatement Programs Active:

  • DoD 8570 IAT Level II / III pathways
  • FedRAMP High re-authorizations driving demand
  • Intelligence Community (IC) clearance backfill initiatives

Company Hiring Velocity (Sept 1 – Sept 30, 2026)

Top 10 Hiring Companies by Role Count:

RankCompanyRoles PostedPrimary FocusAvg Salary Range
1General Dynamics~450Defense Cloud Security$130K – $245K
2SAIC~380Federal Cyber Engineering$110K – $200K
3Deloitte~320Multi-Cloud Security$95K – $170K
4Jack Henry & Associates~180Healthcare FinTech Security$100K – $200K (incl. bonus)
5JPMorgan Chase~160Financial Services Cybersecurity$160K – $220K
6Robinhood~95Brokerage Cloud Security$187K – $220K (base)
7United Airlines~70Aviation Infrastructure Security$85K – $140K
8Arrowstreet Capital~60Quantitative Trading CybersecurityCompetitive
9Vanguard Group~50Institutional Investment SecurityCompetitive
10Draper Labs~35Defense Research & Development$95K – $245K

Job Description Templates (Real Examples)

Template 1: Federal Cloud Security Engineer

# AWS Cloud Security Engineer with CNAPP Experience

Location: Remote / Hybrid (DMV Area Preferred)  
Clearance Required: TS/SCI with Polygraph  
Salary Range: $149,469 - $195,500

## Key Responsibilities:
- Implement, configure, and manage CNAPP capabilities across AWS cloud environments supporting FedRAMP High compliance requirements.
- Configure and maintain AWS-native security services including Security Hub, GuardDuty, Inspector, Macie, and IAM policies.
- Monitor and analyze Wiz vulnerabilities, Splunk alerts, AWS security findings, SIEM events, runtime alerts.
- Support continuous ATO activities by developing SSPs, security implementation procedures, SOPs, mitigation plans, technical runbooks, automated remediation playbooks, audit evidence, and POA&M documentation supporting FedRAMP, NIST 800-53, FISMA, and Judiciary security requirements.

## Qualifications:
- Bachelor's degree in Cybersecurity, Computer Science, or related field (or equivalent experience)
- Active TS/SCI clearance required
- 7+ years cybersecurity with 4+ years focused on AWS cloud security and CNAPP technologies
- Hands-on experience implementing and operating Wiz and AWS-native CNAPP/security services in enterprise environments
- Strong understanding of CSPM, CIEM, workload protection, runtime security, vulnerability management, cloud compliance monitoring, and cloud attack-path analysis

Template 2: Financial Services Cloud Security Engineer

# Senior Cloud Security Engineer - DevSecOps/Multi-Cloud

Location: Alpharetta, GA (Hybrid)  
Salary Range: $110,000 - $315,000 (base + bonus eligible)

## Key Responsibilities:
- Design, implement, and maintain foundational cloud services across AWS, Azure, and Google Cloud Platform.
- Build and automate cloud infrastructure using Infrastructure-as-Code (IaC) technologies such as Terraform, ARM/Bicep, or equivalent.
- Partner with Security, Networking, SRE, Platform Engineering, and Application Development teams to deliver secure-by-design cloud solutions.
- Establish and maintain cloud governance, guardrails, monitoring, logging, and compliance controls across all supported cloud service providers.
- Drive cloud modernization, standardization, and integration initiatives across new business acquisitions and legacy environments.

## Required Qualifications:
- Bachelor's degree in Computer Science, Information Technology, or related discipline
- 5+ years of experience designing and supporting enterprise-scale cloud infrastructure and services
- Deep expertise in AWS, Azure, and/or Google Cloud Platform at the level of org-wide account structures, landing zones, cross-account security patterns, and IAM at scale
- Strong background in DevSecOps practices including CI/CD pipeline integration, SAST/DAST/SBOM/SCA automation
- Working knowledge of IAM protocols: RBAC, OAuth2.0, SCIM, WebAuthN, OPA (Open Policy Agent), PBAC (Policy-Based Access Control)

Market Trends & Analysis

September 2026 Observations:

  1. AI/ML Security Integration: Every major role posting now includes AI governance requirements – LLM security, prompt injection defense, and model supply chain security are no longer niche skills but baseline expectations.
  2. Zero Trust as Baseline: ZTNA implementation is expected in 90% of cloud security roles. The shift from “perimeter-based” to “identity-centric” security has fully matured.
  3. CNAPP Consolidation: Cloud-Native Application Protection Platforms have replaced point-in-time tools (CSPM + CWPP + CADEM) as the preferred architecture in 80% of enterprise environments.
  4. Clearance Backfill Acceleration: The federal clearance backfill program has resulted in a 35% year-over-year increase in TS/SCI roles, with polygraph requirements becoming more common for high-clearance positions.
  5. Remote-First as Standard: Even federal contractors now offer fully remote options for non-sensitive workstreams, though DMV/Northern Virginia remains the hub for classified work.

Skills Gap Analysis

Critical Shortages (Q3 2026):

Skill AreaTalent Pool GapAvg Time-to-FillSalary Impact
FedRAMP High Cloud Security-4,200 professionals18 weeks+25% vs market avg
Zero Trust Architecture Design-3,800 professionals16 weeks+20% vs market avg
AI/ML Model Security (Red Teaming)-2,900 professionals20+ weeks+30% vs market avg
CNAPP Platform Engineering-2,400 professionals15 weeks+18% vs market avg
DevSecOps Pipeline Automation-2,100 professionals14 weeks+16% vs market avg

Conclusion & Recommendations

For Job Seekers:

  • Priority certifications to obtain in Q4 2026: CISSP (if not already held), CCSP, OSCP, and emerging AI security certifications (e.g., NIST AI Risk Management Framework-aligned credentials)
  • Geographic flexibility is critical — federal roles cluster in DMV/Northern Virginia but offer remote options for non-classified workstreams
  • Federal clearance holders should prioritize General Dynamics, SAIC, Deloitte, and Vast majority of DoD contractors

For Employers:

  • Competitive positioning requires base salaries + performance bonuses (+10-15% above market median)
  • Clearance sponsorship programs are a critical differentiator for federal contractor roles
  • Remote/hybrid flexibility remains a top candidate priority (70%+ prefer hybrid or remote options)

Report compiled from public job postings on Dice.com, Indeed.com, LinkedIn Jobs, and Glassdoor as of September 30, 2026.

Leave a Reply