Jobs News & Market Trends

Global Hiring Trends Report: Q1 2026 Update

This quarter's update drills into one role that keeps appearing on hiring plans worldwide, and the tools, certificates and steps that get you into it.

By Olu Adeyemi · Sep 29, 2026 · 13 min read

Global Hiring Trends Report: Q1 2026 Update

Each quarterly update in this series takes one occupation that employers keep budgeting for and breaks down how to enter it. For Q1 2026 that role is the information security analyst: the person who watches networks for breaches, hardens systems before attackers find the gaps, and explains the risk to people who do not work in IT. In the United States the occupation held about 192,900 jobs in 2025 and employment is projected to grow 21 percent from 2025 to 2035, much faster than the average for all occupations (U.S. Bureau of Labor Statistics, 2025–35 projection).

The route in is unusually flexible. A bachelor's degree is the typical entry-level education (BLS), but some people enter with a high school diploma plus industry training and certifications. What follows is what the work actually involves, how long each step takes, and where the job is harder than the job ads suggest.

What an information security analyst does

An information security analyst plans and carries out the measures that protect an organisation's networks, systems and data, and investigates when something gets through.

A typical day pulls from this list:

  • Monitors networks for security breaches and investigates when one occurs, working through alerts from monitoring tools and deciding which are real (BLS).
  • Installs, uses and maintains firewalls and data encryption software to protect sensitive information in transit and at rest (BLS).
  • Checks systems and applications for vulnerabilities, then tracks the fixes with whoever owns the system.
  • Performs risk assessments and develops plans to safeguard computer files against accidental or unauthorised modification, destruction or disclosure (O*NET).
  • Modifies security files to add new software, correct errors, or change individual access status when someone joins, moves or leaves (O*NET).
  • Prepares reports on security metrics, attempted attacks and actual breaches, usually for managers rather than engineers (BLS).
  • Researches IT security trends, recommends enhancements, helps set security standards, and reviews violations of security procedures with the people who caused them (BLS and O*NET).

Where they work. In-house security teams at banks, insurers, hospitals, retailers, universities, software firms and government bodies; managed security service providers and consultancies serving many clients at once; and vendor security teams. Some sit inside a security operations centre with rotating shifts, others are the only security person in a small IT department.

Schedule and the honest downside. Most information security analysts work full time and some work more than 40 hours per week; they sometimes have to be on call outside normal business hours in case of an emergency (BLS). That is the part people underestimate. An incident does not respect your evening. Alert fatigue is real — a large share of what you investigate turns out to be nothing, and the tedium of triage sits right next to the pressure of missing something that mattered. You will also spend a lot of time persuading colleagues to accept controls that make their work slower. If you want quiet, predictable days with no confrontation, look elsewhere.

How to become one

  1. Complete a bachelor's degree in computer and information technology or a related field such as engineering or maths. This is the typical entry-level education for the occupation (BLS), and it usually takes three to four years full time. Costs swing enormously by country and institution — from fully subsidised public systems to high private-university fees — so check the published fee schedule for the specific programme rather than a national average. If you already hold a degree in another subject, skip to step 2 and lean harder on certifications.
  2. Take an IT support, network or systems administration job first. Many information security analysts have work experience in an IT department, often as a network and computer systems administrator (BLS), and the occupation typically expects less than five years of related experience (BLS). Expect to spend 12 to 24 months here. You are buying the thing no course gives you: knowing how real systems break.
  3. Build a home lab and publish the work on GitHub. Run a few services in Docker containers, capture and analyse traffic in Wireshark, set up Nagios to monitor the lot, then break something deliberately and write up what the logs showed. Allow four to twelve weeks of evenings. Cost is close to nothing if you use hardware you already own; a second-hand machine or a small cloud budget is the only likely outlay. Docker and GitHub are both flagged as Hot Technology for this occupation (O*NET), so naming them in a portfolio is not a gimmick.
  4. Earn an entry-level security certification such as CompTIA Security+. Many employers prefer candidates who hold information security certification, with options for both entry-level and experienced workers (BLS). Budget eight to sixteen weeks of study alongside a job. Total cost typically ranges from about $500 for budget self-study to $2,500 for an intensive bootcamp, and the exam voucher alone costs $425 when bought directly from CompTIA (HackerDNA, a third-party training site).
  5. Shortlist further certifications using CareerOneStop's certification finder. BLS points to CareerOneStop for certification information, including specialised credentials such as systems auditing. Spend an afternoon on it, then pick one target rather than five. Specialisation choices — cloud, auditing, incident response — change which jobs you can apply for more than another general certificate does.
  6. Talk to two working analysts and one hiring manager before you apply. Ask what their last three incidents were and what they wish new hires already knew. Fifteen-minute calls, two to four weeks to arrange through former colleagues, alumni groups or a local security meetup. Free, and it tells you which local employers hire juniors at all.
  7. Document one incident end to end as your interview artefact. Write a two-page report on something from your lab or your helpdesk job: what you saw, how you confirmed it, what you changed, what you would monitor next. One weekend. Interviewers ask for exactly this, and formal on-the-job training for the occupation is typically listed as none (BLS) — employers expect you to arrive able to do the work.
  8. Start logging experience toward a senior credential like CISSP. It requires a minimum of five years of cumulative, full-time paid experience in two or more of the eight domains of the current CISSP Exam Outline, and a relevant bachelor's or master's degree may satisfy up to one year of that requirement (ISC2). Keep a dated record of your duties from your first IT job onward so you are not reconstructing it from memory years later.

Skills you'll need

Hard skills

  • Network traffic analysis with Wireshark. Reading a packet capture and explaining what a host was actually doing is the baseline diagnostic skill. Wireshark is listed among the network monitoring software used in this occupation (O*NET).
  • Infrastructure monitoring with tools such as Nagios. Knowing how alerts are configured, why they fire and why they get ignored is what separates useful monitoring from noise.
  • Firewall configuration and encryption. Installing and maintaining firewalls and encrypting data transmissions are core duties (BLS and O*NET). You should be able to justify each rule you add, not just add it.
  • Data loss prevention tooling, of the kind represented by Symantec Blue Coat Data Loss Prevention (O*NET), plus the policy work that sits behind it — deciding what counts as sensitive before the tool can flag it.
  • Containers and version control: Docker and GitHub. Both are Hot Technology for the occupation (O*NET). You need enough to review how colleagues deploy software and to keep your own scripts and detection rules under version control.
  • Risk assessment and access administration. Performing risk assessments and modifying security files for new software, errors or access changes are listed tasks (O*NET). Much of the job is unglamorous account and permission hygiene.

Soft skills

BLS lists analytical skills, communication skills, creative skills and being detail oriented as important qualities for this occupation.

  • Analytical thinking — show it by walking an interviewer through one investigation where your first hypothesis was wrong and what evidence changed your mind.
  • Communication — show it with a one-page breach report written for a non-technical manager, included in your portfolio. Reviewing security violations with the people who committed them (O*NET) is a conversation, not an email.
  • Creativity — show it by describing how you anticipated an attack path nobody had documented, in your lab or at work.
  • Attention to detail — show it through a change log or an access review you maintained, where small errors would have been visible.

Pay and outlook

In the United States, the median annual wage for information security analysts was $129,180 in May 2025 (BLS). A median means half earned more and half less, and the spread inside that single number is wide.

What moves pay within the occupation is fairly consistent across markets. Sector matters most: finance, defence, cloud providers and regulated healthcare generally pay above general commercial IT, because the cost of a failure is higher and the compliance burden is heavier. Location matters next, both country and city — the same title carries very different pay in a capital-city financial district and a regional manufacturing town. Then comes scope: whether you are triaging alerts to a runbook or designing the controls and standards other people follow. On-call load, willingness to work shifts, eligibility for security clearances, and specialised certifications such as systems auditing credentials all add leverage at the offer stage. Pay is usually structured as an annual salary with a bonus in corporate settings, a day rate in consulting and contract work, and fixed public-sector bands in government.

Demand looks durable rather than fashionable. The occupation held about 192,900 jobs in 2025 and employment is projected to grow 21 percent from 2025 to 2035, much faster than the average for all occupations, with about 14,100 openings projected each year on average over the decade (BLS, 2025–35 projection). Those openings come from growth and from people moving into management or leaving the workforce.

Two cautions. Strong projected growth does not mean strong demand for first-time candidates in every city — entry-level security roles are far scarcer than senior ones, which is why so many analysts arrive via an IT department. And these figures are United States projections; hiring in other countries follows different regulatory and economic pressures.

Check current numbers yourself rather than trusting a jobs board. The BLS Occupational Outlook Handbook entry for information security analysts is the authoritative United States source for wages and projections, and CareerOneStop is the source BLS points to for certification information. Outside the United States, use your national statistics agency or labour ministry, and cross-check against advertised ranges in your own city.

Career path

Titles vary by employer, so match the duties rather than the label. A common progression:

Years 0–2: feeder roles. IT support technician, network and computer systems administrator, junior systems engineer. Many analysts come through exactly this route (BLS). You are learning the estate you will later defend.

Years 1–3: entry security roles. SOC analyst (tier 1), junior security analyst, security operations technician. Shift or on-call work is common. The job is triage: confirm or dismiss alerts, escalate cleanly, document everything. Most people hold an entry-level certification by this point.

Years 3–6: mid-level. Information security analyst, security engineer, incident responder, GRC or compliance analyst. You own investigations end to end, run vulnerability management, write standards and recommend enhancements rather than just executing them. This is also the window in which you accumulate the five years of cumulative full-time experience across two or more CISSP domains that ISC2 requires, with up to one year potentially offset by a relevant degree.

Years 6–10: senior and lead. Senior security analyst, security architect, SOC lead, threat intelligence or cloud security specialist. Analysts advance within the occupation by leading a team or becoming an expert in a specialty area (BLS). Two routes diverge here — deep technical specialism, or people and programme leadership.

Years 10+: management. Computer and information systems manager, head of security, chief information security officer or chief security officer (BLS). Budget, board reporting and vendor negotiation replace most hands-on work. Some senior specialists deliberately stay technical instead, and in consulting that path can be equally well paid.

Sideways moves are normal and often faster than waiting for a promotion: from operations into audit, from engineering into architecture, or from in-house into consulting to see many environments in a short time.

Frequently asked questions

Do I need a degree to become an information security analyst?

A bachelor's degree in computer and information technology or a related field such as engineering or maths is the typical entry-level education for the occupation, but some workers enter with a high school diploma plus relevant industry training and certifications (BLS). Without a degree you will usually need more demonstrable experience — an IT or sysadmin job, a portfolio of lab work, and a recognised certification. Some employers, particularly in government and large regulated firms, still filter on the degree regardless of skill. Requirements differ by country and employer, so read several real job ads in your market before deciding.

Can this job be done remotely?

Often partly, sometimes fully. Monitoring, investigation, reporting and policy work are screen-based and travel well. What pulls people back on site is physical infrastructure, classified or clearance-restricted environments, client premises in consulting, and employers who want a security operations centre in one room. On-call rotations exist whether you are remote or not — BLS notes that analysts sometimes have to be on call outside normal business hours in case of an emergency. Remote hiring across borders also depends on the employer's legal and tax setup, which is worth asking about directly rather than assuming.

How long does it take to get a first security job?

If you are already working in IT, commonly one to three years: long enough to build relevant duties into your current role, finish an entry-level certification, and produce a portfolio. Starting a degree from scratch adds three to four years. Coming from an unrelated career, plan on two to four years including an interim IT support or sysadmin job. The spread depends on how many junior security roles your local market actually posts, whether your current employer will let you take on security tasks, and how much study time you have each week.

Which certification should I start with, and is it worth the cost?

An entry-level credential such as CompTIA Security+ is the usual first step; total cost typically ranges from about $500 for budget self-study to $2,500 for an intensive bootcamp, with the exam voucher alone at $425 when bought directly from CompTIA (HackerDNA, a third-party training site). Many employers prefer candidates who hold information security certification, and specialised options such as systems auditing exist for later (BLS). Use CareerOneStop's certification finder to compare before paying. A certificate opens screening filters; it does not substitute for being able to explain an investigation you actually ran.

What part of the job makes people leave it?

On-call disruption, alert fatigue and the political side. Most analysts work full time and some work more than 40 hours per week (BLS), and incidents arrive at inconvenient times. Day to day, a lot of the work is repetitive triage and access administration, punctuated by pressure when something real lands. You also have to review security violations with the colleagues who caused them (O*NET), which means regular low-grade conflict. People who last tend to enjoy investigation and are comfortable being unpopular for a good reason.

Sources

  1. U.S. Bureau of Labor Statistics — Information Security Analysts : Occupational Outlook Handbook: U.S. Bureau of Labor Statistics (2025)
  2. O*NET OnLine (sponsored by U.S. Department of Labor/Employment and Training Administration) — 15-1212.00 - Information Security Analysts - O*NET OnLine
  3. ISC2 — Experience Needed for the ISC2 CISSP Certification
  4. HackerDNA (third-party training site, not CompTIA) — CompTIA Security+ Exam Cost 2026: Fees, Bundles & Savings

More in Jobs News & Market Trends

Top Companies Hiring This Month (Updated Weekly)
News

Top Companies Hiring This Month (Updated Weekly)

"Top companies hiring this month" lists are produced by people — recruitment researchers, sourcers and labour market analysts who pull public hiring data, check employer career pages, and refresh the list before it goes stale. This guide covers what that work involves day to day, how to get into it, and how to build the same list for your own job search.

Sofia Bauer · 11 min read

4-Day Workweek Countries and Companies Adopting It
News

4-Day Workweek Countries and Companies Adopting It

Iceland, Belgium and Spain have moved furthest at government level on the four-day week, and hundreds of private employers now run one after coordinated pilots by 4 Day Week Global, the 4 Day Week Foundation and the Autonomy Institute. Most of that work sits in software, marketing, professional services, charities and parts of the public sector, and almost all of it was negotiated employer by employer rather than handed down by law.

Daniel Ortiz · 12 min read

Skilled Worker Visa Updates: US, UK, Canada, Germany
News

Skilled Worker Visa Updates: US, UK, Canada, Germany

Becoming the person who tracks skilled worker visa updates across the US, UK, Canada and Germany means learning four separate rulebooks and the fee schedules attached to them, then translating changes into decisions hiring managers can act on. Most people enter through an HR, recruitment or legal-support seat rather than a dedicated immigration degree, and build country depth on the job.

Marcus Lee · 11 min read

Average Salary by Role and Country: 2026 Benchmarks
News

Average Salary by Role and Country: 2026 Benchmarks

If you want to be the person who produces "average salary by role and country" tables, the job you are looking for is usually called compensation analyst, reward analyst or salary benchmarking analyst — and the work is data cleaning, job matching and methodology notes far more than it is headline numbers.

Ananya Rao · 12 min read