TL;DR
Cybersecurity salary by company is the search that ruins your week, because the number changes depending on who you ask. You check one site and see $95,000. You check another and see $210,000 for the same job title. Neither number is wrong. They are just describing different employers.
Here is the real problem. Most salary advice treats cybersecurity like one flat market, when it is actually dozens of markets stacked inside a single job title.
A security engineer at a regional bank and a security engineer at Google can be $150,000 apart, doing work that sounds identical on paper. I run into this constantly while researching IT pay data over at whatisthesalary.com, and company is usually the single biggest variable people overlook.
That gap is not random, and it is not about who is more skilled. It comes down to company size, industry, equity structure, and location, and once you see how those pieces fit together, the confusing headlines start making sense. That is what this guide breaks down.
Why the Company Name Moves the Number More Than the Job Title Does
Base salary alone tells you almost nothing at a public tech company. Total comp, meaning base salary plus RSUs (restricted stock units) plus annual bonus, is what actually lands in your account, and the stock portion is where the real separation happens.
A cybersecurity engineer at a regional insurer might see a package that is almost entirely base salary, with a small annual bonus attached. A security engineer at Google or Meta might see base salary make up less than half of total comp, with the rest coming from a four year vesting schedule of company stock.
That is why comparing headline base salaries between a Big Tech offer and a mid market offer is misleading. You have to compare total comp, and you need to understand the vesting schedule before you sign anything.
If you are deciding between titles rather than just companies, the breakdown of cybersecurity analyst vs engineer vs architect is worth reading before you negotiate, since level structure varies by role as much as by employer.

Big Tech Cybersecurity Salaries: Company by Company
Here is what the major tech employers report paying security engineers in 2026, based on submitted and reported compensation data.
| Company (Role Level) | Median / Avg Total Comp | Base Salary | Stock + Bonus |
| Amazon, Security Engineer L6 (senior) | $378,494 avg | $169,408 | $176,169 stock / $32,917 bonus |
| Google, Security Software Engineer L3-L7 | $320,000 median (range $192K-$608K) | Varies by level | GSUs (RSUs) + bonus, vests quarterly to monthly |
| Meta, Security Engineer IC4-IC6 | $312,000-$333,000 median | $168,000 (IC4) | $66.7K stock / $33.3K bonus (IC4) |
| Apple, Security Engineer | $258,000 median (range $258K-$447K) | Not separately reported | Included in total package |
| Microsoft, Security Engineer (broad title average) | $123,000-$155,000 total pay | $116,997 avg | $6K-$18K bonus |
| Industry baseline (all employers, US) | $122,890 avg (ZipRecruiter) / $160,488 avg (Glassdoor) | Varies | Varies |
A few things stand out. Amazon’s average sits highest here, but that is an L6 (senior) figure, and Amazon’s leveling structure compresses pay more at junior tiers while stretching it wide at senior and principal levels.
Google’s range is the widest of the group, running from $192,000 at L3 to $608,000 at L7, which shows how much leveling drives total comp inside one company, sometimes more than the employer name does.
Microsoft’s broader security engineer average looks lower here mostly because that figure blends a wide mix of titles and seniority, including roles that do not carry the same specialized scope as a Big Tech security engineering track.
Company specific security titles at Microsoft, particularly in Azure security and identity, tend to price closer to the Google and Meta range once you filter for scope and level.
If FAANG security engineer L5 total compensation is what you are benchmarking against, expect a range roughly between $300,000 and $450,000 depending on company, with the ceiling climbing fast at staff and principal levels.
Total Compensation vs Base Salary: What Job Seekers Get Wrong
I have seen candidates turn down a $210,000 total comp offer because the base salary line read $150,000, then accept a $175,000 all base offer instead, because that number looked bigger at first glance. That math works against you, and it costs people real money.
Total comp usually breaks into three pieces:
The vesting schedule matters as much as the grant size. A four year RSU grant that vests 25 percent each year pays out very differently than one that is backloaded, where year one looks thin and year three or four carries the bulk of the value.
Amazon is known for backloaded vesting on new hire grants, which is part of why a year one Amazon offer can look smaller on paper than actual year three pay.
If you are early in your career and trying to figure out where you land on this scale, the entry-level cybersecurity salary in the US breakdown and the cybersecurity analyst salary by experience level guide both walk through realistic offers at each stage, before stock and bonus complicate the picture.
CISO Compensation Packages: The Widest Spread in Security
No title in cybersecurity has a wider pay range than Chief Information Security Officer, and the sources genuinely disagree with each other, which is itself informative.
Glassdoor puts median CISO pay near $321,000. Salary.com lands higher, around $385,000. A 2025 survey from IANS and Artico Search, covering 566 CISOs across the US and Canada, found total compensation rose close to 7 percent year over year, with most respondents between $250,000 and $700,000, and top earners passing $3.1 million.
The gap between these numbers usually comes down to equity. Roughly 70 percent of CISOs now receive stock as part of their package, and for the highest earners, equity can make up half the total.
A source that only counts cash misses that entirely, which is how two reputable salary sites can describe what is technically the same role and land $200,000 apart.
Company size drives most of the remaining variance. A CISO at a Series A startup and a CISO at a Fortune 100 bank carry the same title but manage entirely different budgets, headcounts, and board exposure. For the full range by company size and industry, the CISO salary guide breaks down what to expect at each tier.
Startup vs Enterprise Pay: Which One Actually Wins
This depends heavily on timing and risk tolerance, and there is no single correct answer.
Enterprise and Big Tech employers pay more in guaranteed cash and liquid stock. If you need predictable income, a known company with public stock is the safer bet, since RSUs at a public company convert to real money on a fixed schedule.
Startups pay less in cash, sometimes significantly less, but offer equity that could be worth far more than a Big Tech grant if the company succeeds, or worth nothing if it does not. A Series B security hire might take a $30,000 pay cut against a Big Tech offer in exchange for equity that stays illiquid until an exit event that may never happen.
Neither path is wrong. The mistake is comparing a startup’s paper equity value directly against a public company’s vested RSU value as if they are the same kind of money, because they are not.

Remote Security Jobs and the Salary by Location Question
Remote work changed how location factors into security salaries, but it did not erase the effect. Most large employers now use location based pay bands, meaning a remote security engineer living in a lower cost city typically earns less than a colleague doing the same job from San Francisco or New York, even with identical titles and performance.
That said, the gap has narrowed compared to five years ago. Companies competing for scarce security talent, particularly in cloud security and application security, are increasingly willing to pay near top tier rates for strong remote candidates rather than lose them to a competitor that will.
CISO pay by metro still shows real separation. Recent 2026 data puts average CISO compensation at roughly $400,000 in San Francisco, $375,000 in New York, $360,000 in Seattle, and $350,000 in Washington DC, reflecting both cost of living and the concentration of regulated industries and high value targets in those cities.
If you want to see how your specific city or state compares, the cybersecurity salary by city and cybersecurity salary by state breakdowns go much deeper than a national average can.
Specialized Roles That Beat the Median
Title alone undersells how much specialization changes pay inside cybersecurity. A generalist security engineer and a cloud security engineer with the same years of experience can be $20,000 to $30,000 apart, because cloud security skill is scarcer relative to current demand.
2026 data on emerging specializations shows AI and ML security roles commanding a median around $175,000, cloud security architects near $168,000, application security engineers around $158,000, and senior penetration testers close to $152,000. Each of these has grown faster year over year than general security engineering pay.
If you are weighing offensive security work specifically, the penetration tester salary in the US guide covers what that specialization pays across experience levels.
If you are earlier in your career and working SOC rotations, the SOC analyst salary breakdown shows the realistic path from Tier 1 monitoring into higher paying specialized roles. And if you are on the consulting side rather than in house, the cybersecurity consultant salary guide covers how billing structure changes the pay math.
Certifications, Career Path, and How You Actually Get to These Numbers
None of these company level numbers matter much if you cannot get in the door for the interview. Certifications function less as an automatic pay bump and more as a negotiation anchor. CISSP commonly adds somewhere between $25,000 and $35,000 to an offer when the role genuinely requires it, and cloud security certifications tied to AWS or Azure carry similar weight for cloud focused positions.
If you are deciding how to break into the field in the first place, whether through a degree, a bootcamp, or hands on experience, it is worth reading how those paths actually compare before committing years and tuition to one route.
The best cybersecurity certifications guide, the cybersecurity bootcamp vs degree comparison, and the cybersecurity career path roadmap all cover this from different angles.
If a four year degree is not part of your plan, cybersecurity analyst without a degree walks through what employers actually require versus what job postings imply they require.

How to Actually Use This Data When You Negotiate
Stop researching once you have two or three solid comparison points from credible sources. Research past that point is usually delay dressed up as due diligence.
When you do have an offer, negotiate the full package, not just base salary. Ask specifically about the RSU vesting schedule, sign on bonus structure, and whether a competing offer changes the number, because most companies have more room to move on equity and sign on pay than they do on published base bands.
If you are weighing a Big Tech offer against a smaller company, run the actual math on year one, year two, and year three total comp, not just the headline number, since backloaded vesting can make an offer look worse on paper than it performs in practice.
Common Misconceptions About Big Tech Security Pay
Frequently Asked Questions
-
What company pays cybersecurity engineers the most in 2026?
Based on reported compensation data, Amazon and Google currently show the highest average total compensation for senior security engineering roles, though Meta’s median stays close behind and its top reported packages exceed both at the highest levels.
-
Do FAANG companies pay security engineers the same as software engineers?
Largely yes at most FAANG companies. Security engineering typically sits on the same or a closely aligned leveling and pay track as general software engineering, though scope and promotion speed can differ.
-
Is a CISO salary higher than a security engineer’s?
At the median, yes, often by a wide margin. But a senior or staff security engineer at a top paying tech company can out-earn a CISO at a small or mid size company once total comp is compared.
-
Does remote work lower cybersecurity salaries?
It can, depending on the employer’s location based pay policy, but the effect has weakened as competition for security talent has intensified.
-
Are startup cybersecurity salaries always lower than Big Tech?
Not always. Cash comp is often lower, but well funded startups occasionally match or beat Big Tech to win scarce security talent, offset by equity that carries real risk.
A Quick Note on How This Was Put Together
This article pulls from publicly reported compensation data, including company submitted figures on Levels.fyi, Glassdoor’s aggregated salary reports, ZipRecruiter and PayScale market averages, and industry compensation research including a recent CISO compensation survey. No figures here were invented or estimated without a source behind them. Ranges reflect data current as of mid to late 2026, and given how fast security compensation moves, it is worth checking current listings before using any single number in a real negotiation.

Shahzada Muhammad Ali Qureshi (Leeo)
I’m Shahzada — a software engineer by education and an SEO professional by trade. I built WhatIsTheSalary.com to go beyond just showing salary numbers — every page is manually researched across sources like BLS, Glassdoor, LinkedIn Salary, and PayScale to give you the full picture in one place. If you found what you were looking for here, that’s exactly the point.
