Skip to content
careertips

Home IT & Software

Cyber Security Analyst

Cyber security analysts watch an organisation's networks and systems for signs of attack, then investigate and contain the ones that get through.

Illustration of a person working as a cyber security analyst
Median salary
$128,000

3.7%vs last year, before tax

People employed
13,300

1.5%vs last year

Projected growth
+24%

to 2035

AI exposure*
Moderate
automation risk
Average hours
42/wk

+2h vs all jobs

Shortage status
Not in shortage

national

Cyber security analysts usually sit in a security operations centre or an IT security team, watching alerts and system logs for anything that looks like an intrusion. The role is different from a penetration tester, who is hired to break in on purpose, because an analyst catches and contains the attacks that happen anyway, often against a clock set by how fast the breach is spreading. Most work for professional and technical services firms, government agencies, banks or insurers, where the value of the data being protected is the reason the team exists.

How much do cyber security analysts earn?

The median full-time salary for a cyber security analyst is $128,000 per annum, before tax, up $26,400 since 2018.

Sector moves pay more than almost anything else: defence, intelligence, banking and large insurers pay above the average, and a current security clearance carries a premium because it takes months to obtain. On-call rosters, shift work in a security operations centre that runs round the clock, and contracting day rates all lift earnings. Certifications matter most early, when they help you move from an IT support desk into a security team, and count for less once you have a few years of incident work behind you.

Median annual salary, 2018–2028
Salaries rose $26,400 a year to 2024; the dashed line shows a projection to 2028 based on the real ABS Wage Price Index growth rate, not a role-specific forecast.
Full cyber security analyst salary breakdown →

What does a cyber security analyst do day to day?

The list below is what fills most weeks; the exact mix shifts with seniority and whatever stage the current work is at.

  • Triaging alerts and logs to work out which one is a real threat and which is noise
  • Chasing an incident from the first alert through to what actually happened and why
  • Running vulnerability scans to find the holes before someone else does
  • Keeping pace with new attack techniques and the tools that shift month to month
  • Explaining a risk in plain terms to a business team that just wants it fixed

What skills do cyber security analysts need?

Employers look for cyber security, risk and internal controls, regulatory compliance, backed by SIEM platforms (Splunk, IBM QRadar) fluency and strong problem solving.

Specialist skills

  • Cyber security
  • Risk and internal controls
  • Regulatory compliance
  • Data analysis

Software and tools

  • SIEM platforms (Splunk, IBM QRadar)
  • Intrusion detection systems (Snort, Suricata)
  • Vulnerability scanners (Nessus, Qualys)
  • Packet analysis tools (Wireshark)
  • Cloud security platforms (AWS GuardDuty, Azure Sentinel)

General skills

  • Problem solving
  • Attention to detail
  • Written communication
  • Stakeholder management

Is the job growing?

About 13,300 people work as cyber security analysts in Australia, and employment is projected to grow 24% over the decade to 2035. That's very strong growth. Few roles in Australia are expanding this fast, and it points to solid demand for years to come.

Employment, 2015–2024, projected to 2035
Employment grew 2,300 to 2024; the dashed line shows the official projection to 2035.

How do you become a cyber security analyst?

Here's the path most cyber security analysts take, step by step.

  1. 1
    Build a technical foundation

    A bachelor degree in cyber security, computer science or IT is the standard entry point, and around 42% of people working as cyber security analysts hold one. A diploma or advanced diploma in a related field is a workable alternative, particularly when it is followed by industry certifications and hands-on experience.

  2. 2
    Get hands-on with systems first

    Many analysts spend a year or two in IT support, a help desk or systems administration before moving into security, because the work depends on knowing how accounts, networks and servers are actually configured. Internships, a home lab and capture-the-flag competitions all count as evidence you can do the work when you have no paid security experience yet.

  3. 3
    Add the certifications employers ask for

    CompTIA Security+ is the common starting certificate, followed by vendor training for the platforms a team runs, such as Splunk or Microsoft Sentinel. Senior and consulting roles often ask for the CISSP, which requires several years of experience before you can be certified, so it belongs later in the pathway.

  4. 4
    Join a security operations team and pick a direction

    Entry usually starts at tier one in a security operations centre, clearing alerts under supervision before moving to tier two and leading investigations. From there analysts tend to specialise in incident response, threat hunting, cloud security or governance and risk. Government and defence work usually requires a security clearance, which takes time to obtain and is worth starting early.

Ready to apply as a cyber security analyst?

Whether you're working toward becoming a cyber security analyst or already are one and want a hand with the next step (sharpening your resume for ATS screening, tightening your cover letter, or knowing what you'll actually be asked at interview), here are examples grounded in this specific role, not generic templates.

What jobs can a cyber security analyst move to?

Moving into Cyber Security Architect typically comes with the biggest pay rise, worth $7,200 a year more on average.

Move toTypical pay changeOverlapRetraining
Cyber Security Architect

Security architects design enterprise-wide defences, a natural progression from analyst work in threat detection and risk.

+$7,200
44%reskill
Penetration Tester

Penetration testers apply offensive security techniques that build directly on an analyst's threat detection and incident response experience.

$600
79%minimal
Network Engineer

Cyber security analysts bring threat awareness and network hardening skills to network engineering roles that focus on secure infrastructure.Known move

$7,900
44%reskill
Cyber Security Engineer

Cyber security engineers design and build defences, extending the analyst's monitoring and incident response skills into engineering.

$11,000
44%reskill
IT Auditor

IT auditors apply the same control and compliance knowledge that cyber security analysts use to protect systems and records.

$18,800
79%minimal

Moves are chosen from Jobs and Skills Australia's Data on Occupation Mobility, which follows income tax records between 2011-12 and 2020-21, together with entry requirements and skill overlap. A known move is one people were seen making in that data. Pay change compares median full-time pay for the two roles.

Who works as a cyber security analyst?

The typical cyber security analyst is 39 years old; 84% are men, 92% work full-time, and full-timers average 42 hours a week.

39
Median age
16%
Female share
92%
Full-time
+2h
vs all-jobs avg

What's it like being a cyber security analyst?

The job runs in two gears. Long stretches of monitoring give way to an incident that swallows a day or a week, and the shift between them suits someone who is patient with detail but likes a problem that has to be solved now. It also rewards people who can explain technical risk to colleagues who do not share their vocabulary.

What people like

  • Investigations that end in an answer. A suspicious login or a phishing email becomes a timeline you can reconstruct, and closing a case with a clear cause is a large part of why people stay in the work.
  • The whole organisation passes through your screens. Analysts see cloud accounts, endpoints, email and staff behaviour across every team, which builds a broad picture of how a business actually runs.
  • Attackers keep the job interesting. Techniques and tooling move quickly, so there is always a new detection rule to write or a platform to learn, and that learning sits inside the job rather than alongside it.
  • Specialisms open up early. After a couple of years in a security operations centre, analysts can move towards threat hunting, cloud security, incident response or governance, and each carries a different daily rhythm.

What people find hard

  • Much of the day is triage. Alert queues fill with false positives, so a large share of the work is dismissing what does not matter rather than chasing what does.
  • Incidents ignore business hours. An incident that starts overnight will reach whoever is on call, and an active breach can mean long days until it is contained.
  • You are often the person saying no. Closing a port or blocking a service makes someone else's job harder, and analysts spend part of the week defending a restriction to a team that wants it lifted.
  • The knowledge treadmill. Vendor certifications need renewing, platforms get replaced every few years, and the techniques worth detecting change faster than most job descriptions admit.

Based on our synthesis of professional-body surveys and public accounts of the role, not first-person verified reviews.

Which industries employ cyber security analysts?

Professional, Scientific and Technical Services employs the largest share of cyber security analysts, followed by Public Administration and Safety.

Top employing industries

  1. 1Professional, Scientific and Technical Services
  2. 2Public Administration and Safety
  3. 3Financial and Insurance Services

Ranked by employment share; the source doesn't publish an exact percentage per industry.

Highest qualification held
Bachelor degree
41.5%
Postgraduate
26.8%
Year 12 or below
10.7%
Diploma / Advanced Diploma
9.6%
Certificate III/IV
6.2%

Will AI replace cyber security analysts?

AI sits in the middle of this job rather than at its edges. Analysts already work with tools that correlate events, rank alerts and draft summaries, which speeds up triage and the paperwork around an incident. Deciding whether an alert is a genuine threat, containing it and explaining the risk to the business still depends on a person who knows the environment and what can safely be switched off.

high · 40%
moderate · 25%
low · 35%

Share of typical working time by exposure level

  • Investigating and containing live incidents
    Working out how an attacker got in and cutting off their access means reading logs across several systems, making calls under pressure and knowing what the business can tolerate losing.
    35%
    low
  • Monitoring and triaging the alert queue
    Correlation rules and machine learning ranking already filter most of the noise before an analyst sees it, so the work is increasingly about judging the alerts that survive.
    25%
    high
  • Reporting to business teams and documenting controls
    An incident write-up or a control description comes together faster with a language model, though the judgement about what a particular risk means for a particular team is not transferable.
    25%
    moderate
  • Vulnerability scanning and patch follow-up
    Scanners produce the findings and AI tools can group and prioritise them, but someone still has to chase system owners and confirm the fix actually landed.
    15%
    high

Moves least exposed to AI

These career moves from cyber security analyst work are rated low for AI exposure:

  • Penetration Tester

    High skill overlap (79%), little retraining to get there, and a low automation-risk profile.

  • Cyber Security Architect

    Solid skill overlap (44%), reskill to get there, and a low automation-risk profile.

Common questions about becoming a cyber security analyst

Straight answers to the questions people ask most.

How much do cyber security analysts earn?

Cyber security analysts earn a median of $128,000 per annum, before tax, based on full-time workers. Sector, security clearance, on-call arrangements and whether you work as a contractor move that figure more than years of experience do.

How do you become a cyber security analyst?

Most people arrive through an IT or computing degree and a year or two in a support or systems role, then move into a security team. Around 42% of people in the job hold a bachelor degree, but a diploma plus industry certifications and demonstrated hands-on skill is a realistic second route.

Are cyber security analysts in demand?

Cyber security analysts are currently not in shortage, and employment is projected to grow 24% over the decade to 2035. The work is concentrated in professional and technical services, government and financial services, so those three sectors are where most of the openings sit.

Will AI replace cyber security analysts?

AI is already doing part of the job, ranking alerts, correlating events across logs and drafting summaries of what happened. Judging whether an alert is a real threat, containing an active incident and explaining the risk to a business team still rests with an analyst who knows the environment.

What can a cyber security analyst move into?

Detection work transfers well into penetration testing, which shares 79% of its skills with this role and pays $600 less. Analysts who would rather work with controls and evidence move into IT auditing, where the skill overlap is 79% and pay is $18,800 less.

What hours do cyber security analysts work?

Full-time cyber security analysts average 42 hours a week, and incidents or on-call rosters push some weeks well past that. Security operations centres in banks, telecommunications companies and government agencies often run round-the-clock coverage, so shift work and after-hours escalation are common in those teams.

Related roles

Not sure this is you? Take the career quiz and get a ranked shortlist of roles that fit how you like to work.

careertips is an independent, data-first guide to Australian careers, built to help you understand what a role actually pays and where it can take you, not to sell you something.

Where available, figures are sourced from Jobs and Skills Australia and the Australian Bureau of Statistics (CC BY 4.0). Figures marked * are our own analysis. How we source and label our data. Last updated 2026-09-01.