Post job

How to hire an information security analyst

Information security analyst hiring summary. Here are some key points about hiring information security analysts in the United States:

  • There are a total of 33,770 information security analysts in the US, and there are currently 112,818 job openings in this field.
  • The median cost to hire an information security analyst is $1,633.
  • Small businesses spend $1,105 per information security analyst on training each year, while large companies spend $658.
  • It takes between 36 and 42 days to fill the average role in the US.
  • It takes approximately 12 weeks for a new employee to reach full productivity levels.
  • HR departments typically allocate 15% of their budget towards recruitment efforts.
  • New York, NY, has the highest demand for information security analysts, with 33 job openings.

How to hire an information security analyst, step by step

To hire an information security analyst, consider the skills and experience you are looking for in a candidate, allocate a budget for the position, and post and promote the job opening to reach potential candidates. Follow these steps to hire an information security analyst:

Here's a step-by-step information security analyst hiring guide:

  • Step 1: Identify your hiring needs
  • Step 2: Create an ideal candidate profile
  • Step 3: Make a budget
  • Step 4: Write an information security analyst job description
  • Step 5: Post your job
  • Step 6: Interview candidates
  • Step 7: Send a job offer and onboard your new information security analyst
  • Step 8: Go through the hiring process checklist

What does an information security analyst do?

An information security analyst is an individual who is responsible for carrying out security measures to protect the computer network and systems of an organization. Information security analysts erect firewalls and encrypt data transmissions to protect the organization's data from being inappropriately accessed or used. They must be aware of reports on computer viruses and should share this information with the management or customer. Information security analysts are also required to conduct training for all the organization's employees regarding computer security and information safeguarding.

Learn more about the specifics of what an information security analyst does
jobs
Post an information security analyst job for free, promote it for a fee
  1. Identify your hiring needs

    First, determine the employments status of the information security analyst you need to hire. Certain information security analyst roles might require a full-time employee, whereas others can be done by part-time workers or contractors.

    Determine employee vs contractor status
    Is the person you're thinking of hiring a US citizen or green card holder?

    You should also consider the ideal background you'd like them an information security analyst to have before you start to hire. For example, what industry or field would you like them to have experience in, what level of seniority or education does the job require, and how much it'll cost to hire an information security analyst that fits the bill.

    This list shows salaries for various types of information security analysts.

    Type of Information Security AnalystDescriptionHourly rate
    Information Security AnalystInformation security analysts plan and carry out security measures to protect an organization’s computer networks and systems. Their responsibilities are continually expanding as the number of cyberattacks increases.$34-64
    AnalystAnalysts are employees or individual contributors with a vast experience in a particular field that help the organization address challenges. They help the organization improve processes, policies, and other operations protocol by studying the current processes in place and determining the effectiveness of those processes... Show more$25-47
    Security EngineerSecurity engineers are responsible for developing and overseeing data and security software to help prevent data breaches, leaks, and taps related to cybercrime. Other duties and responsibilities include developing new systems to help protect computer networks and assets, configuring firewalls, and conducting penetration testing to pinpoint vulnerabilities... Show more$37-67
  2. Create an ideal candidate profile

    Common skills:
    • Incident Response
    • Risk Assessments
    • Windows
    • SIEM
    • Data Loss Prevention
    • Network Security
    • PCI
    • HIPAA
    • Corrective Action
    • Linux
    • DOD
    • ISO
    • Vulnerability Assessments
    • Security Incidents
    Check all skills
    Responsibilities:
    • Manage IA personnel in the performance of IAVM tasks.
    • Lead maritime IP intrusion detection analysis special project providing models to identify Cyber terrorist's capabilities, methods, and strategies.
    • Manage and configure perimeter Cisco routers and switches.
    • Implement a manage endpoint encryption solution utilizing TrendMicro MobileArmor to secure university workstations against sensitive data loss.
    • Perform vulnerability assessment and remediation of systems to ensure compliance to policies, regulations and controls (HIPAA & NIST).
    • Monitor and analyze SIEM events to identify security issues for remediation.
    More information security analyst duties
  3. Make a budget

    Including a salary range in your information security analyst job description is one of the best ways to attract top talent. An information security analyst can vary based on:

    • Location. For example, information security analysts' average salary in nebraska is 35% less than in california.
    • Seniority. Entry-level information security analysts 47% less than senior-level information security analysts.
    • Certifications. An information security analyst with certifications usually earns a higher salary.
    • Company. Working for an established firm or a new start-up company can make a big difference in an information security analyst's salary.

    Average information security analyst salary

    $98,144yearly

    $47.18 hourly rate

    Entry-level information security analyst salary
    $71,000 yearly salary
    Updated December 18, 2025

    Average information security analyst salary by state

    RankStateAvg. salaryHourly rate
    1California$123,557$59
    2Washington$104,120$50
    3Massachusetts$101,471$49
    4New Jersey$100,385$48
    5New York$99,224$48
    6Pennsylvania$96,001$46
    7Oregon$95,856$46
    8Arizona$95,025$46
    9District of Columbia$94,302$45
    10Virginia$93,782$45
    11Maryland$92,515$44
    12North Carolina$91,399$44
    13Minnesota$91,139$44
    14Illinois$90,704$44
    15Connecticut$90,489$44
    16Texas$90,401$43
    17Michigan$87,317$42
    18Georgia$86,447$42
    19Ohio$84,980$41
    20Colorado$83,993$40

    Average information security analyst salary by company

    RankCompanyAverage salaryHourly rateJob openings
    1The Walt Disney Company$147,610$70.9732
    2Meta$145,857$70.12658
    3Apple$145,665$70.0333
    4McKinsey & Company Inc$141,735$68.146
    5PayPal$141,357$67.9613
    6StubHub$136,535$65.64
    7Google$136,469$65.61343
    8Bloomberg$133,530$64.202
    9eBay$133,299$64.096
    10NVIDIA$133,297$64.0912
    11Amazon$131,921$63.42360
    12Square$131,432$63.19
    13First Republic Bank$131,145$63.05
    14Conning$130,478$62.73
    15WLRK$129,979$62.494
    16Palo Alto Networks$129,624$62.3236
    17SoFi$129,396$62.2115
    18Western Digital$128,780$61.9168
    19Coty$127,495$61.30
    20Avid$127,473$61.296
  4. Writing an information security analyst job description

    An information security analyst job description should include a summary of the role, required skills, and a list of responsibilities. It's also good to include a salary range and the first name of the hiring manager. To help get you started, here's an example of an information security analyst job description:

    Information security analyst job description example

    The NVIDIA Information Security team is seeking a passionate, highly motivated Information Security Analyst to enhance our programs and initiatives. As a member of the Standards and Awareness group, you will need a solid understanding of various Information Security concepts, frameworks, and tools. You are expected to take a strong, hands-on approach to develop of effective security policies and guides, implement security requirements, deliver a world-class training and awareness program, and optimize our security tools.
    What You'll be Doing:
    Implement automation to improve service delivery. Develop and manage dashboards that deliver actionable metrics. Enhance our security awareness and training program through new initiatives. Perform social engineering exercises, including phishing simulation tests. Expand and support our security documentation, websites, and other resources. Provide policy, technical guidance, and outreach to help teams improve their security posture. Create and record security training videos and other awareness content. Support and manage our Password Manager and Asset Discovery solution.
    What We Need to See:
    6+ years working experience in Information Security. BS Degree or equivalent experience; MS preferred in Information Technology. Recent experience with writing code, scripts, and/or applications. Demonstrated ability to implement security controls and projects. A data-driven approach to drive improvements to the program. Strong verbal and written communication skills.
    Ways to Stand Out from the Crowd:
    Certifications in one or more of the following areas: CISSP, CISA, CISM, CEH, OSCP. Broad understanding of security frameworks and concepts. Prior experience with security awareness and training programs.
    With competitive salaries and a generous benefits package, NVIDIA is widely considered to be one of the technology world's most desirable employers. We have some of the brightest people in the world working for us and, due to unprecedented growth, our elite engineering teams are rapidly growing. If you're a creative and autonomous engineer with a real passion for technology, we want to hear from you.

    The Colorado Equal Pay for Equal Work Act requires that NVIDIA provide the compensation range and benefits offered for this position if performed in Colorado.The base salary range for this position in Colorado is $111,600.00 - 153,450.00 USD.
    NVIDIA also offers a comprehensive benefits package. We provide health care coverage, dental and vision,401(K), including company matching and after tax contributions,Employee Stock Purchase Program (ESPP), Employee Assistance Program (EAP), company paid holidays, paid sick leave, vacation leave,professional time off,life and disability protection. Employees in eligible sales and positions may also be eligible for commission.

    Base pay is based on market location and may vary based on factors including experience, skills, education,and other job-related reasons.

    NVIDIA is committed to fostering a diverse work environment and proud to be an equal opportunity employer. As we highly value diversity in our current and future employees, we do not discriminate (including in our hiring and promotion practices) on the basis of race, religion, color, national origin, gender, gender expression, sexual orientation, age, marital status, veteran status, disability status or any other characteristic protected by law.
  5. Post your job

    To find information security analysts for your business, try out a few different recruiting strategies:

    • Consider internal talent. One of the most important talent pools for any company is its current employees.
    • Ask for referrals. Reach out to friends, family members, and your current work to ask if they know any information security analysts they would recommend.
    • Recruit at local colleges. Attend job fairs at local colleges to recruit entry-level information security analysts with the right educational background.
    • Social media platforms. LinkedIn, Facebook, and Twitter have more than 3.5 billion users, and they're a great place for company branding and reaching potential job candidates.
    Post your job online:
    • Post your information security analyst job on Zippia to find and attract quality information security analyst candidates.
    • Use niche websites such as dice, engineering.com, stack overflow, it job pro.
    • Post a job on free websites.
  6. Interview candidates

    Your first interview with information security analyst candidates should focus on their interest in the role and background experience. As the hiring process goes on, you can learn more about how they'd fit into the company culture in later rounds of interviews.

    You should also ask about candidates' unique skills and talents to see if they match the ideal candidate profile you developed earlier. Candidates good enough for the next step can complete the technical interview.

    Sometimes, it's not enough to interview information security analyst candidates, so you can ask them to do a test project. If you are not a technical person and don't know what a test project should be, you can use these websites:

    • TestDome
    • CodeSignal
    • Testlify
    • BarRaiser
    • Coderbyte

    The right interview questions can help you assess a candidate's hard skills, behavioral intelligence, and soft skills.

  7. Send a job offer and onboard your new information security analyst

    Once you've found the information security analyst candidate you'd like to hire, it's time to write an offer letter. This should include an explicit job offer that includes the salary and the details of any other perks. Qualified candidates might be looking at multiple positions, so your offer must be competitive if you like the candidate. Also, be prepared for a negotiation stage, as candidates may way want to tweak the details of your initial offer. Once you've settled on these details, you can draft a contract to formalize your agreement.

    It's equally important to follow up with applicants who don't get the job with an email letting them know that the position has been filled.

    After that, you can create an onboarding schedule for a new information security analyst. Human Resources and the hiring manager should complete Employee Action Forms. Human Resources should also ensure that onboarding paperwork is completed, including I-9s, benefits enrollment, federal and state tax forms, etc., and that new employee files are created.

  8. Go through the hiring process checklist

    • Determine employee type (full-time, part-time, contractor, etc.)
    • Submit a job requisition form to the HR department
    • Define job responsibilities and requirements
    • Establish budget and timeline
    • Determine hiring decision makers for the role
    • Write job description
    • Post job on job boards, company website, etc.
    • Promote the job internally
    • Process applications through applicant tracking system
    • Review resumes and cover letters
    • Shortlist candidates for screening
    • Hold phone/virtual interview screening with first round of candidates
    • Conduct in-person interviews with top candidates from first round
    • Score candidates based on weighted criteria (e.g., experience, education, background, cultural fit, skill set, etc.)
    • Conduct background checks on top candidates
    • Check references of top candidates
    • Consult with HR and hiring decision makers on job offer specifics
    • Extend offer to top candidate(s)
    • Receive formal job offer acceptance and signed employment contract
    • Inform other candidates that the position has been filled
    • Set and communicate onboarding schedule to new hire(s)
    • Complete new hire paperwork (i9, benefits enrollment, tax forms, etc.)
    Sign up to download full list

How much does it cost to hire an information security analyst?

Recruiting information security analysts involves both the one-time costs of hiring and the ongoing costs of adding a new employee to your team. Your spending during the hiring process will mostly be on things like promoting the job on job boards, reviewing and interviewing candidates, and onboarding the new hire. Ongoing costs will obviously involve the employee's salary, but also may include things like benefits.

You can expect to pay around $98,144 per year for an information security analyst, as this is the median yearly salary nationally. This can vary depending on what state or city you're hiring in. If you're hiring for contract work or on a per-project basis, hourly rates for information security analysts in the US typically range between $34 and $64 an hour.

Find better information security analysts in less time
Post a job on Zippia and hire the best from over 7 million monthly job seekers.

Hiring information security analysts FAQs

Search for information security analyst jobs

Ready to start hiring?

Browse computer and mathematical jobs