CISO Salary Guide: Base Pay, Bonuses, Equity, and What Drives the Difference

  •   min.
  • Updated on: July 27, 2026

    • Expert review
    • Home
    • /
    • Resources
    • /
    • CISO Salary Guide: Base Pay, Bonuses, Equity, and What Drives the Difference

    Most salary figures you will find for the CISO role report only the base salary. At the executive level, that number tells less than half the story. Bonuses, equity, deferred compensation, and benefits regularly represent 30 to 50 percent of a CISO's total annual earnings, which means the base figures that appear in most salary searches dramatically understate what top-earning CISOs actually take home.

    The base salary variance is already significant on its own. Glassdoor reports an average of $262,245. Salary.com puts the average at $385,292. Those two figures come from the same job title in the same country in the same year, and neither is wrong. They reflect different slices of the market: Glassdoor draws heavily from self-reported salaries across all company sizes, which pulls the average down. Salary.com leans toward larger enterprise roles, which pulls it up.

    Knowing why those gaps exist is more useful than picking one number to trust. This guide breaks down the full picture: base salary across multiple sources, what total compensation actually looks like at different levels, how industry and company size move the numbers, what credentials and factors drive the highest packages, and what the realistic career path to the role looks like.

    What CISOs Actually Earn: The Data Side by Side

    Three sources give the most reliable snapshot of CISO base salary in the US market, and they measure the role slightly differently.

    Glassdoor's CISO salary data shows an average of $262,245 per year, with the middle range of earners falling between $198,894 and $351,411. The top 10 percent report earning up to $452,134. Glassdoor's figures draw from 88 self-reported salaries and reflect a broad sample that includes smaller organizations and less-established CISO roles.

    Glassdoor's more specific search for "CISO Chief Information Security Officer" pulls from 283 salaries and shows a higher average of $303,830, with the typical range running from $227,268 to $372,982. The larger sample and more precise job title filter produce a figure closer to what established enterprise CISOs report.

    Salary.com shows the highest average at $385,292, with most CISO roles falling between $314,455 and $470,725. Salary.com's methodology relies more heavily on compensation survey data from larger employers and tends to reflect enterprise and Fortune 500 compensation packages rather than the full market range.

    The most useful way to read these three figures together: a CISO at a mid-size company in a competitive market can expect a base salary somewhere between $250,000 and $350,000. A CISO at a large enterprise or Fortune 500 company in a major metropolitan area will often exceed $380,000 in base salary alone, before bonuses and equity are factored in.

    CISO Total Compensation: What the Base Salary Misses

    Base salary is the starting point. For most CISOs at the enterprise level, it is not the largest variable in the total compensation equation.

    Annual performance bonuses at the CISO level typically range from 20 to 40 percent of base salary, tied to security program outcomes, regulatory compliance milestones, and organizational risk reduction goals. A CISO earning $300,000 in base salary with a 30 percent bonus target has $390,000 in total cash compensation before equity.

    Equity compensation is where the largest gaps open between company types. CISOs at publicly traded companies receive restricted stock units (RSUs) that vest over three to four years. CISOs at pre-IPO technology companies may receive stock options that carry significant upside if the company exits. A CISO at a large public tech company with $300,000 in base salary, a 35 percent bonus, and $200,000 in annual RSU grants is earning roughly $605,000 in total annual compensation. Government agency CISOs and nonprofit CISOs earn significantly less in cash terms but may receive defined benefit pensions, job security, and clearance-related benefits that carry their own value.

    Location also adjusts total compensation significantly. Salary.com's Washington DC data shows an average CISO salary of $425,956 in the DC metro area, reflecting the concentration of defense, government contracting, and federal agency roles that carry high base salaries alongside clearance premiums.

    CISO Salary by Company Size

    Company size is one of the strongest predictors of CISO compensation. The scope of the role, the complexity of the environment, and the board-level accountability all scale with organizational size, and so does the pay.

    Role

    Typical salary range

    Typical salary range

    Notes

    Small (under 500 employees)

    $130,000–$180,000

    $150,000–$220,000

    Often first security hire, broad scope

    Mid-market (500–5,000)

    $175,000–$250,000

    $210,000–$320,000

    Growing security function, some board exposure

    Enterprise (5,000+)

    $250,000–$380,000

    $350,000–$600,000

    Complex environment, direct board reporting

    Fortune 500 / public company

    $300,000–$500,000+

    $500,000–$1,000,000+

    Equity, significant, regulatory and legal exposure

    Small company CISOs often take on a broader scope than their enterprise counterparts, handling everything from technical security operations to compliance to vendor management. The compensation reflects the smaller budget rather than the smaller workload. Enterprise and Fortune 500 CISOs operate at higher compensation partly because of the complexity of the environment and partly because personal legal exposure under SEC disclosure rules and breach notification requirements has made the role significantly riskier in recent years.

    CISO Salary by Industry

    The industry sector moves CISO compensation more consistently than almost any other variable outside company size.

    1. Financial services is the highest-paying sector for CISOs across all company sizes. Banks, investment firms, and insurance companies operate under strict regulatory frameworks (SOX, PCI-DSS, state financial regulators) and face sophisticated, well-funded threat actors. The combination of regulatory pressure and breach consequence keeps CISO compensation at the top of the market in this sector.
    2. Technology companies rank second, particularly at larger public firms where equity compensation drives total packages well above $500,000. The competitive hiring market for security talent in tech means CISOs command premium total compensation even when base salary is similar to other industries.
    3. Healthcare has seen CISO compensation rise sharply over the past several years, driven by the sector's sustained exposure to ransomware and the regulatory weight of HIPAA. Healthcare CISOs at large hospital systems now routinely earn $250,000 to $350,000 in base salary.
    4. Defense and government contracting pay strong base salaries with clearance premiums adding $20,000 to $40,000 on top. Federal government CISO roles pay less in cash than the private sector but offer stability, defined benefit retirement plans, and clearance sponsorship.
    5. Government agencies sit at the lower end of the cash compensation range, with federal civilian CISO roles typically capped by government pay scales. State and local government CISOs earn considerably less than their private sector equivalents, though the gap is closing as governments compete for qualified security leadership.

    Looking for some exam prep guidance and mentoring?


    Learn about our personal mentoring

    Image of Lou Hablas mentor - Destination Certification

    What Drives CISO Compensation Beyond Experience

    Years of experience predict CISO compensation up to a point. Above roughly fifteen years, these factors matter more.

    Board reporting responsibility and legal exposure

    Board reporting responsibility and legal exposure have become the single biggest compensation driver at the enterprise level. The SEC's cybersecurity disclosure rules, enacted in 2023, require public companies to disclose material cybersecurity incidents and describe their CISO's role in managing cyber risk. That regulation shifted personal legal liability directly onto CISOs in ways that simply did not exist a decade ago. As the Harvard Business Review notes in its analysis of board-level cybersecurity conversations, the ability to communicate security risk in business terms is now one of the most valued competencies a CISO can demonstrate. Organizations pay significantly more for CISOs who can present to a board fluently rather than those who need translation.

    Credentials

    Credentials are the most reliable signal employers use to evaluate CISO readiness before a hire. CISSP and CISM are the most consistently cited combination in CISO job descriptions. CISSP validates broad security competence across technical and governance domains. CISM validates the management-first thinking that senior security leadership requires. For a detailed look at how the two work together in a career context, the CISSP vs CISM comparison walks through the sequencing and value of holding both. Whether CISSP alone justifies the time and cost is addressed directly in the is CISSP worth it guide.

    Geographic location

    Geographic location moves base salary by 15 to 25 percent between top and bottom markets. New York, San Francisco, Washington DC, and Seattle are the highest-paying metro areas for CISO roles. Remote CISO positions, while increasingly available, often target the bottom of the local market range rather than the top.

    Security clearance

    Security clearance adds a consistent premium in defense and government-adjacent roles. An active Top Secret clearance adds $20,000 to $40,000 to base salary for roles that require it, and speeds up hiring timelines considerably in the defense contracting sector.

    The Career Path to CISO

    The CISO title is typically earned after 15 to 20 years in security and adjacent roles for large enterprise positions, and sometimes faster for mid-size and small company roles where the bar is lower, and the role scope is broader.

    The most common path runs through a security analyst, security engineer or architect, security manager, and then a Director or VP of Security before reaching CISO. Some professionals take a risk management or compliance track through GRC roles before moving into security leadership. Others come through audit or legal with security specialization layered on top.

    What separates the professionals who reach the CISO level from those who plateau at Director or VP is usually not technical depth. It is the ability to operate at the executive level: communicating risk in business terms, building relationships with board members, managing budgets and headcount, and making governance decisions under uncertainty.
     
    That shift from technical thinking to governance thinking is exactly what CISSP and CISM are designed to validate, and why those credentials appear so consistently in CISO job postings. For a detailed look at what the full CISO career track involves, the how to become a CISO guide maps the path in practical detail.
     
    For a full picture of where CISO compensation sits relative to other senior security roles, the highest-paid cybersecurity jobs guide maps the full spectrum.

    Certification in 3 Days 


    Study everything you need to know for the AAISM exam in a 3-day bootcamp!

    Frequently Asked Questions 

    What is the average CISO salary in the US?

    The average varies significantly by source and company size. Glassdoor reports an average of $262,245 based on self-reported salaries across all company types. Salary.com shows $385,292 based on compensation survey data weighted toward larger employers. The most useful planning range for mid-to-large company CISO roles is $250,000 to $380,000 in base salary, with total compensation running considerably higher once bonuses and equity are included.

    How much do Fortune 500 CISOs earn in total compensation?

    Total compensation for Fortune 500 CISOs typically runs between $500,000 and $1,000,000 or more annually when base salary, performance bonuses, and equity grants are combined. Base salary in this tier generally falls between $300,000 and $500,000, with bonuses of 30 to 40 percent on top and annual equity grants ranging from $100,000 to $300,000 or more, depending on the company and the CISO's tenure.

    What certifications do most CISOs hold?

    CISSP and CISM are the most commonly cited certifications in CISO job postings and among practicing CISOs. CISSP validates broad security competence across eight domains, including technical architecture, risk management, and governance. CISM validates security management leadership specifically. Many CISOs also hold CRISC for risk governance depth, and CCSP for cloud security expertise. The combination of CISSP and CISM is the most widely recognized pairing for senior security leadership roles.

    Is CISO the highest-paid role in cybersecurity?

    Yes, in most organizations, the CISO is the highest-compensated security role. The next highest-paid roles are typically VP of Security, Security Architect, and Director of Information Security, which fall below CISO compensation at equivalent company sizes. At very large technology companies, some specialized security roles like Principal Security Researcher or Distinguished Security Engineer can approach CISO-level base salaries, though total compensation, including equity, usually still favors the CISO title.

    How long does it take to become a CISO?

    Most large enterprise CISO roles require 15 to 20 years of security and leadership experience. Mid-size company and startup CISO roles are reachable faster, sometimes in 8 to 12 years for strong candidates with the right credential stack and management experience. The typical path moves through security analyst, security engineer or architect, security manager, and then Director or VP of Security. Credentials like CISSP and CISM accelerate progression by validating governance and management competence before the title is formally awarded.

    CISO-Level Thinking Starts Before the Title. Build It Now

    CISO compensation reflects the weight of the role: board accountability, regulatory exposure, organizational risk ownership, and the expectation that you can translate technical complexity into business decisions. The credentials that validate that thinking, CISSP and CISM, are not just resume lines. They are the formal proof that you can operate at the level the role demands.

    Destination Certification offers one of the most comprehensive CISSP preparation programs available, with expert-led instruction across all eight domains and an adaptive learning system that identifies your specific knowledge gaps. The CISSP Bootcamp delivers five intensive days of live online instruction, Monday through Friday, ten hours per day.
     
    Want to take it to the next level? The CISSP MasterClass gives you the same expert instruction in a self-paced format that adjusts to your schedule and focuses your study time on what you still need to learn.

    For the management and governance thinking that defines the CISO role specifically, Destination Certification offers one of the most comprehensive CISM preparation programs available. The CISM Bootcamp runs four intensive days of live online instruction, Monday through Thursday. The CISM MasterClass gives you the same depth in a self-paced format with flexible study timelines that fit around your current role.

    Start building the foundation with the free CISSP MindMaps and free CISM MindMaps from Destination Certification, visual domain-by-domain overviews of everything both exams test, at no cost.

    CISO compensation reflects more than experience. It reflects how well you can translate security into business risk.

    Image of Rob Witcher - Destination Certification

    Rob is the driving force behind the success of the Destination Certification CISSP program, leveraging over 15 years of security, privacy, and cloud assurance expertise. As a seasoned leader, he has guided numerous companies through high-profile security breaches and managed the development of multi-year security strategies. With a passion for education, Rob has delivered hundreds of globally acclaimed CCSP, CISSP, and ISACA classes, combining entertaining delivery with profound insights for exam success. You can reach out to Rob on LinkedIn.

    Free Class:
    Crack Cryptography for the CISSP Exam

    A free 3-part class that makes one of the CISSP's hardest topics click.

    • Why cryptography questions confuse even experienced security professionals on exam day
    • How symmetric and asymmetric encryption actually differ the way the CISSP tests it
    • What digital signatures are really doing and why the exam frames questions around them the way it does
    • A practice test at the end so you leave knowing exactly where your understanding holds up

    The easiest way to get your CISSP Certification 


    Learn about our CISSP MasterClass

    Image of masterclass video - Destination Certification