1

Principal Cyber Security Analyst Jobs (NOW HIRING)

next page

Showing results 1-20

Principal Cyber Security Analyst information

See salary details

$43K

$99.4K

$150K

How much do principal cyber security analyst jobs pay per year?

As of Jun 16, 2026, the average yearly pay for principal cyber security analyst in the United States is $99,400.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,500.00 and $115,500.00 per year, depending on experience, location, and employer.

What is a Principal Cyber Security Analyst?

A Principal Cyber Security Analyst is a senior-level professional responsible for overseeing and guiding an organization’s cybersecurity strategy and operations. They lead efforts to identify, assess, and mitigate cyber threats, as well as develop security policies and incident response plans. This role involves mentoring junior analysts, conducting risk assessments, and ensuring compliance with security standards and regulations. Principal Cyber Security Analysts often collaborate with IT teams and executive leadership to protect critical assets and infrastructure.

What is the difference between Principal Cyber Security Analyst vs Cyber Security Analyst?

AspectPrincipal Cyber Security AnalystCyber Security Analyst
Certifications CISSP, CISM, CEHCompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentStrategic, leadership-focused, often in senior teamsOperational, technical, hands-on security tasks
ResponsibilitiesOversees security strategy, manages teams, develops policiesMonitors security systems, investigates incidents, implements controls

The Principal Cyber Security Analyst typically holds more senior certifications and focuses on strategic planning and leadership within cybersecurity teams. In contrast, the Cyber Security Analyst is more involved in day-to-day security operations and technical tasks. Both roles are essential in an organization's security framework, but they differ mainly in scope, responsibilities, and experience level.

Can you make $500,000 a year in cyber security?

Principal Cyber Security Analysts with extensive experience, advanced certifications, and specialized skills can potentially earn salaries approaching or exceeding $500,000 annually, especially in high-demand industries or senior leadership roles. However, such compensation is uncommon and typically requires a combination of technical expertise, management responsibilities, and strategic influence. Most cybersecurity professionals earn lower salaries, with top-tier roles in large organizations or consulting firms more likely to reach high compensation levels.

What does a principal security analyst do?

A principal security analyst leads cybersecurity efforts by developing security strategies, analyzing threats, and implementing protective measures. They often oversee security teams, conduct risk assessments, and utilize tools like intrusion detection systems, with certifications such as CISSP or CISM being common. Their role ensures the organization's information systems are secure against cyber threats.

What is the 80 20 rule in cyber security?

The 80/20 rule in cybersecurity suggests that approximately 80% of security issues are caused by 20% of vulnerabilities or threats. As a Principal Cyber Security Analyst, focusing on the most critical vulnerabilities and implementing prioritized controls can significantly improve an organization’s security posture.

What are the key skills and qualifications needed to thrive as a Principal Cyber Security Analyst, and why are they important?

To thrive as a Principal Cyber Security Analyst, you need extensive expertise in information security, risk management, and incident response, typically supported by a bachelor’s or master’s degree in cybersecurity or a related field. Familiarity with SIEM tools, vulnerability assessment platforms, and certifications such as CISSP or CISM are highly valued. Strong analytical thinking, leadership, and effective communication skills enable you to develop strategies and guide teams through complex security challenges. These competencies are critical for safeguarding organizational assets, leading security initiatives, and effectively mitigating cyber threats.

How much does a principal cyber security analyst make at Fidelity?

A principal cyber security analyst at Fidelity typically earns between $120,000 and $160,000 annually, depending on experience, certifications, and location. The role often requires advanced skills in security tools, threat analysis, and leadership responsibilities.

What types of projects and teams does a Principal Cyber Security Analyst typically collaborate with during their daily work?

A Principal Cyber Security Analyst often collaborates with cross-functional teams, including IT, network engineering, risk management, and compliance, to lead security initiatives and respond to potential threats. They may be involved in projects such as security architecture reviews, incident response planning, and vulnerability assessments. Daily responsibilities also include mentoring junior analysts and coordinating with external vendors or stakeholders to ensure comprehensive security coverage. This collaborative environment provides opportunities to influence security strategies and advance into leadership roles.
More about Principal Cyber Security Analyst jobs
What cities are hiring for Principal Cyber Security Analyst jobs? Cities with the most Principal Cyber Security Analyst job openings:
What job categories do people searching Principal Cyber Security Analyst jobs look for? The top searched job categories for Principal Cyber Security Analyst jobs are:
Infographic showing various Principal Cyber Security Analyst job openings in the United States as of June 2026, with employment types broken down into 40% Full Time, and 60% Contract. Highlights an 100% In-person job distribution, with an average salary of $99,400 per year, or $47.8 per hour.

Principal Cybersecurity Compliance Analyst

GFT.

Roseville, CA

$150K - $200K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 13 days ago


Job description

GFT is seeking a Principal Cybersecurity Compliance Analyst to join our Security and Safety team in Northern Califonria! This role follows a hybrid work model, requiring regular attendance at our client's office.

What you’ll be challenged to do:
As a Principal Cybersecurity Compliance Analyst, you will support critical compliance initiatives across a client’s generation assets. This role will focus on ensuring adherence to regulatory requirements, internal cybersecurity standards, and industry best practices. The ideal candidate will have a proven track record of managing compliance projects within highly regulated environments, particularly in the energy or utilities sector.

In this capacity, the successful candidate will be responsible for the following: 

  • Lead and support the development, implementation, and continuous improvement of governance, risk, and compliance (GRC) programs aligned with FERC (D2SI SPHP Section 9) and NERC CIP standards for PG&E’s power generation assets.
  • Develop, maintain, and operationalize policies, procedures, standards, and guidelines to meet regulatory requirements and industry best practices.
  • Conduct compliance gap assessments, risk analyses, and control testing for cybersecurity and OT systems.
  • Prepare and maintain audit-ready documentation, including compliance narratives, evidence repositories, and records retention practices.
  • Coordinate and support internal and external audits, including NERC Regional Entity audits, spot checks, and self-certifications.
  • Collaborate with cybersecurity, IT, OT, engineering, legal, and enterprise risk teams to align compliance requirements with business operations.
  • Serve as a liaison between technical teams and compliance leadership to translate regulatory requirements into actionable controls.
  • Track compliance metrics, risks, and issues; prepare reports and dashboards for leadership.
  • Monitor regulatory developments, FERC and NERC standards changes, and enforcement trends.
  • Support compliance training and awareness efforts for internal stakeholders.
  • Assist in the integration of compliance controls into operational and cybersecurity processes.
  • Participate in mock audits, tabletop exercises, and incident response planning.

What you will bring to our firm: 
  • Bachelor’s degree in cybersecurity, information systems, engineering, business, or a related field.
  • Minimum of 10 years of relevant experience in the power utility industry, with a focus on governance, risk, and compliance (GRC), cybersecurity, or operational technology.
  • Deep working knowledge of NERC CIP standards and the FERC regulatory environment.
  • Direct experience supporting NERC CIP audits (self-certifications, spot checks, or enforcement actions).
  • Experience with compliance documentation, evidence collection, and audit support.
  • Familiarity with electric utility operations, OT environments, or ICS/SCADA systems.
  • Strong analytical, organizational, and technical writing skills.
  • Excellent communication and interpersonal skills, with the ability to work independently and collaboratively.
  • Certification from a recognized risk, governance, or cybersecurity organization (e.g., CISSP, CISM, RIMS-CRMP, or equivalent) required
 
What we prefer you bring: 
  • Experience in the energy sector, particularly power generation or utilities.
  • PMP certification
  • Familiarity with SCADA/ICS systems and processes.
  • Knowledge of related frameworks (e.g., NIST CSF, NIST SP 800-53, ISO 27001).
  • Experience in project management, including scope, schedule, and budget tracking.
  • Involvement in professional organizations or industry committees.
 
Compensation:
The salary range for this role is $150,000 - $200,000. Salary is dependent upon experience and geographic location.
 
Featured Benefits: 
• Hybrid (in-person and remote) work environment.
• Comprehensive benefits package including wellness programs, parental leave, and pet insurance, in addition to medical, dental, vision, disability, and life insurance.
• Tax-deferred 401(k) savings plan.
• Competitive paid-time-off (PTO) accrual.
• Tuition reimbursement for continued education.
• Commitment to professional development, access to internal and external training programs, and support of active participation in professional organizations
• Incentive compensation for eligible positions.

At GFT, a privately held AEC firm, we innovate where transportation, water, power, and buildings converge. We call this the Infrastructure of Life. We measure our success by the strength of our relationships – that’s why we’re the employer of choice for 5,000+ of the industry’s brightest engineers, planners, architects, inspectors, designers, and more.

Our clients choose us for our expertise and prefer us for our nimble approach, creativity, and personal touch. Backed by over a century’s experience, together we’re building a lasting legacy for future generations: stronger communities, a healthier planet, and better lives.
GFT: Ingenuity That Shapes Lives™ is an Equal Opportunity Employer. All qualified candidates will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veterans’ status or other characteristics protected by law.

Unsolicited resumes from third party agencies will be considered the property GFT.

GFT does require the successful completion of a criminal background check for all advertised positions. 

Location: Sacramento, CA; Roseville, CA; Oakland, CA
Core Business Hours: 8:00 AM – 5:00 PM
Employment Status: Full-Time

Applicants in the County of Los Angeles- Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.

Applicants in the City of San Francisco- Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Applicants in the State of California-Qualified applications with arrest or conviction records will be considered for employment in accordance with the California Fair Chance Act.

#LI-hybrid

#LI-KV1