Cybersecurity Analyst.
Defend banks, hospitals and companies from real attackers — spotting break-ins, stopping them, and cleaning up when something slips through. One of the few tech careers with a genuine talent shortage in India, no mandatory degree, and a ceiling that runs all the way to CISO. Here's the honest version — including how AI is changing the entry rung.
A cybersecurity analyst detects, investigates and responds to cyber attacks. No degree is mandatory — certifications like CompTIA Security+ plus hands-on labs can land the first SOC job in 9–18 months. Freshers earn ₹3.5–6L a year; with experience and specialisation, pay reaches ₹15–50L, and security architects and CISOs go well beyond. India has a structural shortage of these professionals.
Open TryHackMe(free, in your browser) and start the “Pre Security” path. Finish the first room. Close the laptop.
Free, zero setup, no install — tonight. This single habit, repeated, is what actually gets people into a SOC. Everything else on this page is just continuing it.
Is cybersecurity still worth it? The 30-second answer
Before everything else, the truth about this career in three lines.
- You'll watch for attacks, investigate alerts, and respond when something breaks in — first in a Security Operations Centre (SOC), then in deeper roles like pentesting, cloud security or architecture.
- You don't need a CS degree or an elite college — you need fundamentals, one or two certifications, and hands-on proof from labs like TryHackMe and Hack The Box. Employers say they prefer credentialed, practical hires over pedigree.
- It pays like the rest of tech at entry but pulls ahead fast for specialists — and unlike most of tech, demand outstrips supply. The catch: entry SOC work runs shifts, and AI is automating the most routine Tier-1 tasks, so you have to keep levelling up.
- DemandStructural shortage
- CompetitionModerate at entry
- AI riskReshapes Tier-1, not the field
- Time to first job9–18 months
- Cost to get thereLow–medium
- Growth ceilingVery high (CISO)
What does a cybersecurity analyst actually do?
Every bank, hospital and company runs on systems that criminals want to break into — to steal data, money, or hold things to ransom. A cybersecurity analyst is the person watching for those attempts and stopping them. Think of it as being the security guard, detective and emergency responderfor a company's digital world, all at once.
Most people start in a Security Operations Centre (SOC). A tool called a SIEM (like Splunk or Microsoft Sentinel) collects logs from across the company and raises alerts. Your job is to triage them: is this a real attack or a false alarm? You investigate, escalate the genuine threats, and write up what happened so the next analyst can pick up where you left off. Analysts typically work through 25–35 alerts a day.
From there the field forks wide. Some go offensive (penetration testers who legally break in to find holes first). Some go into incident response and forensics (the people called when a breach has already happened). Some move into cloud security, governance and risk (GRC), or architecture — designing how an entire company stays safe.
A SOC shift — what's it actually like?
Based on a Tier-1/2 SOC analyst with 1–3 years of experience at a GCC or managed-security provider in India. SOC roles often run rotating shifts, so this could be days, evenings or nights.
- 8:00Shift handoverMeet the outgoing analyst. Review overnight incidents, open tickets and anything still being investigated.
- 8:30Triage the alert queueWork through the SIEM dashboard — failed logins, odd traffic, malware flags. Decide: real threat, or false positive?
- 10:30Investigate a real oneA suspicious login from an unusual location. Pull logs, check threat intel, trace what the account touched.
- 12:00Escalate + documentHand a confirmed incident to Tier 2 / incident response with a clear write-up. Good notes are half the job.
- 13:00LunchStep away from the screens. Alert fatigue is real — breaks are part of staying sharp.
- 14:00Threat huntingDon't just wait for alerts — proactively search logs for signs of attackers the tools missed.
- 15:30Tune the toolsToo many false positives? Adjust SIEM rules so the team wastes less time tomorrow. Increasingly, supervising AI triage.
- 17:00Handover + learnBrief the next shift. Read a threat report or finish a TryHackMe room to keep levelling up.
Reality check: a lot of SOC work is routine and repetitive, and night shifts wear on you. But when a real attack is unfolding, it's the most adrenaline this job offers — and the moment you realise why it matters. Consulting, pentest and architect roles trade the shifts for project deadlines.
The honest test — before you commit a year of your life.
Don't pick this because it pays well or sounds cool. Pick it because the way it works fits you.
- You're curious about how things break and how people get in
- You can stay calm and methodical when something's on fire
- You enjoy puzzles, patterns and chasing down anomalies
- You're okay with constant learning — attackers never stand still
- You like the idea of protecting people, not just shipping features
- You can handle routine work and shifts without losing focus
- Rotating or night shifts (common in SOC roles) are a dealbreaker
- You want every day to be creative and varied from day one
- Reading logs and writing detailed notes sounds unbearable
- You panic under pressure instead of focusing
- You dislike continuous studying and certification renewals
- You want to be 'done learning' once you land the job
What does a cybersecurity analyst earn in India?
Entry pay looks like the rest of tech — the difference is how fast specialists pull ahead. Here's the full distribution, not just the headline. All figures are annual, and the top ends are indicative.
| Experience | Role | Pay range |
|---|---|---|
| 0–2 yrs | SOC / Cybersecurity Analyst Fresher SOC analyst offers cluster around ₹3.5–6L (Glassdoor's India average for SOC analysts sits near ₹5L). With a degree, Security+ and a good lab portfolio you land at the higher end; product companies and GCCs pay more than small MSSPs. | ₹3.5L–₹12L/yr |
| 2–5 yrs | Security Engineer / Analyst II Once you specialise — SIEM engineering, cloud security, network security — pay jumps. upGrad/Glassdoor put cyber security engineers around ₹9–15L; strong performers at product cos and BFSI go higher. Switching jobs here is the biggest single raise. | ₹8L–₹25L/yr |
| 4–8 yrs | Penetration Tester / Specialist Offensive security pays a premium. Indeed's India average for pentesters is ~₹17L, with the upper band (per 6figr) running ₹25L+ and well into ₹50L+ for elite red-teamers with OSCP and a bug-bounty record. Specialisation, not years, drives this. | ₹14L–₹50L/yr |
| 8–12 yrs | Security Architect / Manager Designing security for whole organisations. upGrad/industry data put security architects around ₹27–45L, reaching ₹60L at large BFSI and product companies. Information security managers land in a similar band. | ₹25L–₹60L/yr |
| 12+ yrs | CISO / Head of Security The executive tier. Typical CISO pay runs ₹35–80L, with 75th-percentile and large-enterprise CISOs crossing ₹1 crore (one source puts the 75th percentile near ₹1.07Cr). BFSI and big product companies pay most. | ₹35L–₹1.2Cr+/yr |
Sources differ a lot here (Glassdoor, PayScale, Indeed, 6figr and industry reports rarely agree), so treat these as ranges, not promises. Certifications, specialisation and employer type move pay more than raw years. BFSI, GCCs and product companies pay the most; small managed-security providers the least. Bengaluru leads, with Hyderabad and Mumbai close behind.
Where Indian security pros actually land, by stage. Annual.
Scale: 0 to ₹1.2 Cr per year. Top end is indicative.
Will this still be a great career in 10 years?
Honest answer: this is one of the safest bets in tech — but the entry rung is being reshaped by AI. Here's the data, both sides.
The demand story is unusually strong. India has roughly one million unfilled cybersecurity roles — one of the largest workforce gaps in the world. Fortinet's 2024 survey found 92% of Indian organisationssuffered at least one breach that year, and 98% of IT leaders said they prefer to hire candidates with security credentials. New regulation (the DPDP Act) is forcing companies to invest in security whether they want to or not, and India's cybersecurity market is growing at roughly 14–18% a year.
So why isn't it a guaranteed easy ride? Because the entry tier is changing. Gartner expects AI to drive about half of security incident-response work — and automate more than half of routine Tier-1 SOC tasks — by 2028.That's exactly the alert-triage-and-log-sorting work that juniors traditionally learned on. The field isn't shrinking; the lowest rung is being automated, which means you have to climb past it faster than analysts a few years ago did.
What about AI overall?Gartner and industry researchers frame it as augmentation, not replacement — and attackers use AI too, which only raises the need for skilled defenders. The realistic plan: don't stop at "alert watcher." Learn to use and supervise AI security tools, then specialise (cloud, offence, response, GRC). That's where demand is growing fastest and pay is highest.
- · Cloud security (AWS / Azure / GCP)
- · Penetration testing & red teaming
- · Incident response & forensics (DFIR)
- · GRC, DPDP / privacy & compliance
- · People who supervise AI security tools
- · Pure Tier-1 "watch the dashboard" roles
- · Manual alert triage with no analysis
- · Checkbox-only compliance jobs
- · Roles that never touch cloud
- · Anyone who stops learning after one cert
“AI is automating the night-shift alert queue — not the analyst. It's erasing the bottom rung and raising the pay of everyone who climbs past it.”
What you need to study — and what you don't.
A degree gets you past some HR filters and into campus placements. But in cybersecurity, the certifications and hands-on labs do the heavy lifting — Security+ to start, then CEH or a cloud/offence cert. The degree opens the door; the certs and write-ups get you the job.
Plenty of analysts come from non-CS branches, B.Sc, or self-taught backgrounds — there are well-known stories of people landing SOC jobs with no degree at all. You'll need certifications, a TryHackMe/Hack The Box track record and published CTF write-ups to prove it. Without placements the first job takes longer; the ceiling afterwards is the same.
- An IIT/NIT or top-50 college (skills and certs > brand here)
- A specialised 'cybersecurity degree' — fundamentals + certs work fine
- To be a hardcore coder on day one — but scripting helps you grow
- Expensive bootcamps — most foundations are free on TryHackMe
- Perfect Class 12 marks
What it'll cost you to actually get there.
A laptop + mostly free labs (TryHackMe has a free tier) + the CompTIA Security+ exam (~₹33–36k, plus optional training). One of the cheapest credible routes into tech.
Security+ + CEH (~₹1.5–3L with training) + a cloud cert, or building toward OSCP (₹1–1.5L). Worth it once you know your direction — not all at once.
A BCA/B.Sc/B.Tech alongside certifications. ROI depends on the certs and labs you add, not the degree brand.
Faster than full stack's entry market right now, because demand is higher — but you still need certs plus real lab proof. Studying without hands-on labs is the slow way.
You touch networking, OS, cloud and threats. Not genius-level, but the surface area is wide and you must keep learning. Easier to enter than NEET/UPSC; harder to coast in.
How to become a cybersecurity analyst in India — step by step
The route that actually works for self-taught and career-switching Indians — built for the 2026 market, where the entry rung rewards proof over theory. Adjust pace, not order.
Foundations
Months 0–4- Learn networking: TCP/IP, DNS, HTTP, ports, firewalls. This is non-negotiable.
- Get comfortable in Linux and Windows — command line, users, permissions, logs.
- Work through TryHackMe's 'Pre Security' and 'Cyber Security 101' paths (free).
- Learn core concepts: CIA triad, common attacks, the SOC and SIEM idea.
- Start a habit of writing up everything you learn — your future portfolio.
Get certified + hands-on
Months 4–9- Earn CompTIA Security+ — the standard 'I'm ready for entry' credential in India.
- Go deeper on TryHackMe and start Hack The Box for harder, realistic boxes.
- Learn a SIEM (Splunk or Microsoft Sentinel) — log analysis and alert triage.
- Build a small home lab (a couple of VMs, some Windows/AD, attack-and-defend).
- Publish 3–5 CTF / lab write-ups on Medium or a blog — interviewers read these.
Specialise + prove it
Months 9–14- Pick a direction: blue team / SOC, offence (pentest), or cloud / GRC.
- Add a focused cert — CEH, AZ-500 (Azure), or begin OSCP prep for offence.
- If offence: start a bug-bounty or HackTheBox track record you can show.
- Learn basic Python scripting to automate the boring parts.
- Tighten your portfolio: GitHub, blog, LinkedIn — make your proof easy to find.
Get hired
Months 14–18- Target SOC analyst, security analyst and junior security engineer roles.
- Apply hardest at GCCs, BFSI, IT services and consulting (Big4) — they hire volume.
- Lean on referrals and an active LinkedIn; recruiters DM for security skills.
- Be honest about shifts — many first SOC roles are rotational; take the foot in the door.
- Take the first solid offer. The 2nd job, after you specialise, is the big pay jump.
Which certs are worth it — and which to skip for now.
In cybersecurity, certifications do what a portfolio does for developers: they're how you prove you're ready. But buy them in order, when you need them — not all at once. Costs are indicative and change.
The default entry credential. Vendor-neutral, covers the fundamentals employers expect, and clears a lot of HR filters for your first SOC role. If you do one cert, do this.
Tool- and cloud-specific certs that map directly to SOC and cloud-security jobs. Highly practical, often cheaper than the big names, and increasingly in demand as everything moves to cloud.
CEH is widely recognised by Indian HR; OSCP is the one that earns real respect from practitioners because it's a gruelling hands-on exam. OSCP plus a bug-bounty record is the offensive-security ticket.
Management- and architecture-level credentials that need years of experience to qualify. They correlate with notably higher pay — but they're a year-5+ move, not a starting point. Skip for now.
A cert without hands-on practice is a paper tiger — interviewers can tell in minutes. Pair every certification with lab work and write-ups. The combination is what gets hired.
Where it can take you in 10–12 years.
Two numbers per stage: where most people land, and what the top performers make. The top end is real but specialisation-dependent — don't plan your life around it. Two long-term forks: go deep (architect / principal) or go broad (manager / CISO). Both pay well.
Learn triage, SIEM and incident basics on the job. Often shifts. Don't job-hop yet — earn the fundamentals.
Specialise (cloud, SIEM, network, pentest). Switch jobs once — usually the biggest single raise of your career.
Deep expertise pays. Offensive security, DFIR or cloud security at product/BFSI companies. Reputation starts to matter.
Depth track: design security for whole orgs. Breadth track: lead a security team. Choose your fork here.
Own security strategy at the company level. BFSI and large product companies pay the most. Board-level responsibility.
Six very different lives — all cybersecurity.
MNCs running security teams from India — Deutsche Bank, HSBC, Target, etc. The biggest, most accessible entry point for freshers. Bangalore, Hyderabad, Pune.
Banks, insurers, fintech. Highest stakes, strong pay, heavy compliance (RBI, DPDP). Stable and respected. Mumbai, Bangalore, anywhere.
TCS, Infosys, Wipro, HCL security practices. Easier first job, structured, lower pay, big training pipelines. Anywhere in India.
Deloitte, EY, KPMG, PwC. Advise many clients, fast exposure, GRC and audit-heavy. Good for breadth and a strong CV. Metros.
Product companies and security firms (CrowdStrike, Palo Alto, Indian startups). Build security, not just operate it. Highest skill bar, top pay.
Hunt vulnerabilities for bounties (HackerOne, Bugcrowd) or consult independently. Uncapped upside, unpredictable income, pure skill.
The honest trade-offs.
- · Genuine talent shortage — demand outstrips supply
- · No mandatory degree; certs and skills decide it
- · High ceiling — specialists and CISOs earn a lot
- · Meaningful work — you protect real people and money
- · Recession- and AI-resilient relative to the rest of tech
- · Many specialisations to grow into
- · Globally portable skills
- · Entry SOC roles often run rotating / night shifts
- · Tier-1 work is repetitive — and AI is automating it
- · Alert fatigue and on-call stress are real
- · You must keep learning and renewing certs, forever
- · High accountability when something goes wrong
- · Entry pay is ordinary; the money comes after specialising
- · Broad surface area can feel overwhelming early on
What people get wrong about this career.
You need a degree (or a special cybersecurity degree) to get in.
No degree is mandatory. Employers hire on certifications, lab proof and clear write-ups — there are documented cases of people landing SOC jobs with no degree at all. A degree helps with placements and some HR filters, but it's not the gate.
It's all hooded hackers breaking into systems.
Most cybersecurity work is defensive: watching dashboards, triaging alerts, writing reports, tuning tools, and responding to incidents. Offensive 'hacking' (pentesting) is one specialised — and competitive — corner, not the whole field.
AI will make cybersecurity analysts obsolete.
Gartner expects AI to automate over half of routine Tier-1 SOC tasks by 2028 — but it frames this as augmentation, not replacement. Attackers use AI too, so demand for skilled defenders is rising. The bottom rung shrinks; the field grows.
You'll earn a fortune from day one.
Fresher SOC analysts earn ₹3.5–6L — ordinary tech pay. The big money (₹15–50L+, then architect and CISO bands) comes after you specialise and switch jobs. The ceiling is high; the floor is normal.
Get one certification and you're set.
Certs open doors, but cybersecurity moves fast and employers value continuous learning. A single cert with no hands-on practice rarely survives an interview. It's a career of constant levelling up.
Who actually makes it — and how?
Composite stories drawn from common Indian cybersecurity paths — including the ordinary one, not just the highlights. Names and details changed.
“BCA from a college nobody's heard of. Spent evenings on TryHackMe and got Security+. First SOC job at a GCC on rotating shifts — ₹4.5L. After two years and a cloud cert, moved to a security-engineer role at a bank for ₹14L.”
₹14L by year 3“Non-CS engineering degree, joined an IT-services security practice through campus at ₹4L. Honestly it was a lot of night shifts and ticket-closing for a while. Now grinding certs and write-ups to specialise — that's where I know the jump happens.”
₹4L start, climbing“Started as a SOC analyst, but loved breaking things more than watching them. Did bug bounties on the side, then OSCP. Switched to a pentesting role at a product company. The bounty record mattered more than my degree ever did.”
₹28L as a pentesterOther careers this path also opens.
Most people who start in a SOC don't stay there — and that's the point. These are the natural specialisations your fundamentals, certs and network open up.
If breaking things is more fun than watching dashboards, offensive security is the highest-skill, highest-paid corner. OSCP plus a bug-bounty track record is the usual route in.
Less hands-on-keyboard, more policy, risk and compliance (ISO 27001, DPDP Act, SOC 2). Big4 and BFSI hire heavily; communication matters as much as tech here.
Securing AWS/Azure/GCP is the fastest-growing specialisation. Your security fundamentals plus a cloud cert is a rare, well-paid combination right now.
The people called when something has already gone wrong — forensics, malware analysis, breach containment. Intense, respected, paid for being calm under fire.
Build security into software at product companies — application security, secure SDLC, threat modelling. Coding skills push this toward the top of the band.
Advise many clients instead of guarding one. Big4 and boutique firms hire for breadth; you trade depth for variety and faster exposure to senior rooms.
One concrete action — based on where you are right now.
Doesn't matter what stage. The hardest part is starting; the rest is just continuing.
Make a free TryHackMe account and start the 'Pre Security' path tonight. Learn how the internet actually works — that's the real first step.
Take CS or Informatics if you can, but it's optional. Do one TryHackMe path this holiday and read about one famous cyberattack a week.
Stream doesn't gate this. Start TryHackMe's free 'Cyber Security 101' now — 1 hour a day, 5 days a week. Networking first.
Finish 2–3 TryHackMe paths this year and target CompTIA Security+. Publish your write-ups. Apply for security internships at GCCs and BFSI from year 2.
Block 8–10 hours/week and plan for 9–18 months. Do TryHackMe, get Security+, build a home lab, and use referrals — security's talent shortage works in a switcher's favour.
The shortlist. No fluff.
Hundreds of resources exist. These are the ones working analysts in India actually recommend.
- TryHackMe (free tier)FreeBrowser-based labs, beginner to job-ready
- Hack The BoxFreeHarder, realistic boxes — level up here
- Professor Messer (YouTube)FreeThe free Security+ course everyone uses
- TCM Security (YouTube)FreePractical ethical hacking, India-friendly
- Cybrary / free MOOCsFreeStructured intro courses
- OWASP Top 10FreeThe web-security basics every analyst must know
- CompTIA Security+PaidThe entry credential employers look for
- TCM Security PNPT / coursesPaidAffordable, hands-on pentest path
- TryHackMe / HTB subscriptionsPaidFull learning paths and lab access
- OSCP (later)PaidThe offensive cert that earns real respect
A note to read with your parents.
The honest answers to the questions every Indian parent quietly worries about.
Is it stable?
Among the most stable corners of tech. India has roughly a million unfilled cybersecurity roles, 92% of Indian organisations reported a breach in 2024, and the law now forces companies to invest in security (the DPDP Act). When the rest of tech hiring slows, security usually holds — you protect things that cannot be switched off.
Does it pay well?
Yes, and the ceiling is high. A fresher SOC analyst starts at ₹3.5–6L — similar to other entry tech roles — but specialists pull ahead fast: experienced penetration testers and security engineers reach ₹15–50L, architects ₹25–60L, and a CISO can cross ₹1 crore. Few careers pay this well without a mandatory degree.
Will AI take this job?
AI is changing the entry tier, not erasing the field. Gartner expects AI to drive about half of routine Tier-1 security-operations work by 2028 — alert triage, log sorting — the exact tasks juniors used to cut their teeth on. But every AI tool needs people to tune it, judge real attacks and respond to breaches. Demand for skilled analysts is rising, not falling; the work simply starts at a higher rung.
What about lifestyle?
Mostly desk work. SOC roles often run rotating shifts (including nights) because attacks don't keep office hours — worth knowing going in. Consulting and architect roles are more standard hours but can spike during an incident. Less physically punishing than medicine; more on-call pressure than a 9-to-5 desk job.
What about the 'log kya kahenge?' question
Cybersecurity is an easy one to explain with pride — your child protects banks, hospitals and people's money from criminals. It sits inside the respected 'IT / engineer' bucket most Indian families already value, with a clear public-good story attached.
Cybersecurity analyst in India: quick answers
The questions people actually search — answered straight.
- What does a cybersecurity analyst earn in India?
- A fresher SOC or cybersecurity analyst earns about ₹3.5–6L a year, rising to ₹6–9L with a couple of years and the right certs. Security engineers reach ₹8–25L, penetration testers and specialists ₹14–50L, security architects ₹25–60L, and CISOs ₹35L–1.2Cr+. Pay depends heavily on certifications, specialisation and employer (BFSI and product pay most). All figures are annual.
- Is cybersecurity a good career in India in 2026?
- Yes — it's one of the safer bets in tech. India has roughly a million unfilled cybersecurity roles, demand is driven by relentless attacks and new laws like the DPDP Act, and the market is growing at double digits. AI is automating routine Tier-1 SOC work, so plan to skill up past pure alert-watching, but the overall field is expanding, not shrinking. Expect a 9–18 month runway to the first job.
- Do you need a degree to become a cybersecurity analyst in India?
- No degree is strictly required — employers hire on skills, certifications and hands-on proof, and many analysts come from BCA, B.Sc, non-CS engineering or self-taught backgrounds. A CS/IT degree helps with campus placements and some HR filters, but certs (Security+, CEH) plus lab work on TryHackMe or Hack The Box and a CTF write-up portfolio matter more for the first SOC job.
- What skills does a cybersecurity analyst need in India?
- Networking and operating-system fundamentals first (TCP/IP, Linux, Windows), then a SIEM tool like Splunk or Microsoft Sentinel, log analysis and alert triage, plus basics of cloud (AWS/Azure) security. Add scripting (Python), threat-intelligence literacy and clear incident write-ups. Increasingly, knowing how to use and supervise AI security tools is part of the bar, not a bonus.
Figures on this page were last reviewed on 22 June 2026 by the Path10x Editorial Team. Exam statistics, seat counts and pay scales change every cycle — always confirm against the official notification before acting. Compiled from:
- Glassdoor — Cybersecurity / SOC Analyst salary in India
- upGrad — Cyber Security Salary in India by role & experience (2026)
- Indeed — Penetration tester salary in India
- 6figr — Penetration Testing salaries in India (distribution)
- whatisthesalary — CISO salary in India (percentiles)
- Entrepreneur India — shortage of ~1M cybersecurity professionals in India
- Fortinet — 2024 Cybersecurity Skills Gap Report (92% breached, 98% prefer credentials)
- Gartner — AI to drive 50% of cybersecurity incident response by 2028
- CompTIA Security+ exam cost in India
- OSCP certification cost in India
- TryHackMe — free beginner security training paths
Decided this might be it?
Tell us where you are right now and we'll map the exact steps from there to your first job in security.