The State of Cybersecurity Training in America
The numbers tell a story that career changers and new graduates are starting to notice. The Bureau of Labor Statistics projects a 29% jump in information security analyst roles from 2024 to 2034 — that is more than five times the national average for all occupations. The median salary in the field sits around $124,910, and entry-level professionals coming out of cybersecurity training programs report starting compensation near $83,000. When you add a certification like CompTIA Security+, your earning potential can climb another 12% to 18% compared to peers without it.
But the talent pipeline is not keeping up. ISACA's 2025 State of Cybersecurity Report found that 55% of cybersecurity teams are understaffed and 65% of organizations have unfilled security positions. What makes this particularly strange is that fewer companies are training existing non-security staff to move into these roles. Just 29% of enterprises offered such training in 2025, down from 41% the year before. The message is clear: if you want into this field, you will likely need to drive your own training.
For someone sitting in Columbus, Ohio or Austin, Texas right now, wondering if cybersecurity is a viable pivot, the answer is yes — but the path you pick matters enormously. A mid-career accountant in Phoenix will need a different approach than a 22-year-old computer science graduate in Raleigh. And a military veteran transitioning to civilian life in San Diego has access to resources the other two do not.
Training Paths That Actually Lead to Jobs
There are four broad routes people take into cybersecurity in the US, and they are not mutually exclusive. Many professionals combine two or three of them over time.
Bootcamps have become the most talked-about entry point. They are short, intense, and designed to get you job-ready in 12 to 24 weeks. The average cybersecurity bootcamp costs around $10,636, but the range is wide. Nucamp runs a part-time cybersecurity fundamentals program at the lower end of the spectrum, while Fullstack Academy and similar providers charge more for full-time immersive experiences. Bootcamps typically include certification prep for exams like CompTIA Security+ or Certified Ethical Hacker (CEH), and many offer career services like resume reviews and mock interviews. The downside is pace: if you are juggling a full-time job and family, the 40-plus-hour weekly commitment of a full-time bootcamp may not be realistic.
Certifications are the traditional route and still the most flexible. CompTIA Security+ costs around $392 for the exam and is widely considered the entry-level standard. From there, professionals often pursue the CEH, which runs roughly $1,199 for training and exam, or the CISSP for those with several years of experience under their belt. SANS GIAC certifications are highly respected but come with a steeper price tag — their courses often run into the thousands, though the Paller Cybersecurity Scholarship covers full tuition and certification costs for selected candidates. CISA also offers free training resources for federal, state, and local government IT professionals looking to expand their cybersecurity skills.
University programs — from associate degrees to master's degrees — remain a solid option, especially for those who qualify for federal financial aid or employer tuition reimbursement. Schools designated as Centers of Academic Excellence in Cybersecurity by the NSA, such as California State University San Bernardino, offer curricula aligned with government and industry needs. The catch is time: a bachelor's degree takes four years, and a master's adds another one to two. Bootcamps are 75% to 90% cheaper than a bachelor's degree in the field, which is why they have gained so much traction.
Self-study and community resources round out the picture. Platforms like TryHackMe, Hack The Box, and the MITRE eCTF competition give learners hands-on experience with real-world scenarios. MITRE's embedded Capture the Flag competition runs annually from January to April and is open to high school and college students. It is free to participate and builds both offensive and defensive skills on actual hardware platforms. For those who learn best by doing, these resources are invaluable — and they cost little to nothing.
Training Options at a Glance
| Training Type | Examples | Typical Cost Range | Duration | Best For | Key Limitation |
|---|
| Bootcamp (Part-Time) | Nucamp, Springboard | $2,100–$7,000 | 15–24 weeks | Career changers with jobs | Less depth than full-time |
| Bootcamp (Full-Time) | Fullstack Academy, Flatiron | $12,000–$18,000 | 12–16 weeks | Quick career transition | Intensive time commitment |
| Certification (Entry) | CompTIA Security+ | ~$392 exam fee | 2–4 months self-paced | Beginners, IT generalists | Requires renewal every 3 years |
| Certification (Advanced) | CISSP, CEH, GIAC | $750–$1,200+ exam | 3–6 months prep | Experienced professionals | Experience prerequisites |
| University Degree | CAE-designated schools | Varies widely | 2–4 years | Federal/gov career paths | Longest time investment |
| Free/Community | CISA, TryHackMe, MITRE eCTF | Free to low cost | Self-paced | Skill building, exploration | No formal credential |
Real People, Real Decisions
Consider Marcus, a 34-year-old IT support specialist in Atlanta. He had been resetting passwords and managing help desk tickets for six years and wanted out. He enrolled in a part-time cybersecurity bootcamp through Nucamp, paying around $2,400 over several months while keeping his day job. The program covered network defense, threat analysis, and Security+ exam prep. He passed the certification on his first attempt and landed a junior security analyst role at a healthcare company three months later. His salary jumped from $52,000 to $78,000.
Then there is Priya, a recent graduate from the University of Texas with a degree in information systems. She wanted to work in penetration testing but had no hands-on experience. She spent six months on Hack The Box and TryHackMe, earned her CEH certification, and participated in a local DEF CON group in Austin. A recruiter found her through LinkedIn after she posted a write-up of a vulnerability she discovered in a public bug bounty program. She now works on a red team at a midsize firm.
Military veterans have a particularly strong on-ramp. EC-Council offers free admission to its Hacker Halted and Global CISO Forum events for active-duty service members, veterans, and military spouses. The Federal Cybersecurity Workforce Expansion Act also directs resources toward training programs for transitioning service members. Many bootcamps accept GI Bill benefits, and the SANS Paller Scholarship specifically welcomes veterans into its New to Cyber track, covering all tuition, materials, and GIAC certification exam fees.
Regional Resources Worth Knowing About
Cybersecurity training is not evenly distributed across the country, but you do not need to live in Silicon Valley or the DC metro area to find quality options. Texas has a growing concentration of cybersecurity employers and training providers, particularly in Austin and San Antonio, where the military presence creates steady demand. California remains a hub, with both university programs and bootcamp providers clustered around Los Angeles and the Bay Area. The Southeast — Atlanta, Charlotte, Raleigh — has seen a surge in cybersecurity training programs tied to the banking and healthcare industries.
Community colleges have become an underrated entry point. Many now offer cybersecurity certificates that cost a fraction of university tuition and include internship placements with local employers. The CISA Workforce Training Guide is a free, downloadable resource that maps out career pathways and training options for anyone from absolute beginners to experienced IT professionals transitioning into security.
If you are in a rural area or a smaller city, online programs close the gap. Nucamp, Coursera, and Udemy all offer cybersecurity content that can be accessed from anywhere. The key is ensuring the program you choose includes hands-on labs — employers consistently say that practical experience matters more than any credential on a resume. Scenario-based training, where you respond to simulated ransomware attacks or phishing incidents, has become the benchmark for effective cybersecurity education.
Making a Decision That Sticks
The cybersecurity training landscape rewards people who match their learning style to the right format. If you thrive under structure and deadlines, a bootcamp with live instructors and a cohort-based model might keep you accountable. If you are self-disciplined and budget-conscious, the certification self-study route paired with free online labs can get you there for under $1,000 total. If you have GI Bill benefits or employer tuition reimbursement, a university certificate or degree program removes the financial barrier entirely.
One thing that trips up newcomers is chasing the wrong credential too early. A Security+ certification opens doors for entry-level roles; a CISSP without the required five years of experience is not going to help. Start with the certification that matches where you actually are, not where you hope to be in five years. The field moves fast enough that your training path will evolve — the important thing is to start somewhere with a clear, practical goal tied to a real job title.
The 750,000 unfilled positions are not going to fill themselves. Employers are waiting, and the training options are there. The only remaining variable is which path you choose.