How many levels do cybersecurity ladders have?
Data collected on
We read 14 cybersecurity ladders that public employers and companies publish for their own staff and counted their levels. The median is 4 levels for cybersecurity professionals who do not manage people, and 3 is the most common count. Every source is linked below, and the data is free to download.
Key findings
- Ladders run from 2 to 7 levels. The median is 4. The most common count is 3, used by 4 of the 14 ladders.
- 5 of the 11 ladders that use job titles have a Senior level. Its median position is step 3 from the bottom.
- 9 ladders publish a separate track for managers. The 6 that say where it starts put it between step 2 and step 5, and the median is step 3.
- In all 3 ladders that have both a Senior level and a placed manager track, management starts at the Senior level or later.
How many levels cybersecurity ladders have
Each bar is the number of ladders with that many levels for cybersecurity professionals who do not manage people.
- 2 levels2 ladders
- 3 levels4 ladders
- 4 levels3 ladders
- 5 levels3 ladders
- 6 levels1 ladder
- 7 levels1 ladder
Which titles the ladders use
The bars cover the 11 ladders whose levels are job titles. The other 3 use grades or scope names instead of job titles, such as “ASD4” or “Independent - grade 7”. One ladder can use several of these words.
- Senior5 of 11
- Lead3 of 11
- Staff2 of 11
- Principal4 of 11
- Architect3 of 11
Each word counts in any letter case and wherever it sits, like “Lead security architect”.
Where the manager track starts
This chart shows the step, counted from the bottom of each ladder, where the first people-manager role sits. It covers the 6 ladders that say where it starts. Of the rest, 3 have a manager track but do not say where it starts and 5 do not say whether they have one.
- Step 21 ladder
- Step 34 ladders
- Step 40 ladders
- Step 51 ladder
Download the data
One row per ladder: its name, who publishes it, the source link, the number of levels, the level names, the manager track and the step it starts at.
Download the CSVAll 14 ladders
| Ladder | Levels | Level names | Manager track |
|---|---|---|---|
| Australian Signals DirectoratePublic employer(read from the Internet Archive copy) | 7 |
| Not stated |
| Dropbox | 5 |
| Separate, from step 2 (level with IC3 Security Engineer) |
| GitLab | 6 |
| Separate, from step 3 (level with Senior Security Engineer) |
| Privy Council Office, Government of CanadaPublic employer(read from the Internet Archive copy) | 2 |
| Separate, above the top level (step 3) |
| Scottish GovernmentPublic employer | 4 |
| Separate, above the top level (step 5) |
| State of ArkansasPublic employer | 2 |
| Separate, above the top level (step 3) |
| State of TexasPublic employer(read from the Internet Archive copy) | 5 |
| Not stated |
| State of WashingtonPublic employer | 3 |
| Separate; start not stated |
| UK Government Digital and Data ProfessionPublic employer | 3 |
| Not stated |
| UK Government Security ProfessionPublic employer(read from the Internet Archive copy) | 3 |
| Not stated |
| University College LondonPublic employer(read from the Internet Archive copy) | 4 |
| Not stated |
| University of IowaPublic employer | 5 |
| Separate, from step 3 (level with Senior IT Security Engineer) |
| University of Wisconsin–MadisonPublic employer | 4 |
| Separate; start not stated |
| Virginia TechPublic employer | 3 |
| Separate; start not stated |
How we did it
We read 14 cybersecurity ladders that their publishers use for their own staff: 2 from companies and 12 from public employers, on their own sites or in documents they publish. We kept only those whose levels we could read as text. We left out templates written by individuals, professional bodies’ standards and ladders only for general IT, audit or physical security teams.
Levels are the steps a cybersecurity professional can climb without managing people, lowest first. Interns and trainees are left out. When a ladder splits one title into numbered steps, each with its own expectations (like “Cybersecurity Analyst I” and “II”), each step counts. Pay bands inside one level do not. A level above both tracks that the ladder does not open to individual contributors is not counted.
The manager track starts where the ladder puts its first people-manager role: the same band or level number, the same row of its table, or the step where it says the tracks split. When that role sits above the top level, it counts as the next step up. When a ladder has a manager track but does not place it, we do not guess.
Title shares only count ladders whose levels are job titles. A level counts as Senior when its title says Senior or Sr., in any letter case and wherever it sits, so “Cyber security analyst senior” counts, but not Senior Staff or Senior Principal. Lead, Staff, Principal and Architect count as whole words in any letter case, so “Lead security architect” counts for both Lead and Architect.
This is a sample of the ladders people chose to publish, mostly from public employers such as governments and public universities, and some are several years old. It shows what public ladders look like, not what every employer does. Where a live page was gone or blocked automated reading, we read the Internet Archive copy, and the table says so.
We store only public facts: how many levels a ladder has, what the levels are called and where the manager track starts. Each ladder belongs to its publisher, so follow the links for the full text. None of them has reviewed or endorsed this study, and Competrace is not affiliated with them.
Spotted a mistake, or a public ladder we missed? Email support@competrace.com with the link, and we will update the data.
See levels with their skills
The study counts levels. To see what each level needs, browse our cybersecurity career path with the skills each level expects, or read what a career ladder is.
Other levels studies
- 35 public laddersRead the study
- 22 public laddersRead the study
- 9 public laddersRead the study
- 2 public laddersRead the study
- 13 public laddersRead the study
- 10 public laddersRead the study
- 22 public laddersRead the study
- 14 public laddersRead the study
- 11 public laddersRead the study
- 7 public laddersRead the study
- 10 public laddersRead the study
- 6 public laddersRead the study
- 9 public laddersRead the study
- 13 public laddersRead the study
- 10 public laddersRead the study