Skip to main content
All levels studies

How many levels do cybersecurity ladders have?

Data collected on

We read 14 cybersecurity ladders that public employers and companies publish for their own staff and counted their levels. The median is 4 levels for cybersecurity professionals who do not manage people, and 3 is the most common count. Every source is linked below, and the data is free to download.

Key findings

  • Ladders run from 2 to 7 levels. The median is 4. The most common count is 3, used by 4 of the 14 ladders.
  • 5 of the 11 ladders that use job titles have a Senior level. Its median position is step 3 from the bottom.
  • 9 ladders publish a separate track for managers. The 6 that say where it starts put it between step 2 and step 5, and the median is step 3.
  • In all 3 ladders that have both a Senior level and a placed manager track, management starts at the Senior level or later.

How many levels cybersecurity ladders have

Each bar is the number of ladders with that many levels for cybersecurity professionals who do not manage people.

  • 2 levels2 ladders
  • 3 levels4 ladders
  • 4 levels3 ladders
  • 5 levels3 ladders
  • 6 levels1 ladder
  • 7 levels1 ladder

Which titles the ladders use

The bars cover the 11 ladders whose levels are job titles. The other 3 use grades or scope names instead of job titles, such as “ASD4” or “Independent - grade 7”. One ladder can use several of these words.

  • Senior5 of 11
  • Lead3 of 11
  • Staff2 of 11
  • Principal4 of 11
  • Architect3 of 11

Each word counts in any letter case and wherever it sits, like “Lead security architect”.

Where the manager track starts

This chart shows the step, counted from the bottom of each ladder, where the first people-manager role sits. It covers the 6 ladders that say where it starts. Of the rest, 3 have a manager track but do not say where it starts and 5 do not say whether they have one.

  • Step 21 ladder
  • Step 34 ladders
  • Step 40 ladders
  • Step 51 ladder

Download the data

One row per ladder: its name, who publishes it, the source link, the number of levels, the level names, the manager track and the step it starts at.

Download the CSV

All 14 ladders

Levels for cybersecurity professionals who do not manage people, lowest first, as each publisher names them.
LadderLevelsLevel namesManager track
Australian Signals DirectoratePublic employer(read from the Internet Archive copy)7
  1. ASD2
  2. ASD3
  3. ASD4
  4. ASD5
  5. ASD6
  6. EL1
  7. EL2
Not stated
Dropbox5
  1. IC2 Security Engineer
  2. IC3 Security Engineer
  3. IC4 Security Engineer
  4. IC5 Staff Security Engineer
  5. IC6 Principal Security Engineer
Separate, from step 2 (level with IC3 Security Engineer)
GitLab6
  1. Associate Security Engineer
  2. Intermediate Security Engineer
  3. Senior Security Engineer
  4. Staff Security Engineer
  5. Principal Security Engineer
  6. Distinguished Security Engineer
Separate, from step 3 (level with Senior Security Engineer)
Privy Council Office, Government of CanadaPublic employer(read from the Internet Archive copy)2
  1. Entry-level
  2. Mid-level
Separate, above the top level (step 3)
Scottish GovernmentPublic employer4
  1. Cyber security analyst associate
  2. Cyber security analyst
  3. Cyber security analyst senior
  4. Cyber security analyst lead
Separate, above the top level (step 5)
State of ArkansasPublic employer2
  1. IT Security Analyst I
  2. IT Security Analyst II
Separate, above the top level (step 3)
State of TexasPublic employer(read from the Internet Archive copy)5
  1. Cybersecurity Analyst I
  2. Cybersecurity Analyst II
  3. Cybersecurity Analyst III
  4. Cybersecurity Analyst IV
  5. Cybersecurity Analyst V
Not stated
State of WashingtonPublic employer3
  1. IT Security - Journey
  2. IT Security - Senior/Specialist
  3. IT Security - Expert
Separate; start not stated
UK Government Digital and Data ProfessionPublic employer3
  1. Security architect
  2. Lead security architect
  3. Principal security architect
Not stated
UK Government Security ProfessionPublic employer(read from the Internet Archive copy)3
  1. Associate
  2. Lead
  3. Principal
Not stated
University College LondonPublic employer(read from the Internet Archive copy)4
  1. Developing/Skilled - grade 6
  2. Independent - grade 7
  3. Advanced - grade 8
  4. Senior - grade 9
Not stated
University of IowaPublic employer5
  1. IT Security Analyst
  2. IT Security Engineer
  3. Senior IT Security Engineer
  4. IT Security Architect
  5. Senior IT Security Architect
Separate, from step 3 (level with Senior IT Security Engineer)
University of Wisconsin–MadisonPublic employer4
  1. Information Security Analyst I
  2. Information Security Analyst II
  3. Information Security Analyst III
  4. Information Security Analyst IV (MSN)
Separate; start not stated
Virginia TechPublic employer3
  1. Analyst, IT Security
  2. Senior Analyst, IT Security
  3. Architect, IT Security
Separate; start not stated

How we did it

We read 14 cybersecurity ladders that their publishers use for their own staff: 2 from companies and 12 from public employers, on their own sites or in documents they publish. We kept only those whose levels we could read as text. We left out templates written by individuals, professional bodies’ standards and ladders only for general IT, audit or physical security teams.

Levels are the steps a cybersecurity professional can climb without managing people, lowest first. Interns and trainees are left out. When a ladder splits one title into numbered steps, each with its own expectations (like “Cybersecurity Analyst I” and “II”), each step counts. Pay bands inside one level do not. A level above both tracks that the ladder does not open to individual contributors is not counted.

The manager track starts where the ladder puts its first people-manager role: the same band or level number, the same row of its table, or the step where it says the tracks split. When that role sits above the top level, it counts as the next step up. When a ladder has a manager track but does not place it, we do not guess.

Title shares only count ladders whose levels are job titles. A level counts as Senior when its title says Senior or Sr., in any letter case and wherever it sits, so “Cyber security analyst senior” counts, but not Senior Staff or Senior Principal. Lead, Staff, Principal and Architect count as whole words in any letter case, so “Lead security architect” counts for both Lead and Architect.

This is a sample of the ladders people chose to publish, mostly from public employers such as governments and public universities, and some are several years old. It shows what public ladders look like, not what every employer does. Where a live page was gone or blocked automated reading, we read the Internet Archive copy, and the table says so.

We store only public facts: how many levels a ladder has, what the levels are called and where the manager track starts. Each ladder belongs to its publisher, so follow the links for the full text. None of them has reviewed or endorsed this study, and Competrace is not affiliated with them.

Spotted a mistake, or a public ladder we missed? Email support@competrace.com with the link, and we will update the data.

The study counts levels. To see what each level needs, browse our cybersecurity career path with the skills each level expects, or read what a career ladder is.

Other levels studies