Career 9 min read 19 March 2026 IT Compliance Jobs

CISO Salary in the US: What Does a Chief Information Security Officer Earn in 2026?

The Chief Information Security Officer has become one of the most critical and highly compensated executive roles in corporate America. With the frequency and severity of cyber attacks continuing to escalate, and regulatory obligations expanding under SEC disclosure rules, state privacy laws and sector-specific mandates, organizations are investing heavily in security leadership. But what does a CISO actually earn in the United States in 2026?

This guide provides a detailed breakdown of CISO compensation across experience levels, industries and regions, including the equity and RSU packages that make US tech sector CISO roles among the most lucrative in the world. Whether you are pursuing a CISO position or building a competitive offer, these are the numbers you need.

CISO salary overview 2026: from VP-level to Fortune 500

CISO compensation in the US varies substantially based on company size, industry, geography and the scope of the role. The table below presents current base salary ranges derived from 2026 compensation surveys and executive recruiting data.

LevelTypical ContextBase Salary (USD)Total Compensation (USD)
VP of Security / Deputy CISOMid-market, Series B-D startups$180,000 - $230,000$250,000 - $400,000
CISO (mid-market)Companies with 500-5,000 employees$220,000 - $280,000$300,000 - $450,000
CISO (large enterprise)Fortune 1000, major financial institutions$280,000 - $350,000$400,000 - $600,000
CISO (Fortune 500 / Big Tech)Global enterprises, FAANG-level companies$350,000 - $400,000+$600,000 - $1,000,000+

Note: Total compensation includes base salary, annual bonus (typically 20-40% of base), equity/RSU grants and benefits. At the highest levels, equity can represent 40-60% of total compensation.

Fortune 500 versus startup compensation

The structure of CISO compensation differs markedly between established Fortune 500 companies and venture-backed startups. Understanding these differences is essential for anyone evaluating opportunities in the US market.

Fortune 500 and large enterprise

CISOs at Fortune 500 companies receive the highest guaranteed compensation. Base salaries typically range from $300,000 to $400,000 or more, with annual bonuses of 25-40% and RSU packages vesting over three to four years. Benefits include comprehensive healthcare, executive retirement plans, deferred compensation and sometimes company car allowances. The trade-off is a more structured environment with established security programs and larger teams. Board-level reporting is increasingly common, with approximately 60% of Fortune 500 CISOs now reporting directly to the CEO or board.

Startups and growth-stage companies

Startup CISOs may accept lower base salaries in the range of $180,000 to $250,000, but they typically receive significantly larger equity grants. At a pre-IPO company, a CISO might receive stock options or RSUs worth $500,000 to $2,000,000 or more over four years. If the company goes public or is acquired at a high valuation, this equity can dwarf the total compensation available at an established enterprise. The risk, of course, is that equity may end up being worth little or nothing. Startup CISOs also tend to wear more hats, often building the security program from scratch with a small team.

The Silicon Valley premium

Geography continues to play a significant role in CISO compensation, though the widespread adoption of remote and hybrid work has narrowed the gap compared to pre-pandemic levels.

CISOs based in the San Francisco Bay Area and Silicon Valley earn 20-35% more in base salary than the national average. This premium reflects the concentration of technology companies, the intensity of competition for security talent and the high cost of living. New York City commands a similar premium, driven by financial services firms on Wall Street and a growing technology sector. Washington DC and Northern Virginia also offer above-average compensation, fueled by defense contractors, federal agencies and the cybersecurity firms that serve them.

Other technology hubs including Seattle, Austin, Boston and Denver offer competitive salaries that typically fall 5-15% above the national median. The growth of remote-first companies has created opportunities for CISOs to earn near-coastal salaries while living in lower-cost regions, though some companies are adjusting pay bands based on location.

Equity and RSU packages explained

Equity compensation is a defining feature of CISO packages in the US, particularly in the technology sector. Understanding how these packages work is critical for evaluating the true value of an offer.

  • Restricted Stock Units (RSUs): The most common equity vehicle at public companies. RSUs vest over a schedule, typically four years with a one-year cliff. At large tech firms, annual RSU grants for CISOs range from $200,000 to $500,000 or more in value at the time of grant.
  • Stock options: More common at startups, options give the right to purchase shares at a fixed strike price. The value depends entirely on the company's future valuation. Early-stage CISOs may receive options representing 0.1% to 0.5% of the company.
  • Performance-based equity: Some companies tie a portion of equity to performance metrics such as security incident reduction, compliance audit outcomes or overall company targets. This can increase or decrease the actual payout from the initial grant value.
  • Sign-on equity: To attract top CISO talent, companies frequently offer one-time sign-on RSU grants of $100,000 to $300,000 on top of the standard annual equity package.

CISO salary compared with other security leadership roles

To contextualize CISO compensation, the following table compares it with other senior security and compliance roles in the US market.

RoleAverage Base Salary (USD)Difference vs CISO
Chief Information Security Officer (CISO)$220,000 - $350,000-
VP of Information Security$190,000 - $280,000-15% to -20%
Director of Security Engineering$180,000 - $260,000-20% to -25%
Director of IT Compliance / GRC$160,000 - $220,000-25% to -35%
Senior Security Architect$170,000 - $240,000-20% to -30%
IT Risk Director$155,000 - $210,000-30% to -35%

Tips for CISO salary negotiation in the US

Negotiating a CISO package requires a strategic approach that goes beyond base salary. The following recommendations are tailored to the US executive market.

Benchmark with precision: Use data from sources such as Heidrick and Struggles, Korn Ferry, Levels.fyi and the IANS CISO Compensation Survey to establish your market value. Be specific about your comparison set: company size, industry, region and reporting structure all matter.

Negotiate total compensation: In the US market, base salary is often the least flexible component. Focus negotiation energy on equity grants (initial and refresher), sign-on bonuses, annual bonus targets and acceleration clauses in the event of acquisition or termination.

Leverage your certifications: CISSP, CISM and CCISO remain the most valued credentials. Board-level experience and an MBA from a top program can add 15-25% to total compensation. Highlight any public speaking, published research or advisory board positions.

Quantify your track record: Present measurable outcomes from previous roles. Examples include breach cost avoidance, compliance certifications achieved, security program maturity improvements and reduction in mean time to detect and respond to incidents.

Evaluate the full package: Consider factors beyond cash and equity. Executive severance terms, D&O insurance coverage, board reporting structure, team size and budget authority all affect the true value and sustainability of the role.

Looking for a CISO position in the United States?

Browse our complete overview of CISO vacancies and security leadership roles across the US. Find your next opportunity at a Fortune 500 company, high-growth startup or leading technology firm.

Browse Security Vacancies

Frequently asked questions about CISO salary in the US

What is the average CISO salary in the US in 2026?

The average CISO base salary in the US ranges from $180,000 to $280,000 per year. Total compensation including bonuses, equity and benefits can reach $350,000 to $600,000 or more at Fortune 500 companies and major technology firms.

Do CISOs earn more in Silicon Valley than other US regions?

Yes, CISOs in the San Francisco Bay Area and Silicon Valley typically earn 20-35% more in base salary than the national average. However, when adjusted for cost of living, the premium narrows. New York City and Washington DC also command above-average CISO salaries.

What equity packages do CISOs receive at US tech companies?

CISOs at large tech companies typically receive RSU packages worth $200,000 to $500,000 or more per year, vesting over four years. Pre-IPO startups may offer larger equity stakes with higher risk. Equity can represent 30-50% or more of total compensation at technology firms.

How does a Fortune 500 CISO salary compare to a startup CISO?

Fortune 500 CISOs earn higher base salaries ($250,000-$400,000+) with structured bonuses and benefits. Startup CISOs may accept lower base salaries ($180,000-$250,000) in exchange for significant equity stakes that can be worth substantially more if the company succeeds.