Zorky CRMZorky CRM
EN|RU
@ekaterinovikova

Security in IT — CIS and Europe market

Security Engineer (information security engineer) — the specialist who protects a company's products and infrastructure from attacks: designing secure architectures, finding vulnerabilities, monitoring incidents, responding to threats, compliance. The role family: Application Security (AppSec) — code and application security, DevSecOps — security of CI/CD pipelines, Cloud Security — AWS/GCP/Azure defence, Penetration Tester / Red Team — ethical hacking, SOC Analyst — 24/7 incident monitoring, IAM Engineer — access management, Network Security. Core stack — Burp Suite, OWASP (Top 10, ZAP, Dependency-Check), SAST/DAST (SonarQube, Checkmarx, Snyk), SIEM (Splunk, ELK), Kali Linux, Metasploit, Wireshark, Python for scripts. According to Zorky CRM, 645 active openings are open for Security engineers with a median salary of $7140/mo. 89% remote. Active employers — Sber, Tinkoff, Kaspersky, Group-IB, Positive Technologies, Yandex, plus international teams Revolut, GitLab, Cloudflare.

Updated: 5/29/2026, 9:07:01 PM

Security is one of the core roles on IT teams. Over the last 3 months of observation across our 1000+ CIS and European sources this direction accounts for a significant slice of open IT jobs: 645 active positions as of the latest data refresh. Charts below render across the full available data window; text figures in the hero — the last quarter. On salary: median across the whole specialisation — $7 140/mo. Senior earns roughly 1.7× more than Junior — one of the most stable compensation gradients in IT. Security — one of the most remote-friendly IT specialisations: 89% of open positions are remote. There are 8 sub-specialisations inside this direction — a detailed breakdown of each follows below on this page.

Open over 3 months
645
live positions
Median / month
$7,140
Remote
89%
Top stack
go
171 jobs

Sub-specializations

Security breaks down into 8 sub-specialisations: Security Engineer (general), Application Security (AppSec — code security), DevSecOps (security in CI/CD), Cloud Security (AWS/GCP/Azure), IAM Engineer (access management), Penetration Tester / Red Team (ethical hacking), SOC Analyst (24/7 monitoring), Network Security. Each niche has its own salary range — click a card for detail.

Click to see detailed analytics.

Security Engineer (general)
379 jobs
~$7,980/mo
Application Security (AppSec)
94 jobs
~$12,799/mo
DevSecOps
74 jobs
~$6,125/mo
Cloud Security
37 jobs
~$7,980/mo
Penetration Tester / Red Team
11 jobs
~$4,528/mo
Network Security
11 jobs
~$6,930/mo
IAM Engineer
4 jobs
SOC Analyst
3 jobs

Demand trend

Over recent weeks the Security direction has produced a steady flow of new openings. Fluctuations are normal (postings cluster at the start of the month) — look at the overall trend.

How many new jobs appear each week.

Seniority distribution — trend

How the share of Junior/Middle/Senior/Lead in open jobs shifts week over week. A trend toward Senior usually signals a mature specialization where companies look for ready-made talent; the opposite — a rise in Junior — signals expansion and ground-up team building.

Share of each level in % of all jobs with a stated grade per week.

Salary by level

Security Engineer salary ladder: Junior $4000/mo, Middle $4500/mo, Senior $6750/mo, Lead $10656/mo. Junior openings are scarce — the market expects either a technical background or specialised certifications (OSCP, CISSP).

Median salary (USD/month) at each grade plus the jump vs the previous one.

LevelMedian $/moJump vs prev.Jobs with salary
Junior$4,0005
Middle$4,500+12.5%23
Senior$6,750+50%137
Lead$10,656+57.9%21

Biggest salary jump — between Senior and Lead (+57.9%).

Salary distribution — trend

The median Security salary on the market is $7140/mo. Most active jobs sit in the $4,000-9,000 band — the main mid-Senior segment. The $10K+ band is Senior AppSec/Cloud at international companies, Security Architect, Lead.

What share of jobs each price band holds week over week.

65% of jobs are in the $5–8K range (the core market). High-end $8K+ segment: 23% — usually US-remote or senior-international roles.

Hiring geography

The leader by Security job count is 🇵🇱 Poland (170 positions), followed by the major IT hubs of CIS and Eastern Europe. Russia — a strong market thanks to security vendors (Kaspersky, Group-IB, Positive Technologies).

Job distribution by country.

These numbers reflect the distribution across the sources we parse. Poland often looks dominant because of dense NoFluffJobs / JustJoin.it / Pracuj coverage — the Polish IT market is genuinely large, but in our sample its share is overweighted relative to the real volume of all IT jobs in the region. Same caveat for other top countries: this is «where our parsers look», not «the true size of the market».

Remote / Hybrid / Office — trend

89% of Security jobs are full-remote. Lower than Backend/DevOps, because banks require hybrid due to compliance and production-system access.

How the share of each work format shifts week over week.

89% — remote. Specialisation is well-adapted to remote format.

Top in-demand technologies

Top Security Engineer stack 2026 — Burp Suite, OWASP, Python, Linux, SIEM (Splunk/ELK). Pen-Test adds Kali Linux + Metasploit, AppSec — SAST/DAST (Snyk/Semgrep), Cloud Security — AWS Security Hub / GCP SCC.

go
171
171
rust
86
86
devsecops
81
81
visio
62
62
azure
60
60
databricks
57
57
aws
46
46
kubernetes
42
42
python
40
40
scala
20
20

Technology combinations

The most common tech pairs in Security jobs: Burp Suite + OWASP, Snyk + SonarQube, Splunk + ELK, Kali + Metasploit, Vault + Kubernetes. If you're planning a learning roadmap — these combinations give maximum market coverage.

Which pairs of technologies appear together most often in a single job.

databricks + rust
32
32
devsecops + go
30
30
devsecops + python
27
27
go + rust
23
23
rust + visio
23
23
databricks + visio
23
23
go + kubernetes
21
21
devsecops + golang
19
19
go + golang
19
19
golang + kubernetes
19
19
devsecops + kubernetes
19
19
aws + gcp
18
18

Where we see these jobs

Security jobs surface across most major sources: web parsers (HH, Habr Career, Djinni, DOU, NoFluffJobs, JustJoin.it) provide the bulk of the volume. Telegram channels add an exclusive stream — Bug Bounty offers, niche Pen-Test jobs, security conferences.

Telegram channels
2%
13
Job boards and websites
98%
632

Security vs other directions

Security is one of the highest-paid IT specialisations by median thanks to criticality and the scarcity of specialists. Click any direction's bar for a detailed comparison.

Volume of open jobs across IT directions.

Backend
4,867
Full-stack
3,372
Data Engineer
2,380
Sales
1,937
DevOps / SRE
1,816
AI / ML / DS
1,638
QA / Testing
1,593
Architecture
1,457
Frontend
1,070

Latest jobs

Latest open Security jobs — the most recent 10 positions with adequate description quality. The full list is available in our CRM or via the "see all" link below.

Senior Application Security Engineer : Reston, VA
Reston · ~$14765/мес · today
gorestsolid
Junior AI Security Engineer
~$4000/мес · today
DevSecOps Engineer
~$6510/мес · today
devsecops
Senior DevSecOps Engineer [M/F]
~$7140/мес · today
devsecopspython
Cyber Security Engineer
~$6375/мес · today
Consultant – Cyber Security Engineering
~$10656/мес · today
azure
Principal Cybersecurity Engineer
Reston · ~$19835/мес · today
Security Engineer
Johns Creek · ~$14114/мес · today
scala
Senior Security Engineer
~$4875/мес · today
SailPoint Security Architect
Bangalore · today
go
See all 645 jobs →

Key takeaways

  • Demand is real: 645 Security jobs opened over the last 3 months — not a theoretical market live positions with active hiring.
  • Salary anchor: median $7 140/mo. Senior earns noticeably more than Junior — compensation gradient is substantial.
  • Remote-friendly: 89% of positions are remote. You can work from any country in the region without relocating.
  • Top technology: go with 171 jobs — if you're just starting in Security begin there.

If you plan to grow in Security or hire a team — these numbers give a hands-on slice of the market. To watch in real time or get alerts on new jobs matching specific parameters — that's our CRM product for recruitment agencies and in-house teams.

What we can offer

If you work with Security jobs or you're in this role yourself — we can close a specific task. Pick a format, leave a contact — we reply within 24 hours.

CRM for recruiters
We onboard you onto our CRM. Upload a Security job — get a list of matching candidates with full contact data within your plan limits. Auto-matching plus explainability. Per-month contact limits are configurable.
Candidate access
Are you a candidate looking for Security work? Buy direct access to employer contact data — N views per month. No middlemen: message the hiring manager directly.
Talent Supply Audit
We'll show how many Security specialists are realistically available for your job: by level, geo, format, budget. An honest answer instead of "we have 100 million resumes".
Custom analytics
A personalized quarterly market report on your ICP — salary benchmarks, talent supply, competitor hiring activity. PDF plus raw data.
Are you a candidate looking for work?Upload resume →

Frequently asked questions

The most common questions about the Security market: pay by level, stack (Burp/OWASP/SIEM), AppSec vs DevSecOps vs Pen-Tester vs SOC, remote, how to start a career, Senior skills. Answers recompute automatically from current data.

How much does a Security Engineer earn in 2026?

The median Security Engineer salary across CIS and Europe is $7140/mo per Zorky CRM data (645 active jobs). Pay depends on level and specialisation: Junior around $4000/mo, Middle $4500/mo, Senior $6750/mo, Lead $10656/mo. Security is one of the top-3 highest-paid IT specialisations thanks to criticality and the scarcity of specialists. Senior AppSec and DevSecOps at large banks (Sber, Tinkoff, Alfa) and fintech — $7,000-12,000/mo. Penetration Tester with OSCP certification — $6,500-11,000/mo. In international teams (Cloudflare, GitLab, Revolut, HackerOne, Bug Bounty Hunter freelance) — $9,000-18,000+ for Senior.

What does a Security Junior, Middle, Senior, or Lead earn?

Security Engineer salary ladder (median USD/mo): Junior $4000, Middle $4500, Senior $6750, Lead $10656. Junior Security openings are scarce — the market expects either a technical background (Backend/DevOps → AppSec/DevSecOps) or a specialised degree + certifications. The most accessible entry points: SOC Analyst Tier 1 (incident monitoring) and Junior Pen-Tester (after OSCP). The strongest pay jump is between Middle and Senior at specialisation (AppSec / Cloud / Pen-Test). Lead Security = Security Architect or Head of Security, in front of C-level (CISO). Career flow: SOC Analyst → AppSec/Cloud Security → Senior → Security Architect → CISO.

How much do Security Engineers earn in Moscow and St Petersburg?

In Moscow and St Petersburg Security Engineers get close to the market median — $7140/mo. Moscow traditionally pays more thanks to large banks (Sber, Tinkoff, Alfa, VTB), Kaspersky, Group-IB, Positive Technologies, Yandex Security. St Petersburg — close thanks to Kaspersky Lab, Positive Technologies, JetBrains. Remote is partial: 89% of jobs are full-remote, but banks require hybrid because of compliance and production-system access. In Poland (Warsaw, Krakow) Security Senior — $5,500-10,000/mo. Berlin and Prague — €6,000-10,500. Almaty — $3,000-6,500. International remote (Cloudflare, GitLab, Revolut, HackerOne) — $8,000-15,000+ for Senior. Bug Bounty freelance — $50K-300K+/yr for top reporters.

What stack does a Security Engineer most often need?

Top 5 technologies in Security jobs: go, rust, devsecops, visio, azure. Mandatory basics: OWASP Top 10 (must-know), Linux (advanced), Python and Bash for automation, Git. Web security: Burp Suite (the pen-test standard), OWASP ZAP, OWASP Dependency-Check. SAST/DAST: SonarQube, Checkmarx, Snyk, Semgrep. SIEM: Splunk, ELK (Elasticsearch + Logstash + Kibana), QRadar. Pen-test: Kali Linux, Metasploit, Nmap, Wireshark. Cloud security: AWS Security Hub, GCP Security Command Center, Azure Sentinel. IAM: HashiCorp Vault, Keycloak. Certifications: OSCP (offensive), CISSP (managerial), OSCE, CEH, AWS Security Specialty.

How is AppSec different from DevSecOps, Pen-Tester, and SOC Analyst?

AppSec (Application Security) — code and application security, code review, SAST/DAST, threat modeling, OWASP. Works inside a product team. DevSecOps — embeds security into CI/CD pipelines, secrets management, container scanning, GitOps. Close to DevOps + security. Pen-Tester / Red Team — ethical hacking, attack simulation, hunting 0-day vulnerabilities, OSCP/OSCE certifications. More often consulting or specialised companies (Positive Technologies, Group-IB). SOC Analyst (Security Operations Center) — 24/7 incident monitoring, triage, response, working with SIEM (Splunk/QRadar). By pay: AppSec ≈ DevSecOps > Pen-Tester ≈ Cloud Security > SOC Analyst. Career flow: SOC Tier 1 → Tier 2 → AppSec/Cloud → Senior → Security Architect.

Can Security Engineers work remotely?

Partially: 89% of Security jobs are full-remote. Lower than Backend/DevOps, because banks and fintech (Sber, Tinkoff, Alfa) require hybrid or office due to compliance — work with PII, payment data, production access. Local security vendors (Kaspersky, Positive Technologies, Group-IB) — more often hybrid. International product teams (Cloudflare, GitLab, Revolut, HackerOne) — almost always remote. Pen-Tester freelance (Bug Bounty on HackerOne/Bugcrowd) — fully remote, flexible schedule, ceiling depends only on skill. SOC Analyst — many remote jobs (often shift work). Cloud Security — typically remote (everything through AWS/GCP console).

How is Security Engineer different from DevOps?

DevOps owns the infrastructure and CI/CD — automation, observability, production reliability. Security Engineer owns defence: vulnerability hunting, threat modeling, incident management, compliance. The stack overlaps (Linux, Docker, Kubernetes, cloud) but the focus differs. DevSecOps — the hybrid: a DevOps engineer with security specialisation who embeds SAST/DAST/secrets-scanning into pipelines. By pay Security typically pays 10-20% above DevOps for the specialisation and scarcity. Career flow: Senior Backend → DevOps → DevSecOps; or a separate Security track (SOC → AppSec → Senior Security). Seniors can converge into Security Architect — the top level.

Which companies actively hire Security Engineers?

The top Security employers across CIS and Europe: Kaspersky, Group-IB, Sber — large banks, security vendors and fintech. Kaspersky, Group-IB, Positive Technologies, Solar, Servicepipe — Russian security vendors with large AppSec, Pen-Test, Research teams. Banks (Sber, Tinkoff, Alfa, VTB) and marketplaces (OZON, Wildberries, Avito) keep their own Security Operations Centers (SOC). Yandex Security and VK Security also actively hire AppSec/Cloud Security. On the international side — Cloudflare, GitLab, Revolut, JetBrains, HackerOne (Bug Bounty platform), Snyk (DevSecOps) hire Senior on remote with pay above the local market. The full list is in the "Top companies" section above.

Where to start to become a Security Engineer in 2026?

There's no direct path into Security — usually an evolution from an adjacent role. The two most common entry points: 1) Backend / DevOps Middle (2-3 years) → move into AppSec/DevSecOps by picking up OWASP Top 10, SAST/DAST, threat modeling. 2) SOC Analyst Tier 1 (junior-friendly, shift monitoring) → Tier 2 → specialisation. Pet projects: HackTheBox, TryHackMe (CTF platforms for practising skills), OverTheWire, contributions to open-source security tools. Certifications: OSCP (Offensive Security Certified Professional — must-have for Pen-Test), CISSP (managerial track), AWS Security Specialty, CKS (Kubernetes Security). Books: "The Web Application Hacker's Handbook" (Dafydd Stuttard), "Black Hat Python", "Threat Modeling" (Adam Shostack).

How many Security Engineer jobs are open across CIS and Europe?

As of the latest data refresh, the Zorky CRM sample contains 645 active open Security positions across CIS and Eastern Europe. These are postings published in the last 90 days — companies actually hiring. Geography is distributed; the leaders are 🇵🇱 Poland, 🇷🇺 Russia, 🇺🇦 Ukraine. Data is collected from 1000+ sources: Telegram channels (especially for niche Pen-Test and Bug Bounty jobs, security conferences, anti-leak communities), specialised job sites (HH, Habr Career, Djinni, DOU, NoFluffJobs, JustJoin.it, Pracuj.pl), career pages of security vendors. Security is a niche area, so the job volume is smaller than Backend/Frontend, but one of the highest-paid.

Where do Security Engineers earn more — in Russia or in Europe?

Russia and Poland are close in absolute terms for Senior AppSec/DevSecOps ($6,000-10,000/mo median). Germany and Czechia are a bit higher (€6,000-10,500). The main driver is contract currency and specialisation. Pen-Test and Cloud Security usually pay a premium (+20-30% over the median). International remote jobs (Cloudflare, GitLab, Revolut, HackerOne, Snyk, US startups on Wellfound) pay $8,000-15,000+/mo for Senior regardless of country of residence. Bug Bounty freelance — a separate economy: top reporters on HackerOne and Bugcrowd earn $100K-500K+/yr through bounty programmes from Apple, Google, Meta, Microsoft. Local Russian banks (Sber, Tinkoff) on rouble contracts have closed the gap to the Polish market over 2 years for Senior. Kazakhstan — a growing hub at $3,000-6,500.

What skills does a Senior Security Engineer need in 2026?

A Senior Security engineer owns the full defence stack in one of the specialisations (AppSec / DevSecOps / Cloud Security / Pen-Test). Basics: OWASP Top 10, Linux (advanced), Python + Bash, Git. Understanding of the development stack (pick one: Backend or Frontend at Senior level). For AppSec: SAST/DAST (SonarQube, Checkmarx, Snyk, Semgrep), Burp Suite advanced, OWASP ZAP, secure code review, threat modeling (STRIDE, PASTA). For DevSecOps: secrets management (HashiCorp Vault), container scanning (Trivy, Snyk), GitOps. For Cloud Security: AWS Security Hub / GCP SCC / Azure Sentinel, IAM at the policy level, compliance (SOC 2, ISO 27001, GDPR). Certifications (OSCP/CISSP/AWS Security/CKS), experience with incident management, leadership.

Similar specializations

DevOps / SREBackendArchitecture

Methodology

  • Data period: in the hero and copy — the last 3 months. In the charts — the full available observation period (since parsers were launched, usually 2-3 months).
  • Data is collected automatically from 1000+ sources — Telegram channels and job boards across CIS and Europe.
  • Only live open jobs with a clear description are counted. Spam and duplicates are filtered out.
  • Salaries are converted to USD/month at the current rate. Outlier values (
    lt;500 or
    gt;50K) are filtered out.
  • Levels are normalized: Mid → Middle, Intern/Trainee → Junior, Principal/Staff/Expert → Lead.
  • The first 2 weeks of data (parser ramp-up period) are not shown in the charts.
  • Data is recomputed every day.

Authorship and citation

Analytics prepared by Zorky Research Team. Last updated: May 29, 2026 at 9:07 PM.

Data sources and methodology

Data is collected automatically from 1000+ sources — Telegram job channels and job boards across CIS and Eastern Europe (HH, Habr Career, Djinni, DOU, NoFluffJobs, JustJoin.it, Pracuj.pl and others). Parsing runs 24/7, duplicates are filtered by description and URL, salary outliers are stripped. Detailed methodology — on the "How it works" page.

Cite this page:
Zorky CRM (2026). Security in IT: CIS and Europe market. Accessed: 5/29/2026. URL: https://zorky.tech/en/research/security
Data collected automatically from 1000+ sources • Source: Zorky CRM