Survey: Raises for security pros decline
Computerworld - Salary increases for security professionals have dropped over the past 18 months, despite the renewed focus on security since the Sept. 11 terrorist attacks, according to a survey released yesterday by the SANS Institute.
Even though they remain among the highest-paid IT workers, security and systems administrators are still affected by the dot-com bust and the overall gloomy economic climate, according to the survey of 1,214 security and systems administration professionals.
The survey, conducted during April and May, found that salary increases for security professionals have declined since December 2000 from 11.6% to 7%. But, according to SANS, a research and education organization, security professionals still get better raises than their colleagues who work in networking and application development.
The average annual salary paid to the security and systems staff surveyed was $69,340. Bonuses paid to security pros last year averaged 14.5% of base salaries, SANS said.
Alan Paller, director of research at Bethesda, Md.-based SANS Institute, said there has been a fundamental shift for a once highly mobile community.
Paller said companies suffering from budget cuts aren't hiring new security personnel and instead are training their current employees in security functions. Therefore, there's been no increase in demand to drive up salaries.
Another recent survey, by Foote Partners LLC, a management consultancy and IT workforce research firm in New Canaan, Conn., found that salaries for corporate security positions increased from the first quarter of 2001 to the first quarter of 2002 by an average of 3.1%, while bonuses increased by an average of 9.5%. (David Foote, president of Foote Partners, is a Computerworld columnist.)
But security pros fared better than other high-tech workers, whose salaries dropped 5.5% on average during that same time period, according to Foote Partners, which interviewed 30,000 IT workers, including 1,245 security pros.
New England, New York and New Jersey reported salaries that were 9% more than the U.S. average, while the West Coast and Mid-Atlantic states reported salary increases of 4% and 3% above the national average, respectively, according to the SANS survey.
Companies that had more than 10,000 employees paid their security and systems administration staff nearly 10% more on average than smaller employers, SANS said. And security and systems administrators overseeing Unix systems reported salaries 25% higher than those who worked mostly with Windows systems.
Read more about Careers in Computerworld's Careers Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Careers White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Careers Webcasts