SalesCareer GuideGo-to-Market

How to Get Into Cybersecurity Sales in 2026 (Without a Security Background)

IJB

InfoSec Job Board

August 19, 2026 · 12 min read

TL;DR: cybersecurity has a hiring shortage everyone talks about and a go-to-market machine almost nobody writes about. On this board there are 3,161 live sales and go-to-market roles at security vendors, measured on 19 August 2026 - several times the size of our security-classified technical board. Most of them do not require a security background, several of them pay more than the engineering roles at the same company, and the entry rung hires explicitly for potential. This is the honest guide to what those jobs are, what they actually pay, and the four routes people really take in.

What "cybersecurity sales" actually means

It is not one job. A security vendor's revenue organisation is ten distinct functions, and they hire for very different things. Here is the whole map, with the live inventory we were tracking on 19 August 2026:

  • Account Executive (1,012 live roles). The closer. Owns the full cycle from first conversation to signature. The highest-earning individual-contributor seat in the industry.
  • Account Manager (473). Owns the customers the vendor already has: renewal, expansion, and being the person a security team calls when the product has to stretch. Named, territory, enterprise and technical account management all live here.
  • Sales Engineer (384) and Solutions Engineer (266). The technical half of the deal. Demos, proofs-of-concept, and the architecture conversation that decides whether a security team trusts the product.
  • Sales management and leadership (382). Managers, Directors, regional and enterprise leaders, VPs of Sales and CROs. They own the number and, increasingly, a board seat at the table.
  • SDR and BDR (312). The entry rung. Prospecting, qualifying, and booking meetings for the AEs.
  • Channel and Partner (157). Revenue through resellers, MSSPs and technology alliances rather than direct deals. A large share of security spend flows through this route.
  • Solutions Architect (135). The most technical seat on a revenue team: reference architectures, migration paths, and how the product fits the rest of a customer's stack.
  • Sales Operations and Enablement (79). Territory and quota design, forecasting, CRM, and the training that makes reps productive. Mostly salaried rather than commission-heavy.
  • Renewals (71). Protecting recurring revenue. Security software is overwhelmingly subscription-based, so this is a permanent, quota-carrying function at every vendor.

Two things fall out of that list immediately. First, the revenue organisation at a security vendor is bigger than its security-engineering organisation. Second, only two of the ten families genuinely require you to know security before you arrive.

The part nobody tells career-changers: you do not need a security background

The single most common reason people rule themselves out of this industry is that they have no security credentials and assume every door is gated behind one. For go-to-market work that assumption is simply wrong, and it is worth being precise about where the line actually falls.

Roles that do not require a security background: SDR and BDR, Account Executive, Account Manager, renewals, channel and partner, sales operations and enablement, and most sales management. These hire for sales skill, coachability, process discipline and resilience. Vendors expect to teach you the domain, because they have to teach it to every new hire anyway - the product changes faster than any curriculum.

Roles that do require real technical depth: Sales Engineer, Solutions Engineer and Solutions Architect. You will stand in front of a security team, demo a product, and be asked hard questions live. You do not need to have been a penetration tester, but you need to hold a credible conversation about identity, cloud, networking or detection, depending on what the vendor sells.

That split is also the reason this is one of the most accessible high-earning paths into cybersecurity. If you are weighing it against the technical route, our guide to getting into cybersecurity covers the practitioner side, and it is honest about how much harder the entry-level squeeze is over there.

What the money actually looks like

Sales pay is base plus commission, quoted as OTE (on-target earnings): the number you make if you hit quota exactly. Miss quota and you earn less than the headline; beat it and, in most plans, you earn more.

The honest caveat first. Only about 12% of the live go-to-market roles we track publish a salary range (369 of 3,161 on 19 August 2026). That is too thin, and too skewed toward the US and toward the companies that disclose by policy, for us to publish a defensible median. So instead of inventing one, here are real bands exactly as they appeared on live postings that day:

  • Cloudflare, Senior Named Account Executive: $269,000 - $360,000
  • Opal, Enterprise Account Executive: $250,000 - $350,000
  • Saviynt, Named Enterprise Account Executive (San Francisco): $170,000 - $185,000
  • JFrog, Enterprise Account Executive (New Logo): $140,000 - $160,000
  • Coalfire, Account Executive (Compliance Sales): $88,000 - $150,000
  • HackerOne, Senior Account Executive, EMEA Commercial: £65,000 - £79,000

Note that postings are not consistent about whether a published band is base or OTE, so read each one carefully before comparing them. As a rough market picture, and this is observation of how these roles are commonly advertised rather than data we measured: enterprise AE seats commonly carry $200,000 or more OTE at scale, Sales Engineering and Solutions Architecture sit around $180,000 to $330,000, and SDR and BDR entry seats sit nearer $60,000 to $100,000. Leadership goes considerably higher.

One structural point that matters more in sales than in any other job: because so much of the package is variable, tax treatment moves your take-home a long way. A tax-free Gulf package can beat a bigger headline number elsewhere. Our take-home pay calculator compares two offers after tax, and the Saudi Arabia and UAE sales pages exist because the Gulf is, for the vendors we track, a go-to-market market far more than a practitioner one.

The four routes people actually take in

1. Start at the bottom rung: SDR or BDR

This is the designed entrance, and it is the only go-to-market role that hires deliberately for potential rather than track record. You will spend a year prospecting and booking meetings, you will be measured weekly, and if you are good the promotion path to Account Executive is well-worn and fast. There are 312 of these roles live right now. If you are changing careers with no sales history at all, this is the highest-probability door.

2. Come across from SaaS sales in another vertical

If you already sell software, you already have the transferable half. What you are missing is the buyer and the category map, and both are learnable in weeks rather than years. Vendors hire proven closers from adjacent verticals constantly, and the pay step up into security is usually real, because security budgets are large and defensible.

3. Come across from security engineering into pre-sales

Sales Engineer, Solutions Engineer and Solutions Architect are the natural landing spots for practitioners who want commission upside without abandoning the technical work. You already have the credibility that takes a career-changer years to build. What you are adding is discovery, storytelling and comfort with a room. Many security engineers find that the pre-sales seat pays better than the operations seat they left, and our security engineering board is the honest comparison point if you are weighing the two.

4. Come across from support or customer success into renewals or account management

The most underrated route. If you have spent two years supporting a security product, you already know the product, the customers and the failure modes. Renewals and account management are where that knowledge converts into a quota-carrying, commission-earning seat, and hiring managers actively look for it. There are 544 renewals and account management roles live between the two families.

What to learn in your first 90 days

You do not need certifications for most of these roles. You do need to stop sounding like an outsider, and that is a much smaller job than it looks:

  • Learn the buyer. Who signs, who blocks, and who lives with the consequences. A CISO buys risk reduction, a security engineering manager buys fewer alerts at 2am, and a compliance lead buys an auditor going away. They are three different conversations.
  • Learn the category map. Endpoint, identity, cloud security, application security, detection and response, governance and compliance. You need to know roughly what each does and who the big names are. Our company directory is a fast way to build that map, since it groups vendors by sector.
  • Learn the buying cycle. Security purchases are slow, committee-driven, and frequently tied to an audit, a breach, a renewal date or a compliance deadline. If you sell like it is a self-serve SaaS tool you will lose.
  • Learn enough of the language to be credible. Not to bluff - security buyers detect bluffing instantly and it is fatal. Enough to know what you do not know, and to bring the Sales Engineer in at the right moment.

Where the jobs actually are

Remote: 929 of the 3,161 roles, about 29%, are fully remote. Cyber sales went remote-first ahead of most of tech, for the simple reason that the buyer is on a video call either way. Browse remote cybersecurity sales jobs if location is your constraint.

Employers: the deepest go-to-market benches on the board on 19 August 2026 were Zscaler (235 open GTM roles), Palo Alto Networks (144), Cloudflare (129), Netskope (122), CrowdStrike (106), Okta (99), Cyera (98) and Wiz (95). The larger platform vendors hire continuously across every one of the ten families.

Geography: the United States dominates, followed by the UK, Germany, Japan, India, Australia and Singapore. One counter-intuitive finding worth knowing if you are job-hunting in Europe or the Middle East: when a security vendor enters a region it staffs go-to-market first, often years before it opens a local engineering team. That is why Saudi Arabia and the UAE have real sales inventory and almost no practitioner inventory, and why markets like Ireland and Italy carry more GTM roles than their technical hiring would suggest. Israel is the mirror image: it is one of the largest security-engineering markets we track, but its vendors sell from the United States, so only 8 of its live roles are go-to-market.

How to run the search

  1. Start from the family that matches your background, not from the company. Use the cybersecurity sales hub and pick the sub-page for your route in.
  2. Apply directly. Every listing here links to the employer's own application page. In sales especially, an application that arrives through a recruiter adds a fee to your hire and a reason to pass on you.
  3. Ask about the plan before you ask about the base. Quota size, ramp period, territory definition, accelerators over quota, and how many reps hit quota last year. That last question tells you more than the OTE does.
  4. Set an alert. Go-to-market reqs open and fill faster than technical ones, so the roles you want are frequently gone in a fortnight.

Frequently asked questions

Do you need a cybersecurity background to work in cybersecurity sales?

For most of the roles, no. Account Executives, Account Managers, SDRs and BDRs, renewals specialists and sales operations hire for sales skill, coachability and process discipline, not for a security certification. The two families that genuinely need technical depth are Sales Engineering and Solutions Architecture, where you have to demo the product and answer a security team's hard questions live. Everyone else learns the domain on the job, and the vendors expect to teach it, which is why go-to-market is one of the most accessible entry points into the cybersecurity industry.

How much do cybersecurity sales jobs pay?

Pay is base plus commission, quoted as OTE. Only about 12% of the live go-to-market roles we track publish a range, so treat any single figure with care. Among the ones that do disclose, real bands observed on 19 August 2026 include a Cloudflare Senior Named Account Executive at $269,000 to $360,000, an Opal Enterprise Account Executive at $250,000 to $350,000, a Saviynt Named Enterprise Account Executive at $170,000 to $185,000, and a Coalfire compliance-sales Account Executive at $88,000 to $150,000. The pattern is that enterprise closing roles pay the most, entry-level SDR seats pay the least, and the technical pre-sales roles sit in between.

What is the easiest way into cybersecurity sales?

The SDR or BDR seat. It is the designed entry rung: you prospect, qualify and book meetings for the Account Executives, no security background is required, and it is the one go-to-market role that hires deliberately for potential rather than experience. We track 312 live SDR and BDR roles. The other three realistic routes in are a lateral move from SaaS sales in another vertical, a move from security engineering into Sales Engineering or Solutions Architecture, and a move from support or customer success into renewals or account management.

How many cybersecurity sales jobs are there?

We track 3,161 live go-to-market roles at cybersecurity vendors as of 19 August 2026, which is several times the size of the security-classified technical board. The breakdown: 1,012 Account Executive, 473 Account Manager, 384 Sales Engineer, 382 sales management and leadership, 312 SDR/BDR, 266 Solutions Engineer, 157 channel and partner, 135 Solutions Architect, 79 sales operations and enablement, and 71 renewals. About 29% are fully remote.

A closing note on why this market is worth your time

Security spend is one of the few technology budgets that survives a downturn, because the thing it defends against does not take a year off. That flows directly into go-to-market headcount, and it is why the ten families above hold thousands of open roles while the entry-level technical market stays tight. If you can sell, and you are willing to learn a genuinely interesting domain, this is one of the best-paid rooms in software to be standing in.

Live cybersecurity sales and go-to-market roles

Browse all cybersecurity sales jobs

Get weekly alerts for Get weekly alerts for new cybersecurity sales jobs:
Share:LinkedInXWhatsApp

Related guides

Stay ahead of the curve. Get new infosec jobs in your inbox.