MastersinDataScience.org is owned by 2U, LLC, parent company of edX. Our goal is to help learners make confident, informed decisions about their education and career. Some programs shown here are offered by universities that partner with 2U, for which 2U provides marketing and operational support and receives compensation. Other programs shown may be paid advertisements from third parties. Both types of programs are identified with the word AD or Advertisement. We aim to keep information current and accurate. Learn more about edX and our partners.

Your Guide to Online Cybersecurity Bootcamps

Cybersecurity is the fastest-growing computer occupation in the United States, and one of the hardest fields to enter directly. Understanding why those two facts sit together is the whole point of this guide.

Information security analysts earn a median of $129,180 (Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025; retrieved July 2026), and the occupation is projected to grow 29% between 2024 and 2034 — the fastest growth of any computer occupation and the fifth fastest in the entire economy, against 3% for all occupations (Bureau of Labor Statistics, Employment Projections, 2024–34; retrieved July 2026).

And yet the entry-level cybersecurity job, as most people imagine it, largely does not exist. Security is a destination occupation. People arrive in it from IT — from help desk, from systems and network administration, from software engineering — bringing the operational knowledge that security work depends on. You cannot secure a system you do not understand.

That has two consequences, and they shape everything below. First, a bootcamp that promises to take a complete beginner directly into a security role is promising something the field's hiring structure does not readily support. Second — and this is the part that separates cybersecurity from every other field in these guides — the credential this industry actually hires on is a certification, and certifications cost hundreds of dollars, not thousands.

What Do Cybersecurity Professionals Earn?

Annual wages, information security analysts (SOC 15-1212), 190,650 workers nationally:

PercentileAnnual wage

10th

$75,090

25th

$97,810

Median (50th)

$129,180

75th

$163,500

90th

$199,850

Mean

$132,510

(Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025; retrieved July 2026)

The pay is excellent throughout. Even the 10th percentile, $75,090, is roughly $24,000 above the median for all U.S. occupations. There is no bad end of this distribution.

The catch is the one described above: this table shows what security analysts earn, not how one becomes a security analyst.

The pipeline — and the pinch in the middle

This is the table that actually explains the field, and you will not find it on many other pages.

SOCOccupationEmploymentMedianProjected 2024–34

11-3021

Computer and information systems managers

670,570

$175,140

+15%

15-1212

Information security analysts

190,650

$129,180

+29%

15-1244

Network and computer systems administrators

314,340

$99,130

−4%

15-1231

Computer network support specialists

146,190

$76,220

15-1232

Computer user support specialists (help desk)

717,190

$61,860

All U.S. occupations

155,495,730

$50,980

+3%

(Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025, and Employment Projections, 2024–34; retrieved July 2026)

Read it from the bottom up, because that is the direction most careers travel. Help desk is the largest occupation on the table by far — 717,190 people — and the lowest paid. Network support sits above it. Systems and network administration sits above that. Information security analyst sits above that, at more than twice the help desk median.

Now notice the problem. The traditional feeder occupation is shrinking. Network and computer systems administrators are projected to decline 4% through 2034, with about 14,300 openings a year, all of them from workers leaving rather than positions being created (BLS, Employment Projections, 2024–34; retrieved July 2026). Meanwhile the destination occupation is growing 29%, with about 16,000 openings a year.

So the field a career-changer wants is expanding, and the road that traditionally led into it is contracting. That is a real structural squeeze, and nobody advertising a cybersecurity bootcamp will mention it. It does not make security a bad career — the growth is genuine and the pay is excellent. It means the on-ramp is more competitive than the headline growth rate implies, and that you should be deliberate about how you get on it.

About the "millions of unfilled cybersecurity jobs"

You will see this figure everywhere, usually in the millions, and it is worth knowing where it comes from.

The federal projection is about 16,000 openings a year for information security analysts (BLS, Employment Projections, 2024–34; retrieved July 2026). Figures in the millions come from industry sources using a far broader definition of "cybersecurity job" — one that includes IT roles with a security component across the whole economy, often globally rather than nationally. Many of those figures are published by organizations that also sell cybersecurity training and certification.

That does not make them fabricated, and the underlying shortage of skilled security people is real. But a number produced by a body with a commercial interest in your enrolling in something deserves more scrutiny than a number produced by the Bureau of Labor Statistics, and the two are not measuring the same thing. When a school quotes you a workforce gap in the millions, ask which figure it is using and who produced it.

The Certification Question — Read This Before You Compare Bootcamps

In most fields, a bootcamp is competing against other bootcamps. In cybersecurity, it is competing against a certification, and the certification usually wins on price.

CompTIA Security+ is the industry-standard entry credential. It is vendor-neutral, it appears in a large share of entry-level security job postings, and it is a baseline requirement for many U.S. federal and defense roles. The exam costs a few hundred dollars.

Google Cybersecurity Professional Certificate is $49 per month on Coursera, self-paced, comprising about 170 hours of instruction over roughly six months at seven hours a week. It teaches Python, Linux, SQL, SIEM tools, and intrusion detection systems, it is explicitly designed to prepare you for the Security+ exam, and graduates get access to that exam at a discounted price — so you finish with a dual credential. Google maintains an employer consortium of more than 150 U.S. companies that have committed to considering graduates (Grow with Google and Coursera program pages; retrieved July 2026). Coursera financial aid is available.

ISC2 Certified in Cybersecurity (CC) is an entry-level, ANSI-accredited credential from the body behind the CISSP, created specifically to lower the cost barrier for newcomers. ISC2 has run a free-exam initiative for this certification; confirm current pricing directly with ISC2 before assuming.

Advanced certifications — CISSP, CISM, OSCP — carry real weight and real experience prerequisites, typically several years. They are destinations, not entry points, and no bootcamp confers them.

Do the arithmetic before you read the next section. The Google certificate plus a Security+ exam is a few hundred dollars and six months of part-time study, and it produces the credential employers screen for. Most cybersecurity bootcamps cost $10,000 or more. The bootcamp is not automatically the wrong choice — but it now has to justify a difference of roughly an order of magnitude, and that is the correct question to put to every admissions adviser you speak to.

What Cybersecurity Bootcamps Are Available?

Springboard — Cybersecurity Career Track. Around six months, part-time, online, mentor-led, with a conditional job guarantee for graduates authorized to work in the U.S. or Canada. Verify current tuition and prerequisites directly.

Flatiron School — Cybersecurity. Full-time and flexible pacing, online and on campus, with career coaching included for a defined period after graduation. Verify current tuition directly.

TripleTen — Cybersecurity. $9,800, roughly 28 weeks, part-time and fully online, no prerequisites, with a conditional money-back guarantee: a relevant job within ten months of graduation or a full refund, provided you complete the career services program, apply actively, stay in contact with a coach, and are a U.S. resident (TripleTen program pages; retrieved July 2026).

4Geeks Academy — Cybersecurity. Online and at campuses including Florida, with small cohorts and long-run career support. Verify current tuition directly.

Evolve Security. Part-time cybersecurity training with a hands-on, applied focus. Verify current tuition and cohort availability directly.

SANS Institute / SANS Technology Institute. The serious end of the market, and priced accordingly — SANS courses run into the thousands per course and are aimed at practitioners rather than beginners. Mentioned because SANS credentials (the GIAC family) carry genuine weight with employers, and because it is worth knowing that the most respected training in this field is not sold as a career-change bootcamp at all.

What a good cybersecurity bootcamp must include

Given that a certification path costs a fraction of the price, a bootcamp has to add something the certification cannot. Insist on all three:

  1. Certification preparation and exam vouchers built into the tuition. If a program does not prepare you for Security+ or an equivalent, it is not preparing you for the way this industry actually hires. If it charges you $12,000 and you still have to buy the exam yourself, ask what exactly you paid for.
  2. Hands-on lab work you can describe in an interview. Security hiring is intensely practical. Real defensive work in a real environment — building it, breaking it, detecting the break, responding to it — is what separates a candidate from a certificate holder. Ask to see the labs.
  3. A realistic account of where graduates actually land. The honest first destination is usually a SOC analyst (tier one), a junior security operations role, or an IT support role with a security component — not a security engineer. A program that talks only about the ceiling and never about the floor is managing your expectations rather than meeting them.

Federal Grant Money Now Covers Short Programs

This is new — it took effect on 1 July 2026 — and almost no bootcamp guide has caught up with it.

Workforce Pell Grants extend federal Pell funding to short-term training for the first time in the program's history. Eligible programs run 150 to 599 clock hours over at least 8 and fewer than 15 weeks. The maximum Pell award for 2026–27 is $7,395, prorated by program length (U.S. Department of Education, Workforce Pell Grant final rule fact sheet, May 2026; retrieved July 2026).

You can hold a bachelor's degree and still qualify. A bachelor's normally makes you Pell-ineligible; under Workforce Pell it does not. That provision is written into the rule, and it describes the typical career changer precisely. A graduate credential does disqualify you.

And the accountability standards are the strongest consumer protection this market has ever had. To keep eligibility, a program must, every year:

  • Graduate 70% of participants within 150% of normal completion time;
  • Have 70% of completers employed in the second quarter after they exit; and
  • Keep total published tuition and fees at or below its graduates' "value-added earnings" — the median earnings of working completers, less 150% of the federal poverty guideline.

Fail any of these and the program loses eligibility, with a two-year waiting period before it can try to regain it — during which it cannot launch a substantially similar program.

Set that against what a federal regulator found at BloomTech: advertised placement as high as 86%, internal figures nearer 50%, and as low as 30% in some cohorts. Under Workforce Pell, a 50% placement rate strips a program of its funding.

So ask every school one question before any other: "Is this program approved for Workforce Pell?" If the answer is yes, the program has cleared a federal outcomes screen — the Governor's approval, the Secretary's approval, and annual 70/70 thresholds. That is a bar no bootcamp's own marketing has ever had to meet.

Two honest caveats. The program must be offered by an accredited institution participating in federal student aid — which most private bootcamps are not, though universities are. And few programs have completed approval yet: states are still building their frameworks, with the pipeline expected to fill over the next 12 to 18 months. Check your state's higher education agency for the approved-program list rather than relying on a school's admissions office, and file the FAFSA early.

And check WIOA as well. Every state maintains an Eligible Training Provider List for federal workforce funding. If you are unemployed, underemployed, dislocated from a job, or low income, public money may cover your tuition through that route too. Your state workforce agency can tell you what you qualify for.

Cybersecurity Master's Degree vs. Bootcamp vs. Certification

Three different products, three different purposes.

CERTIFICATIONBOOTCAMPMASTER'S
Cost

Hundreds of dollars

Roughly $10,000+

Substantially more

Time

Weeks to months, part-time

Months

One to two years

What it's for

The credential employers actually screen on at entry

Structure, labs, mentoring, and career support around that credential

Depth, theory, leadership and specialist tracks, and roles that screen for a degree

Best fit

Almost everyone starting out, and anyone already in IT

People who need accountability, hands-on labs, and a cohort — and who have checked the arithmetic

People aiming at senior, research, policy, or management roles

Honest caveat

A credential is not experience; build a lab and get IT exposure

Must justify a ten-times price premium over the certification path

Long and expensive; no substitute for hands-on skill

If you are already working in IT, the certification path is very likely your answer, and a bootcamp is likely an expensive way to buy structure you may not need. If you are coming from outside technology altogether, be realistic: your first stop is probably an IT role, and the certification is what gets you there.

How to Choose a Cybersecurity Bootcamp

Provider-reported outcomes are unreliable by default, and the federal government has proven it. In 2024, the Consumer Financial Protection Bureau permanently banned BloomTech — formerly Lambda School — and its chief executive from consumer-lending activities after finding the school advertised job-placement rates as high as 86% when its actual internal rates were closer to 50%, and as low as 30% in some cohorts. Students borrowed money against the advertised numbers (Consumer Financial Protection Bureau, 2024; retrieved July 2026).

That does not mean every school lies. It means you cannot tell from the outside, so the burden of proof belongs on the school.

Ask this before anything else: is the program approved for Workforce Pell? If it is, it must annually graduate 70% of participants and place 70% of completers into jobs, or lose its federal funding. That is an outcomes bar no marketing claim can substitute for — and as of July 2026 it is the single most informative question available to you.

Demand these in writing, before you pay

The burden of proof belongs on the school. Demand these in writing, before you pay.

  1. 1

    Which certifications the program prepares you for, and whether exam vouchers are included

  2. 2

    What graduates' first jobs actually are

  3. 3

    The placement rate with its denominator

  4. 4

    The definition of "placed"

  5. 5

    Placement data from the last twelve months

  6. 6

    Whether outcomes are independently audited

  7. 7

    Median graduate salary — not average — with sample size

  8. 8

    The full conditions of any job guarantee

  9. 9

    The lab environment

  10. 10

    Whether the school's own marketing is accurate

The thing no school can give you

There is no reliable, independent data on what cybersecurity bootcamp graduates earn or how many get hired. No federal agency tracks them as a group. Every placement rate you see is either self-reported or borrowed from a market benchmark.

What is verifiable is the occupation: information security analysts earn a median of $129,180, with a 10th percentile of $75,090 and a 90th of $199,850, and the occupation is projected to grow 29% through 2034 (BLS, OEWS May 2025 and Employment Projections 2024–34; retrieved July 2026). That is a genuinely excellent career. Getting into it usually means going through IT first, holding the certification the industry screens on, and being able to demonstrate that you have actually defended something.

A bootcamp can help you do that. It cannot do it for you, and it is not the only way — or, for most people, the cheapest way — to get there.

Cybersecurity Bootcamp Directory

Cybersecurity bootcamps currently enrolling.

Flatiron School • New York, NY

Cybersecurity

Enrollment Type

Full-Time and Part-Time

Length of Program

Full-time and flexible pacing

Admission Requirements

Contact the school for current admission requirements.

TripleTen

Cybersecurity

Enrollment Type

Part-Time

Length of Program

~28 weeks part-time

Admission Requirements

Contact the school for current admission requirements.

4Geeks Academy

Cybersecurity

Enrollment Type

Full-Time and Part-Time

Length of Program

Part- and full-time

Admission Requirements

Contact the school for current admission requirements.

Information last updated: July 2026