TRX International

Nuclear cyber security engineerSalary, qualifications, licensing and career path, 2026 edition

A nuclear cyber security engineer protects the digital systems a reactor depends on, and proves it to a regulator. That means identifying which assets could affect safety, security or emergency preparedness, designing the layered defences around them, and running a programme that satisfies requirements written after the industry accepted that digital systems can be attacked as deliberately as anything physical. It is the security programme discipline of nuclear, spanning both corporate systems and plant equipment.

Cross-sectorSOC 15-1212Cyber programme10 CFR 73.54ComplianceHigh hiring demand
In short

Nuclear cyber security engineers earn a median of around $136,000 in the United States and roughly £53,000–£70,000 at mid to senior level in the UK, rising past £110,000 for a principal. This is the top of the nuclear digital pay range, because nuclear competes for security talent against every other industry.

No single licence is required. What gates the work is security competence plus clearance: CISSP or equivalent certification, security clearance (often at a higher level than neighbouring roles), and the ability to run a programme a regulator will accept.

US median annual base, TRX market analysis 2026
$0
UK nuclear workforce, against a 120,000 target for 2030
0people
Additional UK skilled workers the sector must recruit
0by 2030
Of UK nuclear employers reporting difficulty filling critical roles
0%
Role snapshot

The role at a glance

Everything an employer will ask about in the first fifteen minutes of a screening call.

Latest Nuclear Cyber Security Engineer Jobs
Also called
Cyber security engineer (nuclear) · cyber security analyst · security architect · CDA assessor · nuclear security engineer (digital)
Entry qualification
BEng/BSc in computer science, cyber security, electronic engineering or a related discipline. Security fundamentals and networking are screened for directly.
Typical entry pay
$83,000–$115,000 (US) · £32,000–£39,000 (UK graduate)
Senior / principal pay
$158,000–$218,000 (US) · £79,000–£110,000 (UK principal)
Contract day rates
£620–£820 for nuclear cyber security; £750–£1,000 for regulatory-programme and safety-system security work outside IR35; $115–$185/hr on US cyber support
Professional gate
No licence. CISSP, CISM or equivalent is the practical currency, alongside internal security authority. UK: SQEP designation for defined scopes.
Security
Higher than most roles here. UK SC is common and DV frequent; US unescorted access authorisation plus, for many posts, citizenship. Clearance is often the binding constraint on hiring.
Where the work sits
Operating utilities, reactor vendors, I&C suppliers, regulators, and specialist security consultancies. Programme work is hybrid-friendly; assessments bring site time.
Travel
Low to moderate. Programme and architecture work is office-based; assessments, audits and site surveys bring travel.
TRX segments
Operating fleet · Large new build · New technology development · Fuel handling & fuel cycle · Decommissioning & dismantling · Fusion
What the job is

Six versions of the same job title

"Nuclear cyber security engineer" changes with the driver: meeting a regulatory programme on an operating fleet, designing security into a new plant, or protecting sensitive material at a fuel-cycle facility. Note the top segment: the regulatory requirements bite hardest on plants already running. Bar shows relative hiring volume across TRX's 2026 desk activity.

Operating fleet

Running the cyber security programme at operating stations: identifying critical digital assets, applying and evidencing controls, assessments, and demonstrating compliance to the regulator. US fleet under 10 CFR 73.54, UK fleet under ONR expectations.

ROLESCyber security engineer · CDA assessor · compliance engineer · security analyst

Large new build

Designing security into a new plant from the start: architecture, segmentation, secure development expectations on suppliers, and the security case that accompanies the safety case. Hinkley Point C, Sizewell C.

ROLESSecurity architect · cyber security engineer · secure-design engineer

New technology development

Security for SMRs and advanced reactors, where higher automation, remote monitoring concepts and modern digital platforms all widen the attack surface that must be designed against. Rolls-Royce SMR, X-energy, TerraPower.

ROLESSecurity architect (SMR) · cyber security engineer · remote-operations security engineer

Fuel handling & fuel cycle

Security at fuel-cycle facilities, where digital systems intersect with material accountancy and safeguards, and the consequences of compromise extend beyond plant safety.

ROLESCyber security engineer (fuel cycle) · safeguards-systems security engineer · security analyst

Decommissioning & dismantling

Securing ageing digital estates on decommissioning sites, where systems are obsolete, poorly documented and often cannot be patched or replaced quickly.

ROLESLegacy-security engineer · cyber security engineer (decommissioning) · risk assessor

Fusion

Security for fusion facilities and their extensive digital infrastructure, an area building its security practice as devices scale toward power production. UKAEA, ITER, private fusion.

ROLESCyber security engineer (fusion) · security architect · security analyst
A working day

What the week actually looks like

A composite day for a mid-level nuclear cyber security engineer at a utility or vendor, owning part of a security programme. Programme and architecture work is hybrid; assessments bring site time. Regulatory submissions and assessment cycles shape the rhythm — noted below.

Programme and architecture · typical TuesdayHybrid, with site time
08:15
Programme reviewReviewing where the programme stands: which assets are assessed, which controls are evidenced, and what is outstanding before the next regulatory milestone.
09:15
Critical digital asset workDetermining which digital assets could affect safety, security or emergency preparedness, and therefore what protection and evidence each one needs. Getting this scoping right shapes everything downstream.
10:45
Architecture and controlsWorking the defensive architecture: layered defences, segmentation between corporate and plant networks, access control, and how far a compromise could travel.
12:00
Engineering interfaceTalking to the I&C, control and operations teams, because security measures that make a plant harder to operate safely will be rejected, and rightly.
13:30
Assessment and evidenceAssessing controls, reviewing evidence, or preparing material for an audit or regulatory inspection, where the programme has to be demonstrated rather than described.
15:00
Deep workThe protected block. An architecture design, a risk assessment, a critical digital asset determination, or a supplier security review.
17:00
RecordsIssuing assessments, evidence and programme documentation into the controlled system. Nothing counts until it is issued.
In nuclear, security measures must not degrade safety. Standard security practice can be actively unsafe here. Automatic patching can disturb a running plant, aggressive network scanning can disrupt control equipment, and access controls that delay an operator in an emergency create a hazard worse than the one being prevented. Nuclear cyber security therefore works within a hard constraint: protection must never make the plant less safe or less operable. That is why the discipline is engineering-led rather than transplanted from corporate IT, and why credibility with the operations and I&C teams matters as much as security knowledge.
Pay, 2026

What nuclear cyber security engineers are paid in 2026

Bars show the 25th to 90th percentile of base salary. The marker is the median. Switch currency to move between the US and UK markets, which behave differently.

Base salary by level · excludes bonus and contract uplift
$0$66k$133k$199k$265k
Graduate cyber security engineer0–2 yrs
$91k
Nuclear cyber security engineer2–5 yrs
$117k
Senior cyber security engineer5–9 yrs
$153k
Principal cyber security engineer9–15 yrs
$189k
Cyber security manager12+ yrs
$204k
25th–90th percentileMedianTRX market analysis, Q3 2026

How nuclear cyber security compares to adjacent roles

US figures. The nuclear engineer and information security analyst medians are BLS OEWS May 2025; the specialism ranges are TRX market analysis, because these are not separately coded by BLS.

OccupationMedianP10P90What moves the number
Nuclear cyber security engineer$136,000$91,000$218,000Regulatory programme ownership, safety-system security, clearance
Information security analysts (all industries)$124,910$79,000$190,000+Cross-industry competition keeps the whole security market high
OT security specialist (nuclear)$132,000$88,000$208,000Hands-on plant-systems security, industrial protocols
Reactor protection systems engineer$135,000$90,000$214,000The reactor's safety-classified trip system

Sources: US BLS OEWS May 2025 for the coded occupations; TRX market analysis Q3 2026 for the specialism ranges. Note that the general anchor here is unusually high compared with the engineering occupations used elsewhere in this cluster, because security salaries are bid up across all industries. Nuclear must compete with technology and finance for the same people, which is a large part of why this role sits at the top of the nuclear digital range.

Premium 01

Regulatory programme ownership

Engineers who can own a cyber security programme and carry it through regulatory inspection are scarce, because it requires security depth plus the ability to evidence and defend a position.

Premium 02

Safety-system security

Securing systems that perform safety functions, without compromising their safety qualification, is the hardest problem in the field and is priced accordingly.

Premium 03

Clearance held

Because clearance is often the binding constraint on hiring, engineers who already hold SC or DV can command a real premium simply by being available immediately.

Routes in

Three ways in, and only one of them starts with a nuclear degree

Nuclear cyber security draws from two directions: security professionals moving into a regulated engineering environment, and engineers moving into security. The second route is often more effective, because plant credibility is harder to acquire than security certification.

Route A

Graduate, United Kingdom

Four to seven years to senior.

Year 0BEng or BSc in computer science, cyber security or electronic engineeringWith networking and security fundamentals.
Year 0–2Graduate schemeEDF, Sellafield, a vendor, or a security consultancy. Security programme and assessment rotations.
Year 1–3Clearance and certificationClearance sponsorship and CISSP or equivalent, which together open most of the market.
Year 2–4Own a scopeRunning the security case for a system or facility, the artefact interviewers ask about.
Year 4–7Senior engineer or architectWith SQEP designation for defined scopes and CEng as an optional marker.
Route B

Graduate, United States

Four to eight years to senior.

Year 0BS in computer science, cyber security or engineeringABET accreditation matters less here than in design disciplines.
Year 0–3Utility or vendor security teamUtility cyber programmes under 10 CFR 73.54 are the largest employer and the best training ground.
Year 1–3Unescorted access and certificationCISSP or equivalent, plus site access authorisation.
Year 3–6CDA assessment and programme workOwning critical digital asset determinations and control evidence.
SpecialiseProgramme ownership, safety-system security, or architecture as the market pulls.
Route C

Career changer

Six to twenty-four months, from security or from engineering.

Step 1aFrom securitySecurity professionals from finance, government or technology convert well on the security side, and must then learn the plant, the safety constraints and the regulatory regime.
Step 1bFrom engineeringI&C, control or electrical engineers converting into security often progress faster, because plant credibility is scarcer than certification and they already have it.
Step 2Get certifiedCISSP or equivalent is the recognised currency, and employers frequently fund it.
Step 3Get clearedClearance is often the real gate, so employer sponsorship matters more than any other single step.
Step 4Enter through a utility or consultancyBoth hire continuously, and fleet compliance programmes are the widest door.
Before you apply

Are you actually ready to compete for a nuclear cyber role?

Everything above tells you what the market pays and what it asks for. It does not tell you how your CV reads against the other candidates applying for the same security post, and in a field where clearance, certification and plant credibility decide offers, that is the part that costs candidates the job.

Free resume scoring on avua, TRX's job search and application platform. Your score is yours; it is not shared with employers.
Example scorecardIllustrative
68out of 100

A strong corporate security CV can still miss the shortlist if it does not show plant systems, safety constraints or regulated programme work. The gap is the part you can fix.

A typical IT security CV
68
Average of shortlisted candidates
79
Top decile for nuclear cyber roles
91

Illustrative figures based on TRX shortlisting patterns across nuclear cyber security vacancies. Your own score is generated by avua from your CV and the role you are targeting.

Licences & clearance

The credentials that actually gate the work

Cyber security is not a licensed profession, but it is the most clearance-gated discipline in this cluster. Certification is the professional currency and clearance is frequently the binding constraint on who can be hired at all.

CredentialJurisdictionRequired forTimeNotes
Security clearance (SC / DV)UKMost nuclear security posts2–20 wkOften the binding constraint; DV can take five months. Holding it is a major advantage.
Unescorted access authorisationUnited StatesSite security work4–10 wk10 CFR 73 background check.
CISSP / CISM or equivalentInternationalSenior and architect gradesExam + experienceThe recognised professional currency in this field.
Security sign-off authorityUS / UKApproving security assessments and designsRole-specificInternal, granted once competence for a defined scope is demonstrated.
Regulatory framework knowledgeUS / UKProgramme and compliance rolesOngoing10 CFR 73.54 in the US; ONR expectations in the UK.
SQEP designationUKSigning or approving security deliverablesRole-specificEmployer-assessed against a defined scope; not portable without reassessment.
CitizenshipUSFederal, DOE and naval security posts—Required for federal and naval work; not for NRC-regulated private firms.
CEng registrationUK / CommonwealthOptional; engineering-led security roles4–7 yrsVia the IET; a useful marker for those from an engineering route.

Requirements change with programme and site, and clearance timelines vary considerably. Confirm the specific scope with the employer before assuming a credential transfers.

Skills screened

What appears on a 2026 nuclear cyber security engineering shortlist

Drawn from the nuclear cyber security requirement specifications TRX has worked in the last twelve months, ordered by how often each is a hard filter.

Hard filters

Named on the specification

  • Security architecture — Layered defences, segmentation and access control
  • Regulatory frameworks — 10 CFR 73.54, ONR expectations and related guidance
  • Risk assessment — Threat, vulnerability and consequence analysis for digital assets
  • Critical digital asset determination — Scoping which systems the programme covers
  • Networking — The infrastructure security controls actually apply to
  • Evidence and audit — Demonstrating compliance rather than asserting it
Differentiators

What decides between two shortlisted candidates

  • Programme ownership — Carrying a cyber programme through regulatory inspection
  • Safety-system security — Protecting systems without compromising safety qualification
  • Plant credibility — The operations knowledge that makes security advice land
  • Supply-chain security — Assessing vendors and their development practices
  • Writing — The security case and its evidence are the deliverable
  • Clearance held — Immediate availability is itself a market advantage here
One thing candidates consistently underweight. Nuclear security interviews test whether you know when not to apply a standard control. A common probe: a critical vulnerability is announced for a system running on plant, and the vendor patch is available, so when do you deploy it? The interviewer wants to see that you do not answer immediately, that patching operational equipment can disturb a running plant or invalidate its qualification, and that the real answer involves compensating measures, outage planning and engineering agreement, because in nuclear a security action that degrades safety is not a security improvement.
Where the jobs are

The 2026 demand map

Cyber demand is driven by regulatory obligation on operating plants and by security-by-design on new ones. Programme work is hybrid; assessments and audits bring site time.

ProgrammeLocationPhase in 2026Engineering demand
US operating fleetNationwideCompliance and operationsVery high; every station runs a programme under 10 CFR 73.54
EDF UK fleetUKOperations and life extensionContinuous programme and assessment work
Hinkley Point C / Sizewell CUKDesign and commissioningSecurity architecture and security case
SMR developersUS, UK & CanadaDesign and licensingSecurity-by-design for higher-automation plants
Sellafield & NDA estateCumbria, UKDecommissioningLegacy digital estate security
Security consultanciesGlobalCross-programmeEngineers supplied across every programme above
Regulators (NRC, ONR)US & UKAssessmentAssessing licensee cyber programmes
Fuel-cycle facilitiesGlobalOperationsSecurity intersecting safeguards and material accountancy
I&C suppliersGlobalCross-programmeProduct and supply-chain security
Naval and defence programmesUK & USSustainedClearance-gated security work

Programme phases move. Confirm current status before making a relocation decision; TRX tracks these weekly.

Read the market this way

Mandatory, funded and competing with every other industry.

Nuclear cyber demand is unusually reliable, because it is driven by regulatory obligation rather than by project cycles: every operating station must run a programme regardless of market conditions. The difficulty is supply. Nuclear competes for security professionals against technology, finance and government, all of which pay well and none of which require clearance or site attendance, which is why this role sits at the top of the nuclear digital pay range.

The demographic squeeze

Why experienced nuclear cyber engineers have leverage.

The combination this role needs, security depth plus plant understanding plus clearance, is rare, and each element takes time to acquire. Clearance alone can take months, which means the pool of immediately deployable candidates is far smaller than the pool of qualified ones. Experienced, cleared nuclear cyber security engineers have some of the strongest leverage of any role in this cluster.

Where it leads

Adjacent and onward roles

Cyber security spans the corporate and plant worlds and connects to the disciplines it protects. These are the moves TRX sees most often.

OT security specialist (nuclear)The hands-on plant-systems side of nuclear security
I&C engineerThe instrumentation and control systems being protected
Digital I&C modernisation engineerThe upgrades that bring new systems into scope
Nuclear software assurance engineerThe assurance discipline sharing the same evidence-led approach
Nuclear fission explainedThe physics behind the plant you protect, with an interactive chain reaction
Nuclear energy in the United StatesFleet, pipeline, employers and hiring in the largest nuclear market
Questions

Questions we get asked every week

How much does a nuclear cyber security engineer earn in 2026?

In the United States the market runs from about $83,000 for a graduate to $136,000 at the median, with principals past $218,000. In the UK it runs from £32,000–£39,000 for a graduate to £83,000–£110,000 for a principal. This is the top of the nuclear digital range, largely because nuclear competes for security talent against technology and finance. Contract engineers bill £750–£1,000 a day outside IR35 for programme and safety-system security work.

Do you need a licence to work as a nuclear cyber security engineer?

No licence exists, but this is the most clearance-gated role in the family. Security clearance (SC or DV in the UK, unescorted access authorisation in the US) is frequently the binding constraint, and CISSP or an equivalent certification is the professional currency alongside internal security authority.

Can you become a nuclear cyber security engineer without a nuclear degree?

Yes, and most people in the field do not have one. Security professionals from finance, government and technology convert in, and so do I&C and control engineers moving into security. Interestingly, the engineering route often progresses faster, because plant credibility is harder to acquire than security certification, and security advice that ignores operational reality does not get adopted.

Is nuclear cyber security a good career in 2026?

It is among the strongest in the sector. Demand is driven by regulatory obligation rather than project cycles, so it does not fluctuate with construction, and the supply of cleared people with both security and plant knowledge is genuinely short. The honest caveat: clearance requirements and site attendance make it less flexible than commercial security work, and the regulated environment means more evidence and documentation than many security professionals expect.

What is the difference between a nuclear cyber security engineer and an OT security specialist?

A nuclear cyber security engineer works at programme and architecture level across the whole organisation: identifying critical digital assets, designing layered defences, and demonstrating compliance to the regulator across both corporate and plant systems. An OT security specialist works hands-on with the plant equipment itself: the PLCs, DCS and SCADA, their industrial protocols, and the practical realities of securing systems that cannot simply be patched or rebooted. Put simply, one owns the programme and the architecture; the other secures the operational equipment in place. They work closely and the boundary varies by organisation, but the cyber engineer is broader and more compliance-facing while the OT specialist is deeper into the plant systems.

Which nuclear cyber security skills are most in demand in 2026?

Regulatory programme ownership leads, because carrying a programme through inspection needs security depth plus the ability to evidence and defend it. Close behind is safety-system security and, bluntly, holding current clearance. Security architecture, regulatory frameworks and risk assessment are the near-universal hard filters.

Nuclear only

We only recruit in nuclear. That is the whole point.

TRX works across large new build, fusion, new technology development, decommissioning, radioactive waste management and nuclear medicine, in 14+ countries. Send us your CV and we will tell you honestly which security path your experience actually fits, and what it is worth.