Nuclear cyber security engineerSalary, qualifications, licensing and career path, 2026 edition
A nuclear cyber security engineer protects the digital systems a reactor depends on, and proves it to a regulator. That means identifying which assets could affect safety, security or emergency preparedness, designing the layered defences around them, and running a programme that satisfies requirements written after the industry accepted that digital systems can be attacked as deliberately as anything physical. It is the security programme discipline of nuclear, spanning both corporate systems and plant equipment.
Nuclear cyber security engineers earn a median of around $136,000 in the United States and roughly £53,000–£70,000 at mid to senior level in the UK, rising past £110,000 for a principal. This is the top of the nuclear digital pay range, because nuclear competes for security talent against every other industry.
No single licence is required. What gates the work is security competence plus clearance: CISSP or equivalent certification, security clearance (often at a higher level than neighbouring roles), and the ability to run a programme a regulator will accept.
The role at a glance
Everything an employer will ask about in the first fifteen minutes of a screening call.

- Also called
- Cyber security engineer (nuclear) · cyber security analyst · security architect · CDA assessor · nuclear security engineer (digital)
- Entry qualification
- BEng/BSc in computer science, cyber security, electronic engineering or a related discipline. Security fundamentals and networking are screened for directly.
- Typical entry pay
- $83,000–$115,000 (US) · £32,000–£39,000 (UK graduate)
- Senior / principal pay
- $158,000–$218,000 (US) · £79,000–£110,000 (UK principal)
- Contract day rates
- £620–£820 for nuclear cyber security; £750–£1,000 for regulatory-programme and safety-system security work outside IR35; $115–$185/hr on US cyber support
- Professional gate
- No licence. CISSP, CISM or equivalent is the practical currency, alongside internal security authority. UK: SQEP designation for defined scopes.
- Security
- Higher than most roles here. UK SC is common and DV frequent; US unescorted access authorisation plus, for many posts, citizenship. Clearance is often the binding constraint on hiring.
- Where the work sits
- Operating utilities, reactor vendors, I&C suppliers, regulators, and specialist security consultancies. Programme work is hybrid-friendly; assessments bring site time.
- Travel
- Low to moderate. Programme and architecture work is office-based; assessments, audits and site surveys bring travel.
- TRX segments
- Operating fleet · Large new build · New technology development · Fuel handling & fuel cycle · Decommissioning & dismantling · Fusion
Six versions of the same job title
"Nuclear cyber security engineer" changes with the driver: meeting a regulatory programme on an operating fleet, designing security into a new plant, or protecting sensitive material at a fuel-cycle facility. Note the top segment: the regulatory requirements bite hardest on plants already running. Bar shows relative hiring volume across TRX's 2026 desk activity.
Operating fleet
Running the cyber security programme at operating stations: identifying critical digital assets, applying and evidencing controls, assessments, and demonstrating compliance to the regulator. US fleet under 10 CFR 73.54, UK fleet under ONR expectations.
Large new build
Designing security into a new plant from the start: architecture, segmentation, secure development expectations on suppliers, and the security case that accompanies the safety case. Hinkley Point C, Sizewell C.
New technology development
Security for SMRs and advanced reactors, where higher automation, remote monitoring concepts and modern digital platforms all widen the attack surface that must be designed against. Rolls-Royce SMR, X-energy, TerraPower.
Fuel handling & fuel cycle
Security at fuel-cycle facilities, where digital systems intersect with material accountancy and safeguards, and the consequences of compromise extend beyond plant safety.
Decommissioning & dismantling
Securing ageing digital estates on decommissioning sites, where systems are obsolete, poorly documented and often cannot be patched or replaced quickly.
Fusion
Security for fusion facilities and their extensive digital infrastructure, an area building its security practice as devices scale toward power production. UKAEA, ITER, private fusion.
What the week actually looks like
A composite day for a mid-level nuclear cyber security engineer at a utility or vendor, owning part of a security programme. Programme and architecture work is hybrid; assessments bring site time. Regulatory submissions and assessment cycles shape the rhythm — noted below.
What nuclear cyber security engineers are paid in 2026
Bars show the 25th to 90th percentile of base salary. The marker is the median. Switch currency to move between the US and UK markets, which behave differently.
How nuclear cyber security compares to adjacent roles
US figures. The nuclear engineer and information security analyst medians are BLS OEWS May 2025; the specialism ranges are TRX market analysis, because these are not separately coded by BLS.
| Occupation | Median | P10 | P90 | What moves the number |
|---|---|---|---|---|
| Nuclear cyber security engineer | $136,000 | $91,000 | $218,000 | Regulatory programme ownership, safety-system security, clearance |
| Information security analysts (all industries) | $124,910 | $79,000 | $190,000+ | Cross-industry competition keeps the whole security market high |
| OT security specialist (nuclear) | $132,000 | $88,000 | $208,000 | Hands-on plant-systems security, industrial protocols |
| Reactor protection systems engineer | $135,000 | $90,000 | $214,000 | The reactor's safety-classified trip system |
Sources: US BLS OEWS May 2025 for the coded occupations; TRX market analysis Q3 2026 for the specialism ranges. Note that the general anchor here is unusually high compared with the engineering occupations used elsewhere in this cluster, because security salaries are bid up across all industries. Nuclear must compete with technology and finance for the same people, which is a large part of why this role sits at the top of the nuclear digital range.
Regulatory programme ownership
Engineers who can own a cyber security programme and carry it through regulatory inspection are scarce, because it requires security depth plus the ability to evidence and defend a position.
Safety-system security
Securing systems that perform safety functions, without compromising their safety qualification, is the hardest problem in the field and is priced accordingly.
Clearance held
Because clearance is often the binding constraint on hiring, engineers who already hold SC or DV can command a real premium simply by being available immediately.
Three ways in, and only one of them starts with a nuclear degree
Nuclear cyber security draws from two directions: security professionals moving into a regulated engineering environment, and engineers moving into security. The second route is often more effective, because plant credibility is harder to acquire than security certification.
Graduate, United Kingdom
Four to seven years to senior.
Graduate, United States
Four to eight years to senior.
Career changer
Six to twenty-four months, from security or from engineering.
Are you actually ready to compete for a nuclear cyber role?
Everything above tells you what the market pays and what it asks for. It does not tell you how your CV reads against the other candidates applying for the same security post, and in a field where clearance, certification and plant credibility decide offers, that is the part that costs candidates the job.
Free resume scoring on avua, TRX's job search and application platform. Your score is yours; it is not shared with employers.A strong corporate security CV can still miss the shortlist if it does not show plant systems, safety constraints or regulated programme work. The gap is the part you can fix.
Illustrative figures based on TRX shortlisting patterns across nuclear cyber security vacancies. Your own score is generated by avua from your CV and the role you are targeting.
The credentials that actually gate the work
Cyber security is not a licensed profession, but it is the most clearance-gated discipline in this cluster. Certification is the professional currency and clearance is frequently the binding constraint on who can be hired at all.
| Credential | Jurisdiction | Required for | Time | Notes |
|---|---|---|---|---|
| Security clearance (SC / DV) | UK | Most nuclear security posts | 2–20 wk | Often the binding constraint; DV can take five months. Holding it is a major advantage. |
| Unescorted access authorisation | United States | Site security work | 4–10 wk | 10 CFR 73 background check. |
| CISSP / CISM or equivalent | International | Senior and architect grades | Exam + experience | The recognised professional currency in this field. |
| Security sign-off authority | US / UK | Approving security assessments and designs | Role-specific | Internal, granted once competence for a defined scope is demonstrated. |
| Regulatory framework knowledge | US / UK | Programme and compliance roles | Ongoing | 10 CFR 73.54 in the US; ONR expectations in the UK. |
| SQEP designation | UK | Signing or approving security deliverables | Role-specific | Employer-assessed against a defined scope; not portable without reassessment. |
| Citizenship | US | Federal, DOE and naval security posts | — | Required for federal and naval work; not for NRC-regulated private firms. |
| CEng registration | UK / Commonwealth | Optional; engineering-led security roles | 4–7 yrs | Via the IET; a useful marker for those from an engineering route. |
Requirements change with programme and site, and clearance timelines vary considerably. Confirm the specific scope with the employer before assuming a credential transfers.
What appears on a 2026 nuclear cyber security engineering shortlist
Drawn from the nuclear cyber security requirement specifications TRX has worked in the last twelve months, ordered by how often each is a hard filter.
Named on the specification
- Security architecture — Layered defences, segmentation and access control
- Regulatory frameworks — 10 CFR 73.54, ONR expectations and related guidance
- Risk assessment — Threat, vulnerability and consequence analysis for digital assets
- Critical digital asset determination — Scoping which systems the programme covers
- Networking — The infrastructure security controls actually apply to
- Evidence and audit — Demonstrating compliance rather than asserting it
What decides between two shortlisted candidates
- Programme ownership — Carrying a cyber programme through regulatory inspection
- Safety-system security — Protecting systems without compromising safety qualification
- Plant credibility — The operations knowledge that makes security advice land
- Supply-chain security — Assessing vendors and their development practices
- Writing — The security case and its evidence are the deliverable
- Clearance held — Immediate availability is itself a market advantage here
The 2026 demand map
Cyber demand is driven by regulatory obligation on operating plants and by security-by-design on new ones. Programme work is hybrid; assessments and audits bring site time.
| Programme | Location | Phase in 2026 | Engineering demand |
|---|---|---|---|
| US operating fleet | Nationwide | Compliance and operations | Very high; every station runs a programme under 10 CFR 73.54 |
| EDF UK fleet | UK | Operations and life extension | Continuous programme and assessment work |
| Hinkley Point C / Sizewell C | UK | Design and commissioning | Security architecture and security case |
| SMR developers | US, UK & Canada | Design and licensing | Security-by-design for higher-automation plants |
| Sellafield & NDA estate | Cumbria, UK | Decommissioning | Legacy digital estate security |
| Security consultancies | Global | Cross-programme | Engineers supplied across every programme above |
| Regulators (NRC, ONR) | US & UK | Assessment | Assessing licensee cyber programmes |
| Fuel-cycle facilities | Global | Operations | Security intersecting safeguards and material accountancy |
| I&C suppliers | Global | Cross-programme | Product and supply-chain security |
| Naval and defence programmes | UK & US | Sustained | Clearance-gated security work |
Programme phases move. Confirm current status before making a relocation decision; TRX tracks these weekly.
Mandatory, funded and competing with every other industry.
Nuclear cyber demand is unusually reliable, because it is driven by regulatory obligation rather than by project cycles: every operating station must run a programme regardless of market conditions. The difficulty is supply. Nuclear competes for security professionals against technology, finance and government, all of which pay well and none of which require clearance or site attendance, which is why this role sits at the top of the nuclear digital pay range.
Why experienced nuclear cyber engineers have leverage.
The combination this role needs, security depth plus plant understanding plus clearance, is rare, and each element takes time to acquire. Clearance alone can take months, which means the pool of immediately deployable candidates is far smaller than the pool of qualified ones. Experienced, cleared nuclear cyber security engineers have some of the strongest leverage of any role in this cluster.
Adjacent and onward roles
Cyber security spans the corporate and plant worlds and connects to the disciplines it protects. These are the moves TRX sees most often.
Questions we get asked every week
How much does a nuclear cyber security engineer earn in 2026?
In the United States the market runs from about $83,000 for a graduate to $136,000 at the median, with principals past $218,000. In the UK it runs from £32,000–£39,000 for a graduate to £83,000–£110,000 for a principal. This is the top of the nuclear digital range, largely because nuclear competes for security talent against technology and finance. Contract engineers bill £750–£1,000 a day outside IR35 for programme and safety-system security work.
Do you need a licence to work as a nuclear cyber security engineer?
No licence exists, but this is the most clearance-gated role in the family. Security clearance (SC or DV in the UK, unescorted access authorisation in the US) is frequently the binding constraint, and CISSP or an equivalent certification is the professional currency alongside internal security authority.
Can you become a nuclear cyber security engineer without a nuclear degree?
Yes, and most people in the field do not have one. Security professionals from finance, government and technology convert in, and so do I&C and control engineers moving into security. Interestingly, the engineering route often progresses faster, because plant credibility is harder to acquire than security certification, and security advice that ignores operational reality does not get adopted.
Is nuclear cyber security a good career in 2026?
It is among the strongest in the sector. Demand is driven by regulatory obligation rather than project cycles, so it does not fluctuate with construction, and the supply of cleared people with both security and plant knowledge is genuinely short. The honest caveat: clearance requirements and site attendance make it less flexible than commercial security work, and the regulated environment means more evidence and documentation than many security professionals expect.
What is the difference between a nuclear cyber security engineer and an OT security specialist?
A nuclear cyber security engineer works at programme and architecture level across the whole organisation: identifying critical digital assets, designing layered defences, and demonstrating compliance to the regulator across both corporate and plant systems. An OT security specialist works hands-on with the plant equipment itself: the PLCs, DCS and SCADA, their industrial protocols, and the practical realities of securing systems that cannot simply be patched or rebooted. Put simply, one owns the programme and the architecture; the other secures the operational equipment in place. They work closely and the boundary varies by organisation, but the cyber engineer is broader and more compliance-facing while the OT specialist is deeper into the plant systems.
Which nuclear cyber security skills are most in demand in 2026?
Regulatory programme ownership leads, because carrying a programme through inspection needs security depth plus the ability to evidence and defend it. Close behind is safety-system security and, bluntly, holding current clearance. Security architecture, regulatory frameworks and risk assessment are the near-universal hard filters.
We only recruit in nuclear. That is the whole point.
TRX works across large new build, fusion, new technology development, decommissioning, radioactive waste management and nuclear medicine, in 14+ countries. Send us your CV and we will tell you honestly which security path your experience actually fits, and what it is worth.