May 21, 2024 By Mark Stone 2 min read

We recently published an article about the importance of security clearances for roles across various sectors, particularly those associated with national security and defense.

But obtaining a clearance is only part of the journey. Maintaining and potentially expanding your clearance over time requires continued diligence and adherence to stringent guidelines.

This brief explainer discusses the duration of security clearances, the recurring processes involved in maintaining them and possibilities for expansion, as well as the economic benefits of these credentialed positions.

Duration of security clearances: Variations and standards

Security clearances are never indefinite; the validity of a security clearance largely depends on the level of clearance and the specific regulations of the issuing agency.

Here’s a breakdown:

  • Confidential level clearances: The most basic level of security clearance, typically reevaluated every 15 years.
  • Secret level clearances: Requires reinvestigation every 10 years.
  • Top secret level clearances: The highest level of clearance often involves sensitive and critical information; reinvestigations are required every 5 years.

These intervals are set to ensure all clearance holders are periodically vetted to manage risks associated with changes in their personal circumstances or risk profiles.

Maintenance and expansion processes

Maintaining a security clearance typically involves regular background checks and, depending on the clearance level, continuous monitoring or evaluation.

Key components of the maintenance process include:

  • Periodic reinvestigations: Similar to the initial vetting process, these investigations may involve checks into financial records, personal behavior and foreign contacts.
  • Self-reporting obligations: Clearance holders are often required to report any significant life changes, including financial difficulties, foreign travel or changes in marital status.

Expanding a clearance means upgrading the level of accessible information due to changes in job roles or responsibilities. This process can be similar to gaining initial clearance, especially in terms of the depth of background checks conducted.

Holding a security clearance: Compensation

Jobs that require a security clearance often command higher salaries compared to non-cleared positions. The better compensation is due to the limited pool of qualified candidates and the extra responsibilities associated with such roles.

Average salary ranges vary significantly based on clearance level, industry and job location, but here are some general trends:

  • Non-cleared positions: Typically see average industry-standard salaries.
  • Confidential and secret clearances: Can expect a salary increase of 5%-15% over non-cleared positions.
  • Top-secret clearances: Often command premium pay that can be 15%-25% higher than similar roles without clearance.

Of course, one needs to consider years of experience.

For example, a software engineer position requiring a top-secret clearance can earn about $128,000 annually in San Antonio, Texas. Higher responsibility roles such as a cyber training and exercise manager at Booz Allen Hamilton or a FORGE C2 program manager at Lockheed Martin can command up to $212,000 per year and $267,000 per year, respectively.

These financial incentives recognize the additional loyalty and integrity required by roles that handle sensitive information.

Why diligence is key for maintaining clearance

The process of maintaining or expanding a security clearance is continuous and rigorous and reflects the high standards expected of those in trusted positions. The payoff, however, includes monetary benefits as well as career advancements within privileged sectors.

As global and domestic landscapes evolve, so do the criteria for security clearances.

Those at the forefront of national and corporate security must be both capable and dependable, traits typically reflected in compensation. For individuals in these roles, a proactive approach and a clear understanding of the expectations can make a significant impact on their career trajectory and success.

More from Risk Management

Remote access risks on the rise with CVE-2024-1708 and CVE-2024-1709

4 min read - On February 19, ConnectWise reported two vulnerabilities in its ScreenConnect product, CVE-2024-1708 and 1709. The first is an authentication bypass vulnerability, and the second is a path traversal vulnerability. Both made it possible for attackers to bypass authentication processes and execute remote code.While ConnectWise initially reported that the vulnerabilities had proof-of-concept but hadn’t been spotted in the wild, reports from customers quickly made it clear that hackers were actively exploring both flaws. As a result, the company created patches for…

Researchers develop malicious AI ‘worm’ targeting generative AI systems

2 min read - Researchers have created a new, never-seen-before kind of malware they call the "Morris II" worm, which uses popular AI services to spread itself, infect new systems and steal data. The name references the original Morris computer worm that wreaked havoc on the internet in 1988.The worm demonstrates the potential dangers of AI security threats and creates a new urgency around securing AI models.New worm utilizes adversarial self-replicating promptThe researchers from Cornell Tech, the Israel Institute of Technology and Intuit, used what’s…

What should Security Operations teams take away from the IBM X-Force 2024 Threat Intelligence Index?

3 min read - The IBM X-Force 2024 Threat Intelligence Index has been released. The headlines are in and among them are the fact that a global identity crisis is emerging. X-Force noted a 71% increase year-to-year in attacks using valid credentials.In this blog post, I’ll explore three cybersecurity recommendations from the Threat Intelligence Index, and define a checklist your Security Operations Center (SOC) should consider as you help your organization manage identity risk.The report identified six action items:Remove identity silosReduce the risk of…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today