What you’ll learn in this article…
- SLCGP funds states, territories, and tribes, while locals apply through the state.
- NASCIO wants SLCGP restored, but no FY 2026 appropriation exists in 2026.
- Grant-funded roles may end with the grant, so ask how funding continues.
The State and Local Cybersecurity Grant Program is the main federal dollar stream for state and local government cyber defense, and NASCIO has made restoring it a top congressional priority for the upcoming year. Where that money flows determines whether agencies hire for information security analyst jobs, fund managed security services, or pay for workforce training.
That creates a practical tension for job seekers on a cybersecurity career path: grant-funded roles can appear quickly but often end when the award expires, and public-sector pay can lag private-sector offers. Tracking subawards and hiring timelines, not just job boards, is what separates candidates who find these roles from those who miss them.
What the State and Local Cybersecurity Grant Program Funds
Who runs it and who receives the money The State and Local Cybersecurity Grant Program is a federal cybersecurity grant run jointly by CISA and FEMA. It awards money to states, territories, and tribes to reduce cyber risk to government-owned and operated systems.1 The structural detail matters for people pursuing cybersecurity jobs: only a state's State Administrative Agency applies directly to the federal government. That agency must pass through at least 80 percent of the funds to local governments, and at least 25 percent of the total allocation must support rural areas.1 Local and tribal governments participate as subrecipients through the state or territory, not as direct federal applicants.2 In practice, most grant-funded projects appear at the local level through counties, cities, or regional agencies.
What the money can pay for
Spending is cybersecurity-focused and must fit an approved state or territorial plan.1 Common allowable uses include: - Multi-factor authentication - Endpoint detection and response - Network traffic monitoring - Cybersecurity planning and governance work - Incident response and continuity of operations - Security awareness training and professional development3
How it differs from related programs
The Tribal Cybersecurity Grant Program is a separate funding stream aimed directly at tribal governments, rather than routing funds through a state.2 SLCGP is also separate from the State Homeland Security Program, which readers sometimes confuse with it. SLCGP is specifically limited to cybersecurity activities tied to the approved plan; it is not a general-purpose homeland security fund.
Where SLCGP Funding Stands in 2026 and Why NASCIO Wants It Restored
Is SLCGP funded for FY 2026, and how much? As of October 2026, the precise answer is that the program has an authorization extension but no new FY 2026 federal appropriation or nationwide notice of funding opportunity has been posted by FEMA or CISA.2
A Short Timeline of the Current Gap
The State and Local Cybersecurity Grant Program was created under the 2021 infrastructure law. Congress approved a reauthorization on February 3, 2026, extending the program only through September 30, 2026, but did not attach new program funding in that extension. Reporting from GovTech described the result as "reauthorized, but not funded." A clear national FY 2026 SLCGP funding round is absent from FEMA and CISA public materials as of this writing; CISA's January 30, 2026 deadline for resubmitting approved cybersecurity plans ties to the prior round, not a new one.
Why NASCIO Wants Restoration
NASCIO's published congressional priorities and StateScoop coverage point to restoration as a top ask. In a June 23, 2026 appropriations letter, NASCIO explicitly advocated for 2027 funding for SLCGP. The association frames the issue around preserving state and local cybersecurity capacity as the current funding cycle winds down. That concern follows steep cuts: total program funding fell from $279.9 million in FY 2024 to $91.7 million in FY 2025.
What Restoration Would Mean in Practice
Restored funding would open new state-administered award cycles, not instant job postings. States would still need to obligate funds, subaward to localities, and roll out hiring or training projects. Some states are still managing late-cycle activity, such as Maryland's more than $4.9 million round announced in August 2026, while others like Mississippi have said the next round is not scheduled and likely not expected until early 2027.1
How Grant Dollars Become Cyber Jobs and Training
The core tension is speed versus permanence: grant money can move quickly into contractors, term staff, and training, but it rarely creates permanent civil-service jobs by itself. Under the FY 2025 SLCGP notice of funding opportunity, workforce development and cyber jobs are eligible when they support an approved Cybersecurity Plan and its planning, organization, equipment, training, and exercise activities. General workforce spending is not an open-ended education subsidy; it has to tie back to allowable personnel or training functions.
What the Grant Can Pay For
- Personnel: Hiring, overtime, and backfill for roles such as training and exercise coordinators, program managers and planners, and cybersecurity navigators.
- Contractors: Contracted support is allowed for monitoring and assessment staff and for services such as jointly procured cybersecurity training.
- Training and exercises: Training costs, including cybersecurity certifications, are allowable when tied to an assessment-identified gap, and exercises must follow HSEEP. FEMA encourages existing courses, with ADDIE if new courses are developed.
Reimbursement Shapes Hiring Speed
SLCGP is reimbursement-based. Local agencies typically spend first, then submit costs for federal reimbursement. That pass-through slows the moment a grant award becomes a posted job, and it favors short-term or contract spending over permanent positions. The sequence matters for job seekers: state award, local subaward, local spend, then reimbursement. Postings usually appear after the state and locality finalize their subaward.
Why Most Roles Are Term or Contract
The funding is time-limited, and personnel funded by the grant must be sustainable after the program ends. In practice, that means states often buy managed services, vCISO support, term roles, or shared-service staffing rather than permanent civil-service hires. FEMA's guidance includes an example of two states jointly procuring one contractor to deliver cybersecurity training, then running their own programs with that contractor. Exercises can range from tabletop discussions to functional drills, often built on Hands-On Cybersecurity Labs, as long as they follow HSEEP and address gaps identified in the plan.
Expect contract and term positions to appear first. Permanent state or local hiring depends on whether the legislature or local budget picks up the salary after the grant expires.
Public-Sector Cyber Roles and the Certifications Agencies Ask For
State and local cybersecurity postings show a split between entry-level support roles and senior analyst or leadership positions. Many analyst roles accept either a bachelor's degree with relevant coursework or a combination of experience and technical certifications, which creates multiple entry paths for career changers. CompTIA Security+ appears as a common baseline credential in several analyst postings, while senior and leadership roles consistently prefer CISSP, CISM, CISA, or comparable advanced certifications.
| Role | What the Job Involves | Common Certifications | Typical Education or Experience |
|---|---|---|---|
| IT Security Analyst II, City of Las Vegas | Posting excerpt does not provide detailed duties. | One or more of CompTIA Security+, CEH, GSEC, CISSP, CISM, CISA, or an equivalent, required at application. | Bachelor's degree in computer science, telecommunications, management information systems, or a related field. |
| Information Security Analyst, City of Santa Monica | Posting excerpt does not provide detailed duties. | One of CISSP, CISA, CRISC, GIAC, CEH, CHFI, or similar certified within six months of hire. AWS Certified Security Specialty and Microsoft MCSA or MCSE are desirable. | Bachelor's degree in computer science, management information systems, or a closely related field. |
| Cybersecurity Analyst, City of San Jose | Posting excerpt does not provide detailed duties. | A current terminal-level certification such as CISSP, CISA, CISM, CGEIT, CRISC, or equivalent. MCSE or equivalent may also be required. | Bachelor's degree in a relevant field and four years of progressively responsible professional or journey-level experience, including two years of lead technical work. |
| IT Professional Security (Cybersecurity Analyst), City of Houston | Posting excerpt does not provide detailed duties. | Not specified in posting excerpt. | Associate's degree in computer science, management and information systems, business, or a related field. System-specific technical certifications may substitute for the associate's degree, and relevant experience may substitute for education year-for-year. |
| Systems Analyst Cybersecurity, City of Torrance | Posting excerpt does not provide detailed duties. | Certifications in governance and risk management, security operations, incident response and forensics, penetration testing, cloud security, network and infrastructure security, and regulatory compliance are highly desired. | Bachelor's degree in computer science, information technology, or a closely related field, plus five to seven years of progressively responsible professional IT experience. One year of supervisory or lead experience is highly desired. |
| Chief Information Security Officer, Texas Health and Human Services Commission | Posting excerpt does not provide detailed duties. | Preference for CISSP, CISM, CISA, CRISC, GIAC certifications, cloud-security certifications, or comparable advanced cybersecurity credentials. | Bachelor's degree in information technology, cybersecurity, computer science, business administration, public administration, or a related field. |
Pay, Benefits and Background Checks in State and Local Cyber Jobs
Approximate 2025 BLS data for Information Security Analysts shows a national median of $129,180, with the middle half of earners between $97,810 and $163,500. Those figures cover all sectors, so state and local government pay may land below private-sector pay in some areas. Public-sector roles often trade that gap for pensions, health benefits, job stability, and possible Public Service Loan Forgiveness; background checks are standard, while clearance requirements are less common at state and local levels than federal. These salaries reflect occupations, not a specific degree program.
| Occupation | 25th percentile | Median annual wage | 75th percentile |
|---|---|---|---|
| Information Security Analysts | 97,810 | 129,180 | 163,500 |
| Computer User Support Specialists | 49,000 | 61,860 | 79,040 |
| Computer and Information Systems Managers | 138,060 | 175,140 | 220,730 |
Related Articles
How Local Governments Apply and What to Know About Matching and Reimbursement
Some federal grants let a city or county apply directly to the funding agency. SLCGP works differently: local governments apply as subrecipients through their state's administrative agency.
The Application Path
FEMA awards SLCGP funds to the state or territory through its State Administrative Agency, usually housed in the state's homeland security or emergency management office. After the award, the state's cybersecurity planning committee sets funding priorities and opens subaward opportunities. Local governments, including municipalities, counties, and tribal governments, do not submit directly to FEMA; they respond to the state's request and must follow state law and federal requirements. States must pass through at least 80% of total funding to local and tribal governments, but the exact timing and application format vary by state.
Matching Funds by Year
Cost-share requirements changed each fiscal year, so local applicants should check the notice that applies to their project. The nonfederal share started at 10% in FY 2022, rose to 20% in FY 2023, 30% in FY 2024, and reaches 40% in FY 2025 for most projects; multi-entity projects for FY 2025 use a 30% nonfederal share.1 In the FY 2025 notice, the nonfederal share can be cash or third-party in-kind contributions, as long as they are certifiable, reasonable, and allocable.2 The match is calculated at the project or activity level, not pooled across projects1, and an entity generally cannot use other federal funds unless another law allows it.
Reimbursement and Cash-Flow Risk
In practice, grant-funded work often operates on a reimbursement model: the local agency pays for approved activities, documents the expense, and requests payment from the state, which draws down federal funds. This can strain small jurisdictions with limited reserves. FEMA requires selected applicants to agree to an acceptable cost-share agreement before funding2, so the matching obligation must be planned before the project starts.
Tip: local IT leaders should contact the state CIO or CISO office early. Getting into the state's cybersecurity plan can move a locality ahead of the next subaward announcement.
Cyber hiring follows the grant cycle: money moves from Congress to the state, to the locality, and only then to a job posting.
How to Track Grant-Funded Cyber Job Postings in Your State
Grant-funded cyber roles rarely sit beside permanent openings on a single job board. You are tracking two timelines at once: the grant cycle that assigns subawards, and the slower hiring cycle that follows. Most states now publish enough SLCGP documentation to connect those dots.
Start With Your State's SLCGP Administrative Agency
Local governments apply through the governor-designated State Administrative Agency (SAA), often housed in emergency management or homeland security. The FEMA and CISA State and Local Cybersecurity Grant Program pages identify state-specific contacts and preparedness officers. If a contact is unclear, use the SLCGP support email listed by FEMA. For example, Connecticut's Department of Emergency Services and Public Protection (DESPP/DEMHS) serves as the SAA and posts SLCGP project materials on its program page.
Watch CIO, CISO and Planning Committee Announcements
Your state's cybersecurity planning committee reviews and coordinates SLCGP projects, so its minutes and notices often name subaward recipients before positions are posted. Check the state CIO or CISO website and the SAA's SLCGP page. California's Cal OES runs the grant through its State & Local Projects Unit and coordinates with Cal-CSIC; Iowa's Department of Management and HSEM post state-specific guidance. North Carolina's NCEM portal lists SLCGP guidance and project announcements.
Set Job Board Alerts and Follow Local Agendas
Use state and local government job boards with keyword alerts like "cybersecurity", "grant-funded", "limited term", or "SLCGP". County and city council agendas are another early signal: subrecipient award approvals often appear before requisitions become public postings. Review those agendas monthly if you are targeting a specific region. Bookmark the state SAA page if it publishes a dedicated SLCGP project list.
Next Steps for Students and Career Changers
What should you do now to turn the SLCGP funding debate into a realistic job plan? Build a foundation before the grants move. Start by completing an entry-level cybersecurity certificate or associate degree and earning a Security+ level credential on the CompTIA Security+ career path. Then pick one or two target states, follow their state IT and homeland security agencies, and monitor local government job boards for grant-funded SOC analyst, IT security specialist, and cyber coordinator openings.
Education pathways vary: a certificate or associate degree can prepare you for SOC and IT security support roles, while a bachelor's deepens your route toward analyst and coordinator tracks. Use onlinecybersecurity.org's cybersecurity career path for students and scholarship guides, including NSF CyberCorps: Scholarship for Service, and review state government hiring pages for entry-level progression.
Remember that restored SLCGP funding is a possibility, not a guarantee. The same Security+ baseline, SIEM exposure, and incident-response practice transfer directly to private-sector roles if grants stall, so build skills that work in both worlds and align with Skills-Based Cybersecurity Hiring.










