Skip to content

Security resume examples that show judgement, not a certification stack.

Information security is one of the fastest-growing occupations BLS tracks, and entry level is still crowded — because everyone arrives with the same three certifications and the same list of tools. What a SOC lead is actually trying to establish is whether you can tell a real alert from noise at volume, whether you close the loop on what you find, and whether you can be trusted with information about incidents. This guide covers the numbers that demonstrate the first two, and the disclosure discipline that demonstrates the third.

Ideal length
1–2 pages
The metric
Alerts vs false positives
Second metric
MTTD / MTTR
Median (May 2024)
$124,910

Priyanka Raut

Security Analyst · Detection & Response · Tier 2

Chicago, IL · github.com/praut-detections · linkedin.com/in/priyanka-raut

Summary

Tier 2 security analyst in a 24/7 SOC covering 6,000 endpoints and about 40 cloud accounts. Triage roughly 120 alerts a week; rewrote the eight noisiest detections and cut the queue's false-positive rate from 71% to 38%, which took median time to triage from 22 minutes to 9. Wrote 30+ Sigma rules and led the containment step on four confirmed intrusions. Security+, CySA+, studying for the OSCP.

Experience

Security Analyst, Tier 2 · Managed detection and response provider (24/7 SOC)

2022 — Present

  • Triage ~120 alerts a week across 6,000 endpoints and ~40 cloud accounts in Splunk and CrowdStrike; escalate and own investigations through containment.
  • Cut the queue's false-positive rate from 71% to 38% by rewriting the eight noisiest detections — median time to triage fell from 22 minutes to 9.
  • Authored 30+ detections in Sigma mapped to MITRE ATT&CK, including coverage for a technique the previous rule set missed entirely.
  • Led containment on four confirmed intrusions — isolation, credential revocation and handover to the IR retainer, with timeline documentation used in the client report.
  • Built the phishing triage automation in the SOAR platform that removed roughly 300 manual steps a month.
  • Run the weekly detection review with two junior analysts and maintain the on-call runbook.

IT Support Specialist → Junior Analyst · Regional healthcare provider

2019 — 2022

  • Moved from endpoint support into the security team; owned vulnerability scanning across 1,400 assets and the monthly patch reporting.
  • Reduced critical unpatched findings from 340 to under 40 in nine months by rebuilding the maintenance-window process with system owners.
  • Supported HIPAA security-rule evidence collection for two annual assessments.

Skills

SIEM (Splunk, Microsoft Sentinel)EDR (CrowdStrike, Defender)Detection engineering (Sigma, KQL, SPL)MITRE ATT&CK mappingIncident response and containmentThreat huntingVulnerability management (Nessus, Qualys)SOAR automationCloud security (AWS, Azure)Log analysis and correlationPhishing analysisPython scripting

Education

B.S. Information Technology — DePaul University, 2019

Certifications

CompTIA Security+ (2020) · CompTIA CySA+ (2022) · Microsoft SC-200 · OSCP — in progress, exam booked

Languages

English (fluent) · Hindi (native) · Marathi (native)

Why this example works

Alert volume and false-positive rate together

120 alerts a week is scale; 71% to 38% false positives is judgement. A SOC lead reads the second number as evidence you can tell signal from noise — and it is the thing an analyst can improve that nobody thinks to write down.

Detections written, mapped to a framework

'30+ Sigma rules mapped to MITRE ATT&CK, including coverage for a technique the rule set missed.' Detection engineering is the clearest route out of tier-1 triage, and naming the framework makes the claim legible to any security reader.

Incidents described without disclosure

'Four confirmed intrusions — isolation, credential revocation, handover to the IR retainer.' Actions and role, no client, no attacker detail, no data at risk. In security hiring, how you write about incidents is itself part of the assessment.

Cybersecurity Analyst resume summary examples

Three to four lines: scope, stack or specialism, one quantified win. Match the register to your seniority.

Entry / career changer

Security analyst candidate moving from IT support, where I already owned vulnerability scanning across 1,400 assets and cut critical unpatched findings from 340 to under 40. Security+ certified, home lab running Sentinel and Sysmon, and 12 detections published to my GitHub. Comfortable in log analysis and looking for a tier-1 SOC seat.

SOC analyst (tier 1)

SOC analyst triaging around 100 alerts a week across endpoint, email and cloud telemetry in Sentinel. Escalate with a documented investigation trail and maintain the phishing triage runbook. Reduced repeat escalations on two alert types by proposing the tuning that the detection team implemented. Security+ and SC-200.

Tier 2 / detection engineering

Tier 2 analyst in a 24/7 SOC covering 6,000 endpoints and ~40 cloud accounts. Cut the queue's false-positive rate from 71% to 38% by rewriting the noisiest detections, taking median triage from 22 minutes to 9. Authored 30+ Sigma rules mapped to MITRE ATT&CK and led containment on four confirmed intrusions.

Cloud security focus

Security analyst focused on cloud posture across ~200 AWS accounts. Built the guardrail set that cut publicly exposed storage findings to zero and kept them there through two quarters of growth. Write detections in KQL and Terraform-managed policy; partner with platform engineering rather than filing tickets at them.

GRC / compliance track

Security analyst on the governance side: control testing, evidence collection and risk register ownership for a regulated financial services business. Ran two SOC 2 Type II cycles and an ISO 27001 surveillance audit with no major nonconformities, and rebuilt the access-review process that had been the previous cycle's finding.

Skills that belong on a cybersecurity analyst resume

Detection and response

  • SIEM (Splunk, Sentinel, Elastic)
  • EDR (CrowdStrike, Defender, SentinelOne)
  • Detection engineering (Sigma, KQL, SPL)
  • MITRE ATT&CK mapping
  • Incident response and containment
  • Threat hunting

Infrastructure and cloud

  • Cloud security (AWS, Azure, GCP)
  • Identity and access management
  • Network security and traffic analysis
  • Vulnerability management (Nessus, Qualys)
  • Endpoint hardening
  • Log pipeline and telemetry design

Governance and tooling

  • Frameworks (NIST CSF, ISO 27001, CIS)
  • SOC 2 / audit evidence
  • Risk assessment
  • SOAR automation
  • Python / PowerShell scripting
  • Security awareness and phishing programmes

Bullet point formulas that get interviews

Fill the brackets with your numbers — the structure does the selling.

  • Triage [n] alerts a week across [scope] — e.g. “~120 a week across 6,000 endpoints and 40 cloud accounts.”
  • Cut false positives from [x]% to [y]% — e.g. “71% to 38% by rewriting the eight noisiest detections.”
  • Reduced MTTD/MTTR from [x] to [y] — e.g. “Median time to triage from 22 minutes to 9.”
  • Authored [n] detections mapped to [framework] — e.g. “30+ Sigma rules mapped to MITRE ATT&CK.”
  • Led containment on [n] confirmed incidents — e.g. “Four intrusions: isolation, credential revocation, handover to the IR retainer.”
  • Cut critical vulnerabilities from [x] to [y] — e.g. “340 to under 40 in nine months by rebuilding the maintenance-window process.”
  • Automated [process], removing [effort] — e.g. “Phishing triage in SOAR, removing ~300 manual steps a month.”
  • Passed [audit] with [outcome] — e.g. “Two SOC 2 Type II cycles with no major nonconformities.”
  • Closed a coverage gap — e.g. “Added detection for an ATT&CK technique the previous rule set missed entirely.”
  • Ran [review/programme] with [n] people — e.g. “Weekly detection review with two junior analysts; maintain the on-call runbook.”

ATS keywords for cybersecurity analyst roles

Filters match tokens from the posting. These are the terms worth mirroring — verbatim — when they appear in the job ad.

KeywordPriority
SIEM (Splunk, Microsoft Sentinel)High
incident responseHigh
EDR (CrowdStrike, Defender)High
MITRE ATT&CKHigh
vulnerability managementHigh
threat huntingHigh
log analysis / correlationHigh
cloud security (AWS, Azure)High
NIST CSF / ISO 27001Medium
Security+ / CySA+ / CISSPMedium
SOAR / automationMedium
phishing analysisMedium
Python / PowerShellMedium
identity and access managementMedium

Don't guess — score your resume against the specific posting and see exactly which terms are missing.

How to write a cybersecurity analyst resume

  1. Lead with alert volume and what you did to the noise

    Alerts triaged per week, across how many endpoints, users or accounts — then the false-positive rate before and after you tuned. Everyone in a SOC triages alerts; the analyst who measurably reduced the noise is the one who understands the detections rather than just clicking through them.

  2. Give a time metric

    Mean or median time to detect, triage, contain or respond. If your organisation does not track it formally, use what you have — escalations per shift, queue depth at handover, repeat alerts eliminated. Time is the currency of detection work and almost no resume quotes it.

  3. Describe incidents by action and role, never by identity

    'Led containment on four confirmed intrusions — isolation, credential revocation, handover to the IR retainer.' No client name, no attacker attribution, no description of what data was at risk. Employers are watching how you handle sensitive information while you tell them how you handle sensitive information.

  4. Put detections and automation above certifications

    Rules authored, frameworks mapped, playbooks written, manual steps removed. Certifications clear filters and open the first door; written detections and automation are what move you out of tier 1. If you have a public repository of rules or scripts, link it as visible text.

  5. Name the stack exactly as the posting does

    Splunk and Sentinel are not interchangeable to a filter, and CrowdStrike, Defender and SentinelOne are different tools with different query languages. Security hiring matches literally on the installed platform, because retraining and migration are expensive.

Skip the blank page.

Build this resume in Resumap — free templates, unwatermarked PDF, and an ATS check against the exact posting when you're ready.

Start free

Mistakes that filter cybersecurity analysts out

A resume that is mostly a certification list

Certifications open the first door and stop mattering after it. Lead with alert volume, tuning, detections and outcomes.

Describing an incident in identifying detail

No employer, client, sector-plus-date combination or data description. Actions and your role only — this is part of the assessment.

'Monitored security alerts' with no volume

Volume and false-positive rate are what distinguish analysts. Without them the claim is the job description.

Listing every tool you have opened once

Name the platforms you can be questioned on, and show query-language depth in the bullets. A 30-tool list reads as a course syllabus.

No evidence of anything written

Detections, playbooks, scripts, automations. Security work that produces artefacts is what gets you past tier 1 — and a public repository is worth more than another certificate.

Claiming offensive skills without evidence

'Penetration testing' with no engagements, no methodology and no lab record invites a technical screen you will fail. Say what you have actually done, including in a lab, and label it as such.

Ignoring the IT background you came from

Endpoint, network and systems administration experience is genuinely valuable in a SOC — it is why you understand what normal looks like. Frame it as the foundation, not as a gap.

Cybersecurity Analyst salary ranges (US)

United States market. Absolute figures differ by country — the gaps between levels travel better than the numbers.

Median (information security analysts, May 2024)$124,910
Entry / tier 1 SOCwell below the median; this is the crowded end
Tier 2 / incident responsearound the median, depending on sector
Detection engineering and cloud securityabove the median
Growth note+29% projected through 2034, but on a small base

BLS median for information security analysts is $124,910 (May 2024), with employment projected to grow 29% through 2034 — much faster than average — and roughly 16,000 openings a year. Note the shape of that: a very high growth rate on a comparatively small base, which is why the field feels simultaneously fast-growing and hard to break into. Pay separates by track — cloud security, detection engineering and offensive roles sit above general SOC analysis.

Primary source: U.S. Bureau of Labor Statistics (OEWS/OOH). Self-reported aggregator figures are labelled as such.

Certifications worth listing

  • CompTIA Security+ — the standard entry credential, and a hard filter in government and defence-adjacent roles
  • CompTIA CySA+ or Microsoft SC-200 — the analyst-level step up; SC-200 matters where the shop runs Microsoft's stack
  • OSCP — the credential that signals genuine hands-on offensive capability; expensive in time, and respected accordingly
  • CISSP — management-leaning and experience-gated; valuable for senior and GRC roles, less so for hands-on analysis
  • Cloud security certifications (AWS Security Specialty, AZ-500) — increasingly the differentiator, since most new attack surface is cloud

Templates that fit cybersecurity analyst resumes

Cybersecurity Analyst resume FAQ

Why is entry-level security hard if the field is growing 29%?

Because the growth is on a comparatively small base — roughly 16,000 openings a year — while the supply of certified entry candidates is very large. Most successful entries come sideways from IT support, systems or network administration, where you have already learned what normal looks like on a network.

What numbers should a security analyst put on a resume?

Alerts triaged per week and the scope they cover, false-positive rate before and after tuning, time to triage or contain, detections authored, vulnerabilities closed, manual steps automated, and audit outcomes. Volume shows scale; the rest shows judgement.

How do I write about an incident I worked without disclosing it?

Describe your actions and role in general terms — 'led containment on a confirmed intrusion: isolation, credential revocation, handover to the IR retainer'. Never name the employer's client, the sector plus date, the attacker, or what data was at risk. Employers read disclosure discipline as a core competency, and the resume is the first sample of it.

Which certification should I get first?

Security+ if you are starting, because it clears the most filters, especially in government-adjacent work. Then CySA+ or SC-200 depending on the stack you want to work in. Save OSCP for when you are targeting offensive work specifically, and treat CISSP as a later, experience-gated credential.

Does a home lab count as experience?

It counts as evidence, not experience — and it is worth including early. Describe what you built and what it detected: 'Sentinel and Sysmon lab, 12 detections published, including one for a technique I could not find public coverage for'. That is far more persuasive than another course completion.

Do I need a clearance to work in security?

Only for government and defence-contract roles, where it can be decisive and expensive for an employer to sponsor. If you hold one, state the level and status — it is one of the few resume lines that can move you to the front of a queue by itself.

How long should a security resume be?

One page early, two once you have incident work, detection engineering and a real tool set. Keep the alert volume, the tuning result and the platform names in the first half of page one — that is what a SOC lead reads before deciding.

More resume examples

Your cybersecurity analyst resume, done properly — free.

Unwatermarked PDF, ATS-safe templates, and a real score against any posting when you want it.

Build my resume