Cybersecurity Analyst resume example

Security hiring screens hard on two things: certifications, because compliance frameworks and clients demand them, and demonstrated incident work, because nothing else proves you can act under pressure. A security resume that carries both, with numbers, clears the filter that most don't.

Updated

Also written as Security Analyst, SOC Analyst and Information Security Analyst.

What hiring managers look for first

  • Certifications, listed prominently — this field genuinely screens on them
  • Incidents handled, with severity, volume and outcome
  • Detection engineering: rules written, false positives reduced
  • Frameworks by name — NIST, ISO 27001, SOC 2, MITRE ATT&CK
  • Evidence you reduced risk, not just monitored it

A full cybersecurity analyst resume

Every figure below is invented, but the shape is the point: each bullet names what was owned, what changed, and the number that moved. It’s laid out in the Ashford template — switching template re-renders the same content rather than starting it over.

Owen FitzgeraldCybersecurity Analyst
owen.fitzgerald@email.com+353 87 555 0142Dublin, Irelandlinkedin.com/in/owenfitzgerald

SUMMARY

Security analyst with 5 years in a 24/7 SOC and a detection engineering bias. Cut alert noise 64% while raising true-positive rate, led response on 40+ confirmed incidents, and took the organisation through its first SOC 2 Type II.

EXPERIENCE

Security Analyst, Tier 2, Corrib Financial

May 2022 – Present

Dublin, Ireland

  • Led response on 40+ confirmed incidents, including a business email compromise contained in 22 minutes with no funds lost
  • Rewrote 120 SIEM detection rules mapped to MITRE ATT&CK, cutting alert volume 64% while raising true-positive rate from 12% to 38%
  • Ran the vulnerability management programme across 2,300 endpoints, cutting mean time to patch critical CVEs from 28 days to 6
  • Owned the technical evidence for the company's first SOC 2 Type II, passed with no exceptions
  • Built the phishing simulation programme; reported-click rate fell from 18% to 4% over four quarters

SOC Analyst, Tier 1, Shannon Managed Security

Feb 2020 – Apr 2022

Limerick, Ireland

  • Triaged ~200 alerts per shift across 30 client environments in a 24/7 SOC
  • Wrote the triage playbooks for the six most common alert types, cutting average handling time 40%
  • Escalated and documented the intrusion that led to a client's full credential rotation

EDUCATION

BSc, Computer Security & Digital Forensics, Technological University Dublin

Sep 2016 – May 2020

Dublin, Ireland

SKILLS

  • SIEM (Splunk, Sentinel)
  • Incident response
  • MITRE ATT&CK
  • EDR (CrowdStrike)
  • Vulnerability management
  • Python scripting
  • Network analysis
  • SOC 2 / ISO 27001
  • Threat hunting
  • Cloud security (Azure)

CERTIFICATIONS

CompTIA Security+, CompTIA

Jan 2020

GIAC Certified Incident Handler (GCIH), SANS / GIAC

Apr 2023

Microsoft Certified: Security Operations Analyst, Microsoft

Jun 2022

How to write it

Certifications go where they'll be found

Security is one of the few fields where certifications are a genuine screening gate. Security+, GCIH, GSEC, CISSP, CISM and the cloud security certifications are often written into the requisition, and sometimes into the client contract, so a recruiter is looking for those exact strings.

Put them in their own clearly labelled section with the issuer and year, and mention the headline one in your summary if it's the role's stated requirement. This is the opposite of the advice for software engineering, and it's because the market is different.

Incidents are the proof; describe them safely

Nothing establishes a security analyst faster than incidents actually handled. The trick is writing them without disclosing anything you shouldn't: describe the class of incident, the scale, your role, and the time to contain — never client names, internal tooling detail, or anything that would help an attacker.

"Business email compromise contained in 22 minutes with no funds lost" is specific, impressive and discloses nothing. Volume works too: 40 confirmed incidents, or 200 alerts triaged per shift, establishes the environment you've operated in.

Detection engineering separates analysts from alert-watchers

Tier 1 triage is necessary work and it's also where the largest number of candidates sit. What moves you above it is improving the detections themselves: rules written, coverage mapped to ATT&CK, false positives eliminated, playbooks automated.

The metric pair to aim for is noise down and quality up together, because either alone is ambiguous — "cut alert volume 64% while raising true-positive rate from 12% to 38%" proves you tuned rather than just suppressed.

  • Detection rules written or tuned, and ATT&CK coverage added
  • Alert volume and true-positive rate, before and after
  • Mean time to detect, and mean time to contain
  • Time to patch critical vulnerabilities, before and after
  • Phishing click rate across a simulation programme

Compliance work is worth real space

Analysts often treat audit support as the boring part of the job and leave it off. That's a mistake: SOC 2, ISO 27001, PCI DSS and GDPR work is directly commercially valuable, and someone who has produced technical evidence for a clean audit is solving a problem the business feels acutely.

Name the framework and the result. "Owned the technical evidence for the first SOC 2 Type II, passed with no exceptions" is a sentence a hiring manager can take to their own leadership as a reason to hire you.

Show risk reduced, not vigilance performed

Monitoring is an activity; reduced risk is an outcome. Wherever you can, express the work as an exposure that shrank — endpoints patched faster, credentials rotated, an attack path closed, a click rate that fell.

This framing also handles the field's awkward reality that a good quarter looks like nothing happening. You can't quantify breaches that didn't occur, but you can quantify the window an attacker would have had.

Cybersecurity Analyst skills and ATS keywords

These are the terms that appear in cybersecurity analyst postings, which is what an applicant tracking system matches your resume against. Take the ones that are genuinely true of you — a keyword you can’t defend in an interview costs more than the match is worth.

Operations

  • SIEM
  • Splunk
  • Microsoft Sentinel
  • EDR
  • CrowdStrike
  • SOAR
  • Incident response
  • Threat hunting
  • Digital forensics
  • Malware analysis

Frameworks

  • MITRE ATT&CK
  • NIST CSF
  • ISO 27001
  • SOC 2
  • PCI DSS
  • GDPR
  • Risk assessment
  • Zero trust

Technical

  • Network security
  • Firewalls
  • IDS/IPS
  • Vulnerability management
  • Penetration testing
  • Cloud security
  • Azure
  • AWS
  • Identity and access management
  • Python

Certifications

  • Security+
  • CISSP
  • CISM
  • GCIH
  • GSEC
  • OSCP
  • CEH
  • AZ-500

Mistakes that cost cybersecurity analysts interviews

  • Burying certifications at the bottom in a field that screens on them
  • Naming clients, internal tools or specific vulnerabilities you shouldn't disclose
  • "Monitored security alerts" with no volume, outcome or tuning work
  • Listing every security tool ever touched instead of what you detected or contained
  • Omitting compliance and audit work, which is commercially the easiest sell
  • Claiming penetration testing experience on the strength of a lab course

Cybersecurity Analyst resume FAQs

How do I describe incidents without breaching confidentiality?

Use the class of incident, the scale, your role and the containment time, and leave out client names, tooling specifics and anything that maps to a live weakness. "Contained a business email compromise in 22 minutes with no funds lost" is safe and strong. If in doubt, describe the outcome and omit the mechanism.

Which certification should I get first?

Security+ is the standard entry gate and appears in a large share of junior requisitions. After that, follow the work you want: GCIH or a SOC analyst certification for operations, OSCP for offensive roles, CISSP or CISM once you're heading toward management.

Can I move into security from IT support or networking?

Yes, and it's the most common route in. Lead with the security-adjacent work you already do — patching, access reviews, hardening, phishing response — get Security+ to clear the keyword filter, and be explicit in the summary that you're targeting a security role.

Do home labs and CTFs belong on a security resume?

While you're breaking in, yes — they're credible evidence of hands-on capability, and this field respects them more than most. Keep them to a compact section, name what you actually built or solved, and drop them once you have professional incident work to describe instead.

Related resume examples

Write your cybersecurity analyst resume

Start from a template, get AI help tightening every bullet, and export an ATS-ready PDF. Free to start, and no card at any point.

Start your resume