How to write it
Certifications go where they'll be found
Security is one of the few fields where certifications are a genuine screening gate. Security+, GCIH, GSEC, CISSP, CISM and the cloud security certifications are often written into the requisition, and sometimes into the client contract, so a recruiter is looking for those exact strings.
Put them in their own clearly labelled section with the issuer and year, and mention the headline one in your summary if it's the role's stated requirement. This is the opposite of the advice for software engineering, and it's because the market is different.
Incidents are the proof; describe them safely
Nothing establishes a security analyst faster than incidents actually handled. The trick is writing them without disclosing anything you shouldn't: describe the class of incident, the scale, your role, and the time to contain — never client names, internal tooling detail, or anything that would help an attacker.
"Business email compromise contained in 22 minutes with no funds lost" is specific, impressive and discloses nothing. Volume works too: 40 confirmed incidents, or 200 alerts triaged per shift, establishes the environment you've operated in.
Detection engineering separates analysts from alert-watchers
Tier 1 triage is necessary work and it's also where the largest number of candidates sit. What moves you above it is improving the detections themselves: rules written, coverage mapped to ATT&CK, false positives eliminated, playbooks automated.
The metric pair to aim for is noise down and quality up together, because either alone is ambiguous — "cut alert volume 64% while raising true-positive rate from 12% to 38%" proves you tuned rather than just suppressed.
- Detection rules written or tuned, and ATT&CK coverage added
- Alert volume and true-positive rate, before and after
- Mean time to detect, and mean time to contain
- Time to patch critical vulnerabilities, before and after
- Phishing click rate across a simulation programme
Compliance work is worth real space
Analysts often treat audit support as the boring part of the job and leave it off. That's a mistake: SOC 2, ISO 27001, PCI DSS and GDPR work is directly commercially valuable, and someone who has produced technical evidence for a clean audit is solving a problem the business feels acutely.
Name the framework and the result. "Owned the technical evidence for the first SOC 2 Type II, passed with no exceptions" is a sentence a hiring manager can take to their own leadership as a reason to hire you.
Show risk reduced, not vigilance performed
Monitoring is an activity; reduced risk is an outcome. Wherever you can, express the work as an exposure that shrank — endpoints patched faster, credentials rotated, an attack path closed, a click rate that fell.
This framing also handles the field's awkward reality that a good quarter looks like nothing happening. You can't quantify breaches that didn't occur, but you can quantify the window an attacker would have had.
