Cyber Security Analyst Resume Sample (USA): SOC Analyst Resume Example for 2026
Complete guide · 12 min read · Updated 2026
A security résumé is read by someone deciding which shift, which tier and which alerts they can hand you. Before they read a single bullet they are looking for three things: the size of the environment you have worked in, the tools you have worked in it with, and whether you have run an incident yourself or only escalated one. Everything else on the page argues for those three.
Below is a complete cyber security analyst résumé sample for a US security operations career, annotated section by section, plus what changes for a first security job, for a detection engineering or cloud security move, and for the UK, Canada and Australia. The sample is a senior analyst with seven years across a managed security provider and a health insurer, working Tier 3 and writing the detections the rest of the team runs.
How does your cyber security analyst resume score?
Upload your resume and get its ATS score out of 100, with each finding quoting the line it is about. Free, no account, and the file never leaves your browser — it is read locally and scanned on the results page.
Choosing your template
A security résumé is a tools-and-scale record wrapped around an incident history, and a single-column layout is what keeps the two attached. Single column keeps the platform next to the volume it handled, the certification next to its date, and the framework next to the work it governed. Split those into a sidebar and an applicant tracking system can lift them apart, so "Splunk Enterprise Security, CrowdStrike Falcon, Sigma and MITRE ATT&CK" arrives at a hiring manager as four unconnected words. Security recruiters run keyword searches against their applicant pool more aggressively than almost any other field, because the tool names are unambiguous, so the layout that keeps each term inside its context is the one that gets read rather than only matched.
Browse all 20 templates →Section-by-section: what to write
Header and title line
Put the tier and the strongest credential in the title line. "Senior Security Analyst · SOC Tier 3 & Detection Engineering" answers what level you work at and what you do at that level before anything else is read. Then use the website field for something a security team can click: a public repository of detection rules, a write-up blog, a CTF profile. It is the one field on this résumé that shows work rather than describing it.
Professional summary
Three lines, and at least three numbers. Years, the tier you work at, the size of the environment, and one outcome the team felt. Skip "passionate about cyber security" and skip "detail-oriented": every candidate in the pile has written both, and neither can be checked. The single most useful phrase you can put here is the scale of your environment, because it tells a manager which of their problems you have seen before.
Experience: the current role
Open by sizing the environment rather than with a verb. Log volume, endpoint count, cloud accounts and the SIEM by name tell a hiring manager what level you operate at before a single achievement lands. Then give the numbers a security leader acts on: time to contain, alert volume before and after tuning, technique coverage, and one incident you ran end to end.
The Tier 2 years, kept as their own entry
Split the promotion into two entries rather than collapsing it. It dates the move from triage into investigation, which is the exact transition a hiring manager is trying to place you against, and it gives the queue work somewhere to live. Alert volumes, SLA attainment and the automation you built to survive the volume all belong here, not in the senior entry.
The managed provider years
Time at an MSSP or managed provider is the strongest thing on many security applications and the thing candidates most often undersell. Multi-tenant exposure means you have seen more environments in two years than most in-house analysts see in ten. Write the tenant count, the shift pattern, the alert volume per shift and the SLA, because those four numbers are what make the experience legible.
The job you came in from
Keep the help desk, network or sysadmin job, and keep it to one line. Almost nobody starts in security, so this entry dates the start of your technical career and quietly answers where the fundamentals came from. What it must not do is take the space the certifications block needs.
Education
One block, and do not let it argue with the certifications. Name the degree and the concentration if it is technical, and add anything that shows security specifically: a capstone, a competition team, a lab you built. If your degree is unrelated or you do not have one, put education after certifications instead and let the credentials lead.
Skills, split four ways
Detection and response, security platforms, cloud and identity, scripting and frameworks. Four labelled groups let a manager confirm four separate capabilities at a glance, and the split stops you writing "security tools" where the posting says Splunk, Sentinel or CrowdStrike by name. Name every product individually. A keyword search against an applicant pool matches the product, never the category.
Certifications
Every line gets an issuing body and a date, and anything on a renewal cycle gets its last renewal. Security certifications expire, hiring managers know it, and an undated credential reads as one that lapsed. Order them by what the posting asks for rather than by prestige: a Security+ that satisfies a contract requirement outranks a CISSP the role never mentioned.
Cyber Security Analyst resume sample, annotated
Talia Brennan, a senior security analyst in Austin with seven years across a managed security provider and a 4,200-employee health insurer, working Tier 3 and owning 184 version-controlled detections in Splunk Enterprise Security
Seven years, four employers, four labelled skill groups and a six-line certifications block on one page. Read it as a structure to copy rather than wording to copy, and pay attention to where the annotations say it falls short, because a sample that only praises itself teaches nothing.
The annotations follow the page top to bottom, in the order a security hiring manager reads it.

Header and title line
"Senior Security Analyst · SOC Tier 3 & Detection Engineering" is the best decision on the page. Seniority, tier and speciality arrive together in one line, which is the set a manager needs in order to know whether to keep reading. Most security résumés bury the tier inside a bullet halfway down and make the reader work it out.
The repository link in the header
A public detection-rules repository sits in the contact line next to the email. It is the only field on the page that shows work instead of describing it, and it costs nothing. The caveat is real: if you put one there, it has to have something in it, because a curious reviewer will open it inside the first minute.
Professional summary
Three lines carrying seven years, a tier, an environment size, a rule count and a containment figure. The strongest phrase is "cut median time-to-contain from 4h 10m to 38 minutes", because it is the metric a security leader is measured on personally. The weakest is the last clause about writing reports that go to counsel, which is true but reads as a flourish where a number would do more.
First entry: the sizing bullet
"12 TB/day into Splunk Enterprise Security, 5,600 endpoints in CrowdStrike Falcon, Microsoft 365 and three AWS accounts" answers the level question before any achievement lands. Compare it with the "monitored security alerts using SIEM tools" that opens most résumés in this field, which would equally describe someone on their first week.
The detection library bullet
184 rules under version control, technique coverage from 71 to 148, each rule with a linked playbook. This is the line that separates an analyst from a senior analyst. Version control is the detail most candidates leave out and the one a detection engineering manager notices, because it says the rules are maintained rather than accumulated.
The time-to-contain bullet
4h 10m to 38 minutes, with the mechanism named: host isolation, token revocation and password reset moved into three SOAR playbooks. The before-and-after pair does the work here. A single figure would leave the reader unable to tell whether it was good, and naming the three actions makes the claim checkable in an interview.
The alert tuning bullet
1,900 to 700 alerts a week, with the method attached and four rules retired for never having produced a true positive. Alert fatigue is the problem every SOC manager is living with, and this is the bullet that says you reduce their load rather than add to it. The 63% is fine, but the raw pair of numbers is what makes it land.
The business email compromise bullet
One incident, run end to end, with a containment time, a concrete artefact count and a stated outcome. This is the bullet that answers "have you actually run something", and it is worth more than three general responsibility lines. Note that it names the regulatory step too, which is what makes it a health-sector résumé rather than a generic one.
Splitting the promotion into two entries
Meridian appears twice, which dates the move from Tier 2 triage into Tier 3 investigation and gives the queue work its own home. The phishing pipeline bullet is the one most people would cut first, and it should not be: building automation to survive your own alert volume is exactly the instinct that gets someone promoted.
The managed provider years
"30 client tenants in IBM QRadar and Microsoft Sentinel; 60 to 80 alerts a shift against a 15-minute acknowledgement SLA" is the sentence that makes an in-house application from an MSSP background credible. Two SIEMs and thirty environments in under two years is breadth an in-house analyst cannot easily match, and most MSSP candidates never write the tenant count down.
The runbook bullet
22 playbooks covering the alert types behind 80% of volume, written after auditing which escalations were being passed up untriaged. It shows initiative without using the word, and the audit clause is what turns it from a documentation task into a diagnosis. The weakness is that "still in use" is unverifiable and would be better as the year it was written.
The first job, kept to one line
Correctly sized. It dates the start of the technical career, explains where the endpoint and account fundamentals came from, and then gets out of the way. Three bullets about a help desk role that ended in 2019 would have cost the certifications block its space.
Skills, split four ways
The four groups are the right four for this field, and the second row is what makes this résumé surface when a company searches its applicant pool for Splunk or CrowdStrike. The weakness is inside the first group: "NIST SP 800-61" is a framework sitting in a detection and response row, and it belongs in the fourth group with the other standards.
Certifications at the bottom
Six lines, each with an issuing body and a date, and three carrying renewal years. The placement works only because the title line already carried the tier and the summary named CISSP and GCIA; without that, this block belongs directly under the summary. Ordering by prestige rather than by relevance is the one thing worth changing per application.
The honest gap
There is no cloud security certification and no mention of a clearance, and for a large slice of US security roles the second one is the first filter. There is also nothing about mentoring or on-call leadership, which undersells a senior analyst who plainly runs a rotation. Bring those to the interview; the résumé's job is to get you into the room.
What a security hiring manager checks in the first few seconds
Security hiring is a staffing problem before it is a judgement problem. A team has a rota with a hole in it, a queue that is too long, and a stack of applications where half the candidates have written the same four sentences. The first pass is a series of yes-or-no checks rather than a considered read, and a gap at any one of them ends it.
Five questions, roughly in this order.
Turn security duties into evidence: eight rewrites
Every line below is a real thing security analysts write. The rewrite carries the same fact and adds the scale, the tool or the consequence that makes it worth reading.
Instead ofMonitored security alerts using SIEM tools.
WriteTriaged 60 to 80 alerts a shift across 30 client tenants in IBM QRadar and Microsoft Sentinel, against a 15-minute acknowledgement SLA.
The first version describes a category of work that includes someone on their first day. The second establishes volume, tooling, multi-tenant exposure and the clock you worked against.
Instead ofResponded to security incidents.
WriteContained a business email compromise across 3 mailboxes in 22 minutes: 41 malicious forwarding rules removed, credentials rotated, no funds lost.
"Responded to incidents" is the job description. One incident with a time, a count and an outcome proves you have actually done it, and it gives the interviewer something specific to ask about.
Instead ofReduced false positives.
WriteCut alert volume 63%, from 1,900 to 700 a week, by tuning the ten noisiest rules against a sampled month and retiring four that had never produced a true positive.
A percentage with no denominator cannot be pictured. Adding the method also shows judgement: retiring a rule takes more confidence than tuning one.
Instead ofCreated detection rules for the SIEM.
WriteOwn 184 Sigma detections in Git, each mapped to MITRE ATT&CK with a linked response playbook; technique coverage 71 to 148 in 14 months.
Rule count alone says volume. Version control, framework mapping and paired playbooks say the library is maintained and usable, which is the difference between detection engineering and rule accumulation.
Instead ofWorked on vulnerability management.
WriteTracked remediation against Tenable output for 5,600 assets and drove critical-severity mean time to remediate from 47 days to 12.
Vulnerability management is mostly chasing other teams. The asset count shows the scale of the chasing and the MTTR pair shows you were good at it.
Instead ofAutomated SOC processes.
WriteBuilt a phishing triage playbook that detonates attachments, checks senders against threat intel and quarantines tenant-wide; 4,100 reports in year one, median triage 6 minutes.
"Automated processes" could mean an email filter. Naming the steps, the annual volume and the resulting triage time turns it into a system the reader can imagine inheriting.
Instead ofParticipated in purple team exercises.
WriteRan purple-team exercises with an external red team twice a year; converted 19 of 23 findings into deployed detections within 30 days.
Participation is attendance. The conversion ratio and the deadline are what show the exercise produced something, which is the part most organisations fail at.
Instead ofImproved incident response times.
WriteCut median time-to-contain from 4h 10m to 38 minutes by moving host isolation, token revocation and password reset into three SOAR playbooks.
Time to contain is the metric a security leader reports upward, so quoting it speaks their language. Naming the three automated actions makes the improvement checkable rather than asserted.
A first security job: what actually counts
Nobody starts in security, and every hiring manager in the field knows it, so a career-change or graduate application is a normal application rather than a weak one. What changes is what the page leads with.
What to lead with, by kind of employer
The same seven years should be arranged differently depending on where you are sending it. This is the edit most analysts never make, and it costs them interviews at the places they most want.
| Where you are applying | Lead with | Do not bury |
|---|---|---|
| In-house SOC, large enterprise | Environment size, SIEM and EDR by name, tier, time-to-contain | On-call rotation experience and any mentoring of junior analysts |
| Managed security provider | Alert throughput, SLA attainment, multi-tenant exposure, shift work | Runbook and documentation work, which MSSPs value more than most |
| Detection engineering | Rule counts, ATT&CK coverage, version control, false positive rates | Scripting, testing method and anything you have published |
| Cloud security | CloudTrail, GuardDuty, Entra ID, Kubernetes audit logs, infrastructure as code | Identity work, because most cloud incidents are identity incidents |
| Government or defence contractor | Clearance level and status, then the framework you worked under | Certifications that satisfy a contractual baseline, dated |
| Small company, first security hire | Breadth: response, vulnerability management, identity, awareness, policy | Anything you built alone and any vendor you managed |
Certifications, written so a manager can act on them
This block is short and it is the one most often written carelessly. Three rules cover it.
First, name the issuing organisation and date it. ISC2, GIAC, CompTIA, ISACA, Microsoft and Offensive Security all issue different things with different weight, and "Security Certified" with no issuer and no year tells a reader nothing except that you have not thought about how it reads.
Second, show the renewal, because these credentials expire and hiring managers know the cycles. CompTIA's continuing education pages state that activities must be completed during a three-year renewal cycle, and that renewal takes 50 continuing education units for Security+, 60 for CySA+ or PenTest+, and 75 for SecurityX. Writing the year certified and the year last renewed answers a question the reader would otherwise carry into the interview.
Third, order them by what the posting asks for, not by prestige. A CISSP at the top of a hands-on Tier 2 application can read as overqualified or as paper-heavy; the same line below a GCIH reads as breadth. Move them.
Outside the US: the same résumé, a different gate
The structure of this page travels unchanged: size the environment, name the tools, quote the metrics, date the certifications. What changes is the vetting and the vocabulary, and getting those wrong is the quickest way to look like an outsider to the market you are applying in.
In the United Kingdom the document is a CV rather than a résumé, two pages is normal rather than indulgent, and security clearance is a gate on a large share of roles. Where you hold SC or DV, put it in the header with its status. Certifications read much as they do in the US, and the professional body most often named in job adverts is the Chartered Institute of Information Security, so a membership grade is worth a line where you hold one.
In Canada the résumé conventions follow the US closely, but the federal and defence market runs on its own clearance levels, and Quebec applications may need to be in French. Name the province in your location line, because eligibility and language expectations both turn on it.
In Australia and New Zealand the document is a CV, and the government and defence market runs on Australian Government security clearances at Baseline, NV1 and NV2. Citizenship requirements attach to those, so state your status plainly rather than leaving a reader to infer it. Commercial roles read much like the US ones, and the Essential Eight is the framework worth naming where your work touched it.
What happens after the résumé, and what it means for the page
Security hiring verifies more than most fields and does it earlier. Certifications are confirmed against the issuing body's register, which is public for GIAC and ISC2 and verifiable by code for CompTIA. Employment history and criminal record go through a background screening company. Cleared roles run a full investigation, and a discrepancy found there is far more serious than the same discrepancy anywhere else.
That changes how you write the page rather than whether you write it. Date credentials exactly as they read on the certificate, do not round a log volume or an endpoint count upward, and do not describe a lab exercise in language that implies production. Everything on a security résumé that matters is checkable, which is precisely why the checkable version of each claim is also the persuasive one.
It is also worth knowing what an employer keeps afterwards. Our guide to how long employers keep your résumé covers what the tracking system is set to do with your file once the process ends, and how to ask for it back or ask for it gone.
Keywords ATS looks for
Weave these into your resume where they’re true to your experience, and always mirror the exact wording from the specific job post you’re applying to.
Common mistakes to avoid
Cyber Security Analyst resume: FAQ
What should a cyber security analyst put on a resume?
The tier you work at, the size of the environment, the tools by name, and three or four numbers a manager can check. Log volume and endpoint count for the environment, the SIEM and EDR by product name, time to detect or contain, alert volume before and after tuning, and one incident you ran from first alert to closure. Certifications come next with their issuing bodies and dates. Frameworks and soft skills come last, because the first screen is about what you can be handed on your first shift.
Do you need a certification to get a cyber security analyst job?
Not universally, but it is the fastest way past an automated screen, and some employers make one contractual. CompTIA's own continuing-education pages show what you are signing up for: activities must be completed during a three-year renewal cycle, and renewal takes 50 continuing education units for Security+, 60 for CySA+ and 75 for SecurityX. Put the year certified and the year last renewed on every line, because an undated certification reads to a hiring manager as one that has expired.
How do I write a cyber security resume with no experience?
Lead with things that can be verified rather than with enthusiasm. A certification or a booked exam date, a home lab described concretely enough that someone could rebuild it, detection rules or scripts in a public repository, a CTF ranking, a degree concentration. Then the transferable half: help desk, networking or sysadmin work where you handled access, patching or an incident of any kind counts, and should be written in security language. One documented investigation you actually completed, even in a lab, beats a paragraph about a passion for cyber security.
Is CISSP worth putting on an analyst resume?
Yes when you hold it, but know what it signals. ISC2 requires a minimum of five years of cumulative paid work experience in two or more of the eight domains of its CISSP exam outline, and someone who passes the exam without that experience becomes an Associate of ISC2 with six years to earn it. So the credential reads as seniority and breadth rather than as hands-on depth, which means on a hands-on analyst application it should sit alongside a technical certification rather than instead of one. If you are an Associate, write "Associate of ISC2" honestly; a hiring manager who spots the difference and was not told will assume the rest of the page is padded too.
How long should a cyber security analyst resume be?
One page up to about ten years, two after that or where a clearance and a long project list genuinely need the room. Security work compresses well because most of what matters is a tool list, an environment size, a handful of metrics and a certification block. The sample on this page is seven years across four employers on a single page, which is what it looks like written tightly rather than cut.
Should I put a home lab or a CTF on my resume?
Early on, yes, and prominently. A hiring manager reading a junior application is trying to find any evidence of real hands on real systems, and a lab with named components and a stated purpose supplies it. Write what it runs and what you did with it, not that it exists. Once you have two or three years of paid security work the lab moves to a single line at the bottom, and after five it usually comes off, because the job history now makes the same argument better.
What is the difference between a SOC analyst and a security engineer resume?
A SOC analyst résumé argues about investigation: alert volume, triage speed, time to contain, and the incidents you ran. A security engineer résumé argues about what you built and operate: log source onboarding, tooling deployments, infrastructure as code, integrations, and the platforms you own. Detection engineering sits between them and is written like engineering — rule counts, version control, coverage and false positive rates. Write for the one in the posting, and if you have done all three, lead with the one the job title names.
What is the job outlook for information security analysts?
Strong, and one of the few technology roles still projected to grow quickly. The US Bureau of Labor Statistics puts 2025 median pay for information security analysts at $129,180 a year, employment at 192,900 jobs in 2025, and a 2025 to 2035 job outlook of 21%, which it classes as much faster than average, with about 14,100 openings projected each year on average over the decade. Typical entry-level education is listed as a bachelor's degree, though in practice certifications and demonstrable hands-on work substitute for it more often in this field than in most.
Does a security clearance belong on a resume?
In the US, yes, and near the top: put the level and its status in the header or the summary, because for cleared roles it is the first filter and an uncleared application is usually not read at all. Write the level and whether it is active or lapsed, and nothing more than that. Outside the US the equivalents matter less on the page but still belong in the header where you hold one, such as UK SC or DV, or an Australian Baseline or NV1.
