Cybersecurity Analyst Resume Examples & Writing Guide
A cybersecurity analyst resume gets an interview when the first screen shows the tools you have actually used (SIEM, EDR, vulnerability scanner, by name), the volume you handled (alerts per shift, incidents, assets), your certifications (Security+ at minimum, CySA+ or GCIH for SOC roles) and one detection or response result with a number. Below: a full SOC analyst sample, summaries, bullets, certifications and a no-experience version.
Cybersecurity analyst resume example (SOC analyst, tier 2, 4 years)
This sample is for an analyst who came up through the help desk, spent two years in a managed security provider's SOC and now works in-house at a hospital system. The name, employers and school are made up. Entry-level and career-change versions are further down; the layout stays the same, the scale changes.
Devon Okafor
Cybersecurity Analyst (SOC Tier 2)
Atlanta, GA · (404) 555-0192 · devon.okafor@email.com · linkedin.com/in/devonokafor-sec · github.com/dokafor-detections
Summary
Cybersecurity analyst with 4 years in security operations, including 2 years of tier 1 and tier 2 work at a managed security service provider covering 60 client networks and 2 years in-house at a 4-hospital health system. Triage 80 to 120 SIEM alerts a shift in Splunk and Microsoft Sentinel, lead incident response for endpoint and email compromises, and write detection rules mapped to MITRE ATT&CK. Cut mean time to respond on high-severity alerts from 4.2 hours to 55 minutes. CompTIA Security+, CySA+, GIAC GCIH, Microsoft SC-200.
Experience
Cybersecurity Analyst II · Regional health system (4 hospitals, 11,000 endpoints, HIPAA-regulated)
Jul 2024 – Present
- Monitor and triage 80 to 120 alerts a shift in Microsoft Sentinel and CrowdStrike Falcon across 11,000 endpoints and 14,000 users, escalating an average of 6 true positives a week to incident response.
- Lead response on 40+ confirmed incidents in 2025 (business email compromise, malware on clinical workstations, credential stuffing), containing 92% within one hour of detection.
- Wrote 35 KQL analytics rules mapped to MITRE ATT&CK techniques, which raised true-positive rate on the top 20 alert types from 31% to 58% and removed 1,400 noisy alerts a month.
- Run the monthly phishing simulation for 14,000 staff in Proofpoint; click rate fell from 11.8% to 4.1% over 12 months with targeted retraining for repeat clickers.
- Own weekly Tenable vulnerability reports for 3 clinical application teams: critical findings open over 30 days fell from 210 to 38 in nine months.
SOC Analyst (Tier 1, promoted to Tier 2 in Aug 2023) · Managed security service provider (24x7 SOC, 60 mid-market clients)
Jun 2022 – Jun 2024
- Worked rotating 12-hour shifts in a 24x7 SOC, triaging 150+ alerts a shift in Splunk Enterprise Security and SentinelOne for clients in finance, manufacturing and healthcare.
- Handled 300+ client escalations a year as tier 2, including 18 ransomware precursors caught and isolated before encryption, with written incident reports to client IT leads within 24 hours.
- Built 22 Splunk correlation searches and 9 SOAR playbooks in Splunk SOAR, automating enrichment (VirusTotal, AbuseIPDB, WHOIS) and cutting tier 1 handling time per alert from 11 to 6 minutes.
- Tuned alert thresholds for 12 clients, reducing false positives by 38% in six months without a missed true positive in post-incident reviews.
IT Help Desk Technician · Logistics company (900 users, 3 sites)
Aug 2020 – May 2022
- Resolved 40 to 50 tickets a week in Active Directory, Microsoft 365, Windows 10 and endpoint imaging, and handled first-line response to 60+ reported phishing emails a month.
- Deployed and enforced multi-factor authentication for 900 users over 4 months and documented the process for the security team.
Education
Bachelor of Science in Information Technology, Cybersecurity concentration
Kennesaw State University, Kennesaw, GA, 2020
Certifications
- GIAC Certified Incident Handler (GCIH), 2025
- Microsoft Certified: Security Operations Analyst Associate (SC-200), 2024
- CompTIA Cybersecurity Analyst (CySA+), 2023
- CompTIA Security+, 2021
- Splunk Core Certified Power User, 2023
Skills
What a SOC manager checks in the first 30 seconds
Security analyst postings get hundreds of applicants, many of them career changers with a certificate and no hands-on time. SOC managers look for four things to separate people who have done the job from people who have read about it.
- Named tools with evidence of use. Not "SIEM" but "Splunk Enterprise Security" or "Microsoft Sentinel (KQL)"; not "EDR" but "CrowdStrike Falcon". Then a bullet that shows you used it: alerts triaged, searches written, hosts isolated.
- Incident handling you can tell as a story. One or two real incidents (phishing that led to a mailbox rule, malware on a workstation, a compromised service account) with what you found, what you did and how long it took. Interviewers will ask; the resume should promise the story.
- Certifications that match the level. Security+ is the floor for most analyst roles and is on the DoD 8140 list for federal work. CySA+, GCIH, GCIA, SC-200 or Cisco CyberOps Associate show SOC depth. CISSP on an entry-level resume raises eyebrows unless you have the 5 years it requires.
- Fundamentals. Networking (TCP/IP, DNS, how a packet moves), Windows and Linux logs, Active Directory basics and some scripting. Managers test these in the interview, so a resume that shows them (help desk, sysadmin, home lab, a networking cert) gets the call.
“Show me the SIEM you used, how many alerts you cleared on a bad day, and one incident you owned end to end. Candidates who list twelve frameworks and no incidents have usually never sat a shift.”
Professional summary examples for a cybersecurity analyst resume
Three to four lines under the header. Level and years first, then environment (SOC, in-house, MSSP), then tools, then one result and your certifications.
SOC analyst with 18 months on a 24x7 shift rotation at a managed security provider, triaging 100+ alerts a shift in Splunk and SentinelOne for 40 clients. Escalation accuracy of 94% in monthly quality reviews; wrote 8 correlation searches adopted across the client base. CompTIA Security+ and CySA+.
Cybersecurity analyst with 5 years protecting a 6,000-employee manufacturer: Microsoft Sentinel, Defender for Endpoint and Tenable across 8 plants. Led response on 60+ incidents including two ransomware attempts stopped before encryption, and cut critical vulnerabilities over 30 days old by 78%. GCIH, SC-200, Security+.
Help desk technician with 3 years supporting 1,200 users in Active Directory and Microsoft 365, now moving into security operations. Handled first response on 400+ reported phishing emails, rolled out MFA to 1,200 accounts, and run a home SOC lab (Wazuh, Security Onion, Sysmon) documented on GitHub. CompTIA Security+ (2026), CySA+ scheduled November 2026.
Cybersecurity graduate (B.S., 2026) with a 6-month SOC internship triaging 30 to 50 alerts a day in Microsoft Sentinel and 200+ hours of blue-team labs (LetsDefend, TryHackMe SOC Level 1, Blue Team Labs Online). Built a detection lab with Splunk and Sysmon and wrote 15 ATT&CK-mapped detections. CompTIA Security+ and ISC2 CC.
Objective or summary? Use a summary in every case. Even with no paid experience, the fresher example above says what you have done (internship, labs, detections written) rather than what you hope for.
Cybersecurity analyst experience bullets: weak to strong
Each bullet needs the tool, the volume and the outcome. Six lines that appear on hundreds of analyst resumes, rewritten with the detail a SOC manager wants. Change the figures to yours.
| Weak | Strong |
|---|---|
| Monitored SIEM for security events. | Triaged 90 to 130 alerts a shift in Splunk Enterprise Security across 7,000 endpoints, closing 85% as tier 1 and escalating true positives with full timeline and IOC list. |
| Responded to security incidents. | Led containment on 35 confirmed incidents in 2025 (BEC, infostealer malware, exposed credentials), isolating hosts in CrowdStrike within 15 minutes of confirmation and writing the post-incident report for each. |
| Analyzed phishing emails. | Analyzed 250+ user-reported phishing emails a month, pulled 40 malicious messages from 1,100 mailboxes with Microsoft Purview, and added 60 sender and URL blocks to Proofpoint. |
| Performed vulnerability scans. | Ran weekly Tenable scans on 3,200 servers and workstations, prioritized by exploitability using CISA KEV, and drove the count of critical findings open over 30 days from 180 to 22. |
| Created detection rules. | Wrote 28 KQL analytics rules in Microsoft Sentinel mapped to MITRE ATT&CK (credential access, lateral movement), which surfaced 6 confirmed incidents that existing vendor rules had missed. |
| Reduced false positives. | Tuned 14 noisy alert rules over one quarter, cutting daily alert volume by 41% (from 610 to 360) with zero missed true positives in the following six months of reviews. |
Start with an example, finish in minutes.
No sign-up to start. Download works. One-time $12 for a clean PDF, no subscription.
Cybersecurity analyst skills for your resume (tools, frameworks, fundamentals)
Group the skills section by category and keep it to 12 to 16 entries. Recruiters search applicant tracking systems for tool names, so spell them the vendor's way. List only what you have touched.
- SIEM and log platforms: Splunk Enterprise Security, Microsoft Sentinel, IBM QRadar, Elastic Security, Google SecOps (Chronicle), Sumo Logic, Wazuh (open source)
- Endpoint detection and response: CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Carbon Black, Palo Alto Cortex XDR
- Vulnerability management: Tenable Nessus and Tenable.io, Qualys, Rapid7 InsightVM, CISA KEV prioritization
- Network and perimeter: Palo Alto, Fortinet, Cisco ASA, Zscaler, Wireshark, Zeek, Suricata, Snort
- Email and identity security: Proofpoint, Mimecast, Microsoft Defender for Office 365, Okta, Entra ID (Azure AD), MFA and conditional access
- Automation and scripting: Python, PowerShell, Bash, KQL, SPL, regular expressions, Splunk SOAR, Palo Alto Cortex XSOAR, Tines
- Threat intelligence and analysis: MITRE ATT&CK, VirusTotal, AbuseIPDB, MISP, Shodan, basic malware triage in a sandbox (Any.Run, Joe Sandbox)
- Frameworks and regulations: NIST CSF 2.0, NIST SP 800-53 and 800-61, CIS Controls, ISO/IEC 27001, SOC 2, PCI DSS, HIPAA Security Rule, FedRAMP if you have touched it
- Fundamentals: TCP/IP and DNS, Windows Event Logs and Sysmon, Linux auth and syslog, Active Directory, cloud logging (AWS CloudTrail, Azure Activity Log, GCP audit logs)
Soft skills matter in a SOC but do not list them as words. Show them: "wrote incident reports read by the CISO", "trained 4 new tier 1 analysts". Clear writing under time pressure is the skill managers complain about most.
Certifications on a cybersecurity analyst resume: required, useful, and how to list them
No US state licenses a cybersecurity analyst, so certifications are how employers check your baseline. List them in a separate Certifications section with the year, most recent first, and add the ones you are studying for with the scheduled exam date.
- CompTIA Security+: the baseline. Most analyst postings list it as required or preferred, and it satisfies DoD 8140 (formerly 8570) requirements for many federal and defense contractor roles. If you have nothing else, get this.
- CompTIA CySA+: the SOC-specific step up (log analysis, threat detection, incident response). Common in postings for tier 1 and tier 2 analysts.
- GIAC GCIH (incident handling), GCIA (intrusion analysis), GSEC (fundamentals): expensive, employer-funded in most cases, and strongly respected by SOC managers.
- Microsoft SC-200 (Security Operations Analyst): valuable where the stack is Sentinel and Defender, which is most of corporate America now. Splunk Core Certified User or Power User does the same for Splunk shops.
- ISC2 Certified in Cybersecurity (CC): free training and first exam attempt through ISC2's entry-level program (a $50 annual maintenance fee applies once you pass); a reasonable first line for students. ISC2 SSCP sits one step above.
- CISSP: requires 5 years of paid experience (4 with a degree). Do not list it as "in progress" on an entry-level resume. If you passed the exam without the experience, you are an "Associate of ISC2", and that is the correct wording.
- Security clearance: if you hold an active or recently active US clearance (Secret, Top Secret, TS/SCI), put it in the header line. It is the single most searched keyword for defense and federal contractor roles.
GIAC Certified Incident Handler (GCIH), 2025 · Microsoft SC-200, 2024 · CompTIA CySA+, 2023 · CompTIA Security+, 2021 (renewed 2024)
CompTIA Security+, June 2026 · ISC2 Certified in Cybersecurity (CC), March 2026 · CompTIA CySA+, exam scheduled November 2026
Priya Anand · Cybersecurity Analyst · Active Secret clearance (2024) · Security+ CE
Cybersecurity analyst resume with no experience (entry level, fresher, career change)
"No experience" in security rarely means no relevant experience. Help desk, system administration, networking and military communications roles all contain security work if you pull it out. What you cannot skip is hands-on evidence: a SOC manager needs to see that you have looked at logs and alerts, even in a lab.
- 1Certifications and education at the top: Security+ (or the exam date), ISC2 CC, any networking cert (CompTIA Network+, CCNA), your degree or bootcamp. Add relevant coursework only if you have no certifications yet.
- 2A Projects or Home Lab section written like a job, with numbers: "Built a SOC lab on Proxmox with Wazuh SIEM, Sysmon on 3 Windows VMs and Suricata; wrote 20 detection rules mapped to MITRE ATT&CK and documented 6 simulated attacks on GitHub." Link the GitHub repository in your header.
- 3Platforms and hours, honestly: TryHackMe SOC Level 1 path completed, LetsDefend 40 alerts investigated, Blue Team Labs Online, HackTheBox Sherlocks, CyberDefenders challenges, a college CTF placement. Managers know these names and the effort each represents.
- 4Your current or past job, with the security parts pulled forward: phishing tickets handled, MFA or patch rollouts, AD account audits, firewall change requests, incident write-ups, anything with logs.
- 5Internships and volunteer work: a 3-month SOC internship is worth more than any certificate; put it under Experience with alert counts. Volunteer security work for a nonprofit (MFA rollout, a phishing test) counts too.
Built and maintain a detection lab (Splunk free tier, Sysmon, Atomic Red Team on 2 Windows VMs, pfSense); ran 40 ATT&CK techniques, wrote 18 detections and published the walkthroughs on GitHub (300+ stars).
First responder for 30 to 50 user-reported phishing emails a month: checked headers and URLs, pulled 9 confirmed malicious messages from mailboxes with the security team, and reset 25 compromised accounts.
SOC intern (summer 2026): triaged 25 to 40 alerts a day in Microsoft Sentinel under a tier 2 mentor, wrote 12 incident tickets that were escalated as true positives, and tuned 3 noisy rules that cut daily alert volume by 15%.
Format, length and ATS keywords for a cybersecurity analyst resume
- Length: one page up to about 8 years. Two pages for senior analysts, incident responders and anyone with a long list of engagements or a clearance history.
- Order for experienced analysts: header (with clearance if any), summary, experience, skills grouped by category, certifications, education. Entry level: header, summary, certifications, projects or lab, experience, education.
- Layout: single column, plain headings, standard fonts. Large companies and federal contractors use applicant tracking systems that read text only. A dark technical template such as cvplex cyber-security is fine as long as it stays single column and text-based. No photo in the US.
- Mirror the posting's exact tool and framework names when they are true for you: SIEM, EDR, incident response, threat hunting, vulnerability management, MITRE ATT&CK, NIST, SOC 2, HIPAA, PCI DSS, Splunk, Sentinel, CrowdStrike, KQL, Python. The ATS matches strings, not synonyms.
Frequently asked questions
How do I write a cybersecurity analyst resume?
Open with a 3 to 4 line summary giving your level, environment (SOC, in-house, MSSP), main tools and certifications, and one result with a number. Then give each job 3 to 5 bullets that name the tool, the volume (alerts, endpoints, incidents) and the outcome (MTTR, false positives cut, vulnerabilities closed). Group skills by category and list certifications with years. One page under about 8 years.
What skills should I put on a cybersecurity analyst resume?
The specific SIEM and EDR you used (Splunk, Sentinel, CrowdStrike, Defender), vulnerability scanners (Tenable, Qualys), incident response and phishing analysis, scripting (Python, PowerShell, KQL), MITRE ATT&CK, the frameworks and regulations you have worked under (NIST, SOC 2, HIPAA, PCI DSS) and fundamentals such as TCP/IP, Windows and Linux logs and Active Directory. Only list what you can talk through in an interview.
How do I write a cybersecurity analyst resume with no experience?
Put certifications first (Security+ at minimum, ISC2 CC if you have it), then a Projects or Home Lab section written with numbers (detections written, attacks simulated, labs completed on TryHackMe or LetsDefend), then any IT job with its security tasks pulled forward (phishing tickets, MFA rollout, account audits). Link a GitHub with your lab notes. Keep it to one page.
Which certification is most important for a cybersecurity analyst resume?
CompTIA Security+ is the baseline most postings ask for and it meets DoD 8140 requirements for federal work. For SOC roles, CySA+, GIAC GCIH or Microsoft SC-200 add the most. CISSP is for people with 5 years of experience and should not appear on an entry-level resume as anything other than a future plan.
What is a good professional summary for a cyber security analyst?
Three lines: level and years, environment and tools, a result with a number, and certifications. Example: "SOC analyst with 2 years on a 24x7 rotation triaging 100+ alerts a shift in Splunk and SentinelOne; 94% escalation accuracy; Security+ and CySA+." Use a summary, not an objective, even at entry level.
How is a SOC analyst resume different from an information security analyst resume?
A SOC analyst resume is about detection and response: alerts per shift, incidents handled, SIEM and EDR tools, shift work. An information security analyst resume is often broader and includes governance, risk and compliance: access reviews, vendor assessments, audit evidence, policy work. Read the posting and lead with the side it emphasizes.
Ready to write yours?
The builder suggests a summary from your own experience, then checks it against the job posting.
How this page was made: a first draft was written with AI assistance from cvplex's example library, then edited and fact-checked by the cvplex Careers Team. Examples are fictional composites; numbers are illustrative. Report an error via the editorial policy page.