Information Security Engineer Resume Examples & Writing Guide

A security engineer resume has to show you build and run controls, not just watch alerts. Name the stack you own, the detections and automation you wrote, the vulnerability and incident numbers you moved, the cloud environments you secured, and the audits your controls passed.

By cvplex Careers Team· Reviewed by József Dorcsinecz, Founder· Updated

Information security engineer resume example (cloud and detection)

An invented engineer with a common route in: help desk, then systems administration, then SOC analyst, then security engineering. Every job names the stack owned and the number that changed.

Ivan Petrossian

Information Security Engineer

Austin, TX · (512) 555-0166 | i.petrossian.sec@email.com | github.com/ipetrossian | CISSP, AWS Security Specialty

Summary

Security engineer with 9 years across infrastructure and security, now owning detection engineering and cloud security for a 2,400-employee SaaS company. Wrote 140 production detections mapped to MITRE ATT&CK, cut median time to detect from 41 to 9 minutes, and closed a SOC 2 Type II with no exceptions two years running. CISSP and AWS Security Specialty.

Experience

Information Security Engineer · Northgate Cloud Systems (B2B SaaS, 2,400 employees, AWS and Azure)

Mar 2022 - Present

  • Owns the detection pipeline in Splunk and CrowdStrike: authored 140 production detections mapped to MITRE ATT&CK, raising technique coverage from 38% to 71% of the prioritized set.
  • Cut median time to detect from 41 minutes to 9 and false positives per analyst shift from 60 to 14 by rewriting 30 legacy correlation rules and adding asset context enrichment.
  • Built the cloud security baseline across 42 AWS accounts: SCP guardrails, GuardDuty and Security Hub aggregation, KMS key policy standards, and Terraform modules that ship the baseline with each new account.
  • Runs vulnerability management on 6,800 endpoints and 1,900 cloud workloads in Tenable; raised critical remediation inside the 14-day SLA from 62% to 94%.
  • Wrote 22 SOAR playbooks in Python that auto-triage phishing, impossible-travel and EDR quarantine alerts, removing about 55 analyst hours a month.
  • Led evidence collection and control design for SOC 2 Type II audits in 2024 and 2025, both closed with zero exceptions.
  • Ran incident response on 9 confirmed incidents, including a business email compromise contained in 38 minutes with no data exfiltration confirmed.

Security Operations Analyst · Lone Star Financial Group (regional bank, 4,000 employees)

Jul 2019 - Mar 2022

  • Triaged 90 to 140 alerts a day in Microsoft Sentinel and escalated 6 to 10 true positives a week to incident response.
  • Built the bank's phishing response workflow: user reports rose from 40 to 310 a month and the simulated phishing click rate fell from 18% to 6%.
  • Tuned the endpoint detection deployment across 4,200 devices, cutting duplicate alerts by 47%.
  • Supported PCI DSS assessments as the technical contact for logging, segmentation and access control evidence.

Systems Administrator · Lone Star Financial Group

Jan 2017 - Jul 2019

  • Administered 300 Windows servers, Active Directory and Group Policy for 4,000 users, including a domain-wide patching program at 97% monthly compliance.
  • Rolled out multi-factor authentication to 4,000 accounts in 11 weeks with a 1.2% help desk ticket rate on the migration.

Education

Bachelor of Science, Information Systems
Hill Country State University, 2016

Certifications

  • CISSP, ISC2, through 2028
  • AWS Certified Security - Specialty, through 2027
  • GCIH (GIAC Certified Incident Handler), through 2027
  • CompTIA Security+, 2018

Skills

Detection engineering (Splunk SPL, Sigma, MITRE ATT&CK)SIEM: Splunk Enterprise Security, Microsoft SentinelEDR: CrowdStrike Falcon, Microsoft Defender for EndpointAWS security: IAM, SCPs, GuardDuty, Security Hub, KMSAzure security: Entra ID, Defender for Cloud, Conditional AccessInfrastructure as code: Terraform, CloudFormationVulnerability management: Tenable, QualysSOAR and automation in PythonNetwork security: Palo Alto, segmentation, TLS and PKIKubernetes and container securityIncident response and forensics fundamentalsSOC 2, PCI DSS and NIST CSF control mapping
Fictional example. Names, employers and numbers are illustrative.Use this example in the builder →
Two pages is normal for a security engineer with more than five years. What is not acceptable is a two-page tool list with no numbers attached to any of it.

What security hiring managers check first

Security engineering interviews are expensive, so the resume screen is harsh. Four things get you through.

  • What you own versus what you have touched. Owning a SIEM, an EDR deployment, a cloud baseline or a vulnerability program is a different claim from having used those tools. Say which it is.
  • Things you built. Detections, Terraform modules, SOAR playbooks, scripts, hardening baselines, CI/CD security gates. Engineers ship artifacts, and the resume should list them by count.
  • Numbers that show the control worked. Time to detect and respond, false positive reduction, patch SLA compliance, coverage percentages, phishing click rates, audit exceptions. Security is full of numbers and most resumes contain none.
  • Environment and scale. Endpoint count, cloud accounts, employees, regulated data types. A 200-person startup and a 40,000-seat bank need different engineers, and both are legitimate.

The resumes that stand out have artifacts on them. Number of detections written, playbooks automated, accounts under a baseline you wrote. A list of every security product on the market tells me you sat near them. Tell me what you built and what number moved because of it.

Recruiter panel, Cybersecurity hiring manager, US (name published after review)

Security engineer or security analyst? Write the right resume

These roles overlap and the titles are used loosely, but hiring managers separate them cleanly. Sending the analyst version of your resume to an engineering role is the most common reason strong candidates get passed over.

  • An analyst consumes alerts and investigates. Lead with triage volume, escalation quality, investigation write-ups, mean time to respond and the frameworks you work under.
  • An engineer builds and runs the systems that produce those alerts. Lead with detections written, integrations built, infrastructure as code, tuning results and platform ownership.
  • A network security engineer version leads with firewalls, segmentation, VPN and zero trust architecture, NAC, TLS inspection and the device counts behind each.
  • A cloud security engineer version leads with IAM design, account guardrails, CSPM findings closed, Kubernetes and container controls, and infrastructure as code.
  • An application security version leads with SAST, DAST and SCA in the pipeline, findings triaged, developer training and secure code review counts.
  • Keep one master document and cut a version for each. The bullets are largely the same work reordered, but the top third has to match the posting.

Security engineer summary examples

Three or four lines: years, environment, what you own, two numbers, certification. No objectives.

Detection and cloud focus
Security engineer with 9 years across infrastructure and security, owning detection engineering and cloud security for a 2,400-employee SaaS company. Wrote 140 detections mapped to MITRE ATT&CK and cut median time to detect from 41 to 9 minutes. CISSP, AWS Security Specialty.
Network security engineer
Network security engineer managing 60 Palo Alto firewalls across 14 sites and a 9,000-device NAC deployment. Delivered a segmentation project that cut the flat internal network from 4 zones to 27 and closed 38 pen test findings in one cycle.
Cloud security engineer
Cloud security engineer for a 90-account AWS estate. Built the account baseline in Terraform, reduced high-severity CSPM findings from 1,240 to 180 in nine months, and moved 100% of production workloads to short-lived credentials.
Moving up from the SOC
Security operations analyst moving into engineering. Wrote 45 Sentinel analytics rules and 8 automation playbooks alongside triage duty, cut duplicate alerts 47% across 4,200 endpoints, and completed GCIH. Seeking a detection or cloud security engineering role.
Regulated environment
Security engineer in healthcare, covering 11,000 endpoints and HIPAA-regulated workloads. Owns vulnerability management at 94% SLA compliance, runs the annual risk assessment and closed two HITRUST assessments as the technical lead.

Start with an example, finish in minutes.

No sign-up to start. Download works. One-time $12 for a clean PDF, no subscription.

Build my security engineer resume

Security bullets: weak to strong

Security resumes are full of tool names and empty of outcomes. Every bullet below names the artifact and the number.

Tool-list bulletEngineering bullet
Used Splunk and CrowdStrike for monitoring.Authored 140 production detections in Splunk mapped to MITRE ATT&CK, raising technique coverage from 38% to 71% of the prioritized set.
Reduced false positives.Rewrote 30 legacy correlation rules and added asset context enrichment, taking false positives per analyst shift from 60 to 14 and median time to detect from 41 minutes to 9.
Worked on cloud security.Built a baseline across 42 AWS accounts (SCP guardrails, GuardDuty and Security Hub aggregation, KMS key policy standards) shipped as Terraform modules with every new account.
Managed vulnerabilities.Ran vulnerability management on 6,800 endpoints and 1,900 cloud workloads in Tenable, lifting critical remediation inside the 14-day SLA from 62% to 94%.
Automated security tasks.Wrote 22 SOAR playbooks in Python for phishing, impossible travel and EDR quarantine, removing about 55 analyst hours a month.
Assisted with compliance audits.Designed controls and owned evidence collection for SOC 2 Type II in 2024 and 2025; both audits closed with zero exceptions.
Responded to security incidents.Led response on 9 confirmed incidents, including a business email compromise contained in 38 minutes with no confirmed data exfiltration.
Ran phishing awareness training.Rebuilt the phishing response workflow: user reports rose from 40 to 310 a month and the simulated click rate fell from 18% to 6% over four quarters.
Deployed MFA.Rolled out multi-factor authentication to 4,000 accounts in 11 weeks with a 1.2% help desk ticket rate across the migration.
Hardened servers.Wrote and enforced CIS-aligned hardening baselines for 300 Windows servers, holding monthly patch compliance at 97% through Group Policy and automated reporting.
Do not name your employer's specific unpatched vulnerabilities, internal hostnames, breach details or architecture weaknesses. Percentages and counts are fine; anything that would help an attacker is not, and hiring managers treat it as a judgment failure.

Skills for a security engineer resume

Group by domain rather than dumping a list. Twelve to sixteen lines, all of it defensible in an interview.

  • Detection and monitoring: SIEM (Splunk Enterprise Security, Microsoft Sentinel, Elastic), detection engineering with Sigma and SPL or KQL, MITRE ATT&CK mapping, log pipeline and enrichment design.
  • Endpoint and identity: EDR (CrowdStrike Falcon, SentinelOne, Defender for Endpoint), Active Directory and Entra ID hardening, conditional access, privileged access management, MFA and passwordless rollouts.
  • Cloud: AWS IAM, SCPs, GuardDuty, Security Hub, KMS; Azure Defender for Cloud and Entra ID; GCP equivalents; CSPM tooling; Kubernetes and container security; secrets management with Vault or a cloud KMS.
  • Network: firewalls (Palo Alto, Fortinet, Cisco), segmentation and zero trust design, IDS and IPS, VPN, NAC, TLS and certificate management, WAF and DDoS protection.
  • Vulnerability and application security: Tenable, Qualys or Rapid7; SAST, DAST and SCA in CI/CD (Snyk, Semgrep); patch management; penetration test scoping and remediation tracking.
  • Automation and code: Python, PowerShell, Bash, Terraform, CI/CD pipelines, API integration between security tools.
  • Governance: NIST CSF and 800-53, SOC 2, PCI DSS, ISO 27001, HIPAA or FedRAMP if relevant, risk assessment, incident response planning and tabletop exercises.

Certifications: which ones carry weight

Certifications open doors in security more than in most engineering fields, especially at large and regulated employers. List the issuer and the expiry.

Senior generalist credential
CISSP, ISC2 - through Nov 2028
Cloud specialty
AWS Certified Security - Specialty - through 2027; Microsoft AZ-500 Azure Security Engineer Associate - 2025
Hands-on incident response
GCIH (GIAC Certified Incident Handler), SANS - through 2027
Offensive security
OSCP (Offensive Security Certified Professional), 2024
Entry credential
CompTIA Security+ - 2018 (superseded by CISSP)
In progress
CKS (Certified Kubernetes Security Specialist) - exam booked for Q1 2027

CISSP is the one most often listed as required or preferred in senior postings, and it needs documented experience plus an endorsement. GIAC certifications carry weight for hands-on work, OSCP for offensive skills, and the cloud provider specialties for cloud engineering roles. Security+ helps early and stops mattering later. Government and defense contractor postings sometimes reference specific approved certification lists for particular job categories, so read the posting rather than assuming your certification qualifies you.

Moving into security engineering from IT or the SOC

Most security engineers came from systems administration, networking or the SOC. The resume needs to make that path look deliberate rather than accidental.

  1. 1Reframe your infrastructure work as security work where it honestly was: patching, hardening, access control, MFA rollouts, backup and recovery, logging and network segmentation.
  2. 2Count what you built even when it was not your job title. Scripts, dashboards, detections, automations, runbooks. Engineering hiring is about artifacts.
  3. 3Take on the security work nobody wants at your current job: the vulnerability report, the audit evidence request, the phishing workflow. Then put the numbers on the page.
  4. 4Add a home lab or open-source contribution only if it is real and specific: 'built a Sigma-to-Sentinel conversion tool used by 40 people on GitHub' rather than 'home lab with pfSense'.
  5. 5Get one credible certification. Security+ to start, then GCIH or a cloud security specialty in the direction you want to go.
  6. 6Write the summary as the destination, not the history: name the kind of engineering role you want and the evidence you already have for it.
Sysadmin bullet reframed for security
Wrote and enforced CIS-aligned hardening baselines for 300 Windows servers and held monthly patch compliance at 97% through Group Policy and automated reporting.
SOC analyst bullet reframed for engineering
Wrote 45 Sentinel analytics rules and 8 automation playbooks alongside triage duty, cutting duplicate alerts 47% across 4,200 endpoints.
Project bullet from a networking role
Delivered a segmentation project across 14 sites, taking a flat internal network from 4 zones to 27 and closing 38 penetration test findings in one remediation cycle.

Format, length and keywords

  • One page under five years, two pages after. Reverse chronological. No photo and no date of birth on a US resume.
  • Put certifications and the cloud platform in the contact line. Both are hard filters in a large share of security postings.
  • Mirror the posting's stack names exactly: Splunk, Sentinel, CrowdStrike, Terraform, Kubernetes, SOC 2, PCI DSS. Applicant tracking systems match literally, and security postings are unusually specific.
  • Give environment scale in each employer line: employees, endpoints, cloud accounts, regulated data. It saves the reader from guessing at your level.
  • Skip proficiency bars and word clouds. List tools in plain text grouped by domain instead.
  • Include a GitHub link only if the repositories are current and worth reading. An empty profile costs you more than no link at all.
  • Check that the years add up: nine years in the summary means the dates below cover nine years.

Frequently asked questions

How do I write an information security engineer resume?

Lead with what you own: the SIEM, the EDR deployment, the cloud baseline, the vulnerability program. Then write bullets around artifacts you built (detections, playbooks, Terraform modules, hardening baselines) with the number each one moved: time to detect, false positives, patch SLA compliance, audit exceptions.

What is the difference between a security engineer and a security analyst resume?

An analyst resume leads with triage volume, investigations and escalation quality. An engineer resume leads with what you built and run: detections written, integrations, automation, infrastructure as code and platform ownership. The bullets often describe the same work; the order and the framing decide which job you get called for.

What skills should a security engineer put on a resume?

SIEM and detection engineering, EDR, identity and access management, cloud security on AWS or Azure, network security and segmentation, vulnerability management, automation in Python and Terraform, container and Kubernetes security, incident response, and control frameworks such as NIST CSF, SOC 2 or PCI DSS.

Which certifications matter for a security engineer?

CISSP is the most frequently named in senior postings and requires documented experience plus an endorsement. GIAC certifications such as GCIH carry weight for hands-on work, OSCP for offensive skills, and AWS Security Specialty or AZ-500 for cloud roles. Security+ helps early. Government postings may reference their own approved lists, so read the posting.

What metrics should go on a security resume?

Mean time to detect and respond, false positive reduction, detection coverage against MITRE ATT&CK, patch and vulnerability SLA compliance, endpoints and cloud accounts covered, phishing report and click rates, incidents handled, and audit exceptions. Give the before, the after and the period.

How do I move from IT or the SOC into security engineering?

Reframe your infrastructure work as security work where it genuinely was (hardening, patching, access control, segmentation), count the artifacts you built even outside your job title, volunteer for the security tasks at your current employer, and add one credible certification in the direction you want to move.

How long should a security engineer resume be?

One page under five years, two pages after that. Length is rarely the problem; the common failure is two pages of product names with no outcome attached. If a tool appears on your resume, something you did with it should appear next to it.

Ready to write yours?

The builder suggests a summary from your own experience, then checks it against the job posting.

How this page was made: a first draft was written with AI assistance from cvplex's example library, then edited and fact-checked by the cvplex Careers Team. Examples are fictional composites; numbers are illustrative. Report an error via the editorial policy page.