Cybersecurity Analyst Resume 2026 - SOC triage, SIEM and vulnerability management example free

Антон Литвинов
Published: 25.09.2026 Updated: 25.09.2026

Security hiring has a gate that most technical fields do not: the certification. Plenty of US postings, and effectively every Department of Defense contract role, will not advance a resume without a named credential on it, so the badge has to be readable in the first ten seconds. Past that gate the screening is specific. Which SOC tier did you work, how many alerts a shift, what was your true positive rate, which SIEM, did you write detections or only close tickets, and can you describe one incident from first alert to containment. Vulnerability management is the other half of the field and is judged on remediation, not on scan counts. Below is a full example written that way, plus how a home lab gets an entry-level candidate taken seriously.

What you get

  • A complete cybersecurity analyst resume example
  • 3 ATS-safe PDF templates
  • A formula for writing alert triage and incidents with numbers
  • 6 mistakes that stop security resumes at the first filter
Create resume → 5 minutes - AI suggestions - ATS friendly
Ready example

Cybersecurity analyst resume example

Built around the three things a security manager checks in order: the certification, the tooling you have actually operated, and whether you can tell an incident story end to end.

Certification visible immediately

Security+, CySA+, a GIAC credential or CISSP, written in full with the year. In a field where compliance frameworks and federal contracts mandate specific credentials, an unreadable badge is a rejected application.

SOC tier and alert volume

'Tier 2 analyst, about 60 alerts a shift on a 24/7 rotation, true positive rate raised from 12% to 34% after tuning' tells a manager exactly what you have handled. 'Monitored security alerts' does not.

Detections you wrote, not only closed

Sigma or SPL detections, MITRE ATT&CK coverage, tuning that removed noise, playbooks you automated. Writing detection content is the line between a ticket-closer and an analyst with a future.

ATS friendly

Single column, standard headings, no photo, no tables. Certification names and framework names must be plain text, because they are the exact strings the first automated filter is matching on.

Sample resume text

Use it as a reference: keep the structure and wording, put in your own facts and numbers.

Devin Marsh

Cybersecurity Analyst, Tier 2 (Splunk, CrowdStrike)
Columbia, MD
devin.marsh@example.com
+1 410 555 0128
linkedin.com/in/example

Profile

Cybersecurity Analyst (Tier 2) with 4 years in a 24/7 SOC defending a 6,000-endpoint financial services estate. Splunk Enterprise Security and CrowdStrike Falcon, around 60 alerts a shift. Tuned the eight noisiest correlation searches and wrote 22 detections mapped to MITRE ATT&CK, raising true positive rate from 12% to 34% and cutting mean time to detect from 41 minutes to 9. Led containment on a business email compromise affecting 14 mailboxes. CySA+ and Security+.

Experience

Cybersecurity Analyst, Tier 22023 - present

Meridian Trust Financial, Baltimore, MD

  • Tuned the eight noisiest Splunk correlation searches and authored 22 new detections for credential access and persistence techniques: true positive rate rose from 12% to 34%, mean time to detect fell from 41 minutes to 9, and the Tier 1 queue dropped from about 400 alerts a day to 150 with no confirmed incident missed
  • Led containment on a business email compromise affecting 14 mailboxes - revoked sessions, reset credentials and blocked the forwarding rules within 38 minutes of the impossible-travel alert, then drove the conditional access change that closed the gap
  • Automated phishing triage with a SOAR playbook that enriches reported messages and detonates attachments, cutting average handling time per report from 22 minutes to 4 across roughly 500 reports a month
  • Ran the monthly vulnerability review with system owners, taking average days to remediate critical findings from 46 to 12 and clearing the entire CISA Known Exploited Vulnerabilities backlog
SOC Analyst, Tier 12021 - 2023

Cobalt Harbor Managed Security, Annapolis, MD

  • Triaged roughly 70 alerts a shift across 18 client tenants in QRadar and Microsoft Sentinel on a 24/7 rotation, with escalation accuracy reviewed weekly and held above 90%
  • Wrote the onboarding runbook for new client log sources, cutting tenant onboarding from about 5 days to 2
  • Identified a credential-stuffing campaign against a client portal from failed-authentication patterns, leading to rate limiting and MFA enforcement for 3,400 accounts
IT Support Specialist2019 - 2021

Wexford Point Services, Annapolis, MD

  • Supported 400 users across Windows and macOS, owning account lifecycle, patching and endpoint protection
  • Built the first phishing reporting workflow and awareness sessions, raising user reporting of simulated phishing from 9% to 41%

Education

Towson University2015 - 2019

B.S. Cybersecurity

Skills

Splunk Enterprise Security, SPL, correlation searchesMicrosoft Sentinel and KQL (secondary)CrowdStrike Falcon: investigation, host isolationDetection engineering: Sigma, MITRE ATT&CK mapping, tuningIncident response: triage, scoping, containment, timelinesVulnerability management: Tenable Nessus, CVSS, CISA KEV prioritisationPhishing analysis: headers, attachments, sandbox detonationActive Directory and Entra ID, conditional access, privileged access reviewWireshark, Zeek, firewall and proxy log analysisPython and PowerShell, SOAR playbook automation

Certifications and lab work

  • CompTIA CySA+ - 2023
  • CompTIA Security+ - 2021
  • Microsoft Certified: Security Operations Analyst Associate (SC-200) - 2024
  • Home lab: Active Directory domain with Elastic Security, Atomic Red Team simulations and 6 published detection write-ups

Download a resume template

Build your resume in our AI builder and export in the format you need

Use this template in the builder →
Profile

Cybersecurity analyst profile summary

Three or four lines: years in security, the tier and the environment, your SIEM and endpoint detection tooling, your certifications, and one measurable result such as dwell time, mean time to detect or critical vulnerabilities closed. Environment matters - a managed security provider watching forty client tenants and an in-house team defending one estate are different jobs.

If you hold or have held a US security clearance and the role calls for one, state the level and status near the top, because it is a hard filter for a large slice of the market. Compliance context is worth naming too: HIPAA, PCI DSS, SOC 2, NIST 800-171 or FedRAMP tells a hiring manager which auditors you have already survived.

WeakMotivated cybersecurity analyst with knowledge of network security, firewalls, SIEM tools and ethical hacking. Passionate about protecting organisations from cyber threats and eager to learn.
StrongCybersecurity Analyst (Tier 2), 4 years in a 24/7 SOC defending a 6,000-endpoint financial services estate. Splunk Enterprise Security and CrowdStrike Falcon, about 60 alerts a shift. Tuned the eight noisiest rules and wrote 22 new detections mapped to MITRE ATT&CK, raising true positive rate from 12% to 34% and cutting mean time to detect from 41 minutes to 9. Led containment on a business email compromise incident affecting 14 mailboxes. CompTIA CySA+ and Security+.
Tip
Name the SIEM you actually operate and what you do in it - writing correlation searches is a different claim from reading a dashboard, and the interview will find out which one is true.
Skills

Cybersecurity analyst skills for a resume

A SIEM you can query, an endpoint detection platform you have investigated in, the network fundamentals underneath both, and a framework vocabulary that lets you talk to auditors as well as to engineers.

Hard skills

  • SIEM operation: Splunk Enterprise Security with SPL, Microsoft Sentinel with KQL, IBM QRadar or Elastic Security - searching, correlation rules, dashboards
  • Endpoint detection and response: CrowdStrike Falcon, SentinelOne or Microsoft Defender for Endpoint - investigation, containment, host isolation
  • Detection engineering: Sigma rules, YARA, MITRE ATT&CK mapping, tuning to cut false positives
  • Network security monitoring: Wireshark, Zeek, Suricata, firewall and proxy log analysis, DNS and TLS inspection
  • Vulnerability management: Tenable Nessus, Qualys or Rapid7 InsightVM, CVSS scoring, the CISA Known Exploited Vulnerabilities catalog, remediation tracking with owners and deadlines
  • Incident response: triage, scoping, containment, eradication, recovery, evidence handling and timeline writing
  • Email security: phishing analysis, header and attachment inspection, sandbox detonation, user reporting workflow
  • Identity and access: Active Directory and Entra ID, privileged access review, multi-factor authentication policy, impossible-travel and token-theft detection
  • Frameworks and compliance: NIST Cybersecurity Framework, NIST 800-53 or 800-171, CIS Controls, ISO 27001, PCI DSS, HIPAA, SOC 2 evidence
  • Scripting and automation: Python or PowerShell, SOAR playbooks in Cortex XSOAR, Splunk SOAR or Sentinel automation rules

Soft skills

  • Staying methodical at 3am on an alert that might be nothing and might be everything
  • Escalating early without crying wolf, and writing the handover the next tier can use
  • Telling an executive what is known, what is suspected and what is still unknown, separately
  • Interviewing a user who clicked the link without making them defensive - they are your best source
  • Pushing a patch deadline with a system owner who has a business reason to refuse
  • Documenting an incident timeline precisely enough to survive legal and regulatory review
  • Writing awareness guidance people will read rather than a policy they will ignore
  • Judging risk proportionately instead of treating every finding as critical
  • Working with IT and engineering as colleagues rather than as auditors to be defeated
  • Discretion with sensitive findings, including about people inside the organisation
Experience

How to write cybersecurity analyst experience

Formula: the environment, what you monitored or found, the tooling, and the measurable outcome. Not 'monitored SIEM alerts', but how many, in which tool, for what estate, and what changed because you were watching.

Security has good metrics that almost nobody puts on a resume. Alerts triaged per shift, true and false positive rates, mean time to detect and to contain, dwell time, critical and high vulnerabilities remediated against total, patch compliance, phishing reporting rate, detection coverage across MITRE ATT&CK tactics. Confidentiality does not prevent any of these - describe the environment by size and sector rather than by name.

Weak- Monitored SIEM alerts, investigated security incidents and escalated issues to senior team members as needed.
Strong- Tuned the eight noisiest Splunk correlation searches and authored 22 new detections mapped to MITRE ATT&CK techniques for credential access and persistence: true positive rate rose from 12% to 34%, mean time to detect fell from 41 minutes to 9, and the Tier 1 queue dropped from about 400 alerts a day to 150 without losing a confirmed incident.
What to include
Estate size and sector - your tier and shift pattern - SIEM and EDR named - alert volume and true positive rate - detections written and ATT&CK coverage - one incident you led, with containment time - vulnerability remediation numbers - compliance regime and clearance if relevant.
Education

Education and certifications

Certifications function as gatekeepers in security more than in any other technical field. Many US government and defence contract roles require an approved baseline credential under the Department of Defense cyber workforce requirements - CompTIA Security+ is the usual way people meet that - and commercial employers have largely copied the habit. Put them high on the page, name them exactly, and include the year, because most of them expire.

  • CompTIA Security+ as the entry gate, CySA+ for the analyst track, Network+ if your networking foundation needs evidence
  • Microsoft Certified: Security Operations Analyst Associate (SC-200) for Sentinel and Defender environments
  • GIAC credentials where the employer values them: GSEC, GCIH for incident handling, GCIA for intrusion analysis
  • CISSP once you meet the experience requirement - it is a management and senior-analyst signal, not an entry one
  • Splunk certifications if Splunk is the employer's SIEM, matched to the exact product
  • Degree, university and year in one line - cybersecurity, computer science, information systems or a converted IT degree
  • Security clearance level and status if you hold one, plus any published detections, CTF placings or write-ups
Careful
Do not list CISSP as held if you have only passed the exam and are still an Associate of ISC2 - that distinction is checked, and getting it wrong in a field built on trust is a bad opening.
Entry level

Cybersecurity analyst resume with no security job yet

Entry-level security is oversubscribed because it is marketed heavily, and the standard application is a Security+ certificate and nothing else. Hiring managers for Tier 1 SOC roles are looking for two things beyond the badge: help desk or system administration experience that proves you understand how an enterprise actually works, and evidence you have investigated something yourself.

A home lab is the accepted currency for that second part. Stand up a small domain, ship logs into Security Onion, Elastic or a free Splunk instance, generate real attack traffic with Atomic Red Team, then detect it and write up what the telemetry looked like. Publishing three of those write-ups gives an interviewer something concrete to ask about, which no certificate does.

  • CompTIA Security+ passed and dated, with CySA+ next if you are aiming at the analyst track
  • A documented home lab: log sources, SIEM, the attack you simulated and the detection you wrote
  • Help desk, system administration or networking experience rewritten around access, patching and incidents
  • Capture the flag placings or Blue Team labs with the platform and what you solved
  • Public write-ups or a blog where you walk through an investigation step by step

Ready to write your cybersecurity analyst resume?

The builder keeps the layout parser-safe, puts your certifications and SIEM keywords where the first filter reads them, and leaves room for the detection and remediation numbers.

Mistakes

Common mistakes

Certifications buried at the bottom

In security the credential is often a hard filter rather than a nice extra. It belongs in the summary line or immediately under it, written out in full so that both the parser and the recruiter find it.

Tools listed without a role in them

Splunk, QRadar, Sentinel, Nessus, Wireshark, Burp and Metasploit in one line reads as a syllabus. Which one you used daily, for what, and what you built inside it is the version a SOC manager believes.

No incident you can narrate

Every security interview asks you to walk through an incident. If the resume has no hook for that question, you are relying on the interviewer to invent one for you. Put one in: what fired, what you found, how it was contained, what changed afterwards.

Vulnerability work measured in scans

'Ran weekly vulnerability scans' describes a scheduled task. Critical and high findings closed, time to remediate, patch compliance and which exploited-in-the-wild vulnerabilities you prioritised describe someone who reduced risk.

Hacking language in a defensive application

Penetration testing tools and offensive vocabulary on a resume for a defensive analyst role suggest you want a different job. If you want offensive security, apply for it directly with the relevant credential; if you want the SOC, lead with detection and response.

Vagueness that is not actually required

Confidentiality stops you naming the employer's systems, not the size of the estate, the sector, the alert volume or the outcome. 'Cannot disclose' where a number would go reads as nothing to disclose.

Takeaways

Takeaways

Remember

  • Certification names in full, with the year, near the top
  • SOC tier, estate size and alert volume per shift
  • Detections written and mapped to MITRE ATT&CK
  • One incident narrated with containment time
  • Vulnerability work measured by remediation, not scans
  • One page under ten years, single column, no photo
Create resume →
FAQ

Frequently asked questions

CompTIA Security+ is the practical baseline in the US market and the credential most often named in postings, partly because it satisfies the approved baseline requirement for many Department of Defense contract positions. CySA+ is the natural analyst-track follow-on. SC-200 matters in Microsoft Sentinel and Defender environments, GIAC credentials carry weight where employers fund them, and CISSP is a senior and management signal that requires five years of experience before you can hold it outright.
A network engineer builds and runs the network; a cloud engineer builds and runs the cloud estate. A security analyst watches both, decides what the telemetry means, and drives the response. The overlap is real - firewall rules, identity, segmentation - and many analysts arrive from those roles, which is an advantage because you already know what normal looks like. See the network engineer and cloud engineer pages for those framings.
It is the single most effective thing you can add, because it gives the interviewer something specific to ask about and it demonstrates curiosity that no certificate does. The bar is modest but real: log sources feeding a SIEM you configured, an attack you simulated with something like Atomic Red Team, a detection you wrote, and a written explanation of what the telemetry showed. Three short write-ups beat a long list of completed courses.
Alerts triaged per shift, true and false positive rate, mean time to detect and mean time to contain, escalation accuracy, detection coverage across MITRE ATT&CK tactics, and the reduction in queue volume after tuning. On the vulnerability side: critical and high findings closed, average days to remediate by severity, and patch compliance. These come from tools you already use, so a resume without them suggests you never looked at your own dashboard.
Describe the shape, not the identity. 'Business email compromise affecting 14 mailboxes at a mid-size financial services firm; detected through an impossible-travel alert, contained by revoking sessions and resetting credentials in 38 minutes, followed by a conditional access policy change that closed the gap.' That is fully informative and names nothing. Never include real indicators of compromise, internal hostnames or client names on a document you email to strangers.
Keep numbers off the resume and raise the topic in the recruiter screen after asking their range. To calibrate, read live postings for your metro area, tier and sector - pay transparency rules in many US states mean listings now show a range, which is the most current reference available. What raises the rate is consistent: moving from Tier 1 triage to detection engineering or incident response, an active security clearance, cloud security depth, a regulated sector, and certifications that employers treat as prerequisites rather than extras.
If you have no security job history, Tier 1 is the realistic entry and is not a dead end - it is where most incident responders and detection engineers started. What shortens the stay is arriving with system administration or networking background, a scripting language, and a home lab that shows you can investigate. Write the resume for the tier you are applying to; a Tier 1 application that claims detection engineering ownership gets discarded for the opposite reason to the one you expect.
Yes - the full example above, and every template on this page. You can build your own resume from any of them in the builder for free and see the result; downloading the finished PDF is paid, by subscription or a one-time payment. The builder keeps the format parser-safe and your certification names as plain text, which is exactly what the first filter in security hiring is looking for.
Useful reading

Resume and interview advice

Tips

How to Tailor a Resume to a Job Description in 10 Minutes

A step-by-step routine with a time budget: how to customize your resume for a specific job in 10 minutes, use keywords from the posting and invent nothing. With a before-and-after example for a B2B sales role.

Read →
ATS

What Is an ATS System? Applicant Tracking Explained

How recruiters work with applications inside an applicant tracking system, whether a "robot" really rejects your resume, and what to do so your resume gets found.

Read →
AI

AI Resume Builder in Claude and ChatGPT via MCP

Create a resume with AI in a normal conversation with Claude or ChatGPT, and get a real document with a template, layout and PDF instead of a wall of text in the chat.

Read →
Related Professions

Resume examples for other roles

Create resume →