Cybersecurity Analyst resume example
Security hiring managers look for evidence you reduce risk: incidents detected and contained, vulnerabilities closed, controls implemented and audits passed. Certifications matter, so make them easy to find.
This is a fictional, illustrative example -- not a real person or a promised result. Replace every detail with your own.
Full example resume
Sample content, for illustration -- not a real person.
SOC analyst with 4 years of experience in detection and response for a 5,000-employee healthcare network. Security+, CySA+. Cut mean time to respond from 4 hours to 35 minutes.
- •Triage 400 alerts a week in Microsoft Sentinel, cutting mean time to respond from 4 hours to 35 minutes.
- •Tuned 60 detection rules, reducing false positives by 50% without missing true incidents in testing.
- •Contained a phishing campaign targeting 300 staff within 1 hour, with no accounts compromised.
- •Wrote 15 response playbooks now used by all 8 analysts.
- •Ran monthly Tenable scans and tracked 1,200 findings to closure.
- •Brought critical vulnerability closure time from 45 days to 12.
- •Supported SOC 2 Type II evidence collection, passing with no exceptions.
Summary: weak vs. improved
Security-minded professional passionate about protecting organisations from threats.
SOC analyst for a 5,000-employee healthcare network. Security+, CySA+. Cut mean time to respond from 4 hours to 35 minutes.
Environment size, certifications and a response-time result tell a security manager exactly where you fit.
Skills to include
- ✓SIEM (Splunk, Microsoft Sentinel)
- ✓Incident detection and response
- ✓Vulnerability management (Tenable, Qualys)
- ✓Endpoint security (EDR)
- ✓Frameworks (NIST CSF, ISO 27001, SOC 2)
- ✓Scripting (Python, PowerShell)
Only list skills you actually have -- the AI review in the editor will flag a skill that doesn't appear anywhere else in your resume.
Bullet examples: weak vs. improved
Monitored security alerts.
Triage 400 alerts a week in Microsoft Sentinel, cutting mean time to respond from 4 hours to 35 minutes.
Volume and response time are the core SOC metrics.
Responded to incidents.
Contained a phishing campaign targeting 300 staff within 1 hour, with no accounts compromised.
A contained incident with a clear outcome shows you perform under pressure.
Managed vulnerability scans.
Brought critical vulnerability closure time from 45 days to 12.
Closure time shows real risk reduction, not just running a scanner.
How this changes by experience level
Lead with certifications, labs (TryHackMe, home SIEM) and any IT support experience.
Built a home SIEM with Wazuh and wrote detections for 10 MITRE ATT&CK techniques.
Show detection, response and vulnerability metrics, like the full example above.
See the full example above.
Show programs you built, architecture reviews and leading responses.
Built the vulnerability management program, bringing critical findings under 7 days for 4 quarters running.
Section order
- Contact
- Certifications (Security+, CySA+, CISSP)
- Short summary
- Skills
- Experience
- Education
Common mistakes to avoid
- !Listing tools without incidents or outcomes
- !Burying certifications
- !Sharing confidential details about past employers’ incidents
Recommended template: Technical
Skills matrix and project highlights for engineers.