Cybersecurity Analyst Resume

A cybersecurity analyst resume has to survive two readers: the ATS that parses it, and the SOC lead deciding in ninety seconds whether you have worked an incident. This guide covers the sections that matter, a full example, the certifications worth naming, and how to write bullets when your day job is triage.

What a cybersecurity analyst resume must include

Security hiring is unusually concrete. A SOC manager is not guessing whether you can read a Splunk search or distinguish a true positive from a false one — the resume either shows it or it does not. Vague claims like “monitored network traffic” read as an absence of detail.

Cybersecurity Analyst Resume Example

Example resume

A one-page analyst resume with certifications, shift metrics and detection work up front, in the linear structure the builder produces.

Jordan Alvarez

Senior Security Operations Analyst — Splunk · Sentinel · Incident Response

Portland, OR · [email protected]

Summary

Security operations analyst with six years across healthcare and financial SOCs. Runs detection tuning and incident response in Splunk and Microsoft Sentinel, and cut mean time to detect from 42 minutes to under nine on a 6,500-endpoint estate.

Experience

Senior Security Operations Analyst — Meridian Health Systems 2022 — Present

Portland, OR

  • Cut mean time to detect from 42 minutes to under nine across a 6,500-endpoint estate by rewriting 60+ Splunk correlation searches and retiring four duplicate rules.
  • Reduced false-positive alert volume 62% over two quarters with a SOAR enrichment playbook that adds asset and identity context before an analyst opens the alert.
  • Led containment and forensic review of a ransomware intrusion reaching 3,000 endpoints, owning the response lifecycle through eradication and the after-action report that changed three controls.
  • Mapped 140 detections to MITRE ATT&CK and closed visibility gaps in 11 techniques used by groups active against healthcare providers.
Security Analyst — Cascade Financial Group 2019 — 2022

Seattle, WA

  • Triaged an average of 220 alerts per shift across Microsoft Sentinel and CrowdStrike Falcon, confirming 4% as genuine incidents and documenting the remainder with tuning notes.
  • Automated phishing triage with a Python tool against the mail API, reducing per-message review from 12 minutes to under two across roughly 90 reports a week.
  • Ran quarterly vulnerability scans over 1,800 assets and drove patch SLAs so critical findings closed within seven days rose from 61% to 94%.
  • Authored 25 incident response runbooks adopted by both analyst shifts and the on-call rotation.

Projects

Detection lab: Windows intrusion scenarios 2023 — Present

Self-hosted lab with Proxmox, Sysmon, Elastic and Velociraptor, reproducing 20+ ATT&CK techniques so rule changes are validated before reaching production.

Skills

Certifications: CompTIA Security+ (2021), CompTIA CySA+ (2023), GIAC GCIH (2025), Microsoft SC-200 (2024)

SIEM & Detection: Splunk (SPL), Sentinel (KQL), Elastic, Sigma rules, SOAR playbooks

Endpoint & Network: CrowdStrike Falcon, Defender for Endpoint, Zeek, Suricata, Wireshark

IR & Forensics: NIST SP 800-61, Volatility, KAPE, Velociraptor, evidence handling

Vulnerability Management: Nessus, Qualys VMDR, CVSS, EPSS, patch SLAs

Scripting & Frameworks: Python, PowerShell, Bash, MITRE ATT&CK, NIST CSF, HIPAA

Education

B.S. Information Systems 2015 — 2019

University of Illinois Urbana-Champaign

Recommended sections

Cybersecurity analyst skills and keywords

Security postings are repetitive by design, because most SOCs run a similar stack. Mirror the posting's exact tool names where you genuinely have them.

How to write bullets when your work is triage

Shift analysts often assume their work looks thin because they are not leading investigations. Triage is a volume business, and volume is measurable: state the scale you operate at, the judgement you applied, then the process improvement you made.

Certifications: what to list and where

ATS notes for security resumes

One point specific to this field: when you describe incidents, give the category, the scale and your own role — the threat class and the technology, not the victim or the unpatched weakness. Check your employer's policy first, since many require approval before incident details are published.

Skills and keywords for this role

Use the terms that genuinely describe your work — an interviewer will ask about anything you list.

  • SIEM & detection: Splunk (SPL), Microsoft Sentinel (KQL), Elastic, IBM QRadar, Sigma rules
  • Endpoint & network: CrowdStrike Falcon, Defender for Endpoint, SentinelOne, Zeek, Suricata, Wireshark
  • Incident response: NIST SP 800-61 lifecycle, containment, eradication, recovery, after-action review
  • Vulnerability management: Nessus, Qualys VMDR, Rapid7 InsightVM, CVSS, EPSS, patch SLAs
  • Threat intel & hunting: MITRE ATT&CK mapping, IOC enrichment, VirusTotal, MISP, threat feeds
  • Scripting & automation: Python, PowerShell, Bash, KQL, SOAR playbooks

Frequently asked questions

Do I need a degree to become a cybersecurity analyst?

No single path is required, and what employers ask for varies. Many postings list a bachelor's degree or an equivalent combination of certification and experience. People enter SOC work from help desk and systems administration roles, from the military, and from self-directed lab work. What is consistent is the ability to read a log, judge an alert and explain your reasoning.

Which certifications should a cybersecurity analyst list first?

Lead with the ones the posting names. For entry roles that is usually CompTIA Security+ or a similar baseline. CySA+ maps onto detection and response, while incident responders add GIAC GCIH or GCIA. CISSP comes later because it expects several years of relevant experience. Check the posting rather than assuming a universal standard.

How do I make triage work sound substantial?

Quantify volume, judgement and process improvement: how many alerts you handled per shift, what proportion were genuine, and what you changed — rules tuned, enrichment automated, playbooks written. A measured reduction in false positives says more than any list of tools.

How long should a cybersecurity analyst resume be?

One page under roughly ten years of experience, and two only if the second page is genuinely full. Analyst resumes carry a lot of list content — certifications, tools, frameworks — so the risk is length from formatting rather than substance. Trim tools you would not want to be interviewed on.

Should I include home lab or capture-the-flag work?

Yes, particularly if you are early-career or moving into security from another discipline. Describe what you built and what you detected: the telemetry collected, the techniques reproduced, the rule written. A list of platform names reads as a hobby; a described lab reads as evidence you can operate the tooling.

How do I describe incident response work without breaching confidentiality?

Describe the category, the scale and your role: a ransomware intrusion across a number of endpoints, the phases you owned, the controls that changed. Leave out victim names, unremediated weaknesses and anything identifying an affected party. Many employers require approval before incident specifics are published.