Cyber Security Analyst CV Example

An example made with the Cvida CV builder — create your own from scratch

A cyber security analyst CV is read for one thing above all: proof you can spot a real threat in the noise and act on it under pressure. A SOC lead or security recruiter skims fast for the tools you've actually operated, the frameworks you think in, and evidence you've handled a real incident rather than just read about one. They want to see that you triage alerts without drowning in false positives, that you can escalate the right thing at the right time, and that you can point to a mean-time-to-respond, a dwell time, or a false-positive rate that changed because of something you did. Whether you're moving up from SOC Tier 1, crossing over from IT support or networking, or specialising into detection engineering, threat hunting, or GRC, the CV that wins the interview reads like evidence, not enthusiasm: a real alert, a real investigation, a real outcome. This example shows how to structure a security analyst CV, which certifications and skills a hiring manager screens for first, how to write experience bullets that survive a technical review, and how to position a move into security from an adjacent role. Everything is editable in the Cvida builder — tailor it to the team, the stack, and the seniority you're aiming for.

Why a cyber security analyst CV is read differently

Security hiring has its own priorities, and they explain every choice below. A SOC lead or a security recruiter reads fast for evidence you can defend real systems, not a list of acronyms you once revised for an exam:

  • Hands-on beats theory: knowing what a SIEM is proves nothing, but writing a detection rule in Splunk or Sentinel that cut alert noise by a measurable amount is exactly the signal a hiring manager screens for first
  • Incident evidence is the headline: any proof you've triaged, investigated, contained, or reported on a real security event carries more weight than every certification on the page combined
  • Frameworks show how you think: naming MITRE ATT&CK, the NIST or SANS incident lifecycle, or the Cyber Kill Chain signals you have a structured method for investigation rather than clicking around at random
  • Signal-to-noise is the daily job: proof you reduced false positives, tuned a noisy rule, or built a playbook that sped up triage separates a working analyst from someone who just closes tickets
  • Trust is everything in security: clean, honest, verifiable claims matter more here than anywhere, because a team is deciding whether to hand you access to the crown jewels

Read your CV the way a SOC lead will: not 'does this person know the words?' but 'can I put them on shift and trust them to catch the thing that matters and escalate it correctly?' Every section below answers that with evidence.

What recruiters and hiring managers actually screen a CV for

The structure that works for a security analyst CV

Keep it to a clean one to two pages and lead with your strongest security signals. For most cyber security analyst applications this order works best:

The sections, in order

  • Header: full name, the role ('Cyber Security Analyst' or 'SOC Analyst'), location, phone, email, and a link to LinkedIn plus any TryHackMe, Hack The Box, or GitHub profile that shows real practice
  • Summary (3-4 lines): your security focus, the tools and environments you've operated, and one headline outcome — a reduced MTTR, a caught intrusion, a false-positive rate you drove down
  • Skills: grouped into security tooling, detection and response, and the frameworks and platforms you actually use — not a wall of every acronym you've heard of
  • Experience: roles in reverse-chronological order, each bullet tying a security task to a measurable outcome for risk, detection, or response time
  • Certifications and education: Security+, CySA+, BTL1, SC-200 and the like, plus your degree — kept tight so the hands-on experience stays front and centre

Where a home lab and projects go

If you're early in security or crossing over, a home lab, a detection you built, or a capture-the-flag write-up is real evidence — treat it like experience, not a hobby. Give it its own short 'Projects' or 'Security labs' block high on the page, and describe what you detected, built, or automated in the same outcome-first style as a job.

Security hiring rewards clarity over decoration, so keep the layout plain, parser-safe, and easy to skim on a phone at 11pm during an on-call handover. If you have real SOC or incident experience, lead with it; if you're breaking in, move labs, projects, and certifications up the page.

How to choose fonts and formatting that keep a CV clean and readable

The summary: focus, stack, and one headline outcome

Three or four lines under your name — the most-read part of the CV. For a security analyst it should answer: what you defend, which tools and environments you've operated, and one outcome worth leading with:

  • Open with your focus and level: 'SOC analyst with 3 years in a 24/7 security operations centre, monitoring a 5,000-endpoint estate across Microsoft Sentinel and Defender'
  • Name the environments you genuinely worked in: cloud (Azure, AWS), endpoint (EDR), network, or identity — pick what you can defend in a technical interview, not a keyword soup
  • Lead with one hard outcome: 'cut mean-time-to-respond from 45 to 18 minutes by rewriting the phishing triage playbook' says more than any adjective and frames you as someone who improves the SOC
  • Signal how you work: mention alert triage, incident response, or threat hunting so a reader sees an analyst who investigates, not one who only forwards alerts up the chain
  • Cut the empty filler: 'passionate about cyber security and eager to learn' says nothing on its own — replace it with a tool, an environment, and a number that proves the claim

A strong security summary reads like someone a SOC lead could roster onto a shift next week. If yours could describe any analyst, add the specific detail — a SIEM, an estate size, an MTTR or a caught incident — that makes it unmistakably yours.

How to write a CV summary that works, with examples

The skills section: tools, detection, and frameworks

Group your skills so a hiring manager scans them in seconds, and only list what you can genuinely operate. For a security analyst they fall into clear buckets:

Security tooling and platforms

  • SIEM and log analytics: Splunk, Microsoft Sentinel, Elastic, or QRadar — and be specific about whether you wrote queries and rules or only read dashboards
  • Endpoint and network: EDR/XDR (CrowdStrike, Defender for Endpoint, SentinelOne), firewalls, IDS/IPS, and packet analysis with Wireshark or Zeek
  • Cloud and identity: Azure or AWS security services, conditional access, and identity-provider logs, which is where a growing share of real incidents now begin

Detection, response, and analysis

  • Detection and hunting: writing and tuning detection rules, KQL or SPL queries, and hypothesis-driven threat hunting mapped to MITRE ATT&CK techniques
  • Incident response: alert triage, containment and eradication, evidence handling, and clear incident write-ups a manager and an auditor can both follow
  • Vulnerability management: scanning with Nessus or Qualys, prioritising by real exploitability rather than raw CVSS, and tracking remediation to an SLA

Be honest about your level — if you list Splunk or KQL, expect the interview to test it live. A short, accurate, tool-specific skills list beats a long generic one, because a SOC lead can immediately picture the kind of alert they'd trust you to own.

How to choose and present the best skills for your CV

Experience bullets: tie every task to detection or response

The strongest security bullets tie an action to a measurable improvement in detection, response, or risk. Compare a vague line with one that gives a hiring manager real evidence:

  • Weak: 'Monitored security alerts and responded to incidents using the SIEM' — no scale, no method, no outcome, and nothing that separates you from any other analyst
  • Strong: 'Triaged 60+ SIEM alerts per shift, investigating true positives to root cause and reducing the team's false-positive rate from 70% to 40% by tuning three noisy detection rules'
  • Strong: 'Led containment on a business email compromise incident end to end — isolated the account, reset credentials, and produced the post-incident report that closed the case in under four hours'
  • Strong: 'Built a phishing-response playbook and Sentinel automation that cut mean-time-to-respond from 45 to 18 minutes across roughly 200 reported emails a month'
  • Pattern to apply: action verb + the threat or task + the tool or method + the outcome (MTTR, dwell time, false-positive rate, criticals patched, incidents contained)

The numbers don't need to be huge — they need to be real and defensible. 'Cut alert triage time 30% by scripting enrichment lookups in Python' is a strong bullet, because it proves exactly what a SOC lead wants: an analyst who makes the whole team faster, not just one who works their own queue.

How to quantify your achievements on a CV, with examples

Certifications, labs, and proof you can do the work

Security is one of the few fields where certifications genuinely move a CV, because they map to a shared bar recruiters trust. But list them like credentials, not a wish list — and pair them with hands-on proof:

Which certifications carry weight

  • Foundational: CompTIA Security+ is the near-universal baseline for analyst roles; Network+ or an ITIL/Azure fundamentals cert supports a crossover story
  • Analyst and blue-team: CompTIA CySA+, Blue Team Level 1 (BTL1), and Microsoft SC-200 signal genuine SOC and detection ability, not just theory
  • Advanced and specialist: SANS GIAC (GSEC, GCIH, GCIA), OSCP for an offensive lean, or CISSP for senior and GRC-facing roles — list 'in progress' honestly if you're studying

Turning practice into evidence

Certifications open the door; demonstrated practice keeps you in the room. A TryHackMe or Hack The Box rank, a detection you published to a GitHub repo, a CTF placement, or a short write-up of a lab where you detected a simulated intrusion all prove you do security, not just study it. One concrete lab described in outcome terms can outweigh a second mid-tier certificate.

Put certifications in their own tight section and keep the letters accurate — a hiring manager will know the difference between CISSP and 'CISSP (Associate)'. Honesty here is non-negotiable, because the whole role is built on trust.

How to tailor a CV for tech and security roles

Breaking into security from IT, networking, or the help desk

Most analysts arrive from an adjacent role, and hiring managers know it — they hire junior and crossover analysts on aptitude, evidence of self-driven learning, and any real exposure to security work. An empty security title is not a problem if you fill the page with the right proof:

  • Reframe adjacent experience in security terms: a help-desk agent who handled account lockouts and phishing reports, a sysadmin who patched and hardened servers, or a network engineer who read firewall logs is already doing security-adjacent work — describe it that way
  • Lead with a home lab: a documented lab where you stood up a SIEM, generated logs, and detected an attack proves more hands-on ability than any 'aspiring analyst' summary line
  • Show the learning path: Security+, BTL1, or a TryHackMe rank signals you're serious and self-driven, which is exactly what a team betting on a junior wants to see
  • Target the real on-ramps: SOC Tier 1, security graduate schemes, and internal transfers exist precisely for switchers, so tailor the CV to how they screen rather than sending one generic version
  • Lead with capability, not apologies: never open with the experience you lack — open with a detection you built, an incident you helped handle, or a lab you can walk through line by line

A crossover security CV wins on evidence of aptitude and self-driven practice, not years with the title. Fill the page with a real home lab, a certification in progress, and any security-adjacent work reframed correctly, and you'll stand out from applicants who send a generic IT CV that ignores what a SOC actually screens for.

How to write a CV when you're changing careers

ATS, keywords, and the recruiter screen

Security roles at larger firms and MSSPs almost always run applications through software and a fast recruiter screen before a SOC lead sees them, so keep the CV clean and matched to the spec:

  • Mirror the job spec's language: if it says 'SIEM', 'incident response', 'threat detection', or 'vulnerability management', use those exact phrases where they're true for you
  • Include the tool and framework keywords: Splunk, Sentinel, CrowdStrike, MITRE ATT&CK, EDR, SOC, and your certifications help both the parser and the recruiter place you fast
  • Use a clear role title: putting 'SOC Analyst' or 'Cyber Security Analyst' as your headline helps the software and the skim-reading recruiter category you correctly
  • Keep the layout parser-safe: standard fonts, clear headings, and no graphics, tables, or columns that mangle in an ATS or hide your best detection work from the screen
  • Save as PDF unless asked otherwise: it keeps your layout intact through the application system while staying readable to most modern parsers

The test is simple: could someone read your CV top to bottom in a plain text editor and still see the tools, the frameworks, and the incidents? If yes, the parser can too. Clean formatting plus the spec's own security keywords gets you past the filter and in front of the SOC lead.

How to get a CV past the ATS, with a practical checklist

Common mistakes on a security analyst CV

Most security CVs are rejected for fixable reasons rather than a lack of ability. Avoid these and you immediately stand out:

  • An acronym wall with no proof: listing 30 tools and frameworks with no bullet showing you used any of them reads as revision, not experience — tie the key ones to a real task
  • No metrics anywhere: a security CV with zero numbers reads as someone who doesn't measure detection or response, so attach a real figure — MTTR, false-positive rate, alerts triaged — to your strongest bullets
  • Overstating your level: claiming 'incident response' when you've only forwarded alerts, or listing a certification you haven't passed, gets exposed instantly and ends the interview in a field built on trust
  • Hiding the investigation: a CV that's all monitoring and no analysis misses the judgement the role pays for — show one incident you took to root cause and what you decided
  • One generic CV for every role: a SOC analyst, a detection engineer, and a GRC analyst are different jobs — tailor the summary, skills, and lead bullets to the team and the spec in front of you

Run the SOC-lead test: in 30 seconds, can they see the tools you've operated, a framework you think in, an incident you handled, and a metric you moved? If yes, you're ahead of most of the stack. The fixes are nearly always the same — prove the acronyms, attach numbers, show real investigation, and tailor to the role.

The most common CV mistakes and how to avoid them

Ready when you are

You've got the knowledge. Now build the CV.

Take what you just read and turn it into a CV that actually gets responses. Pick a template, start typing, and we save your work as you go.