Skip to main content

← CV Examples

Cybersecurity Analyst

Cybersecurity Analyst CV example (2026)

A cybersecurity analyst CV leads with certifications (Security+, CySA+, and anything GIAC) and a summary naming your SOC tier, alert volume, and stack. Bullets should quantify the operational reality — alerts triaged per shift, false-positive rate improvements, incidents worked, detections written — and name every tool. Career-changers should translate IT work into security vocabulary honestly: patching is vulnerability management, access reviews are IAM hygiene. Home labs and CTF work belong on junior CVs; they signal the curiosity the field runs on.

What recruiters scan for in a Cybersecurity Analyst CV

  • 1Certifications with dates: Security+, CySA+, GIAC, CISSP
  • 2Tools by name: Splunk/Sentinel, CrowdStrike, Nessus
  • 3Operational numbers: alerts/day, MTTR, detections authored
  • 4Incident experience — worked, not just watched

Example Cybersecurity Analyst CV

A condensed but realistic example — note how every bullet pairs an action with a number, and how tools and methods are named exactly. Details are fictional.

Nadia Rahman

Cybersecurity Analyst · SOC Tier 2 (CySA+, Security+)

Manchester, UK · nadia.rahman@email.com · tryhackme.com/p/nrahman

Summary

SOC analyst with 4 years from help desk to Tier 2, currently triaging and investigating in Microsoft Sentinel and CrowdStrike for a 6,000-endpoint estate. CySA+ and Security+ certified; wrote 14 custom detections now in production, and cut our phishing-triage time by half with a playbook that's now standard.

Experience

SOC Analyst, Tier 2

2023 – present

Aegis Managed Security (MSSP)

  • Investigate ~30 escalated alerts/day across 12 client environments in Microsoft Sentinel and CrowdStrike Falcon; MTTR on my queue is 40% below team target.
  • Worked 20+ confirmed incidents end to end, including a business-email-compromise case where early containment limited exposure to a single mailbox.
  • Authored 14 KQL analytic rules mapped to MITRE ATT&CK (credential access, lateral movement); two caught real intrusions within a month of deployment.
  • Rebuilt the phishing-response playbook (header analysis, URL detonation, scoped mailbox purge); average handling time fell from 45 to 20 minutes and was adopted across all Tier 1 shifts.

IT Support Analyst → Junior SOC Analyst

2021 – 2023

Pennine Insurance Group

  • Moved from service desk to the internal security team after leading the quarterly access-review process (400 users) and the Windows patching cycle (95%+ compliance).
  • Triaged Tier 1 alerts in Splunk and ran monthly Nessus scans, tracking remediation with system owners.

Skills

  • Microsoft Sentinel (KQL) & Splunk
  • CrowdStrike Falcon EDR
  • Incident response & phishing analysis
  • MITRE ATT&CK · NIST CSF
  • Nessus vulnerability management
  • CySA+ (2024) · Security+ (2022)
  • Python scripting (automation)

Education

BSc Information Technology, Manchester Metropolitan University, 2021

ATS keywords for Cybersecurity Analyst roles

These terms appear most often in Cybersecurity Analyst job descriptions and carry the most ATS score weight. Make sure the ones you can honestly claim appear in your CV — in the exact phrasing.

  • 1SIEM triage and detection (Splunk, Microsoft Sentinel)
  • 2Incident response and escalation procedures
  • 3Security+ / CySA+ / CISSP certifications
  • 4EDR and vulnerability management (CrowdStrike, Nessus)
  • 5MITRE ATT&CK and NIST frameworks

See how your Cybersecurity Analyst CV scores

An example shows the target — the free ATS checker shows your distance from it: score, keyword gaps, and the fixes ranked by impact. And when you're applying to a specific job, the AI Adapt flow rewrites your CV against that exact posting — honestly, without inventing experience. $4 to download.

Cybersecurity Analyst CV FAQ

Can I get a cybersecurity analyst job without certifications?

It's harder — Security+ or CySA+ are ATS knock-outs at many companies, and they're the cheapest credibility in the field. If you're mid-study, list it: 'CySA+ — exam scheduled March 2026'. Pair it with hands-on proof (home lab, TryHackMe/HTB rank) and the combination beats a cert alone.

How do I write a security CV coming from IT support?

Mine your IT work for the security it already contained: patching cycles (vulnerability management), access reviews (IAM), firewall changes, incident tickets you escalated. Phrase it in security vocabulary honestly, add a cert and a lab, and your 'career change' becomes a progression.

Do home labs and CTFs belong on a professional security CV?

For junior and mid roles, yes — one or two lines with specifics ('detection lab: Sentinel + Sysmon on a simulated AD network', platform ranks). They demonstrate the self-directed curiosity SOC managers hire for. At senior level, production incidents replace them.

More for Cybersecurity Analyst