Introduction

A Cyber Security Analyst resume should demonstrate hands-on experience in SOC operations, incident response, threat detection, vulnerability management and security monitoring. Recruiters look for measurable impact — mean time to detect (MTTD) and mean time to respond (MTTR) improvements, tools expertise (SIEM, EDR, IDS/IPS) and relevant certifications (CISM, CISSP, CEH) — all backed by evidence of real-world threat handling.

Skills & Tools

Technical Skills

Security automation (PowerShell, KQL, Kusto Query Language)SIEM (Splunk, MS Sentinel, IBM QRadar)Endpoint Detection & Response (CrowdStrike Falcon, SentinelOne)Intrusion Detection & Prevention (Snort, Suricata, Zeek)Vulnerability Management (Nessus, Qualys, Rapid7 InsightVM)Threat Intelligence (MISP, VirusTotal, AlienVault OTX)Penetration Testing (Metasploit, Burp Suite, Kali Linux)Identity & Access Management (Okta, CyberArk PAM)Cloud Security (AWS GuardDuty, Azure Defender)Security Orchestration & Automation (SOAR — Palo Alto XSOAR)

Additional Skills

Python scriptingYARA rule authoringSigma rule developmentAWS Security HubAWS CloudTrailGitHub for detection-as-codeNetwork SecurityDigital Forensics & Incident Response (DFIR)MITRE ATT&CK FrameworkLog Analysis & Threat HuntingSecurity Architecture & Zero Trust

Competencies

Analytical thinkingThreat modellingRisk assessmentCross-functional collaborationTechnical communicationIncident ownershipThreat intelligenceStakeholder reporting

Profile Summary

Results-driven Cyber Security Analyst with 6+ years of experience in SOC operations, incident response, threat hunting and vulnerability management across financial services and technology sectors. Certified CISM and CEH professional with deep expertise in SIEM platforms (Splunk, Microsoft Sentinel), endpoint detection and response (CrowdStrike Falcon), network security monitoring and MITRE ATT&CK-aligned detection engineering. Proven track record of reducing mean time to detect (MTTD) by 45% and mean time to respond (MTTR) by 38% through automation, improved playbooks and proactive threat intelligence integration.

lightbulbPro Tips
Open with your total years of security experience and the specific domains you specialise in (SOC, incident response, threat hunting, cloud security). Reference one or two quantified achievements — such as MTTD or MTTR improvements, number of incidents handled or vulnerability reduction percentages. List your strongest tools and certifications and keep the summary under five lines. Avoid vague phrases like 'passionate about security' — hiring managers want specific, measurable evidence of your threat detection and response capability.

Work Experience

Senior Cyber Security Analyst
fiber_manual_recordLed a team of 4 SOC analysts monitoring 15,000+ endpoints across hybrid cloud infrastructure, maintaining 24/7 visibility using Microsoft Sentinel and CrowdStrike Falcon with a sustained mean time to detect (MTTD) of under 8 minutes.
fiber_manual_recordDesigned and deployed 45+ custom detection rules in Microsoft Sentinel (KQL) and Splunk (SPL) mapped to MITRE ATT&CK techniques, improving detection coverage from 52% to 79% across priority threat categories within 6 months.
fiber_manual_recordLed end-to-end incident response for a sophisticated supply chain compromise affecting 3 third-party integrations — contained the breach within 4 hours, eradicated persistence mechanisms and prevented lateral movement to payment systems, avoiding an estimated $4M in potential losses.
fiber_manual_recordBuilt a Python-based SOAR playbook on Palo Alto XSOAR that automated phishing triage, IOC enrichment and user quarantine workflows, reducing Tier-1 analyst workload by 60% and cutting average phishing response time from 45 minutes to under 7 minutes.
fiber_manual_recordConducted monthly threat hunting campaigns using hypothesis-driven methodologies, uncovering 2 previously undetected long-term persistence mechanisms (living-off-the-land techniques) that had evaded standard signature-based detection for 60+ days.
fiber_manual_recordProduced executive-level security reporting and presented quarterly risk posture summaries to the CISO and board, translating technical threat data into business risk language and prioritised remediation roadmaps.
Cyber Security Analyst (SOC L2)
fiber_manual_recordTriaged and investigated 80–120 security alerts daily across Splunk SIEM and CrowdStrike EDR, escalating confirmed incidents and closing false positives with documented evidence — maintaining a false-positive rate below 12%.
fiber_manual_recordPerformed vulnerability assessments using Nessus and Qualys across 3,000+ assets for 8 enterprise clients, prioritised findings using CVSS and business context, and tracked remediation to reduce critical vulnerabilities by 67% over 12 months.
fiber_manual_recordInvestigated and responded to 14 confirmed ransomware pre-cursor incidents involving Cobalt Strike beacons and credential harvesting tools, containing all threats before encryption payload deployment through rapid network isolation and credential rotation.
fiber_manual_recordAuthored and maintained 30+ incident response playbooks covering phishing, business email compromise (BEC), ransomware, insider threat and cloud account takeover, reducing average analyst response time by 35% through standardised procedures.
fiber_manual_recordCollaborated with the red team to review purple team exercise findings and implement 12 new detection rules targeting TTPs identified during adversary simulation, closing significant coverage gaps in the detection stack.
Junior Security Analyst (SOC L1)
fiber_manual_recordMonitored and triaged security events across IBM QRadar SIEM for a managed security service client base of 12 organisations, escalating confirmed threats to L2 analysts with detailed investigation notes and supporting evidence.
fiber_manual_recordConducted initial phishing email analysis including header inspection, URL defanging, attachment sandbox detonation (Any.Run, Joe Sandbox) and IOC extraction, processing an average of 40 phishing reports per week.
fiber_manual_recordSupported vulnerability management programme by running Nessus scans, generating remediation reports and tracking patch compliance across Windows and Linux server estates, contributing to a 40% reduction in overdue critical patches.
fiber_manual_recordCompleted Python scripting training and automated repetitive log parsing tasks, saving approximately 3 hours of manual work per analyst per week and improving shift handover documentation quality.
fiber_manual_recordParticipated in the organisation's first internal CTF competition, placing 2nd and demonstrating practical skills in web application exploitation, forensics and cryptography challenges.
lightbulbPro Tips
• Use STAR-style bullets: Situation (the threat or gap), Action (what you did technically), Result (the measurable security outcome). Example: 'Identified a lateral movement campaign targeting domain controllers using Splunk SPL correlation rules; contained 3 compromised hosts within 22 minutes, preventing ransomware deployment across 400+ endpoints.'
• Reference the MITRE ATT&CK framework in your bullet points to demonstrate structured threat knowledge. Example: 'Authored 15 detection rules mapped to MITRE ATT&CK T1078 (Valid Accounts) and T1059 (Command and Scripting Interpreter), improving coverage of credential-based attacks by 30%.'
• Highlight cloud security experience explicitly — AWS Security Hub, Azure Defender, GCP Security Command Center and cloud-native SIEM integrations are increasingly mandatory in modern SOC roles.
• Include a GitHub or portfolio link if you have published detection rules, security scripts, CTF write-ups or open-source tools — tangible evidence dramatically differentiates candidates in competitive security hiring.
• Tailor your resume for each role: SOC roles want alert triage speed and SIEM depth; threat hunting roles want hypothesis-driven investigation; AppSec roles want OWASP knowledge and SAST/DAST tool experience. Match your top bullets to the job description.

Certifications

verified
Certified Information Security Manager (CISM) from ISACA
verified
Certified Information Systems Security Professional (CISSP) from ISC
verified
Certified Ethical Hacker (CEH) from EC-Council
verified
CompTIA Security+ from CompTIA

Training

verified
CISM — Certified Information Security Manager (2026) by ISACA
verified
SOC Analyst Level 3 — Advanced Threat Hunting & Detection Engineering (2025) by LetsDefend / Blue Team Labs Online
verified
Applied Incident Response & Digital Forensics (2024) by SANS Institute (FOR508)
verified
Cloud Security — AWS Security Specialty Preparation (2024) by A Cloud Guru / Pluralsight
verified
Practical Malware Analysis & Triage (2023) by TCM Security Academy

Awards & Recognition

emoji_events SOC Analyst of the Year — Incident Response Excellence (2026)
emoji_events Best Security Innovation — Internal Threat Hunting Hackathon (2025)
emoji_events Zero Critical Breach Award — Maintained zero critical incidents across 18-month monitoring period (2026)

Interests

Capture the Flag (CTF) competitionsOpen-source security toolingThreat intelligence researchBug bounty programmesCyber security podcasts and dark web monitoringMentoring aspiring security professionals

Personal Projects

rocket_launch Open Source Network Monitoring Tool

Developed an open-source network monitoring tool focused on real-time threat detection and reporting, with custom alerting rules for anomalous traffic patterns and automated SIEM ingestion. Published on GitHub (github.com/carlosrico/monitoring-project) with 200+ community stars and active contributor base.

rocket_launch Automated Threat Intelligence Pipeline

Built a Python-based pipeline that ingests threat feeds from VirusTotal, AbuseIPDB and AlienVault OTX, enriches indicators of compromise (IOCs) and auto-creates detection rules in Splunk — reducing manual IOC triage time by 70% and improving alert fidelity across the SOC.

rocket_launch MITRE ATT&CK Home Lab Detection Coverage

Configured a virtualised home lab environment using Proxmox, Wazuh and Elastic Stack to simulate 30+ MITRE ATT&CK techniques and validate detection coverage. Documented gaps and created custom Sigma rules to improve detection coverage from 54% to 81% across the ATT&CK framework.

check_circleResume Do's
• Quantify your security impact: include MTTD and MTTR improvements, number of incidents triaged and resolved, vulnerabilities remediated, and percentage reductions in false-positive alert rates.
• List all SIEM, EDR, vulnerability scanner and threat intelligence tools with context — describe how you used Splunk, CrowdStrike, Nessus or Sentinel to detect, investigate and respond to threats, not just that you used them.
• Demonstrate coverage across the full incident lifecycle: detection, triage, containment, eradication, recovery and post-incident review — hiring managers want end-to-end ownership, not just monitoring.
• Include certifications with issuing body and year (CISSP, CISM, CEH, Security+, OSCP) — these are used as hard filters in many ATS screening workflows.
• Highlight automation and scripting contributions: detection rule authoring (Sigma, YARA, KQL, SPL), Python or PowerShell scripts that improved SOC efficiency, and playbook development that reduced analyst toil.
cancelResume Don'ts
• Avoid vague statements like 'monitored security alerts' or 'assisted with incidents' — quantify your role, the tools used and the measurable outcome of your actions.
• Do not list every security tool you have ever touched without context. Prioritise the tools most relevant to the role and demonstrate how you used them to solve real security problems.
• Do not claim expertise in penetration testing, malware reverse engineering or forensics unless you can defend it technically in an interview — security hiring managers will probe deeply.
• Avoid listing only reactive security work. Balance your resume with proactive activities: threat hunting campaigns, detection engineering, security architecture reviews and red team collaboration.
• Do not include sensitive client names, specific vulnerability details, internal IP ranges or proprietary security configurations — summarise outcomes in general terms instead.

FAQs

Common questions about building a Cyber Security Analyst resume.

01 What are the top cyber security jobs that has work from home option?
expand_more
SOC / Cybersecurity Analyst, GRC Consultant, Penetration Tester, Cloud Security Specialist are the top work from home roles in cyber security
02 Are certifications important for Cyber Security roles?
expand_more
Yes — certifications significantly strengthen credibility. CISSP and CISM are highly valued for senior roles; CEH, CompTIA Security+ and OSCP are strong for technical and penetration testing positions. Always list the issuing body and year.
03 Should I include personal security projects on my resume?
expand_more
Absolutely. Projects such as home labs, CTF (Capture the Flag) participation, open-source security tools and GitHub repositories demonstrating scripting, detection rule writing or threat analysis are highly compelling to security hiring teams.
04 Where can I find Cyber Security Analyst jobs?
expand_more
Check LinkedIn, CyberSecJobs, Dice and Indeed for global roles. In Singapore look at MyCareersFuture and government agency portals (CSA, DSTA, GovTech). Company-specific portals at CrowdStrike, Palo Alto Networks, Zoho, Wipro, IBM, KPMG and Deloitte are also strong sources.

Written by the Winovr Career Team · Last updated 2026-07-22

Rated 4.7 stars starstar starstar star
Trusted by thousands of career builders
🎉 Hundreds of candidates hired at top companies using Winovr