CV example · Technology · Mid level
Cybersecurity Analyst CV Example & Writing Guide
Every security analyst writing a CV hits the same wall: the most convincing thing you did last year is the thing you are contractually and ethically unable to describe. The way through is to write about your detections, your queues and your remediation timelines rather than about the breach, and to let the shape of the work imply the severity. This page is one complete security analyst CV at around six years, plus the bullets, certifications and disclosure boundaries that make the difference between a defensible CV and an interview that ends early.
Use this layout Check my CV free
The full CV example
Read this example for what it leaves out. Not one incident is named, dated or attributed, and the work is still legible to anyone who has sat in a security operations centre.
Noor Zaidi
Security Analyst - detection engineering and vulnerability management
Dublin, Ireland - hybrid, security clearance available on request
Professional summary
Security analyst with six years across telecoms and insurance, split between alert triage and building the detections that generate the alerts. Cut false positives from around 240 a week to 60 while raising true-positive detections, and closed 140 critical vulnerabilities inside a 14-day remediation target. Writes detections and the runbooks the next analyst uses at 2 a.m.
Experience
Security Analyst - Grafton Mutual
2022 - presentInsurance group, 1,400 staff, security team of 8
- Rewrote 31 noisy SIEM correlation rules, cutting false positives from roughly 240 a week to 60 while the count of confirmed true positives rose, because analysts stopped skimming the queue.
- Built 18 detections mapped to specific MITRE ATT&CK techniques, each with a runbook naming the first three containment steps and the evidence to collect before them.
- Cut median triage time on high-severity alerts from 35 minutes to 9 by enriching alerts with asset owner, exposure and recent change history at the point they fire.
- Ran the vulnerability remediation programme with the infrastructure team: 140 critical findings closed inside the 14-day target, and patch coverage across the server estate rose from 78% to 96%.
- Designed and ran two tabletop exercises with the executive team; the second produced a decision tree for supplier compromise that the incident policy now references.
- Raised phishing reporting from 4% to 31% of simulated messages by replacing annual training with a two-minute report-it flow and monthly targeted simulations.
SOC Analyst - Sliabh Telecom
2020 - 202224/7 security operations centre, tier 1 and tier 2 rotation
- Triaged an average of 60 alerts a shift across endpoint, identity and network telemetry, escalating with a written timeline rather than a forwarded alert.
- Wrote the identity-alert playbook after repeated escalations arrived with no session or geolocation context; escalation rework fell by about half over the following quarter.
- Contributed to post-incident reviews as the analyst who reconstructed timelines from log evidence, and tracked the resulting actions to closure.
IT Support Technician - Barrow College
2019 - 2020600 staff and student devices
- Ran endpoint hardening and account lifecycle for the college; the route into security came from owning the phishing reports nobody else wanted.
Education
BSc Computer Science with Digital Forensics - Technological University Dublin
2015 - 2019Final project on log-based timeline reconstruction
Skills
Certifications
CompTIA Security+, Blue Team Level 1, working towards GCIH
Languages
English (native), Urdu (fluent), Irish (basic)
Fictional example. Every name, employer and number here is invented; use your own, and never a real incident's details.
Why this CV works
Five decisions in this example that a typical security CV gets wrong:
-
It describes the work without disclosing the incident
There is no breach narrative, no date, no attacker and no victim. Detection counts, triage times and remediation targets carry the whole argument. A hiring manager in security reads discretion as a qualification, and a CV that names a former employer's incident fails the interview before it starts.
-
Reducing false positives is paired with what did not fall
Anyone can cut alert volume by deleting rules. "False positives from around 240 a week to 60 while confirmed true positives rose" states the trade-off the interviewer was about to raise, and explains it: analysts stopped skimming.
-
Detections are tied to a framework and to a runbook
18 detections mapped to specific ATT&CK techniques, each with the first three containment steps written down. That is the difference between an analyst who writes queries and one who thinks about the person receiving the alert at 2 a.m.
-
Remediation is counted against a target, not in the abstract
140 critical findings closed inside a 14-day target, patch coverage from 78% to 96%. Vulnerability management is where security analysts most often have real numbers and least often use them, because the work feels administrative.
-
The support job explains the route in
One line about owning the phishing reports nobody else wanted. Most security analysts arrive from support, networking or system administration, and naming the moment the pivot happened is more persuasive than hiding a pre-security job.
Professional summary examples
Entry level
At entry level, alert volume and one written artefact are the credible evidence. Certifications belong in the summary here, and only here, because they are part of why you are hireable yet.
Mid level
Mid-level is where you claim detection engineering rather than consumption of other people's rules. Two numbers, one sentence about what you leave behind.
Senior
Senior security CVs are hired on judgement under pressure. Name the programme you own and the problem you want, and leave the tool list to the skills section.
Experience bullet examples
Twelve bullets in weak and strong form. Two boundaries before you adapt them: the figures must be your own, and nothing that identifies a real incident, a real victim or a real vulnerability in a former employer's estate belongs on a CV at all.
- Weak
- Monitored security alerts.
- Stronger
- Triaged an average of 60 alerts a shift across endpoint, identity and network telemetry, escalating with a written timeline rather than a forwarded alert.
- Why
- Volume plus the quality of what you hand on. Triage counts alone say you were present.
- Weak
- Reduced false positives.
- Stronger
- Rewrote 31 SIEM correlation rules, cutting false positives from roughly 240 a week to 60 while confirmed true positives rose.
- Why
- Always state what did not degrade. Tuning that hides real detections is the failure mode a reader suspects.
- Weak
- Created detection rules.
- Stronger
- Built 18 detections mapped to specific MITRE ATT&CK techniques, each shipped with a runbook naming the first three containment steps.
- Why
- The framework mapping and the runbook are what make these detections maintainable by someone else.
- Weak
- Responded to security incidents.
- Stronger
- Cut median triage time on high-severity alerts from 35 minutes to 9 by enriching alerts with asset owner, exposure and recent change history at the point they fire.
- Why
- Describe the mechanism, never the incident. This bullet is a process improvement, which is disclosable.
- Weak
- Worked on vulnerability management.
- Stronger
- Closed 140 critical findings inside a 14-day remediation target and raised patch coverage across the server estate from 78% to 96%.
- Why
- The target is the story. A vulnerability count with no service level attached tells nobody whether you were fast.
- Weak
- Ran phishing awareness training.
- Stronger
- Raised phishing reporting from 4% to 31% of simulated messages by replacing annual training with a two-minute report-it flow and monthly targeted simulations.
- Why
- Report rate is a better number than click rate, because it measures the behaviour you actually want.
- Weak
- Used Splunk and other security tools.
- Stronger
- Wrote the Splunk queries behind the identity dashboard the on-call rotation opens first, and taught two analysts to extend them.
- Why
- A tool name earns its place when attached to something other people now use.
- Weak
- Assisted with compliance work.
- Stronger
- Closed 22 of 27 findings from an ISO 27001 surveillance audit within the agreed window, owning evidence collection for access control and logging.
- Why
- Name the standard and your scope inside it. Compliance help is vague; owning two control families is not.
- Weak
- Improved logging coverage.
- Stronger
- Onboarded 14 previously unmonitored systems into the SIEM, including the VPN concentrator and two SaaS admin logs, which closed the visibility gap a tabletop exercise had exposed.
- Why
- Say what prompted the work. A gap found in an exercise is a legitimate, non-sensitive origin story.
- Weak
- Participated in incident response.
- Stronger
- Reconstructed event timelines from log evidence in post-incident reviews and tracked the resulting remediation actions to closure.
- Why
- Your role in the response is disclosable. The response itself is not, so stay on your own contribution.
- Weak
- Wrote documentation.
- Stronger
- Wrote the identity-alert playbook after escalations kept arriving without session or geolocation context; escalation rework fell by about half in the next quarter.
- Why
- Documentation bullets need the problem that preceded them and a number afterwards, or they read as filler.
- Weak
- Helped improve the security posture.
- Stronger
- Ran two tabletop exercises with the executive team; the second produced a supplier-compromise decision tree now referenced by the incident policy.
- Why
- "Posture" is unfalsifiable. A document that outlives the exercise is not.
Skills that belong on this CV
Hard skills
- Alert triage and escalation with written evidence
- Detection engineering in a SIEM query language (SPL, KQL or equivalent)
- MITRE ATT&CK mapping and detection coverage assessment
- Log analysis across endpoint, identity, network and cloud telemetry
- Vulnerability management: scanning, prioritisation, remediation tracking
- Incident response process and timeline reconstruction
- Identity and access fundamentals, including conditional access and privileged accounts
- Scripting for enrichment and automation, usually Python or PowerShell
Tools and technologies
- A SIEM such as Splunk, Microsoft Sentinel or Elastic
- An EDR such as Defender for Endpoint or CrowdStrike
- A vulnerability scanner such as Tenable or Qualys
- Wireshark or an equivalent packet analyser
- A ticketing and case system
- Python or PowerShell
- A threat intelligence platform or feed
Role-specific strengths
- Judging severity fast with incomplete evidence
- Writing an escalation the receiving team can act on without a phone call
- Knowing which detail about past work you are not free to share
Soft skills worth proving
- Telling an executive what is known and what is not, without softening either
- Disagreeing with an engineering team about a patch window and landing on a date
- Staying methodical during an active investigation
Education and certifications
A computer science, networking or dedicated cyber degree is common but far from universal, and this field hires more career changers from IT support and networking than it admits. Keep education to degree, institution and years below experience once you have two security roles. If you arrived from support, show that entry role in one line rather than removing it: the CV then explains itself instead of leaving a gap.
Certifications
- CompTIA Security+ - The entry credential most adverts name, and the one worth having before the first security role rather than after.
- Blue Team Level 1 or a comparable practical defensive course - Hands-on certifications carry more weight in triage and detection interviews than multiple-choice ones.
- GIAC GCIH or GCIA - Expensive and specific. List when the role is incident handling or detection, where the syllabus matches the day job.
- CISSP - Aimed at experience levels above this example and weighted towards governance. Listing it as "associate" while working towards the experience requirement is honest; listing it outright before you qualify is not.
Certifications count for more here than in software engineering, because many security adverts screen on them. Put them in a labelled block near the top, write the full name once, and state the status plainly when one is in progress.
How an ATS reads this CV
Appliora's ATS Checker runs 14 checks against an uploaded file and shows the text its parser extracted. Four of them are worth particular attention on a security CV, where acronym density and vetting anxiety both cause avoidable problems.
-
Concrete skills
A block of thirty security acronyms is the standard shape of this section and the least useful version of it. The check looks for recognisable skills rather than orphan fragments, so "IR", "IAM" and a bare product version score as noise. Write the term out once, group by function, and keep the list to what you would be examined on.
-
Personal details
Vetting and clearance make security candidates volunteer date of birth, nationality, marital status and sometimes a photograph, none of which a CV needs. Those details belong in the vetting forms when an employer asks for them. A single line saying clearance is held or available on request does the job.
-
Recognised sections
Security CVs often lead with a large certifications block under a custom heading, then hide experience below it. Keep the heading conventional and the order conventional too: a parser finds the section faster and a reader still sees the certificates in the first screen if the block is compact.
-
Spelling
The check separates genuine typos from technical vocabulary it does not recognise, which matters here because half your nouns are product names. A misspelled tool or framework is the one typo a security interviewer notices, so read the flagged list rather than dismissing it as jargon confusion.
Templates that suit this role
-
ATS Structured
Plain single column, which keeps a certifications block and a dense experience section in a predictable extraction order. The right default for government, banking and insurance portals.
-
ATS Clean
Room for a labelled certifications and clearance line near the top without a sidebar, which suits a field where screening often starts with the credentials.
-
Two Column Pro
For direct applications where you want tooling and certifications visible in a side panel while the experience carries detection and remediation numbers.
Build this CV in Appliora
Start from a layout that suits the role, with live preview and a free ATS check before you send it.