← Back to Resume examples
Security

Cyber Security Analyst Resume Example

Security analyst resumes should show how detection became investigation, containment, and prevention. This example organizes SIEM/Splunk work, SOC triage, MTTD, phishing simulations, threat hunting, and DFIR around operational security outcomes.

Adapt it by documenting alert volume, escalation duties, detection logic, incident scope, and training effects while protecting confidential client and threat details.

Cyber Security Analyst Resume Sample

Aisha Verma

Cyber Security Analyst

Pune, Maharashtra · aisha.verma@email.com · +91 98456 12301 · linkedin.com/in/aishaverma

Professional Summary

Cyber Security Analyst with 2.5+ years in SOC operations, threat hunting, and incident response for banking and IT services firms. Reduced mean time to detect (MTTD) from 4.2 hours to 52 minutes by implementing custom Splunk correlation rules and automated alert triage. CompTIA Security+ and CEH certified. Strong in log analysis, malware investigation, and security awareness training.

Cyber Security Analyst Technical Skills

SIEM & Monitoring: Splunk, Microsoft Sentinel, QRadar, ELK SIEM

Vulnerability Mgmt: Nessus, OpenVAS, Qualys, Rapid7

Threat Intel: MITRE ATT&CK, VirusTotal, OSINT, Shodan, Maltego

Network: Wireshark, Nmap, Zeek, Suricata IDS

OS / Admin: Linux (Ubuntu, CentOS), Windows Server, Active Directory

Scripting: Python (automation scripts), Bash, PowerShell

Compliance: ISO 27001, PCI-DSS v4, GDPR, RBI IT Circulars, NIST CSF

Incident Response: DFIR, memory forensics (Volatility), EDR (CrowdStrike, SentinelOne)

Professional Experience

Security Analyst (L2 SOC)Northbridge Infotech, Pune · Jun 2023 – Present
  • Monitors 500+ endpoint SIEM environment (Splunk); triages 50+ alerts daily and escalates confirmed incidents within 15-minute SLA.
  • Built 12 custom Splunk correlation rules targeting lateral movement and credential stuffing patterns, catching 3 real intrusion attempts before data exfiltration.
  • Led investigation and containment of a ransomware precursor threat (Qakbot variant), preventing potential impact to 80 workstations.
  • Reduced MTTD from 4.2 hours to 52 minutes through alert tuning, playbook automation, and Tier-1 triage upskilling sessions.
  • Conducted monthly phishing simulation campaigns for 500 employees; improved report rate from 14% to 63% over 8 months.
SOC Analyst (L1)SecureNet India, Mumbai · Jan 2023 – May 2023
  • First-line triage of security alerts from 8 client environments across BFSI and healthcare sectors.
  • Authored 20+ incident response runbooks now used as standard SOC procedures.
  • Assisted senior analysts with DFIR investigations using Volatility for memory analysis and Autopsy for disk forensics.

Cyber Security Analyst Projects

SIEM Rule LibrarySplunk SPL, MITRE ATT&CK

Repository of 60+ detection rules mapped to ATT&CK tactics, shared internally and open-sourced on GitHub.

PhishSim PlatformPython, GoPhish, Django

Internal phishing simulation platform with campaign management and per-department vulnerability scoring.

Education

B.Tech Computer Science — Savitribai Phule Pune University, 2022 · CGPA 8.2 / 10

Certifications

  • CompTIA Security+
  • Certified Ethical Hacker (CEH v12)
  • TryHackMe — SOC Level 1 Path (Top 5%)

Key Achievements

  • Prevented Qakbot intrusion — recognized with team Excellence Award Q4 2023
  • TryHackMe Top 5% globally — SOC Level 1

All details in this resume example are illustrative and should be replaced with your actual experience, achievements, education, and certifications.

Practical guidance for writing, structuring, and customizing a strong Cyber Security Analyst resume.

How to Write a Cyber Security Analyst Resume

Start with SOC tier, environment size, alert responsibility, and escalation SLA. Then distinguish routine triage from detection engineering, threat hunting, and incident leadership.

For Splunk rules, identify the behaviors targeted and use exact detection outcomes where disclosure is appropriate. Keep MTTD, phishing report rate, and endpoint figures in their documented contexts.

Show investigation depth through MITRE ATT&CK, EDR, network evidence, malware analysis, memory forensics, or disk forensics. Compliance frameworks should appear only where they shaped actual controls or reporting.

Instead of

Monitored security alerts and responded to cyber incidents.

Use

Conducted monthly phishing simulation campaigns for 500 employees; improved report rate from 14% to 63% over 8 months.

What to Include in a Cyber Security Analyst Resume

Include SIEM and SOC scope, alert triage, detection rules, incident response and containment, threat intelligence, endpoint/network tooling, DFIR, scripting, awareness exercises, compliance context, and measured detection outcomes. Add a certifications subsection because this source includes CompTIA Security+; Certified Ethical Hacker (CEH v12); TryHackMe — SOC Level 1 Path (Top 5%); on your resume, list only credentials you actually hold and preserve their official names.

Cyber Security Analyst Resume Summary Example

Summarize SOC and incident-response scope, core SIEM strength, certifications if current, and one verified MTTD, detection, containment, or awareness result.

Cyber Security Analyst with 2.5+ years in SOC operations, threat hunting, and incident response for banking and IT services firms. Reduced mean time to detect (MTTD) from 4.2 hours to 52 minutes by implementing custom Splunk correlation rules and automated alert triage. CompTIA Security+ and CEH certified. Strong in log analysis, malware investigation, and security awareness training.

Important Cyber Security Analyst Skills for a Resume

SIEM & Monitoring

Splunk, Microsoft Sentinel, QRadar, ELK SIEM

Vulnerability Mgmt

Nessus, OpenVAS, Qualys, Rapid7

Threat Intel

MITRE ATT&CK, VirusTotal, OSINT, Shodan, Maltego

Network

Wireshark, Nmap, Zeek, Suricata IDS

OS / Admin

Linux (Ubuntu, CentOS), Windows Server, Active Directory

Scripting

Python (automation scripts), Bash, PowerShell

Compliance

ISO 27001, PCI-DSS v4, GDPR, RBI IT Circulars, NIST CSF

Incident Response

DFIR, memory forensics (Volatility), EDR (CrowdStrike, SentinelOne)

Only include skills you can defend with a project, production example, or troubleshooting story.

Cyber Security Analyst Resume Experience Examples

Security Analyst (L2 SOC)

Conducted monthly phishing simulation campaigns for 500 employees; improved report rate from 14% to 63% over 8 months.

Security Analyst (L2 SOC)

Monitors 500+ endpoint SIEM environment (Splunk); triages 50+ alerts daily and escalates confirmed incidents within 15-minute SLA.

Security Analyst (L2 SOC)

Reduced MTTD from 4.2 hours to 52 minutes through alert tuning, playbook automation, and Tier-1 triage upskilling sessions.

Security Analyst (L2 SOC)

Built 12 custom Splunk correlation rules targeting lateral movement and credential stuffing patterns, catching 3 real intrusion attempts before data exfiltration.

Use real numbers when you can verify them. Do not invent metrics simply to make the resume sound stronger.

Cyber Security Analyst ATS Keywords

SplunkMicrosoft SentinelQRadarELK SIEMNessusOpenVASQualysRapid7MITRE ATT&CKVirusTotalOSINTShodanMaltegoWiresharkNmapZeekSuricata IDSLinux (UbuntuCentOS)Windows ServerActive DirectoryPython (automation scripts)BashPowerShellISO 27001PCI-DSS v4GDPRRBI IT CircularsNIST CSFDFIRmemory forensics (Volatility)EDR (CrowdStrikeSentinelOne)Splunk SPLPythonGoPhishDjangocyber security analyst resume indiasiem resumesoc analyst resume

Choose keywords that match both the Cyber Security Analyst job description and work you can substantiate. Spell out important concepts naturally in summary and experience instead of pasting this list.

Cyber Security Analyst Resume Tips

State SOC operating scope

Use endpoint count, alert volume, tier, and escalation SLA from actual records.

Describe detection intent

Name the lateral-movement, credential, or other behavior a Splunk rule targeted.

Separate detection from response

Clarify whether you found, investigated, contained, escalated, or documented an incident.

Quantify awareness change

Keep phishing simulation and employee-reporting measures tied to the campaign period.

Protect sensitive details

Show technical depth without exposing client identifiers, exploitable configurations, or confidential indicators.

Frequently Asked Questions

What should a Cyber Security Analyst resume include?

Include SOC tier and environment scope, SIEM triage, detection engineering, incident response, threat hunting, endpoint/network analysis, DFIR, scripting, awareness, and measured security outcomes.

What skills should I put on a Cyber Security Analyst resume?

Use truthful skills such as Splunk, Sentinel, QRadar, MITRE ATT&CK, Nessus, Wireshark, Nmap, Zeek, CrowdStrike, Volatility, Python, DFIR, and incident response.

How do I write a strong Cyber Security Analyst resume summary?

State SOC and investigation experience, strongest SIEM capability, and one verified MTTD, detection, containment, or phishing-awareness improvement.

What experience should I highlight on a Cyber Security Analyst resume?

Highlight alert triage, correlation rules, ransomware precursor containment, playbook automation, phishing simulations, runbooks, and memory/disk forensics.

What ATS keywords matter for a Cyber Security Analyst resume?

ATS searches often include cyber security analyst, SOC analyst, SIEM, Splunk, incident response, threat hunting, MITRE ATT&CK, EDR, DFIR, vulnerability management, and MTTD.

Build your Cyber Security resume with AI

Describe your SOC, SIEM, and incident response experience. Get an ATS-optimized security analyst resume in minutes.

Free to start · No credit card required