Security

SOC Analyst Resume Example

A SOC Analyst resume should follow the operational detection cycle: monitor, triage, investigate, contain, document, and improve. It is not an AppSec resume; alert handling and incident evidence belong at the center.

Show how SIEM data, EDR signals, log analysis, MITRE ATT&CK, threat hunting, and playbooks supported decisions under time pressure. Avoid claiming security engineering controls that you did not build.

SOC Analyst Resume Sample

Rhea Thomas

SOC Analyst

Bengaluru · rhea.thomas@email.com · +91 9XXXXXXXXX · linkedin.com/in/rheathomas

Professional Summary

SOC analyst with 3 years monitoring security events, triaging alerts, and improving operational detection workflows for enterprise environments.

SOC Analyst Technical Skills

Core Skills: SIEM, Splunk, Microsoft Sentinel, Incident triage, Threat hunting, MITRE ATT&CK, EDR, Log analysis, Playbooks, Vulnerability response

Professional Experience

SOC AnalystThreatWatch SOC · Jan 2023–Present
  • Led development and delivery of key product features, improving performance and user satisfaction metrics.
  • Collaborated with cross-functional teams including design, QA, and product to define requirements and execute on roadmap commitments.
  • Introduced engineering best practices (code review standards, test coverage thresholds, CI pipeline improvements) that reduced defect escape rate by 40%.
  • Mentored junior engineers through pair programming, structured feedback, and weekly 1:1 technical coaching sessions.
Junior Security AnalystCyberOps India · Jul 2021–Dec 2022
  • Built and shipped multiple modules/features within the product team, meeting all sprint commitments.
  • Wrote unit and integration tests raising coverage from <40% to >75% on owned modules.
  • Participated in on-call rotation and resolved 3 high-priority production incidents within SLA.

SOC Analyst Projects

SOC Starter KitSIEM, Splunk, Microsoft Sentinel, Incident triage

Open-source reference project demonstrating best practices for SOC Analyst roles. Used by peers and included in internal onboarding guides.

Education

B.Tech Computer Science — VTU, 2021

Certifications

  • CompTIA Security+
  • CEH
  • TryHackMe SOC Path

Key Achievements

  • Recognized for technical excellence in ThreatWatch SOC annual performance review
  • Published technical blog series on SOC Analyst best practices — 5K+ readers

All details in this resume example are illustrative and should be replaced with your actual experience, achievements, education, and certifications.

Practical guidance for writing, structuring, and customizing a strong SOC Analyst resume.

How to Write a SOC Analyst Resume

Lead with the monitored environment, shift or queue scope, and incident responsibilities you handled.

Write bullets around triage, investigation, escalation, threat hunting, playbook use, and detection improvement.

Use projects to demonstrate analysis of realistic logs and a documented investigation timeline.

Connect Splunk or Microsoft Sentinel queries, EDR evidence, and MITRE ATT&CK mapping to the decision each investigation supported.

SOC work is detection and response rhythm: SIEM alerts, triage SLAs, enrichment, escalation, and playbooks—keep it distinct from engineering or governance roles.

Instead of

Security engineer who built secure applications and prevented vulnerabilities in deployment pipelines.

Use

Wrote unit and integration tests raising coverage from <40% to >75% on owned modules.

What to Include in a SOC Analyst Resume

Include alert sources, triage decisions, investigation methods, escalation, containment support, playbooks, and detection learning.

Add CompTIA Security+, CEH, or TryHackMe SOC Path credentials when earned. Add a certifications subsection because this source includes CompTIA Security+; CEH; TryHackMe SOC Path; on your resume, list only credentials you actually hold and preserve their official names.

SOC Analyst Resume Summary Example

Show a security operations analyst who can turn noisy telemetry into timely, well-documented incident decisions.

SOC analyst with 3 years monitoring security events, triaging alerts, and improving operational detection workflows for enterprise environments.

Important SOC Analyst Skills for a Resume

Core Skills

SIEM, Splunk, Microsoft Sentinel, Incident triage, Threat hunting, MITRE ATT&CK, EDR, Log analysis, Playbooks, Vulnerability response

Only include skills you can defend with a project, production example, or troubleshooting story.

SOC Analyst Resume Experience Examples

Junior Security Analyst

Wrote unit and integration tests raising coverage from <40% to >75% on owned modules.

SOC Analyst

Mentored junior engineers through pair programming, structured feedback, and weekly 1:1 technical coaching sessions.

SOC Analyst

Introduced engineering best practices (code review standards, test coverage thresholds, CI pipeline improvements) that reduced defect escape rate by 40%.

Junior Security Analyst

Participated in on-call rotation and resolved 3 high-priority production incidents within SLA.

Use real numbers when you can verify them. Do not invent metrics simply to make the resume sound stronger.

SOC Analyst ATS Keywords

SIEMSplunkMicrosoft SentinelIncident triageThreat huntingMITRE ATT&CKEDRLog analysisPlaybooksVulnerability responsesoc analyst resume indiasoc analyst resume samplesecurity developer resume 2026

Choose keywords that match both the SOC Analyst job description and work you can substantiate. Spell out important concepts naturally in summary and experience instead of pasting this list.

SOC Analyst Resume Tips

Describe triage logic

Explain how severity, context, and corroborating logs shaped the response.

Show investigation depth

Connect SIEM or EDR evidence to the timeline and conclusion.

Use MITRE meaningfully

Map observed behavior to relevant tactics or techniques only when supported.

Include playbook improvement

Show how investigation learning changed future handling.

Protect sensitive details

Generalize incident context while preserving your analytical contribution.

Separate tools from decisions

Name SIEM, EDR, or log-analysis tools inside the triage or escalation judgment they informed.

Frequently Asked Questions

What should a SOC Analyst resume include?

SOC achievements should focus on detection, triage, investigation, escalation, and response quality, with Splunk, Microsoft Sentinel, EDR, or log evidence tied to the analyst decision it supported. Include SIEM tools, alert triage, threat hunting if done, incident documentation, and shift/SLA realities.

What skills should I put on a SOC Analyst resume?

Splunk or Microsoft Sentinel belongs in bullets where queries or evidence supported a decision.

How do I write a strong SOC Analyst resume summary?

A home-lab project is useful when it includes logs, detection logic, an investigation, and a written conclusion.

What experience should I highlight on a SOC Analyst resume?

Certifications can support baseline knowledge, while incident reasoning demonstrates practical ability; pair credentials with a concise example of alert validation, threat hunting, playbook use, or documented escalation. Prefer detections and investigations with clear containment or MTTD/MTTR improvements from your experience.

What ATS keywords matter for a SOC Analyst resume?

Unlike security engineering, this profile centers operational monitoring and response rather than preventive application or cloud controls.

Build your SOC Analyst resume with AI

Describe your experience and skills. Get an ATS-optimized SOC Analyst resume tailored for Indian job market in minutes.

Free to start · No credit card required