Information Security Analyst Resume Examples
Security resumes are read for incidents and controls — what you detected, what you contained, what you built so it could not happen again. At $129,180 with much faster than average projected growth, this is the best-paid occupation covered here, and the competition is genuinely technical.
The most common weakness is a resume full of frameworks and acronyms with nothing you personally did. NIST, ISO and zero trust are context. What a hiring manager wants is the alert you investigated, the finding you remediated and the control you own.
Information Security Analyst resume example
A complete one-page example for a information security analyst role. Every detail is fictional — copy the structure, not the facts.
Devon R. Ashworth
Information Security Analyst — SOC, Detection and Incident Response
Baltimore, MD · (555) 013-6628 · [email protected] · linkedin.com/in/example
Professional summary
Security analyst with five years in a 24/7 SOC, triaging 300+ alerts weekly and leading incident response for a 4,000-endpoint estate. Cut mean time to contain from six hours to 90 minutes, raised critical remediation SLA compliance from 62% to 94%, and closed 40 of 62 control gaps ahead of a SOC 2 Type II audit completed with no exceptions.
Professional experience
Security Analyst II — SOC · Chesapeake Financial Services
Feb 2022 – Present
Baltimore, MD
- Triage 300+ SIEM alerts weekly in Splunk across a 4,000-endpoint, 600-server estate, escalating an average of eight true positives a month.
- Led containment on 20+ confirmed incidents including credential compromise and commodity ransomware, cutting mean time to contain from six hours to 90 minutes.
- Wrote and tuned 45 detection rules mapped to MITRE ATT&CK techniques, reducing false positives on the top three noisy rules by roughly 70%.
- Ran the vulnerability management cycle across 4,000 assets, driving critical remediation SLA compliance from 62% to 94% over three quarters.
Security Analyst · Patapsco Technology Group
Aug 2019 – Jan 2022
Columbia, MD
- Closed 40 of 62 identified control gaps ahead of a SOC 2 Type II audit, which was completed with no exceptions.
- Built a phishing simulation and awareness programme, reducing click rate from 18% to 4% across 12 months.
- Produced incident reports and post-incident reviews, feeding findings back into detection and hardening backlogs.
Education
Bachelor of Science, Information Technology · University of Maryland, Baltimore County, Baltimore, MD
2019
Certifications
- CompTIA Security+ · CompTIA CySA+
- AWS Certified Security – Specialty
- CISSP (Associate) — exam passed, experience requirement in progress
Skills
- Detection:
- Splunk SIEM · Alert triage · Detection rule authoring · MITRE ATT&CK mapping · False-positive tuning
- Incident response:
- Containment · Credential compromise · Ransomware · Post-incident review
- Vulnerability management:
- Scanning across 4,000 assets · Remediation SLA tracking · Prioritisation
- Governance:
- SOC 2 Type II readiness · Control gap closure · Phishing simulation · Security awareness
Written for this occupation rather than adapted from a generic template. The sections below explain why it is built this way, and what to change first.
Information Security Analyst pay, demand and entry requirements
Before the resume, the market. These are the national figures for information security analysts, and they matter because they tell you what you are competing for and how many other applicants are competing with you.
| Measure | Figure |
|---|---|
| Median annual wage | $129,180 (BLS OEWS, May 2025) |
| People employed nationally | 182,800 (O*NET, 2024 projections base) |
| Projected growth, 2024–2034 | Much faster than average (7% or higher) |
| Projected annual openings | 16,000 |
| Typical entry-level education | Bachelor’s degree typical; certifications frequently substitute for one |
| BLS SOC code | 15-1212 |
Figures are official US government data and are revised annually — check the current BLS release before quoting a number in an interview.
What the job actually involves
Hiring managers read a resume against the work, so it helps to be precise about what the work is. These are the task statements the US Department of Labor publishes for this occupation.
Read them as a checklist. Anything on this list you have genuinely done belongs on your resume in the language a recruiter already recognises, and anything you have not done should be left off rather than softened into something that sounds close.
- Develop plans to safeguard computer files against accidental or unauthorized modification, destruction, or disclosure and to meet emergency data processing needs.
- Perform risk assessments and execute tests of data processing system.
- Encrypt data transmissions and erect firewalls to conceal confidential information.
- Review violations of computer security procedures and discuss procedures with violators.
- Monitor current reports of computer viruses to determine when to update virus protection systems.
- Modify computer security files to incorporate new software, correct errors, or change individual access status.
- Document computer security and emergency measures policies, procedures, and tests.
What makes a strong information security analyst resume
Quantify detection and response. Alerts triaged per week, incidents escalated, mean time to detect and contain, and false-positive rate on rules you tuned. These are measured in every SOC and rarely quoted.
Distinguish operations from engineering from governance. SOC analysis, security engineering and GRC are different jobs with different pay. Say which one you do rather than implying all three.
Name the tooling precisely and at the level you used it. Splunk, Sentinel, CrowdStrike, Defender — and whether you consumed dashboards or wrote the detection rules. The second is worth far more.
Tie framework work to an outcome. "Closed 40 of 62 gaps ahead of a SOC 2 Type II audit" is evidence; "familiar with SOC 2" is not.
Adapting this information security analyst example
Alert volume and estate size open the summary because they establish what "SOC experience" actually meant: 300+ alerts weekly across 4,000 endpoints and 600 servers. Security teams range from one person with a free SIEM to a 24/7 rotation, and those numbers place you immediately. The escalation figure — an average of eight true positives a month — matters just as much, because it shows you are filtering rather than forwarding.
Mean time to contain is the metric to lead with, and the example quotes it as a reduction rather than an absolute. Containment speed is what limits blast radius during a credential compromise or ransomware event, so a candidate who has moved that number has demonstrably improved the thing security exists to do. Naming the incident types is what makes it concrete; "handled incidents" tells a hiring manager nothing about severity.
Detection engineering mapped to MITRE ATT&CK is the bullet that separates an analyst from a ticket-closer. Writing and tuning 45 rules, and cutting false positives on the noisiest three, is engineering work with a direct effect on the whole team’s workload — alert fatigue is the reason real incidents get missed, so reducing it is a safety contribution, not a convenience one.
"CISSP (Associate)" is written accurately, and that precision matters more in security than almost anywhere. Associate status means the exam is passed but the required experience is not yet complete, and claiming the full certification before endorsement is the kind of misrepresentation that ends an application in a field built on trust. The SOC 2 and phishing-programme bullets round the page out by showing the two non-technical halves of the job — audit evidence and human risk — with the click rate moved from 18% to 4%.
Every detail in the document above is invented. Never send an example with placeholder facts left in it.
Keywords an applicant tracking system will look for
Most employers of information security analysts screen applications through software before a person reads them. The scan is looking for the vocabulary of the job, so the terms below are worth using where they are true of you — and worth leaving out where they are not, because the human read that follows will catch the difference.
- information security analyst · SOC analyst · SIEM · Splunk · incident response · threat hunting · vulnerability management · penetration testing · risk assessment · MITRE ATT&CK · EDR · firewall · IAM · zero trust · phishing · security awareness · SOC 2 · ISO 27001 · NIST CSF · PCI DSS · HIPAA security · CISSP · Security+ · cloud security · log analysis
Systems and software worth naming if you have used them: SIEM platforms, network monitoring software, VPN management, cloud security tooling.
Certification, licensing and what employers verify
Security is one of the few well-paid fields where certifications genuinely substitute for a degree. Security+ is the common entry credential, CySA+ and GCIH sit above it for operations, and OSCP is the recognised offensive credential. The CISSP requires five years of documented experience and is the usual gate for senior and management roles.
Cloud security credentials — AWS Security Specialty, Azure AZ-500 — have become disproportionately valuable as estates move, because the pool of people who understand both security and cloud architecture is small.
Clearances matter enormously in defence and federal work. An active clearance is worth stating prominently: it is expensive and slow for an employer to sponsor, so holding one materially changes which roles are open to you.
Mistakes that cost information security analysts interviews
- Listing frameworks and acronyms without anything you personally did.
- Not distinguishing SOC operations from security engineering from GRC, which pay differently.
- Claiming tools at consumer level when the job needs rule-writing — exposed immediately in a technical interview.
- Omitting detection and response metrics that the SOC measured for you.
- Leaving out clearance status where you hold one, when it is among the strongest signals available.
Where this role leads next
BLS projects much faster than average growth with around 16,000 openings a year across 182,800 analysts. Demand is structural — regulatory pressure, ransomware economics and cloud migration all push in the same direction — which is why pay has held at the top of the IT range.
The paths diverge early. Operations runs SOC analyst to senior analyst to SOC lead. Engineering runs security engineer to architect, and pays best. Offensive work runs penetration tester to red team. Governance runs GRC analyst to security manager to CISO. Choosing deliberately matters more here than in most fields, because the skill sets stop overlapping quickly.
Frequently asked questions
Alerts triaged, incidents led with containment times, detection rules you wrote, vulnerability remediation figures, and framework work tied to an audit outcome. Whether you are operations, engineering or GRC should be obvious in the first line.
The median annual wage was $129,180 in the 2025 OEWS data, across roughly 182,800 analysts — the highest median in this estate. Security engineering and cloud security roles pay above that; entry-level SOC work below.
Often not. This is one of the few well-paid fields where certifications genuinely substitute — Security+ as entry, CySA+ or GCIH for operations, OSCP for offensive work. The CISSP requires five years of documented experience and gates most senior roles.
Security+ while still in support, then build evidence inside your current role: log analysis, phishing triage, patch and vulnerability work, hardening projects. SOC analyst is the usual first security title and recruits heavily from help desk and systems administration.
CISSP for senior and management roles, since it requires documented experience. For hands-on work, OSCP carries the most weight offensively and cloud security credentials (AWS Security Specialty, AZ-500) are currently the scarcest relative to demand.






















