Cybersecurity Analyst resume example

Security hiring managers scan for SOC operations experience first: which SIEM you ran, how many alerts you triaged, and how fast incidents got contained. Vague 'ensured company security' language reads as filler next to a stated mean-time-to-respond number.

Name the compliance framework (NIST, ISO 27001, SOC 2) your work aligned to, since audit-facing experience is a common differentiator between junior and mid-level analyst candidates.

Derek Solomon

Cybersecurity Analyst

Arlington, VA derek.solomon@email.com +1 (703) 555-0112 linkedin.com/in/dereksolomon

Summary

Cybersecurity Analyst with 5+ years of experience in SOC monitoring, threat hunting, vulnerability assessment, and incident response within highly regulated enterprise environments. Proven record of reducing incident response times by 73% across 200 alerts daily, implementing NIST 800-53 security controls, and executing comprehensive vulnerability remediation across critical infrastructure.

Experience

Cybersecurity Analyst II
Ironclad Sentinel Group · Arlington, VA
Mar 2023 — Present
  • Triaged 200 daily Splunk SIEM alerts, cutting mean time to respond from 45 minutes to 12 minutes (73% reduction) and neutralizing 3 phishing intrusions.
  • Led vulnerability scanning operations with Nessus across 800 enterprise endpoints, reducing critical-severity patch cycles from 30 days to 9 days.
  • Aligned incident-response workflows with NIST 800-53 controls ahead of external audits, achieving 100% compliance across 14 security domains.
SOC Analyst I
Blackridge Security · Arlington, VA
Jul 2020 — Feb 2023
  • Monitored network telemetry across 12 customer environments, detecting and isolating an insider data-exfiltration attempt within 20 minutes.
  • Executed penetration testing engagements across 2 client web applications, discovering and remediating 9 high-severity CVEs prior to production.
  • Authored Wireshark packet-analysis playbooks, reducing junior analyst intrusion investigation time by 40% across 6 months.

Skills

Splunk · SIEM · Incident Response · Vulnerability Management · Nessus · Wireshark · NIST 800-53 · MITRE ATT&CK · Firewall Configuration · Threat Intelligence

Education

George Mason University
B.S. Cybersecurity Engineering
2016 — 2020

Certifications

CompTIA Security+ · CompTIA CySA+

Cybersecurity Analyst · Engineering Minimal template · single-column, ATS-safe.

ATS keywords for a Cybersecurity Analyst resume

Applicant tracking systems match your resume against the job description's vocabulary. Mirror the terms below that are true of you — ideally with a metric attached.

SIEMSplunkSOCNIST 800-53Incident ResponsePenetration TestingVulnerability ManagementThreat IntelligenceFirewall ConfigurationIDS/IPSCISSPNessusWiresharkMITRE ATT&CK

What recruiters look for

  • The SIEM platform named explicitly (Splunk, QRadar, Sentinel) and tied to an alert-volume figure.
  • Incident-response metrics: mean time to detect/respond, number of incidents contained.
  • A named compliance framework (NIST, SOC 2, ISO 27001) the analyst's work supported.
  • Vulnerability management evidence — scan cadence, patch SLA, critical-finding remediation rate.
  • Relevant certification (Security+, CySA+, CISSP) listed, since many SOC roles filter on it.

Before & after: one bullet

Weak

Monitored security alerts and responded to incidents as needed.

Strong

Triaged 200+ daily Splunk SIEM alerts, cutting mean time to respond from 45 to 12 minutes and containing 3 phishing-driven incidents before lateral spread.

Common mistakes to avoid

  • No SIEM tool named, which is the first ATS filter for most SOC and analyst postings.
  • Vague 'monitored network security' language with no alert volume or incident count.
  • Missing the compliance framework context that shows the analyst understands audit requirements.
  • Omitting certifications entirely when the role explicitly lists them as required or preferred.