Security Analyst Resume Example

A security analyst defends an organisation in real time: triaging alerts, investigating suspicious activity, responding to incidents, hunting for what automated tooling missed, and tuning detections so the noise goes down. It is the job of catching the attack while it is happening, which is measured very differently from the job of preventing it. The sample above is a six-year SOC analyst, and this guide shows how to write yours.
Written by Emily Radcliffe
5.0
Was this sample helpful? Rate it! Average: 5.0 (24 votes)

Omar Haddad

Security Analyst
[email protected] | 445976823410

Summary

Security analyst with six years defending companies from cyber threats in a security operations centre in Dubai. Watches for the attack and stops it — monitoring alerts, investigating suspicious activity, responding to incidents, and hunting for the threats that slip past automated defences before they turn into a breach. Caught and contained intrusions before damage was done and cut false alerts so the team could focus on real threats. Monitors and triages alerts, investigates and responds to incidents, threat-hunts, tunes detections, and reports on risk. Vigilant, analytical and calm under pressure. Looking for a security-analyst or SOC role with an organisation that takes the threat to its data and systems seriously.

Professional Experience

Security Analyst
Dubai Security Operations Centre, Dubai, UAE
Jan 2020 – Present
  • Watch for the attack and stop it, catching threats before they ever turn into a real breach.
  • Caught and contained intrusions before damage was done and cut false alerts so the team could focus on real threats.
  • Monitor and triage security alerts across the estate, separating the real threats from the constant noise.
  • Investigate suspicious activity and respond to incidents, containing and remediating threats under time pressure.
  • Threat-hunt proactively for what automated defences miss, finding the quiet attackers already inside.
  • Tune detections and report on risk, making the whole monitoring system sharper and keeping leadership informed.
Junior SOC Analyst
UAE Managed Security Provider, Dubai, UAE
Feb 2019 – Dec 2019
  • Monitored alerts and supported incident response for clients under senior analysts, learning SOC work hands-on.
  • Triaged alerts and helped investigations, steadily building detection and response skills over the year.
  • Learned monitoring, triage and incident response on the job during this first role.
  • Gained the certifications and experience that led into a full security-analyst role of my own.

Education

BSc in Cybersecurity, Cybersecurity
American University in Dubai
Sep 2014 – Jun 2018
  • Degree in cybersecurity covering networks, threats, incident response and security operations, with a placement. The programme built the technical foundation defending systems requires. It led directly into security analysis work.
CompTIA Security+ & SOC Analyst Certification, Cybersecurity
CompTIA
Aug 2018 – Jan 2019
  • Industry certifications covering security fundamentals, monitoring and incident response to recognised standards. They sharpened the SOC toolkit. They supported detecting, investigating and responding to threats to a professional standard.

Highlights

Contained intrusions early
  • Caught and contained intrusions before they did damage. Catching an attacker early, before they reach the data, is the difference between an incident and a breach, and is exactly what a security analyst exists to do.
Cut the noise
  • Cut false alerts so the team could focus on real threats. Alert fatigue is how real attacks get missed, so reducing the noise sharpens the whole team's ability to spot and respond to what genuinely matters.

Certifications

Security+ & SOC Analyst Certification
CompTIA
Jan 2019 – Present
  • Industry certifications covering security fundamentals, monitoring and incident response to recognised standards, which sharpened the SOC toolkit and support detecting, investigating and responding to threats to a professional standard.

Recognition

A sharp set of eyes on threats
  • Relied on in the SOC to spot and contain the threats others miss, valued for catching intrusions early, cutting alert noise and staying calm and clear-headed during live security incidents.

Languages

  • English (UK) — Full Professional Proficiency
  • Arabic — Native or Bilingual Proficiency

Technical Skills

  • Threat Monitoring
  • Incident Response
  • Alert Triage
  • Threat Hunting
  • SIEM Tools
  • Malware Analysis
  • Network Security
  • Detection Tuning
  • Risk Reporting
  • Forensics Basics

Personal Skills

  • Vigilance
  • Analytical Thinking
  • Calm Under Pressure
  • Attention to Detail
  • Communication

Activities & Interests

  • Dancing
  • Play Violin
  • Boating
  • Badminton
  • Walking

Security Analyst Resume: The Essentials

SOC hiring managers look for evidence you can hold a queue and investigate properly. These are the signals:
  • Name your SIEM and EDR platforms explicitly, because Splunk, Sentinel, CrowdStrike and SentinelOne are screened as literal keywords.
  • Quantify detection and response with time, since mean time to detect and respond are the numbers a SOC is actually run on.
  • Show false positive reduction, as tuning the queue down is the highest-leverage thing an analyst does for the whole team.
  • Describe investigations by depth rather than volume, because handling four hundred alerts says less than one properly traced intrusion.
  • Distinguish yourself from a security engineer, since analysts are judged on what they caught and engineers on what they prevented.
  • Map your work to a recognised framework such as MITRE ATT&CK, which gives a hiring manager a shared vocabulary for your coverage.

Why This Security Analyst Resume Works

This sample belongs to a six-year analyst in a security operations centre, and it captures both halves of what a SOC is judged on.
  • The opening describes the job as watching for the attack and stopping it, which correctly frames the role around detection and response rather than prevention.
  • It leads on two paired outcomes, containing intrusions before damage and cutting false alerts, covering both the catching and the queue quality that makes catching possible.
  • Cutting false alerts so the team could focus on real threats is the strongest line, because tuning benefits every analyst on every shift rather than just the author.
  • Threat hunting is separated from alert triage, and that distinction matters because hunting is proactive work that many analysts never actually get to do.
  • Reporting on risk to leadership is included, which shows an analyst who can translate technical findings for an audience that does not read alert consoles.
  • The junior SOC role gives a visible apprenticeship, and in security operations the progression from L1 triage to full analyst is exactly what employers look for.

How to Write a Security Analyst Resume

A SOC lead wants to know whether you can be trusted with the queue on a night shift. Write to that.
List your platforms by name and depth
Splunk, Microsoft Sentinel, QRadar, CrowdStrike Falcon, SentinelOne, Defender. Say whether you wrote the queries or consumed the dashboards, because writing detection logic in SPL or KQL puts you in a materially different band from clicking through a console.
Put time on your detection and response
Mean time to detect, mean time to respond, time to containment on a real incident. A SOC is run on these clocks, so an analyst who quotes them speaks the language of the people making the hiring decision rather than describing generic responsibilities.
Show that you reduced the noise
False positive rate cut, alerts per shift reduced, rules tuned or retired. Alert fatigue is the reason real intrusions get missed, so an analyst who has measurably improved queue quality is solving the SOC's most expensive underlying problem.
Describe one investigation properly
Take a single real incident and give the shape of it: initial signal, what you pivoted on, how you established scope, and how it was contained. One well-described investigation demonstrates analytical reasoning in a way that a count of tickets closed never can.
Separate hunting from triage
Threat hunting is forming a hypothesis and going looking, rather than reacting to what a tool surfaced. If you have hunted, say what hypothesis you tested and what you found, since proactive work distinguishes a senior analyst from a queue processor.
Anchor your coverage to a framework
Mapping detections and investigations to MITRE ATT&CK gives a hiring manager an immediate sense of your breadth. It also demonstrates you think about coverage systematically rather than responding to whatever the tooling happens to alert on that day. SOC teams hire in waves when they add a shift or a new client, and the roles fill fast. You can build a security resume free and keep your tooling and certifications ready to send the same day a posting appears.

What to Include in a Security Analyst Resume

Beyond the standard sections, a SOC lead is checking for these specifically:
A platform line per role covering SIEM, EDR and any SOAR or ticketing tooling, with your depth in each.
Response metrics including mean time to detect, mean time to respond and alert volume handled per shift.
Detection tuning outcomes, expressed as false positive reduction or rules written, tuned and retired.
One incident described in enough detail to show your reasoning, without naming the employer's systems or data.
Threat hunting work separated from reactive triage, including the hypotheses tested and anything found.
Shift pattern worked, since twenty-four seven SOCs need people who have genuinely done nights and can say so.
Extra tips
Describe a single incident with the signal, the pivot, how you scoped it and how it was contained.
Alert counts measure the queue's noise; one traced investigation measures you.

Security Analyst Resume Summary Examples

Two summaries from either end of a SOC career, both leading with platforms and measurable response:
Entry-level resume summary example
Junior SOC analyst with fourteen months on a twenty-four seven managed security team, working a rotating shift pattern including nights and weekends across a portfolio of eleven client environments. Triages around a hundred and twenty alerts per shift in Microsoft Sentinel, escalating genuine incidents with a written timeline and initial scope assessment rather than passing raw alerts upward. Writes basic KQL queries for investigation and has authored four detection rules now running in production, one of which caught a credential stuffing attempt against a client tenant. Holds CompTIA Security+ and is studying for CySA+, with a home lab running Sentinel and Sysmon for practising detection engineering. Looking for a full security analyst position with an internal SOC that will develop threat hunting skills.
Senior-level resume summary example
Security analyst with seven years in security operations, currently the senior analyst on a twenty-four seven internal SOC protecting a fifteen thousand employee estate across cloud and on-premise infrastructure. Cut mean time to respond on critical alerts from fifty-two minutes to under fifteen by rebuilding the triage runbooks and automating the initial enrichment steps through the SOAR platform. Reduced false positive volume by around sixty-five percent across the twenty noisiest rules, which took the queue from unmanageable on a night shift to genuinely workable by one analyst. Led the investigation and containment of a business email compromise, establishing full scope across nine mailboxes within four hours and preventing any fraudulent payment. Splunk and CrowdStrike certified, holding GCIH and seeking a lead analyst or detection engineering role.

Security Analyst Work Experience Examples

Three sets covering how SOC work progresses, since L1 triage, incident response and threat hunting are assessed as different capabilities.
Junior / L1 SOC analyst
  • Triaged around a hundred and twenty security alerts per shift across eleven client environments in Microsoft Sentinel, working a rotating pattern that included nights and weekends.
  • Escalated genuine incidents with a written timeline, affected asset list and initial scope assessment attached, rather than passing raw unenriched alerts upward to senior analysts.
  • Authored four detection rules now running in production, one of which caught a credential stuffing attempt against a client tenant before any single account was successfully compromised.
  • Wrote KQL queries to investigate suspicious authentication and process activity, building the query skills that separate a real analyst from someone simply reading a prebuilt dashboard.
  • Maintained a home lab running Sentinel and Sysmon to practise detection engineering, testing new rules against simulated attacker behaviour before ever proposing them in the production environment.
Incident response and detection tuning
  • Cut mean time to respond on critical alerts from fifty-two minutes to under fifteen by rebuilding the triage runbooks and automating the initial enrichment through the SOAR platform.
  • Reduced false positive volume by around sixty-five percent across the twenty noisiest detection rules, taking the night shift queue from unmanageable to workable by a single analyst.
  • Led the investigation and containment of a business email compromise, establishing full scope across nine affected mailboxes within four hours and preventing any fraudulent payment.
  • Ran structured post-incident reviews after every significant event, converting each set of findings into either a new detection rule or a specific documented change to the response runbook.
  • Coordinated containment actions with infrastructure and identity teams during live incidents, isolating affected hosts and revoking sessions without disrupting unrelated business operations.
Threat hunting and reporting
  • Ran structured threat hunts against hypotheses drawn from current threat intelligence, mapping each hunt to MITRE ATT&CK techniques relevant to the organisation's actual architecture.
  • Discovered a persistence mechanism that had evaded automated detection for several weeks, then built and deployed a detection rule that would have caught it within minutes of installation.
  • Produced monthly risk reporting for security leadership, translating detection coverage, incident volume and response times into terms a non-technical audience could genuinely act upon.
  • Expanded detection coverage against the techniques most relevant to the organisation, closing eleven specific gaps identified by mapping the existing rule set against the ATT&CK matrix.
  • Mentored two junior analysts through their first six months on the queue, reviewing every escalation they raised and coaching the investigative reasoning behind each triage decision.

Top Security Analyst Skills

What a SOC lead screens for, weighted toward detection, investigation and the discipline to work a queue well:
Hard skills
  • SIEM (Splunk, Sentinel, QRadar)
  • EDR (CrowdStrike, SentinelOne, Defender)
  • Alert Triage
  • Incident Response
  • Threat Hunting
  • Detection Rule Writing (SPL / KQL)
  • MITRE ATT&CK Mapping
  • Log Analysis
  • Network Traffic Analysis
  • Malware Analysis Basics
  • Digital Forensics Fundamentals
  • Phishing & Email Threat Analysis
  • SOAR & Response Automation
  • Threat Intelligence
  • Vulnerability Assessment
  • Identity & Access Investigation
  • Security Reporting
Soft skills:
  • Vigilance
  • Analytical Reasoning
  • Calm Under Pressure
  • Attention to Detail
  • Clear Written Escalation
  • Shift Reliability

Certifications for a Security Analyst

Security operations is one of the areas where certification genuinely helps get a first interview:
  • CompTIA Security+ — CompTIA
    The standard entry credential and frequently a hard requirement on SOC job adverts. It also satisfies a US Department of Defense baseline requirement for many roles.
  • CompTIA CySA+ — CompTIA
    The natural step after Security+, focused specifically on detection and response rather than general security awareness, which makes it well matched to SOC work.
  • GCIH — GIAC
    Expensive but highly respected for incident response roles. Worth pursuing once you have real investigation experience, and often employer-funded rather than self-funded.
  • Vendor Platform Certification — Splunk, Microsoft or CrowdStrike
    Match it to the platform in the job advert. A Splunk or Sentinel certification proves you can work the specific tool a SOC already runs, which shortens your ramp considerably.

Security Analyst Salary

Analyst pay varies sharply by tier, since an L1 working a managed service queue and a senior incident responder sit far apart within the same job family:
USD 70,000 – USD 160,000 · Information security analyst · US
National median around $129,180 across all information security roles. L1 SOC positions sit well below that median, with senior responders at or above it.

Common Security Analyst Resume Mistakes

These are what keep a capable analyst stuck in the screening pile:
  • Listing security tools without saying what you did in them, so a reader cannot tell whether you wrote detection logic or watched a dashboard.
  • Quoting alert volume alone, which measures how noisy the queue was rather than how well you investigated anything in it.
  • Omitting response times entirely, when mean time to detect and respond are the metrics the whole function is managed against.
  • Never describing a single investigation, which leaves your analytical reasoning completely invisible to someone assessing exactly that.
  • Claiming threat hunting for what was actually alert triage, a distinction any experienced SOC interviewer will unpick in one question.
  • Blurring analyst and engineer responsibilities, which usually results in being screened out of both rather than considered for either.

Security Analyst Resume FAQs

The questions security analysts most often search when applying to SOC roles, answered directly:

Lead with your SIEM and EDR platforms by name, then alert triage, incident response and threat hunting. Add detection rule writing in SPL or KQL and MITRE ATT&CK mapping, since those distinguish an analyst who investigates from one who forwards alerts onward.
An analyst detects and responds, working alerts, investigations and hunts in real time. An engineer builds and hardens, shipping tooling, pipeline controls and cloud guardrails. Analysts are measured on what they caught and how fast; engineers on what they prevented entirely.
Name the ones you have genuinely used and state your depth in each. Writing detection logic in Splunk SPL or Sentinel KQL is worth far more than console familiarity, and employers screen for the specific platform they run, so put it in your skills block verbatim.
Describe the attack type, your actions and the outcome, never the employer's systems, data or the specific weakness exploited. Something like containing a business email compromise across nine mailboxes within four hours communicates capability while disclosing nothing sensitive.
Security+ first, since it appears as a hard requirement on many SOC adverts and satisfies a US Department of Defense baseline. CySA+ is the better match for the work itself, being focused on detection and response, so the usual path is to hold both in that order.
Build a home lab with a SIEM and generate real telemetry, then write and test detections against simulated attacker behaviour. Pair that with Security+ and be explicit about shift availability, since twenty-four seven SOCs hire heavily for nights and weekends.

Get Started With Our
Free Resume Creator today!

Free sign-up. No credit card required.