Security hiring is unusually careful about accuracy, because the consequences of hiring someone who has overstated their experience are immediate. Certifications, clearances and tool access are all verifiable, and reviewers do verify them. The single most important quality of a security CV is that everything on it is true and precisely stated.
Beyond accuracy, reviewers look for evidence that you have handled real alerts rather than laboratory scenarios: what you triaged, what you escalated, what turned out to be a false positive, and what you changed so the same alert did not fire fifty more times.
This example is written for an analyst with four years in a security operations centre moving towards detection engineering.
ayesha.siddiqui@example.co.uk+44 7700 900622London, United Kingdomlinkedin.com/in/example-ayesha-siddiqui
Profile
Security analyst with four years in a 24/5 SOC covering financial services clients. Triage around 120 alerts a day, author Sigma detections mapped to MITRE ATT&CK, and have led containment on business email compromise and credential-stuffing incidents. CompTIA Security+ and Microsoft SC-200 certified.
SupportingPython, PowerShell, Linux, Active Directory
Professional Experience
Security Analyst (Tier 2)
Halberd Managed Security · London, United KingdomMarch 2023 – Present
•Triage around 120 alerts a day as second-line analyst across eight financial services clients, escalating a monthly average of nine confirmed incidents with full timeline documentation.
•Authored 30 Sigma detections mapped to MITRE ATT&CK techniques including T1078 and T1110, validated against replayed historical logs before release.
•Rewrote the credential-stuffing rule that generated roughly half the team’s false positives, bringing it from about 40 a week to 3 without missing a subsequent true positive.
•Acted as scribe and then lead analyst on a business email compromise incident: isolated three mailboxes, revoked sessions and produced the timeline used in the client notification.
•Run the monthly detection review with the engineering team and maintain the coverage matrix against ATT&CK.
Splunk · Microsoft Sentinel · CrowdStrike · Sigma
SOC Analyst (Tier 1)
Halberd Managed Security · London, United KingdomSeptember 2021 – February 2023
•First-line triage on a 24/5 rota, handling phishing reports, endpoint detections and authentication anomalies against documented playbooks.
•Reduced average phishing triage time from 22 minutes to 8 by scripting header and URL extraction in Python.
•Wrote four playbooks for alert types that previously had none, which removed the dependency on a single senior analyst for those cases.
Splunk · Python · Defender for Endpoint
Certifications
CompTIA Security+ (SY0-701)
CompTIAJune 2021
Microsoft Certified: Security Operations Analyst Associate (SC-200)
MicrosoftJanuary 2023
BTL1 – Blue Team Level 1
Security Blue TeamApril 2022
Education
BSc (Hons) Cyber Security
University of Westminster · London, United KingdomSeptember 2018 – July 2021
•Dissertation on detection coverage gaps in small-business Microsoft 365 tenancies.
First Class Honours
Professional Memberships
Chartered Institute of Information Security
Associate MemberJanuary 2022 – Present
Languages
EnglishNative
UrduC1
ArabicA2
Cybersecurity Analyst example on the Minimal ATS layout. All details are fictional and shown for demonstration only.
What recruiters expect
Before writing anything, it helps to know what the person reading is checking for. In this field that is usually a short, specific list:
Alert volumes and triage throughput, with the proportion that turned out to be genuine.
Named tooling: the SIEM, the EDR, the ticketing system. Security teams buy specific products and hire for them.
Framework fluency - MITRE ATT&CK, NIST CSF, ISO 27001 - used in context rather than listed.
Detection content you wrote yourself, and how you tested it.
Certifications stated exactly, with dates, and never implied when they are in progress.
Recommended CV structure
This is the running order the example uses. It is a starting point rather than a rule, but the order reflects what tends to be read first in this profession.
Profile — Three or four lines positioning you for the role.
Technical Skills — Grouped skills, for example "Languages" and "Tooling".
Professional Experience — Paid roles, in reverse chronological order.
Certifications — Completed certifications with the issuing body.
Education — Degrees, diplomas and school-leaving qualifications.
Professional Memberships — Bodies you belong to, with membership numbers where relevant.
Languages — Spoken languages with CEFR levels.
Sections worth adding
Training — Vendor and hands-on lab training is respected while certifications are pending.
Home Lab & Research — Valuable for early-career analysts; describe methodology, not exploits.
Skills worth including
Grouped rather than listed in one block. Grouping makes a long list readable and shows that you can tell the difference between the things you use daily and the things you have touched.
Python scripting · PowerShell · Linux · Active Directory · Jira Service Management
Beyond the technical list: Incident communication, Writing for non-technical stakeholders, Handover discipline, Working to defined escalation paths. These belong inside your experience bullets, demonstrated, rather than in a list of adjectives.
Example professional summary
Three or four lines, positioned for the role rather than describing your personality. Two versions you can adapt:
Security analyst with four years in a 24/5 SOC covering financial services clients. Triage around 120 alerts a day, author Sigma detections mapped to MITRE ATT&CK, and have led containment on business email compromise and credential-stuffing incidents. CompTIA Security+ and Microsoft SC-200 certified.
SOC analyst moving into detection engineering. Comfortable in Splunk and Sentinel, with a focus on reducing alert fatigue - most recently by rewriting the three rules responsible for roughly half of the team’s false positives.
Writing your experience
The difference between a CV that gets a call and one that does not is almost always in the bullet points. Each pair below shows a real rewrite of the kind of line that appears on most CVs in this field.
Weak
Monitored security alerts.
Stronger
Triaged around 120 alerts a day as first responder in a 24/5 SOC, escalating a monthly average of nine confirmed incidents with full timeline documentation.
Gives volume, role in the process and the output the next person receives.
Weak
Wrote detection rules.
Stronger
Authored 30 Sigma rules mapped to MITRE ATT&CK techniques T1078 and T1110, validated against replayed historical logs before release; false positives on the credential-stuffing rule fell from about 40 a week to 3.
Shows detection engineering practice including validation, which is what separates writing rules from tuning them.
Weak
Helped with incident response.
Stronger
Acted as scribe and then lead analyst on a business email compromise incident, isolating three mailboxes, revoking sessions and producing the timeline used in the customer notification.
Concrete containment actions and a deliverable, without exaggerating the level of authority held.
Taken from the example
The sample CV for this profession is fully written. A few sections from it, so you can see the level of specificity that works:
Triage around 120 alerts a day as second-line analyst across eight financial services clients, escalating a monthly average of nine confirmed incidents with full timeline documentation.
Authored 30 Sigma detections mapped to MITRE ATT&CK techniques including T1078 and T1110, validated against replayed historical logs before release.
Rewrote the credential-stuffing rule that generated roughly half the team’s false positives, bringing it from about 40 a week to 3 without missing a subsequent true positive.
Acted as scribe and then lead analyst on a business email compromise incident: isolated three mailboxes, revoked sessions and produced the timeline used in the client notification.
Education
BSc (Hons) Cyber Security, University of Westminster — First Class Honours
Certifications and registration
CompTIA Security+ (SY0-701) — CompTIA
Microsoft Certified: Security Operations Analyst Associate (SC-200) — Microsoft
BTL1 – Blue Team Level 1 — Security Blue Team
Common mistakes
Listing certifications you are studying for as if held
Write "CISSP – studying, exam booked March 2026". Anything less precise is treated as a misrepresentation when it is discovered.
Describing offensive techniques on a defensive CV
Detail about exploitation belongs in a penetration testing CV. For a SOC role, the reviewer wants detection, triage and containment.
No sense of alert volume
Handling 15 alerts a day and 150 are different jobs. Giving the number tells a reviewer immediately which one you have done.
Framework name-dropping
Listing ATT&CK without a technique or a use case is transparent. One sentence about mapping detections to specific techniques is worth more.
ATS considerations
Applicant tracking systems behave differently by sector, and generic advice is often wrong for a given field. These points are specific to cybersecurity analyst applications:
Spell out abbreviations once: "security information and event management (SIEM)", "endpoint detection and response (EDR)".
Use the exact certification titles including the awarding body, because screening is often done against a list.
Name the SIEM product. "SIEM experience" alone will not match an advert asking for Sentinel.
If you hold or are eligible for a security clearance, state it precisely and never imply a level you do not hold.
The Minimal ATS layout is built for this, and the ATS guide covers what parsers do to a file in more detail.
Questions about cybersecurity analyst CVs
Which certification should I get first?
CompTIA Security+ remains the most widely recognised entry point in the UK and much of Europe. Product certifications such as SC-200 or the Splunk track are worth more once you know which platform your target employers run.
Can I mention a home lab?
Yes, especially early in your career. Describe what you detected and how you validated it. Avoid step-by-step attack detail, which reads badly to a corporate reviewer.
How do I write about incidents without breaching confidentiality?
Describe the incident class, the actions you took and the outcome, without naming the client, the affected systems or the specific indicators.
Should I list security clearance?
State it if you hold it, with the level and expiry. If you are eligible but not cleared, say "eligible for clearance" rather than implying you already hold it.