CVLoom

Cybersecurity analyst resume example

The resume below ships inside our Cybersecurity Analyst template and scores 98/100 against our 30 published ATS rules. It reads the way a SOC lead thinks — queue volumes, time to verdict, tuning results, incidents contained — proving capability without exposing a single employer secret.

98/100interview-ready

Measured by exporting this exact resume and running it through the 30 rules we publish. Certified: we only badge templates at 90 or above, a stricter bar than the 85 our checker calls interview-ready, so the design leaves headroom for your own content.

Download sample PDF

Opens in the editor with this content in place — replace it line by line. No signup, no watermark on the PDF. The sample PDF is the exact export the score was measured on.

Erik Lindgren
Cybersecurity Analyst
erik.lindgren@example.comlinkedin.com/in/eriklindgren(555) 493-2276Arlington, VA
Summary

Security analyst with seven years in SOC operations and threat detection for finance and federal-sector clients. Tuned a Splunk deployment that cut false positives 44%, led containment on 60+ confirmed incidents, and keeps median alert-to-verdict time at 12 minutes on a 150-alert daily queue. Monitors a 4,000-endpoint environment, cut mean time to detect from 9 hours to 40 minutes, and leads the incident-response drills the audit committee reviews.

Experience
Cybersecurity AnalystMeridian Vale Financial2021 – Present
  • Triage 150+ SIEM alerts a day in Splunk Enterprise Security; median time to verdict down from 45 minutes to 12
  • Tuned 80 detection rules against MITRE ATT&CK, cutting false positives 44% while widening technique coverage across 12 tactics
  • Led containment on 60+ confirmed incidents, including a phishing campaign that touched 900 mailboxes and zero executive accounts
  • Monitor and triage 800 alerts a day across a 4,000-endpoint environment in Splunk and CrowdStrike
  • Cut mean time to detect from 9 hours to 40 minutes with tuned detections and automated enrichment
  • Lead 4 tabletop incident-response exercises a year and write the after-action reports for the audit committee
SOC AnalystArgus Sentinel Group2019 – 2021
  • Monitored 12 client environments on a 24x7 SOC rotation; escalation accuracy held above 96% across 18 months
  • Wrote 30 Cortex XSOAR playbooks automating enrichment for a tier-1 queue that processes 2,000 alerts a week
  • Investigated 60 incidents a month for 20 clients as a Tier 2 analyst with a 30-minute escalation SLA
  • Wrote 40 detection rules that cut false positives 35%
IT Support SpecialistChesapeake Freight Lines2018 – 2019
  • Administered Active Directory, group-policy baselines, and endpoint protection for 400 users across 3 distribution sites and a headquarters
  • Rolled out MFA to 100% of staff within four months, blocking 300+ credential-stuffing attempts the first year
  • Supported 300 users and hardened 200 laptops to the CIS benchmark
Education
B.S. Information SystemsUniversity of Maryland2018
Skills
DetectionSplunk · Microsoft Sentinel · CrowdStrike Falcon · Wireshark · Zeek · Incident response · Threat hunting
FrameworksMITRE ATT&CK · NIST 800-53 · PCI DSS · CIS Controls
PracticesIncident response · Threat hunting · Vulnerability management · Phishing analysis
Certifications
CompTIA Security+
CompTIA CySA+
GIAC Certified Incident Handler (GCIH), 2023

The live document, not a screenshot. Names and employers are fictional.

Why these bullets work

Every line below is taken verbatim from the resume above.

Triage 150+ SIEM alerts a day in Splunk Enterprise Security; median time to verdict down from 45 minutes to 12

Queue volume plus a median — not an average — tells a SOC lead you actually watch your own metrics. Naming Splunk ES gives the ATS and the human screener the same keyword in one pass.

Tuned 80 detection rules against MITRE ATT&CK, cutting false positives 44% while widening technique coverage across 12 tactics

Anyone can silence a noisy rule by turning it off. 'While widening coverage' is the caveat that proves the tuning was real — precision up and coverage up is the claim an interviewer will happily dig into.

Led containment on 60+ confirmed incidents, including a phishing campaign that touched 900 mailboxes and zero executive accounts

'Led containment' claims a role, not attendance. The 900-mailbox story with its zero-executive-accounts ending is exactly the two-line war story a hiring panel will ask you to retell.

Wrote 30 Cortex XSOAR playbooks automating enrichment for a tier-1 queue that processes 2,000 alerts a week

Automation is how a SOC scales, and this bullet proves you build the machine rather than just work in it. Product name, artifact count, and queue size — three verifiable facts, zero adjectives.

Making it yours

  • Trade this example's queue numbers for yours: alerts per day, median time to verdict, escalation accuracy. SOC hiring runs on throughput metrics, and vague 'monitored security events' lines screen out.
  • Write certifications in the form filters search — Security+, CySA+, CISSP if you hold it — and list them even when they feel entry-level; the ATS boolean does not award partial credit.
  • Name your SIEM and EDR precisely (Splunk ES, Microsoft Sentinel, CrowdStrike Falcon). A shop running Sentinel greps for Sentinel, and 'various SIEM tools' matches nothing.
  • Anchor at least one bullet to a framework — rules mapped to MITRE ATT&CK tactics, controls against NIST 800-53 — because it tells a security manager your work plugs into their program, not just their queue.

Common questions

Can I land a SOC analyst role with just Security+?

Security+ clears the HR filter; the bullets clear the SOC lead. Pair the cert with any measurable handling you've done — even helpdesk-era MFA rollouts and phishing triage, quantified the way this example does — and you're interviewable.

How do I describe incidents without breaching confidentiality?

Count and characterize, never attribute: '60+ confirmed incidents, including a 900-mailbox phishing campaign' names no employer or system. Numbers and technique labels tell the story; the logs and company names stay home.

Check your own against the same 30 rules

Upload your resume and get the score this example earned, rule by rule. Free, unlimited, no signup — and nothing of your file is kept.

Run the free checker

Keep going