Security hiring is certification-gated and metrics-starved: most analyst reqs filter on Security+ or an equivalent before a human ever reads the page, and most of the resumes that survive the filter then say "monitored alerts" with no numbers attached. That combination creates the opening this page is built around. Alert volume, triage times, false-positive reductions, incidents worked end to end, and playbooks adopted are all measurable, almost nobody puts them on paper, and the SOC managers doing the second read notice immediately when someone does. The example below is a working analyst's resume shaped for exactly those two passes: the certification filter first, the queue-numbers read second.
The strongest security bullets follow one shape: the environment, the action, and the number that moved. "Responsible for SIEM monitoring" is a duty that describes every analyst alive. "Triage 60+ Splunk alerts per shift for a 15,000-endpoint environment, holding median time-to-triage under 12 minutes" is a hire, because it answers capacity, tooling, and quality in one line. If your shop never gave you clean metrics, use scale and counts instead: endpoints covered, log sources onboarded, investigations documented, detections written. Our bullet-writing guide covers pulling honest numbers out of ticket systems and shift reports after the fact.
Section order for a working analyst: header, a three-sentence summary, certifications (with clearance if you hold one), experience, skills grouped by operations versus frameworks, education last. Certifications ride that high because they are the gate: a screener who cannot find Security+ or CySA+ in five seconds assumes it is not there. Career changers and new grads flip the bottom: education, certifications, then labs and projects presented as experience entries with real specifics. What never works is a paragraph of security buzzwords up top; every reviewer in this field has seen a thousand resumes that say "passionate about cyber" and hired none of them for the phrase.
Know the reading order. An HR recruiter or sourcer goes first and usually is not technical: they match certification names, SIEM and EDR product names, clearance status, and years against the req checklist. The SOC lead or security manager reads second and looks for texture: whether your escalations were judgments or hot-potato passes, whether you have written detections or only consumed them, whether your incident bullets describe containment decisions or just presence at the incident. Write the top third for the checklist reader and the bullets for the manager, and keep the tool names literal for both, because "a leading SIEM platform" matches nothing in anyone's search.
Write the experience section as environment first, outcomes second. Open each role with the scope line a manager needs to calibrate everything after it: endpoint count, queue volume, industry and its compliance regime (healthcare and HIPAA, federal and FedRAMP, finance and PCI). Then spend the remaining bullets on change: detection rules tuned and the false-positive rate that fell, incidents worked with your specific part named, automations that cut research time, audits your documentation survived. Verbs matter: triaged, contained, tuned, hunted, and escalated are the working vocabulary of the SOC, and they beat "assisted with" and "was involved in" everywhere they are true. Our action verbs guide sorts the options by what you are claiming.
Group skills so a screener can verify the checklist in five seconds. Two or three labeled lines beat one comma wall: operations (SIEM, EDR, vulnerability management, email security, with product names), then frameworks and scripting (MITRE ATT&CK, NIST 800-61, Python, PowerShell, KQL, SPL). Name products exactly, because filters are literal: "Splunk ES", "Microsoft Sentinel", "CrowdStrike Falcon", not "various SIEM tools". List only what you would accept a deep interview question on; security interviewers probe tool claims harder than almost any other field, and one exposed exaggeration ends the loop. The edge cases, including where lab-only tools belong, are in our skills section guide.
Treat certifications as a dated, ordered, load-bearing section. Current and highest-relevance first: for most analyst roles that means CySA+ or GSEC above Security+, with exact official names and dates, because verification is routine and stale dates read as lapsed. If you hold or held a clearance, state it plainly ("Secret clearance, active") in the same section; it is a hard filter for government-adjacent work. Degrees stay short after your first security job: degree, school, year. A cybersecurity degree with no certifications reads weaker in this field than certifications with no degree, which is worth knowing before you spend resume space defending the wrong one.
Format for the parser and the paranoid reviewer at once. One column, standard headings, a common font, PDF export, no photo, no graphics, no skill bars. Security teams run resumes through the same parsing pipelines as everyone else, and a security professional whose resume needs a macro-enabled template or scrambles when flattened to text starts the relationship with an irony nobody enjoys. Name the file plainly: your name and the word resume. Every point of visual novelty is parsing risk with zero payoff in this field; the complete checklist is in our resume format guide.
Know the failure modes that recur on analyst resumes. The big four: tool soup (fifteen product names, zero incidents or numbers), duty bullets ("monitored security alerts" with no volume or outcome), inflated claims (listing forensics because you once opened Autopsy, which the interview will find), and stale artifacts (an expired certification listed as current, a home lab link that no longer resolves). Each takes minutes to fix and costs interviews when left in. There is also a field-specific one: writing about incidents in a way that leaks employer specifics; count and categorize, never narrate identifying detail. Run your draft against our common mistakes guide before it goes anywhere.
A word on the top third before the example: the summary is a claim backed by the bullets below it, three sentences, in a fixed order that works: role and years with environment type first, tooling and scale second, one outcome third. The level-calibrated variants further down this page show that shape at entry, mid, and senior weight. If your title history does not yet say "security" (help desk moving over, military transition, new grad), use an objective instead, and the objective examples below cover those three cases; either way, our summary guide breaks down the construction sentence by sentence.
Tailoring in security is mostly a nouns exercise, because the filters are literal. Read the posting, circle its SIEM, EDR, and framework names, and make sure every one you honestly have appears in your top bullets or skills in the posting's exact form: if they say "Sentinel" and your resume says "Microsoft's cloud SIEM", you lose a match you earned. Mirror the compliance regime too (HIPAA, PCI DSS, FedRAMP), since regulated employers search their own acronyms. This is a ten-minute pass per application, not a rewrite; our tailoring guide shows the method.
The 2026 reality of SOC work is that automation ate the easy tickets. LLM-assisted triage and SOAR playbooks now handle much of the tier-1 volume that used to fill junior resumes, so employers screen harder for what remains human: detection engineering, incident judgment, and the ability to evaluate what the automation got wrong. Bullets about tuning the automation (enrichment you scripted, alert logic you corrected, playbooks you wrote) now outrank bullets about raw ticket throughput. If your experience is mostly volume, convert it: what did the volume teach you to build, fix, or escalate better?
Use this page actively. The resume below is complete and realistic, rendered by the same engine that produces our PDF export, and the "Use this example" button opens it in the builder so you can swap in your own environment, queue numbers, and incidents instead of starting blank. Then raid the bullet bank for structures that fit your shifts, check the keyword list against your target posting, and read the ATS extract at the bottom to see literally what a parser keeps from this layout.
Questions fréquentes
- Can I get a SOC job with just Security+ and no experience?
- It happens, but the certificate alone puts you in the largest pile in the industry, so the play is to manufacture evidence around it. Build a home SOC lab and document it like a professional: Splunk's no-cost tier or Security Onion ingesting Sysmon, firewall, and DNS logs, then a dozen written investigations of simulated attacks (Atomic Red Team makes this easy) mapped to MITRE ATT&CK, with screenshots and conclusions. Present the lab as a project entry with specifics, not as a hobby line. Add CTF or TryHackMe progress the same way: named rooms or competitions, ranking if it flatters you, skills exercised. Then mine whatever job you have for security-adjacent bullets, because almost every IT, help desk, and even retail-operations job has some: phishing reports you handled, access you provisioned, incidents you escalated, fraud you caught. Finally, aim at the right doors: MSSPs, 24/7 federal-contract SOCs, and internships hire tier-1 analysts in volume and promote fast, while famous-brand security teams mostly do not hire first-timers. Structure all of it like work experience; the no-experience guide shows how to make lab material carry a page honestly.
- Should I list tools I only touched in labs?
- Yes, but segmented honestly, because security interviewers probe tool claims harder than interviewers in any adjacent field. The clean pattern is a labeled line in your skills section ("Lab: Wireshark, Volatility, Burp Suite") or a project entry that states the context outright: "Home lab: deployed Wazuh across 5 VMs, wrote 10 custom detection rules, documented 12 investigations." What you must never do is mix lab-only tools into work bullets or an undifferentiated skills list, because the interviewer will ask a production-depth question ("walk me through a time Falcon's containment failed you"), and the gap between your claim and your answer ends the loop and burns the referral. Recruiters and managers read honestly labeled lab experience as initiative, especially for career changers; they read discovered inflation as a character finding. There is also a practical matching benefit: the ATS keyword filter does not distinguish where on the page a tool name appears, so a lab-labeled Splunk still matches a Splunk filter, and you lose nothing by being precise. The rule that keeps you safe in every interview: list nothing you cannot discuss for five minutes, and label everything by where you actually used it.
- How do I show incident response experience if my org had few real incidents?
- Broaden what counts as an incident, honestly. Confirmed phishing with credential entry, malware that executed before EDR caught it, an exposed S3 bucket, a lost laptop with sensitive data: these are incidents with lifecycle stages even when they never made news, and each supports a bullet naming your part ("contained", "built the forensic timeline", "wrote the after-action report"). Second, claim the preparation work, which managers weight more than candidates expect: tabletop exercises you ran or played in, playbooks you wrote or updated, purple-team findings you converted into detections, DR gaps you surfaced. "Led a ransomware tabletop that exposed two recovery gaps later fixed" is an IR bullet, and a good one. Third, if you are in a quiet environment by design, use countable proxies: escalations reviewed and upheld, evidence chains that passed audit, investigations documented to a standard someone else verified. What to avoid: inflating a routine malware cleanup into "breach response", because IR interviewers ask timeline questions (who declared it, what was the containment decision, who was notified) that expose the stretch in one exchange. Precision about small incidents reads senior; drama about invented ones reads junior.
- Which certification should I get after Security+, and how do I order them?
- Match the certificate to the seat you want next, not to a ranking thread. For staying on the analyst track, CySA+ is the natural second step and appears verbatim in many mid-level reqs; GSEC covers similar ground with more lab depth and more employer prestige, at several times the cost, usually only sensible if an employer pays. For incident response specialization, GCIH is the strongest single signal; for government and defense contracting, check the specific 8140 work-role requirements in the posting, because those are binding, not preferences. CISSP belongs later: it formally requires five years of experience, and listing it early (or listing "CISSP Associate" without explanation) makes experienced reviewers wince. On the resume, order the certifications section by relevance and currency rather than chronology: the credential the posting names goes first, current dates on everything, expired ones either renewed or cut. In your summary, name at most the top one or two; a summary that recites five acronyms reads as compensating. And before buying any of them, reread your target postings: ten minutes of counting which certifications actually appear in reqs beats any general advice, including this paragraph's.
- How do I put security clearance on my resume, and what if mine lapsed?
- State it in the certifications section and, for cleared-work applications, in your headline too: "Secret clearance, active" or "TS/SCI, active, poly 2024." It is a hard eligibility filter for federal and defense-contract work, screeners search for it literally, and burying it costs you matches you already earned. Include the investigation or adjudication recency if it is favorable, because reactivation cost drives hiring decisions. If your clearance lapsed, say exactly that ("Secret clearance, inactive since 2023, eligible for reinstatement"), since a recently lapsed clearance is dramatically cheaper to restore than a new investigation and recruiters know the difference even when job boards do not. Never round up: claiming "active" when you mean "had one once" is discoverable in the security process itself, which is the single worst place in hiring to be caught embellishing. On the flip side, if you are applying only to commercial roles, the clearance still earns its line, because it functions as a third-party background check: it tells a hiring manager that a federal investigator examined your history and found you trustworthy, which quietly answers a question every security hire raises.
- How do I move from tier-1 triage into detection engineering?
- Start doing the work at the edge of your current seat, then make it visible in exactly the vocabulary detection reqs use. Every tier-1 analyst has standing to propose tuning: false positives you kept closing, a noisy rule you rewrote, an enrichment step you scripted in Python. Those become the bridge bullets: "tuned 40+ detections against MITRE ATT&CK, cutting false positives 38%" is a detection engineering line even though it happened in an analyst role. Add the craft signals the specialty screens for: detections written in Sigma or your SIEM's native language, a GitHub repo of rules with test events, familiarity with detection-as-code workflows (version control, CI validation, staged rollout), and coverage thinking expressed in ATT&CK technique terms rather than alert names. Threat-hunting write-ups work too: pick a technique, hunt for it in your lab or with employer permission in production, and document the query logic and outcome. On the resume itself, shift your summary's first sentence from queue volume toward detection outcomes, keep one strong triage bullet for operational credibility, and apply to hybrid "analyst / detection" postings where the promotion happens inside the job. Our career change guide covers the general reframe mechanics.