# Cybersecurity Analyst Resume Sample - ATS Template 2026

> Get a Cybersecurity Analyst resume (CV) sample with an ATS-friendly format, strong bullet points, role keywords, and job-specific guidance.

Canonical HTML: https://www.liftmycv.com/resume-samples/cybersecurity-analyst-resume/

Markdown: https://www.liftmycv.com/resume-samples/cybersecurity-analyst-resume.md

Site: https://www.liftmycv.com/

Cybersecurity Analyst Resume Sample - ATS Template 2026

On this page, you can preview an ATS-friendly Cybersecurity Analyst resume template, see what to include in each section, review strong bullet examples and relevant keywords, avoid common mistakes, and create a job-specific resume that matches real cybersecurity analyst job requirements.

{
 "title": "How LiftmyCV Helps with Cybersecurity Analyst Resumes",
 "subtitle": "For a Cybersecurity Analyst resume, LiftmyCV helps create job-specific resumes, generate resumes for each application, and match your resume to relevant roles before autofill and submission.",
 "cards": [
 {
 "icon": "FileText",
 "title": "Create Job-Specific Resumes",
 "desc": "Paste a job description and create a job-specific resume in under a minute for less than $1.",
 "href": "https://www.liftmycv.com/ai-resume-generator/"
 },
 {
 "icon": "Bot",
 "title": "Generate Per-Job Resumes During Auto-Apply",
 "desc": "During auto-apply sessions, LiftmyCV can generate a per-job resume for each role, helping your application stay aligned with the job description.",
 "href": "https://www.liftmycv.com/ai-auto-apply/"
 },
 {
 "icon": "Search",
 "title": "Match Your Resume to Relevant Openings",
 "desc": "LiftmyCV uses AI to match your resume with relevant jobs, autofill application forms, and submit applications automatically.",
 "href": "https://www.liftmycv.com/ai-job-matching/"
 }
 ]
}

{
 "title": "Why This Cybersecurity Analyst Template Works",
 "intro": "A cybersecurity analyst resume needs to be readable to screening systems while still giving a reviewer quick evidence of incident response, vulnerability management, monitoring, and risk reduction work. This structure keeps technical skills, security tools, certifications, and investigation outcomes organized so the resume can be scanned without burying important details in dense paragraphs.",
 "items": [
 {
 "title": "Readable ATS Formatting",
 "text": "Simple headings, standard contact details, and text-based sections support cleaner parsing when the resume moves through applicant tracking systems. Security platforms, certifications, and technical skills such as SIEM monitoring, endpoint protection, network analysis, and threat investigation are kept in plain text rather than graphics or columns that may be read inconsistently."
 },
 {
 "title": "Clear Security Resume Sections",
 "text": "The layout separates summary, skills, experience, certifications, education, and projects so a reviewer can move quickly from credentials to hands-on security work. For a cybersecurity analyst, that means SOC responsibilities, alert triage, vulnerability scans, log analysis, and escalation work are not mixed into one long technical profile."
 },
 {
 "title": "Natural Keyword Placement",
 "text": "Cybersecurity resumes need terms from the job posting, but repeated keyword lists can look thin without context. This structure gives space to use phrases such as incident response, threat detection, vulnerability assessment, SIEM, firewall monitoring, IAM, and risk analysis inside skills and experience bullets where they connect to actual work."
 },
 {
 "title": "Measurable Security Outcomes",
 "text": "Experience bullets are shaped around actions and outcomes, not task lists. A cybersecurity analyst can document results such as reduced false positives, faster alert triage, closed vulnerabilities, improved patch tracking, completed access reviews, phishing investigation volume, or better incident documentation without making unsupported claims."
 }
 ]
}

{
 "title": "What to Include in This Resume",
 "intro": "A cybersecurity analyst resume should connect monitoring, incident response, vulnerability management, and security tooling to clear operational outcomes. Use each section to show how you triage alerts, investigate threats, protect endpoints and cloud environments, and document security work for technical and nontechnical stakeholders.",
 "columns": [
 "Section",
 "What to write",
 "What to avoid",
 "Example"
 ],
 "rows": [
 {
 "section": "Professional Summary",
 "what_to_write": "Summarize years of cybersecurity experience, core defense areas, key tools, and one measurable improvement tied to detection, response, remediation, or compliance work.",
 "what_to_avoid": "Avoid vague security language, unsupported clearance claims, and lists of tools without context or outcomes.",
 "example": "Cybersecurity Analyst with 4+ years of experience across SOC monitoring, incident response, vulnerability management, and endpoint security. Reduced average alert triage time by 32% by tuning Splunk correlation searches, documenting playbooks, and coordinating containment steps with infrastructure teams."
 },
 {
 "section": "Areas of Expertise",
 "what_to_write": "Use focused cybersecurity skill categories that match analyst work, including monitoring, threat investigation, control validation, documentation, and response coordination.",
 "what_to_avoid": "Avoid mixing unrelated IT skills with security keywords or adding every framework, tool, and acronym you have seen.",
 "example": "SOC Monitoring, Incident Triage, Threat Hunting, Vulnerability Management, Endpoint Security, Cloud Security Controls, Log Analysis, Phishing Investigation, Security Documentation"
 },
 {
 "section": "Technical Proficiencies",
 "what_to_write": "List specific platforms, tools, query languages, operating systems, cloud services, and scripting methods used in security analysis or response workflows.",
 "what_to_avoid": "Avoid unsupported expert labels, obsolete tools without context, and long ungrouped lists that read like keyword stuffing.",
 "example": "Splunk, Microsoft Sentinel, CrowdStrike Falcon, Microsoft Defender for Endpoint, Wireshark, Nessus, AWS Security Hub, Azure Entra ID, Python, PowerShell"
 },
 {
 "section": "Professional Experience",
 "what_to_write": "Write bullets around alert triage, investigations, vulnerability remediation, phishing analysis, control monitoring, and cross-team response, using scope, tooling, and measurable outcomes.",
 "what_to_avoid": "Avoid task-only bullets such as monitored alerts or reviewed logs without explaining volume, method, risk, or result.",
 "example": "Cybersecurity Analyst, Meridian Health Systems. Investigated 900+ monthly SIEM and EDR alerts across Windows, Linux, and cloud assets, reducing false positives by 28% through Splunk rule tuning and escalation criteria updates. Coordinated vulnerability remediation with system owners, improving critical patch SLA adherence from 81% to 94% in two quarters."
 },
 {
 "section": "Earlier Roles",
 "what_to_write": "Include earlier IT, help desk, network, systems, or SOC roles that show a path into cybersecurity operations and technical troubleshooting.",
 "what_to_avoid": "Avoid detailed early-career descriptions if they repeat current analyst responsibilities or crowd out stronger recent security work.",
 "example": "IT Support Specialist, Northbridge Services, 2018 to 2020"
 },
 {
 "section": "Education",
 "what_to_write": "Add cybersecurity, computer science, information systems, networking, or related education, with coursework only when it supports security analysis responsibilities.",
 "what_to_avoid": "Avoid listing unrelated coursework, incomplete degrees without clarity, or education details that take space from hands-on security experience.",
 "example": "Bachelor of Science in Cybersecurity, Western Lakes University, 2018. Relevant coursework: network defense, digital forensics, secure systems administration, risk management."
 },
 {
 "section": "Certifications",
 "what_to_write": "Include current, role-relevant certifications that support SOC analysis, defensive security, cloud security, incident response, or vulnerability management.",
 "what_to_avoid": "Avoid expired credentials, unrelated training badges, and oversized certification lists that bury the most relevant security credentials.",
 "example": "CompTIA Security+, CompTIA CySA+, Microsoft SC-200, GIAC GCIH"
 }
 ],
 "quick_tip": "Build the resume around evidence of detection, investigation, containment, remediation, and security tool use, not generic interest in cybersecurity."
}

{
 "title": "Cybersecurity Analyst Resume Example Bullets",
 "intro": "Weak cybersecurity analyst bullets usually list monitoring tasks. Strong bullets show what you investigated, which systems or frameworks you used, how broad the scope was, and what changed after your work.",
 "columns": [
 "Bullet",
 "Strong bullet",
 "Weak bullet"
 ],
 "rows": [
 {
 "section": "SIEM Monitoring",
 "strong_bullet": "Investigated security alerts across Splunk and Microsoft Sentinel, triaged 120 weekly events, and reduced false positives by refining correlation rules with the SOC team.",
 "weak_bullet": "Monitored alerts and reviewed security events."
 },
 {
 "section": "Incident Response",
 "strong_bullet": "Led initial containment for phishing and malware incidents, using endpoint logs, email headers, and EDR telemetry to isolate affected hosts within established response procedures.",
 "weak_bullet": "Responded to cybersecurity incidents when needed."
 },
 {
 "section": "Vulnerability Management",
 "strong_bullet": "Analyzed Nessus scan results for 800 endpoints, prioritized critical CVEs with asset owners, and tracked remediation status through Jira until overdue risks were resolved.",
 "weak_bullet": "Performed vulnerability scans and reported issues."
 },
 {
 "section": "Access Review",
 "strong_bullet": "Reviewed privileged access in Active Directory and Okta, identified inactive administrator accounts, and coordinated removals to reduce unnecessary access across production systems.",
 "weak_bullet": "Helped review user access permissions."
 },
 {
 "section": "Security Reporting",
 "strong_bullet": "Built weekly SOC reports covering alert volume, incident categories, patch status, and recurring control gaps, giving managers clearer evidence for risk and remediation discussions.",
 "weak_bullet": "Created reports about security activities."
 }
 ]
}

{
 "title": "Cybersecurity Analyst Keywords Recruiters Often Look For",
 "intro": "Use these role-relevant terms naturally across your cybersecurity analyst resume, especially in skills, experience, and project bullets.",
 "items": [
 "SIEM",
 "Splunk",
 "Microsoft Sentinel",
 "Incident Response",
 "Threat Detection",
 "SOC Operations",
 "Log Analysis",
 "Vulnerability Management",
 "EDR",
 "CrowdStrike",
 "MITRE ATT&CK",
 "NIST CSF",
 "Network Security",
 "Threat Hunting"
 ]
}

Cybersecurity Analyst Resume Formatting Rules

Use this section to catch formatting and content problems before your Cybersecurity Analyst resume reaches a recruiter or ATS. Check for vague wording, missing security metrics, generic skill lists, tiny fonts, unclear formatting, and unreadable structure that can weaken incident response, monitoring, and risk experience.

- use a clean, ATS-friendly layout
- keep the resume to one page when possible, two pages only when justified
- use readable 10.5 to 12 pt body text
- stick to standard fonts like Arial, Calibri, or Times New Roman
- use clear section headings and a simple reading order
- keep contact details in the main body of the resume
- show measurable cybersecurity impact with numbers and outcomes
- name the cybersecurity tools and platforms you actually used
- tailor keywords naturally to the target Cybersecurity Analyst role
- save the file as a simple .pdf or .docx

- do not use photos or profile pictures
- do not use fancy or decorative fonts
- do not add tables, columns, text boxes, icons, or graphics
- do not place important details in headers or footers
- do not turn the resume into a dense wall of text
- do not write vague claims without metrics or context
- do not list every cybersecurity tool you have ever touched
- do not stuff keywords unnaturally
- do not let the resume run past two pages for this template
- do not use design-heavy layouts that are harder for ATS to parse

## Resume sample

Maya Reynolds

Cybersecurity Analyst

Austin, TX • maya.reynolds@liftmycv.com • linkedin.com/in/mayareynolds

## Professional Summary

Cybersecurity Analyst with 7 years of experience supporting SOC operations, incident response, vulnerability management, endpoint security, and cloud security monitoring. Experienced with SIEM tuning, EDR investigations, phishing triage, threat intelligence enrichment, and control validation across hybrid Microsoft, AWS, and SaaS environments. Known for reducing alert noise, improving response documentation, and translating technical findings into clear risk summaries for IT, compliance, and business stakeholders.

## Areas of Expertise

 Security Monitoring • Incident Response • SIEM Analysis • EDR Investigation • Vulnerability Management • Threat Hunting • Phishing Analysis • Log Correlation • Cloud Security • Risk Assessment • Security Controls • IAM Review • MITRE ATT&CK Mapping • Detection Tuning • Endpoint Hardening • Security Awareness • Compliance Support • SOC Documentation

## Technical Proficiencies

 Splunk • Microsoft Sentinel • Microsoft Defender for Endpoint • CrowdStrike Falcon • Palo Alto Networks • Tenable.io • Qualys • Wireshark • Nmap • Burp Suite • ServiceNow • Jira • AWS Security Hub • GuardDuty • Azure AD / Microsoft Entra ID • Okta • Proofpoint • KnowBe4 • VirusTotal • MISP • Python • PowerShell • KQL • SQL • Windows • Linux • NIST CSF • CIS Controls • ISO 27001 Concepts

## Professional Experience

 BrightWave Financial Services — Austin, TX | March 2023 – Present

Cybersecurity Analyst II

Monitor and investigate security events for a regional financial services firm with 1,800 employees, 2 data centers, and cloud workloads across AWS and Microsoft Azure.

- Investigate an average of 45 security alerts per week across Splunk, Microsoft Sentinel, and CrowdStrike, including suspicious authentication, malware detections, data exfiltration indicators, and endpoint anomalies.
- Reduced recurring false positives by 32% by tuning SIEM correlation rules, suppressing low-value events, and documenting escalation criteria for Tier 1 analysts.
- Led triage for 120+ phishing submissions per quarter using Proofpoint, Microsoft Defender, header analysis, URL sandboxing, and IOC enrichment through VirusTotal and threat intelligence feeds.
- Built KQL and SPL queries to identify impossible travel, risky OAuth grants, suspicious PowerShell execution, and anomalous privileged account activity across 6,500+ monitored assets.
- Partnered with infrastructure teams to remediate high and critical vulnerabilities, improving SLA completion from 74% to 91% within two quarters.
- Mapped detection logic and incident notes to MITRE ATT&CK techniques, improving consistency in post-incident reviews and monthly SOC reporting.
- Created incident response runbooks for compromised accounts, ransomware indicators, endpoint isolation, phishing takedown, and unauthorized cloud access.

Northstar Health Systems — Dallas, TX | June 2020 – March 2023

Cybersecurity Analyst

Supported daily SOC operations, vulnerability tracking, endpoint protection, and security control reviews for a healthcare organization with distributed clinics and remote users.

- Reviewed SIEM, firewall, EDR, and email security alerts across 3,200 endpoints, escalating confirmed incidents with clear timelines, affected assets, evidence, and containment actions.
- Improved malware response time by 28% by standardizing CrowdStrike containment procedures and creating a repeatable checklist for endpoint artifact collection.
- Coordinated monthly Tenable vulnerability scans across servers, workstations, and network devices, tracking remediation for 900+ findings through ServiceNow.
- Analyzed failed login spikes, suspicious VPN activity, privileged account changes, and unusual data access patterns using Splunk dashboards and custom search queries.
- Assisted with HIPAA and internal audit evidence requests by collecting access review records, vulnerability remediation notes, security awareness completion data, and incident response documentation.
- Developed phishing simulation reports for department leaders, contributing to a reduction in repeat click behavior from 14% to 7% over four campaign cycles.
- Worked with system administrators to harden Windows servers using CIS benchmark guidance, local policy review, and endpoint protection configuration checks.

Cobalt Ridge Technology — San Antonio, TX | August 2018 – June 2020

Junior Security Analyst

Provided Tier 1 security monitoring, ticket triage, access review support, and vulnerability reporting for managed IT and cybersecurity clients.

- Triaged endpoint, firewall, and authentication alerts for 20+ client environments, escalating suspected compromise, brute-force attempts, malware detections, and policy violations.
- Prepared weekly vulnerability summaries from Qualys scans, prioritizing internet-facing systems, unsupported software, missing patches, and exploitable critical findings.
- Documented 150+ recurring alert types with expected evidence, severity guidance, client contact paths, and containment steps for the service desk knowledge base.
- Used Wireshark, Nmap, and basic PowerShell scripts to support network validation, host investigation, and asset verification during security reviews.

## Earlier Roles

**IT Support Specialist**, Alamo Business Solutions — San Antonio, TX | May 2017 – August 2018. Supported account provisioning, endpoint troubleshooting, patch verification, antivirus checks, and user security questions for small business clients.

## Education

**Bachelor of Science in Information Technology**
University of Texas at San Antonio — San Antonio, TX

## Certifications

CompTIA Security+ • CompTIA CySA+ • Microsoft Certified: Security Operations Analyst Associate • GIAC Security Essentials (GSEC), in progress

## Example jobs

- **Cybersecurity Analyst - Entry Level — NiSource Corporate Services Co — Columbus OH - 175 Nationwide**: **Cybersecurity Analyst - Entry Level**

**Full Time Perm**

**Shift:** Hybrid - 3 days on location

**Salary:**  $82,200 - $123,200, plus 8% annual bonus

**Location:** Columbus, OH

**Relocation Assistance Provided**

NiSource is one of the largest fully regulated utility companies in the U.S., serving millions of customers across six states. We’re more than an energy provider—we’re a team committed to innovation, inclusion, and growth. At NiSource, you’ll find a workplace that encourages collaboration, supports professional development, and empowers employees to make an impact.

The Cybersecurity department ensures the confidentiality, integrity, and availability of NiSource assets to achieve the company mission. We excel in engineering sophisticated defenses, architecting resilient systems, and proactively defending the vital cyber infrastructure that is crucial to our business operations.

The **Identity and Access Management (IAM) team** is responsible for protecting critical business systems by ensuring the right individuals have the right access at the right time. As a Cybersecurity Analyst you will support the administration, configuration, implementation, and ongoing operation of enterprise identity, privileged access, authentication, and authorization platforms. In this role you will support the CyberArk environment, including Privileged Access Management (PAM), Secure Infrastructure Access (SIA), Certificate Management, and future implementations of Secret Manager and Secrets Hub. You will partner closely with infrastructure, application, cloud, and cybersecurity teams to secure privileged accounts, manage machine identities, strengthen authentication controls, and support identity governance initiatives.

Overall the ideal candidate will possess hands-on experience or strong interest in learning CyberArk solutions and a strong understanding of IAM technologies including Active Directory, Microsoft Entra ID, SailPoint, single sign-on (SSO), federation, and privileged access controls.

**Your responsibilities may include, but are not limited to:**

- Administer, configure, and support CyberArk Privileged Access Management (PVWA) and related CyberArk components
- Support implementation and ongoing operations of CyberArk Secure Infrastructure Access (SIA)
- Support deployment and administration of CyberArk Certificate Manager and machine identity management solutions
- Assist with future implementation and operational support of CyberArk Secret Manager and Secrets Hub
- Manage privileged accounts, safes, platforms, access workflows, session management, password rotations, and onboarding processes
- Perform access reviews and entitlement analysis to ensure compliance with least-privilege and segregation-of-duties principles
- Troubleshoot IAM and PAM-related incidents, service requests, and application integrations
- Support identity lifecycle processes including provisioning, deprovisioning, role changes, and access certifications
- Participate in integrating applications with enterprise authentication and authorization platforms including SSO, MFA, federation, and privileged access solutions
- Collaborate with infrastructure, cloud, application, and security teams to onboard systems and applications into CyberArk and other IAM services
- Support Identity Governance and Administration (IGA) processes and technologies
- Monitor IAM and PAM platforms for operational health, security risks, and compliance gaps
- Create and maintain technical documentation, operational procedures, and security standards related to IAM and PAM technologies
- Support regulatory compliance requirements and audit activities related to identity security and privileged access management
- Participate in IAM and PAM initiatives focused on improving security posture, automation, and operational efficiency

**You must possess the below minimum qualifications to be initially considered for this position. Preferred qualifications are in addition to the minimum requirements and are considered a plus factor in identifying top candidates.**

Experience listed below could be obtained through a combination of school work, classes, research, or any relevant previous job or internship experiences.

**Minimum Qualifications**

- Bachelor's degree or equivalent work experience
- 1+ year of experience supporting Identity and Access Management (IAM), Privileged Access Management (PAM), or related cybersecurity technologies
- Understanding of privileged account lifecycle management, password rotation, session monitoring, and least privilege principles.

**Preferred Qualifications**

- Experience administering CyberArk Privileged Access Management (PVWA)
- Experience onboarding and managing privileged accounts, safes, platforms, and access controls within CyberArk
- Experience with PingFederate and/or PingOne
- Experience implementing or supporting Single Sign-On (SSO), Multi-Factor Authentication (MFA), Federation Services, Identity Governance and Administration (IGA), Privileged Access Management (PAM)
- Experience administering Microsoft Active Directory and Microsoft Entra ID
- Knowledge of identity and authentication protocols including SAML, OAuth 2.0, OpenID Connect (OIDC), LDAP, Kerberos, and federation technologies
- Understanding of role-based access control (RBAC), Privileged Access Management (PAM), and Identity Governance concepts
- Experience with PowerShell automation, API integrations, workflow automation, and identity lifecycle management processes

**Preferred Certifications**

- CyberArk Defender, Sentry, or Guardian
- Microsoft SC-300: Identity and Access Administrator Associate
- SailPoint IdentityIQ and/or Identity Security Cloud Certifications
- CISSP
- CISM
- CompTIA Security+

**Disclaimer**

The preceding description is not designed to be a complete list of all duties and responsibilities required of the position

*****Please note there is a short open-ended questionnaire to complete regarding your work experience towards the end of the application. This questionnaire can take up 10 - 15 minutes to complete.*****

#NiSource #NIPSCO #ColumbiaGas #CybersecurityJobs #CyberJobs #CybersecurityAnalyst #CybersecurityEngineer #IAM #PrivilegedAccess #PAM #IdentityAccess #EntryLevel #NewGrad #NowHiring #OhioMeansJobs

*As a public utility, NiSource is required to provide continuous service to customers at all times. To ensure we fulfill that obligation, employees may be required to work outside their normal work hours and perform tasks outside of their normal responsibilities in support of emergency operations.*

**Work Authorization**

Authorized to work in the United States without requiring sponsorship.

**Workplace Connection**
Value inclusion within your day to day responsibilities by respecting others perspectives/convictions, engaging others opinions, creating a safe environment where people, ideas, and opinions are valued within your Team/Customers and external partners.

Respect the unique lived experiences within your Team/Customers and external work partners by valuing different world views, challenges, and cultures that represents all walks of life and all backgrounds.​

Treat others with respect and consideration. Actively participate in creating and contributing to a positive work environment.

**Equal Employment Opportunity **
NiSource is committed to providing equal employment opportunities in each of its companies to all employees and applicants for employment without regard to race, color, religion, national origin or ancestry, veteran status, disability, gender, age, marital status, sexual orientation, gender identity, sex (including pregnancy, lactation, childbirth or related medical conditions), genetic information, citizenship status, or any protected group status as defined by law. Each employee is expected to abide by this principle.

**By applying, you may be considered for other job opportunities. **

**ADA Accommodations**

If you need a reasonable accommodation to participate in any part of the hiring process or to perform the essential functions of the position, please contact OneHR at [OneHR@nisource.com](mailto:OneHR@nisource.com) or 1-888-640-3320

**Safety Statement**
Promote a safe work environment by actively participating in all aspects of our employee safety program. Report any unsafe conditions and take actions to prevent personal injuries. Support our interdependent safety culture by ensuring the safety of your co-workers. Stay focused on the task at hand and promote productivity through good work habits.

**E-Verify**

NiSource participates in the U.S. Department of Homeland Security’s E-Verify program. As part of this process, we provide the following notices to all job applicants: These documents inform you of your rights and responsibilities under U.S. law. You can view or download them using the links below:

- **E-Verify Poster** (English and Spanish) [E-Verify Participation Poster English and Spanish](https://secure.usverify.com/cdn/docs/E-Verify_Participation_Poster_Eng_Es.pdf)
- **Right to Work Poster** (English and Spanish) [If you have the right to work, don't let anyone take it away](https://www.e-verify.gov/sites/default/files/everify/posters/IER_RightToWorkPoster%20Eng_Es.pdf)

**Salary Range*:**

$82,200.00 - $123,200.00

****The salary offered to a candidate is based on several factors including but not limited to thecandidate’s skills, job-related knowledge, and relevant experience, as well as internal pay equity.***

**Posting Start Date:**

2026-07-22

**Posting End Date (if applicable):**

2026-08-12

# **Please note that the job posting will close on the day before the posting end date.**
- **Cybersecurity SOC Analyst — Fiserv Solutions LLC — Berkeley Heights, New Jersey**: Fiserv, a leader in Fintech and payments, seeks a Cybersecurity SOC Analyst for its Cybersecurity Incident Response Team. This role involves investigating cybersecurity events, analyzing logs, and responding to potential incidents. Candidates should have 1-2 years of experience in cybersecurity operations, along with foundational knowledge of network protocols and incident response processes. Strong analytical and collaborative skills are essential. The position is on-site, requiring availability for shifts that include nights and weekends, with approximately 10% travel expected. A competitive salary range of $97,500 to $164,400 is offered.
- **Cybersecurity SOC Analyst — RIIVIPL RIIV India Private Limited — Mumbai**: # Reporting To:

Associate Manager, SOC

#

# Shift:

US (8:30 pm - 5:30 am IST) (India)

# About Russell Investments, Mumbai:

Russell Investments is a leading outsourced financial partner and global investment solutions firm providing a wide range of investment capabilities to institutional investors, financial intermediaries, and individual investors around the world. Building on an 90-year legacy of continuous innovation to deliver exceptional value to clients, Russell Investments works every day to improve the financial security of its clients. The firm is “Top 12 Ranked Consultant (2009-2024)” in P&I survey 2024 with $962 billion in assets under advisement (as of December 31, 2025) and $376.9 billion in assets under management (as of December 31, 2025) for clients in 30 countries. Headquartered in Seattle, Washington in the United States, Russell Investments has offices around the world, including London, New York, Toronto, Sydney, Tokyo, Shanghai – and has opened a new office in Mumbai, India in June 2023.

Joining the Mumbai office is an incredible opportunity to work closely with global stakeholders to support the technology and infrastructure that drives the investment and trading processes of a globally recognized asset management firm. Be part of the team based out of Goregaon (East) and contribute to the foundation and culture of the firm’s growing operations in India. The Mumbai office operates with varying shifts to accommodate time zones around the world.

For more information, please visit [https://www.russellinvestments.com](https://www.russellinvestments.com).

# Job Description:

We are seeking an experienced Cybersecurity Analyst to join our Security Operations Center (SOC) team. The SOC provides 24x7 security operations monitoring for the Russell Investments environment. You’ll use various tools and dashboards to monitor the environment, triage events to detect legitimate security concerns, and respond according to established processes. You’ll interact regularly with other members of the Cybersecurity team as well as other IT support teams.

**Years of Experience**

- Minimum 3 years’ experience in Cybersecurity or related field

**Key Responsibilities**

- Continuously monitor and analyze security events and incidents using advanced security tools to identify potential threats, vulnerabilities, and suspicious activities across the environment.
- Identify, classify, and assess potential, successful, and unsuccessful intrusion attempts, ensuring timely escalation and response.
- Conduct in-depth investigations of security incidents by correlating alerts, logs, and telemetry data, and leveraging internal and external threat intelligence sources to determine scope, root cause, and impact.
- Perform Incident Response (IR) activities, including containment, eradication, recovery, and post-incident analysis, in line with defined playbooks and SLAs.
- Participate in proactive threat hunting activities to identify hidden or emerging threats that may evade traditional detection mechanisms.
- Research new and evolving threats, attack techniques, and adversary tactics that could impact the organization, and recommend improvements to detection and response capabilities.
- Stay current with the latest cybersecurity news, vulnerabilities, threat trends, and industry best practices, and provide actionable insights to continuously improve security posture.
- Collaborate with IT, infrastructure, cloud, and application teams to gain deeper understanding of the environment and improve security visibility and response efficiency.
- Maintain accurate documentation of incidents, investigations, lessons learned, and recommendations, and contribute to the enhancement of SOC processes, runbooks, and detection use cases.

**Role Requirements**

- Strong understanding of cybersecurity principles, concepts, and best practices across networks, endpoints, and systems.
- Solid knowledge of networking fundamentals, firewalls, and operating systems (Windows and Linux).
- Proven experience in security incident detection, analysis, and response within a SOC or similar environment.
- Hands-on familiarity with security technologies such as SIEM, IDS/IPS, firewalls, endpoint detection and response (EDR), and vulnerability scanning tools.
- Experience correlating and interpreting data from multiple sources to analyze complex security issues and propose effective remediation strategies.
- Working knowledge of industry standards and frameworks, including the NIST Cybersecurity Framework and ISO/IEC 27001.
- Strong analytical and problem-solving skills, with the ability to prioritize incidents and operate effectively under pressure.
- Good communication and documentation skills, with the ability to clearly articulate technical findings to both technical and non-technical stakeholders.

**Core Values**

- Strong interpersonal, oral, and written communication and collaboration skills
- Strong organizational skills including the ability to adapt to shifting priorities and meet frequent deadlines,
- Proactive approach to problem-solving with strong judgment and decision-making capability.
- Highly resourceful and collaborative team-player, with the ability to also be independently effective and exude initiative and a sense of urgency.
- Exemplifies our customer-focused, action-oriented, results-driven culture.
- Forward looking thinker, who actively seeks opportunities, has a desire for continuous learning, and proposes solutions.
- Ability to act with discretion and maintain complete confidentiality.
- Dedicated to the firm’s values of non-negotiable integrity, valuing our people, exceeding client expectations, and embracing intellectual curiosity and rigor.

## FAQ

### What is the best resume format for a cybersecurity analyst?

Use a reverse-chronological format if you have security operations, incident response, SOC, risk, or IT experience. Put a short summary, technical skills, certifications, work experience, and projects near the top so tools like SIEM platforms, vulnerability scanners, EDR, firewalls, and ticketing systems are easy to find.

### How long should a cybersecurity analyst resume be?

Most cybersecurity analyst resumes should be one page if you have under 7 to 10 years of experience. A two-page resume can work if you have deeper incident response work, compliance responsibilities, cloud security projects, leadership experience, or multiple technical certifications that are directly relevant.

### Which skills should I include on a cybersecurity analyst resume?

Include skills tied to the job posting, such as SIEM monitoring, alert triage, log analysis, vulnerability management, endpoint detection, phishing investigation, network security, access control, incident documentation, and risk assessment. Add specific tools where you have hands-on experience, such as Splunk, Microsoft Sentinel, Wireshark, Nessus, CrowdStrike, Qualys, Jira, ServiceNow, or AWS security services.

### Do certifications matter on a cybersecurity analyst resume?

Certifications can help, especially for entry-level and early-career cybersecurity analyst resumes. List relevant credentials such as Security+, CySA+, SSCP, GSEC, CEH, or cloud security certifications in a dedicated certifications section, but keep the experience section focused on what you actually investigated, monitored, remediated, or documented.

### Can I use the same cybersecurity analyst resume for every application?

A base resume is useful, but each application should be adjusted for the specific role. If a posting emphasizes SOC monitoring, move SIEM, alert triage, escalation, and incident response bullets higher; if it emphasizes vulnerability management, prioritize scanning, risk ratings, remediation tracking, and reporting.

### How do I write a cybersecurity analyst resume with limited experience?

Use labs, internships, help desk experience, security coursework, home lab projects, CTF work, or volunteer IT work to show practical security skills. Focus bullets on concrete tasks such as analyzing logs, investigating simulated phishing emails, hardening systems, writing incident reports, using Wireshark, or configuring alerts in a SIEM lab.

Create a Job-Specific Cybersecurity Analyst Resume with LiftmyCV

Create a professional, ATS-friendly Cybersecurity Analyst resume in seconds by pasting a job description. Or turn on per-job resume generation before starting auto-apply, so the AI agent adjusts your resume for each role.
