# SOC Analyst Resume Sample - ATS Template 2026

> Get a SOC Analyst resume (CV) sample with an ATS-friendly format, strong bullet points, SOC keywords, and job-specific guidance.

Canonical HTML: https://www.liftmycv.com/resume-samples/soc-analyst-resume/

Markdown: https://www.liftmycv.com/resume-samples/soc-analyst-resume.md

Site: https://www.liftmycv.com/

SOC Analyst Resume Sample - ATS Template 2026

On this page, you can preview an ATS-friendly SOC Analyst resume template, see what to include in each section, review strong bullet examples and relevant keywords, avoid common mistakes, and create a job-specific resume that matches real SOC analyst job requirements.

{
 "title": "How LiftmyCV Helps with SOC Analyst Resumes",
 "subtitle": "For a SOC Analyst resume, LiftmyCV helps create job-specific resumes, generate resumes per application during auto-apply, and match your resume to relevant roles from one workflow.",
 "cards": [
 {
 "icon": "FileText",
 "title": "Create Job-Specific Resumes",
 "desc": "Paste a job description and create a job-specific resume in under a minute for less than $1.",
 "href": "https://www.liftmycv.com/ai-resume-generator/"
 },
 {
 "icon": "Bot",
 "title": "Generate Per-Job Resumes During Auto-Apply",
 "desc": "During auto-apply sessions, LiftmyCV can generate a per-job resume for each role, helping your application stay aligned with the job description.",
 "href": "https://www.liftmycv.com/ai-auto-apply/"
 },
 {
 "icon": "Search",
 "title": "Match Your Resume to Relevant Openings",
 "desc": "LiftmyCV uses AI to match your resume with relevant jobs, autofill application forms, and submit applications automatically.",
 "href": "https://www.liftmycv.com/ai-job-matching/"
 }
 ]
}

{
 "title": "Why This SOC Analyst Template Works",
 "intro": "A SOC Analyst resume needs to show triage judgment, alert investigation, incident response support, and familiarity with security tooling without burying those details in dense paragraphs. This structure keeps SIEM work, threat analysis, escalation handling, certifications, and measurable security outcomes readable for ATS parsing and practical recruiter review.",
 "items": [
 {
 "title": "Readable ATS Formatting",
 "text": "The layout uses standard headings for summary, skills, experience, education, certifications, and tools, which is safer than columns, graphics, or unusual section labels. That matters for SOC Analyst resumes because SIEM platforms, ticketing systems, endpoint tools, and security certifications need to be captured as plain text."
 },
 {
 "title": "Security Sections Scan Clearly",
 "text": "The section order puts the summary, core security skills, tools, and recent analyst work near the top, so incident triage and monitoring experience are not buried. A recruiter can quickly separate hands-on alert analysis from classroom labs, help desk work, or general IT support."
 },
 {
 "title": "Keywords Fit Naturally",
 "text": "The structure gives SOC keywords a proper place instead of forcing them into every bullet. Terms such as SIEM, incident response, log analysis, phishing investigation, endpoint detection, threat intelligence, vulnerability management, and escalation procedures can appear in skills, tools, certifications, and experience where they read naturally."
 },
 {
 "title": "Achievements Use Security Evidence",
 "text": "Experience bullets are shaped around practical SOC outcomes, such as reducing false positives, documenting escalation steps, investigating suspicious log activity, improving alert runbooks, or supporting containment after a confirmed incident. Those details are more useful than vague claims about monitoring networks or protecting systems."
 }
 ]
}

{
 "title": "What to Include in This Resume",
 "intro": "A SOC Analyst resume should connect alert triage, SIEM investigation, endpoint analysis, incident response, and threat intelligence to clear operational outcomes. Use each section to show how you investigate suspicious activity, reduce noise, escalate incidents, document findings, and work across security tools used in modern SOC environments.",
 "columns": [
 "Section",
 "What to write",
 "What to avoid",
 "Example"
 ],
 "rows": [
 {
 "section": "Professional Summary",
 "what_to_write": "Summarize your SOC level, investigation scope, SIEM and EDR experience, incident response exposure, and one measurable improvement tied to triage, detection quality, or response time.",
 "what_to_avoid": "Avoid vague cybersecurity interest, tool lists without context, or claims of advanced threat hunting without hands-on evidence.",
 "example": "SOC Analyst with 4+ years of experience across alert triage, SIEM investigation, endpoint analysis, and incident escalation. Reduced false positive escalations by 28 percent through Splunk rule tuning, MITRE ATT&CK mapping, and collaboration with incident response engineers."
 },
 {
 "section": "Areas of Expertise",
 "what_to_write": "Include 7 to 10 SOC-focused skills covering monitoring, investigation, detection logic, escalation, documentation, threat context, and response coordination.",
 "what_to_avoid": "Avoid broad security terms that do not describe SOC work, such as general IT support or basic computer skills.",
 "example": "SIEM Monitoring, Alert Triage, Incident Response, Threat Intelligence Correlation, MITRE ATT&CK Mapping, Endpoint Investigation, Phishing Analysis, Log Analysis, Detection Tuning"
 },
 {
 "section": "Technical Proficiencies",
 "what_to_write": "List specific SOC tools, platforms, query languages, frameworks, and analysis utilities that match your actual work or lab experience.",
 "what_to_avoid": "Avoid naming tools you cannot explain in an investigation, especially advanced platforms used only in brief demos.",
 "example": "Splunk, Microsoft Sentinel, CrowdStrike Falcon, Microsoft Defender XDR, Wireshark, ServiceNow, KQL, SPL, MITRE ATT&CK"
 },
 {
 "section": "Professional Experience",
 "what_to_write": "Write bullets around alert volume, investigation workflows, SIEM queries, EDR findings, escalation quality, documentation, containment support, and measurable improvements to SOC operations.",
 "what_to_avoid": "Avoid duty-only bullets like monitored alerts or reviewed tickets without scope, tools, incident types, or results.",
 "example": "SOC Analyst, Meridian Financial Systems. Investigated 450+ monthly alerts across Splunk, Microsoft Defender XDR, and CrowdStrike, reducing duplicate escalations by 22 percent through query refinement and case notes. Coordinated phishing, malware, and suspicious login investigations, improving average triage completion time from 42 minutes to 29 minutes."
 },
 {
 "section": "Earlier Roles",
 "what_to_write": "Use this section for security-adjacent roles that show IT troubleshooting, networking, access management, help desk, systems support, or junior analyst progression.",
 "what_to_avoid": "Avoid lengthy descriptions that repeat your main SOC experience or include unrelated early jobs with no security connection.",
 "example": "IT Security Support Analyst, Northbridge Tech Services, 2019 to 2021"
 },
 {
 "section": "Education",
 "what_to_write": "Include cybersecurity, computer science, information systems, or networking education, plus relevant coursework if it supports SOC fundamentals or incident response knowledge.",
 "what_to_avoid": "Avoid listing unrelated coursework unless it connects to networks, operating systems, scripting, risk, or security operations.",
 "example": "Bachelor of Science in Cybersecurity, Western Lakes University, 2019. Coursework in network defense, digital forensics, Linux administration, and incident response."
 },
 {
 "section": "Certifications",
 "what_to_write": "List certifications that validate security operations, analyst fundamentals, SIEM workflows, cloud security monitoring, or blue team investigation skills.",
 "what_to_avoid": "Avoid expired credentials, unrelated vendor badges, or long training lists that crowd out stronger SOC evidence.",
 "example": "CompTIA Security+, CompTIA CySA+, Microsoft Certified Security Operations Analyst Associate, Splunk Core Certified User"
 }
 ],
 "quick_tip": "Prioritize evidence of real investigations, including alert types, tools used, escalation decisions, and measurable SOC workflow improvements."
}

{
 "title": "SOC Analyst Resume Example Bullets",
 "intro": "Weak SOC Analyst bullets list monitoring tasks. Strong bullets show the alert type, investigation method, security tools used, escalation path, and measurable result.",
 "columns": [
 "Bullet",
 "Strong bullet",
 "Weak bullet"
 ],
 "rows": [
 {
 "section": "Alert Triage",
 "strong_bullet": "Triaged endpoint and network alerts in Splunk and CrowdStrike, validating indicators of compromise, reducing false positives, and escalating confirmed incidents to Tier 2 analysts with documented evidence.",
 "weak_bullet": "Monitored alerts and escalated security issues."
 },
 {
 "section": "Incident Investigation",
 "strong_bullet": "Investigated phishing, malware, and suspicious login events by correlating SIEM logs, EDR telemetry, email headers, and firewall activity to determine scope and containment actions.",
 "weak_bullet": "Investigated security incidents when assigned."
 },
 {
 "section": "Threat Detection",
 "strong_bullet": "Built and tuned SIEM correlation searches for brute force activity, impossible travel, and privilege misuse, improving detection quality and reducing repetitive low-value alerts.",
 "weak_bullet": "Created alerts for possible threats."
 },
 {
 "section": "Case Documentation",
 "strong_bullet": "Maintained incident tickets in ServiceNow with timeline details, affected assets, indicators, analyst notes, and closure rationale, giving responders a clearer handoff during shift changes.",
 "weak_bullet": "Updated tickets for security events."
 },
 {
 "section": "Vulnerability Review",
 "strong_bullet": "Reviewed vulnerability scan findings from Tenable, prioritized exposed systems by severity and asset criticality, and coordinated remediation tracking with infrastructure teams.",
 "weak_bullet": "Reviewed vulnerabilities and reported findings."
 }
 ]
}

{
 "title": "SOC Analyst Keywords Recruiters Often Look For",
 "intro": "Use these SOC Analyst terms naturally across your skills, summary, and incident-focused bullet points.",
 "items": [
 "SIEM",
 "Splunk",
 "Microsoft Sentinel",
 "Alert Triage",
 "Incident Response",
 "Threat Hunting",
 "Log Analysis",
 "EDR",
 "CrowdStrike Falcon",
 "MITRE ATT&CK",
 "SOAR",
 "Phishing Analysis",
 "KQL",
 "ServiceNow"
 ]
}

SOC Analyst Resume Formatting Rules

Use this section to catch formatting and content problems before your SOC Analyst resume reaches a recruiter or ATS. Vague incident response wording, missing alert metrics, generic skill lists, tiny fonts, unclear formatting, and unreadable structure can make security experience harder to evaluate.

- use a clean, ATS-friendly layout
- keep the resume to one page when possible, two pages only when justified
- use readable 10.5 to 12 pt body text
- stick to standard fonts like Arial, Calibri, or Times New Roman
- use clear section headings and a simple reading order
- keep contact details in the main body of the resume
- show measurable security impact with numbers and outcomes
- name the security tools and platforms you actually used
- tailor keywords naturally to the target SOC Analyst role
- save the file as a simple .pdf or .docx

- do not use photos or profile pictures
- do not use fancy or decorative fonts
- do not add tables, columns, text boxes, icons, or graphics
- do not place important details in headers or footers
- do not turn the resume into a dense wall of text
- do not write vague claims without metrics or context
- do not list every security tool you have ever touched
- do not stuff keywords unnaturally
- do not let the resume run past two pages for this template
- do not use design-heavy layouts that are harder for ATS to parse

## Resume sample

Jordan Ellis

SOC Analyst

Austin, TX • jordan.ellis@liftmycv.com • linkedin.com/in/jordanellis

## Professional Summary

SOC Analyst with 6+ years of experience monitoring enterprise security environments, triaging SIEM and EDR alerts, investigating suspicious activity, and supporting incident response across cloud, endpoint, identity, and network telemetry. Experienced with Splunk Enterprise Security, Microsoft Sentinel, CrowdStrike Falcon, Microsoft Defender for Endpoint, Wireshark, TheHive, and MITRE ATT&CK mapping. Known for reducing false positives, improving escalation quality, and documenting repeatable investigation procedures for 24/7 security operations teams.

## Areas of Expertise

 Security Monitoring • Alert Triage • Incident Response • Threat Hunting • SIEM Analysis • EDR Investigation • Log Correlation • Phishing Analysis • Malware Triage • Network Traffic Analysis • Identity Threat Detection • Cloud Security Monitoring • Vulnerability Context Review • IOC Enrichment • MITRE ATT&CK Mapping • Case Management • Escalation Documentation • Detection Tuning

## Technical Proficiencies

 Splunk Enterprise Security • Microsoft Sentinel • IBM QRadar • CrowdStrike Falcon • Microsoft Defender for Endpoint • SentinelOne • Cortex XSOAR • TheHive • MISP • VirusTotal • AbuseIPDB • Wireshark • Zeek • Suricata • Nmap • Nessus • Jira • ServiceNow • Azure AD / Microsoft Entra ID • AWS CloudTrail • Windows Event Logs • Sysmon • PowerShell • Python • KQL • SPL • Sigma Rules

## Professional Experience

 Redwood Financial Systems — Austin, TX | March 2023 – Present

SOC Analyst II

Monitor and investigate security events for a financial technology environment supporting cloud applications, corporate endpoints, privileged access workflows, and customer-facing systems.

- Triaged 450+ SIEM, EDR, identity, and cloud alerts per month using Splunk Enterprise Security, Microsoft Sentinel, CrowdStrike Falcon, and Defender for Endpoint.
- Reduced recurring false-positive alerts by 31% by tuning correlation searches, refining allowlists, and documenting expected administrative activity patterns.
- Investigated phishing, impossible travel, suspicious PowerShell, credential stuffing, endpoint isolation, and malware alerts; escalated confirmed incidents with complete timeline, scope, affected assets, and recommended containment steps.
- Built 18 SPL and KQL queries to identify anomalous login behavior, rare process execution, suspicious parent-child process relationships, and unusual outbound connections.
- Mapped incident findings to MITRE ATT&CK techniques, improving analyst handoffs and giving incident responders clearer context for persistence, privilege escalation, and command-and-control activity.
- Partnered with infrastructure and identity teams to validate containment actions, including host isolation, token revocation, password resets, inbox rule removal, and firewall block requests.
- Created investigation playbooks for phishing triage, suspicious OAuth consent, endpoint malware alerts, and brute-force login activity, cutting average Tier 1 escalation rework by 24%.

Northstar Health Partners — Dallas, TX | July 2020 – March 2023

Security Operations Analyst

Supported a healthcare security operations team responsible for monitoring endpoints, user activity, email security alerts, network events, and vulnerability-related risk signals across multiple clinics and corporate offices.

- Reviewed and resolved 300+ monthly alerts from QRadar, SentinelOne, Proofpoint, Nessus, Cisco firewalls, and Windows event logs while maintaining complete case notes in ServiceNow.
- Improved phishing investigation accuracy by correlating email headers, URL reputation, sandbox results, user click activity, and endpoint telemetry before escalation.
- Assisted with incident response for compromised mailbox events, identifying malicious inbox rules, affected recipients, login source patterns, and required remediation steps.
- Used Wireshark, Zeek logs, and firewall data to investigate suspicious outbound traffic, port scanning, DNS anomalies, and connections to known malicious infrastructure.
- Developed weekly SOC reporting on alert volume, incident categories, top affected assets, recurring noisy detections, and remediation status for security leadership.
- Supported vulnerability prioritization by cross-referencing Nessus findings with endpoint criticality, exploitability notes, and known internet exposure.
- Trained 4 junior analysts on SIEM search basics, IOC enrichment, case documentation, and when to escalate suspected credential compromise or malware execution.

BrightLayer Managed IT — San Antonio, TX | May 2018 – July 2020

Junior SOC Analyst

Performed first-level security monitoring for managed services clients in retail, logistics, and professional services environments.

- Monitored SIEM dashboards, IDS alerts, endpoint security events, and authentication logs for 20+ client environments during assigned shifts.
- Performed initial triage for malware detections, brute-force attempts, suspicious VPN activity, impossible travel alerts, and unauthorized software execution.
- Escalated verified security events with source and destination details, impacted usernames, device names, timestamps, initial indicators, and recommended next actions.
- Used VirusTotal, WHOIS, passive DNS, and threat intelligence feeds to enrich suspicious domains, file hashes, and IP addresses before creating client-facing tickets.
- Maintained shift handoff notes and case updates to support continuity across a 24/7 monitoring schedule.

## Earlier Roles

**IT Support Technician** — Alamo Business Services, San Antonio, TX | August 2016 – May 2018. Supported Windows workstations, Active Directory account administration, endpoint troubleshooting, ticket documentation, patch verification, and basic network connectivity issues.

## Education

**Bachelor of Science in Information Technology**
Texas State University — San Marcos, TX

## Certifications

CompTIA Security+ • CompTIA CySA+ • Microsoft Certified: Security Operations Analyst Associate • GIAC Certified Incident Handler, GCIH

## Example jobs

- **Cyber Security SOC Analyst Intern — Wavenet — Asanti House, Oakwell Way, Birstall, United Kingdom**: Wavenet seeks a Cyber Security SOC Analyst intern for hands-on experience in a Security Operations Centre. This role provides students the chance to apply academic knowledge to practical scenarios while working alongside experienced colleagues. Responsibilities include monitoring security alerts, investigating incidents, and collaborating with threat response teams. Ideal candidates are pursuing a degree in Cybersecurity or a related field and are eager to expand their skills in a fast-paced environment. The placement emphasizes mentorship and professional growth, ultimately leading to potential full or part-time opportunities.
- **Cybersecurity SOC Analyst — Fiserv Solutions LLC — Berkeley Heights, New Jersey**: Fiserv, a leader in Fintech and payments, seeks a Cybersecurity SOC Analyst for its Cybersecurity Incident Response Team. This role involves investigating cybersecurity events, analyzing logs, and responding to potential incidents. Candidates should have 1-2 years of experience in cybersecurity operations, along with foundational knowledge of network protocols and incident response processes. Strong analytical and collaborative skills are essential. The position is on-site, requiring availability for shifts that include nights and weekends, with approximately 10% travel expected. A competitive salary range of $97,500 to $164,400 is offered.
- **Cybersecurity SOC Analyst — RIIVIPL RIIV India Private Limited — Mumbai**: # Reporting To:

Associate Manager, SOC

#

# Shift:

US (8:30 pm - 5:30 am IST) (India)

# About Russell Investments, Mumbai:

Russell Investments is a leading outsourced financial partner and global investment solutions firm providing a wide range of investment capabilities to institutional investors, financial intermediaries, and individual investors around the world. Building on an 90-year legacy of continuous innovation to deliver exceptional value to clients, Russell Investments works every day to improve the financial security of its clients. The firm is “Top 12 Ranked Consultant (2009-2024)” in P&I survey 2024 with $962 billion in assets under advisement (as of December 31, 2025) and $376.9 billion in assets under management (as of December 31, 2025) for clients in 30 countries. Headquartered in Seattle, Washington in the United States, Russell Investments has offices around the world, including London, New York, Toronto, Sydney, Tokyo, Shanghai – and has opened a new office in Mumbai, India in June 2023.

Joining the Mumbai office is an incredible opportunity to work closely with global stakeholders to support the technology and infrastructure that drives the investment and trading processes of a globally recognized asset management firm. Be part of the team based out of Goregaon (East) and contribute to the foundation and culture of the firm’s growing operations in India. The Mumbai office operates with varying shifts to accommodate time zones around the world.

For more information, please visit [https://www.russellinvestments.com](https://www.russellinvestments.com).

# Job Description:

We are seeking an experienced Cybersecurity Analyst to join our Security Operations Center (SOC) team. The SOC provides 24x7 security operations monitoring for the Russell Investments environment. You’ll use various tools and dashboards to monitor the environment, triage events to detect legitimate security concerns, and respond according to established processes. You’ll interact regularly with other members of the Cybersecurity team as well as other IT support teams.

**Years of Experience**

- Minimum 3 years’ experience in Cybersecurity or related field

**Key Responsibilities**

- Continuously monitor and analyze security events and incidents using advanced security tools to identify potential threats, vulnerabilities, and suspicious activities across the environment.
- Identify, classify, and assess potential, successful, and unsuccessful intrusion attempts, ensuring timely escalation and response.
- Conduct in-depth investigations of security incidents by correlating alerts, logs, and telemetry data, and leveraging internal and external threat intelligence sources to determine scope, root cause, and impact.
- Perform Incident Response (IR) activities, including containment, eradication, recovery, and post-incident analysis, in line with defined playbooks and SLAs.
- Participate in proactive threat hunting activities to identify hidden or emerging threats that may evade traditional detection mechanisms.
- Research new and evolving threats, attack techniques, and adversary tactics that could impact the organization, and recommend improvements to detection and response capabilities.
- Stay current with the latest cybersecurity news, vulnerabilities, threat trends, and industry best practices, and provide actionable insights to continuously improve security posture.
- Collaborate with IT, infrastructure, cloud, and application teams to gain deeper understanding of the environment and improve security visibility and response efficiency.
- Maintain accurate documentation of incidents, investigations, lessons learned, and recommendations, and contribute to the enhancement of SOC processes, runbooks, and detection use cases.

**Role Requirements**

- Strong understanding of cybersecurity principles, concepts, and best practices across networks, endpoints, and systems.
- Solid knowledge of networking fundamentals, firewalls, and operating systems (Windows and Linux).
- Proven experience in security incident detection, analysis, and response within a SOC or similar environment.
- Hands-on familiarity with security technologies such as SIEM, IDS/IPS, firewalls, endpoint detection and response (EDR), and vulnerability scanning tools.
- Experience correlating and interpreting data from multiple sources to analyze complex security issues and propose effective remediation strategies.
- Working knowledge of industry standards and frameworks, including the NIST Cybersecurity Framework and ISO/IEC 27001.
- Strong analytical and problem-solving skills, with the ability to prioritize incidents and operate effectively under pressure.
- Good communication and documentation skills, with the ability to clearly articulate technical findings to both technical and non-technical stakeholders.

**Core Values**

- Strong interpersonal, oral, and written communication and collaboration skills
- Strong organizational skills including the ability to adapt to shifting priorities and meet frequent deadlines,
- Proactive approach to problem-solving with strong judgment and decision-making capability.
- Highly resourceful and collaborative team-player, with the ability to also be independently effective and exude initiative and a sense of urgency.
- Exemplifies our customer-focused, action-oriented, results-driven culture.
- Forward looking thinker, who actively seeks opportunities, has a desire for continuous learning, and proposes solutions.
- Ability to act with discretion and maintain complete confidentiality.
- Dedicated to the firm’s values of non-negotiable integrity, valuing our people, exceeding client expectations, and embracing intellectual curiosity and rigor.

## FAQ

### What is the best resume format for a SOC Analyst resume?

Use a reverse-chronological format if you have security operations, IT support, network monitoring, or incident response experience. Put a concise summary at the top, followed by technical skills, certifications, work experience, and projects or labs that show SIEM monitoring, alert triage, log analysis, and escalation workflows.

### How long should a SOC Analyst resume be?

Most SOC Analyst resumes should be one page if you have less than 5 years of experience. A two-page resume is reasonable if you have multiple security roles, incident response work, cloud security exposure, or detailed experience with tools such as Splunk, Microsoft Sentinel, QRadar, CrowdStrike, Wireshark, or ServiceNow.

### Which skills should I include on a SOC Analyst resume?

Include skills tied to daily SOC work, such as SIEM monitoring, alert triage, incident escalation, log analysis, IDS/IPS, endpoint detection, phishing investigation, vulnerability management, ticketing, and basic scripting. Add tools by name when you have used them, such as Splunk, Sentinel, QRadar, CrowdStrike, Nessus, Wireshark, Jira, or ServiceNow.

### Do certifications matter on a SOC Analyst resume?

Certifications can help, especially for entry-level or junior SOC Analyst resumes. Security+, CySA+, Network+, SSCP, GCIH, or vendor-specific security tool certifications should be listed in a dedicated certifications section with the full certification name and issuing organization.

### How can I write a SOC Analyst resume with limited experience?

Use IT support, help desk, networking, system administration, home lab, CTF, or cybersecurity coursework to show security-adjacent experience. Write bullets around tasks such as reviewing logs, documenting incidents, investigating suspicious emails, configuring security tools, analyzing network traffic, or escalating issues through a ticketing system.

### Should I use the same SOC Analyst resume for every application?

No. Adjust the resume for each SOC Analyst posting by matching the job’s tools, alert types, operating systems, cloud platforms, and incident response responsibilities where they reflect your actual experience. For example, a posting focused on Microsoft Sentinel and Azure should use different skill emphasis than one centered on Splunk, Linux logs, and endpoint detection.

Create a Job-Specific SOC Analyst Resume with LiftmyCV

Create a professional, ATS-friendly SOC Analyst resume in seconds by pasting a job description. Or turn on per-job resume generation before starting auto-apply, so the AI agent adjusts your resume for each role.
