Write a Security Analyst Resume Built on Alerts and Outcomes
A security analyst resume that shows alert volume, SIEM tooling, detection work and incident handling, with a sample resume and a writing guide.
Example Security Analyst summary
Security analyst with five years in bank and managed service security operations centers. Triages roughly two hundred fifty alerts a week across Splunk, Microsoft Sentinel and CrowdStrike, and writes detection logic in both query languages instead of waiting on vendor rules. Cut false positives by 46% through rule tuning while extending ATT&CK coverage, and led containment on a business email compromise within twenty-five minutes of the first alert.
Skills to list on a Security Analyst resume
- Splunk
- Microsoft Sentinel
- SIEM tuning
- Endpoint detection and response
- MITRE ATT&CK
- Incident response
- Phishing and email analysis
- Malware triage
- Threat intelligence
- Vulnerability management
- KQL and SPL query writing
- Log source onboarding
- Network traffic analysis
- Playbook automation
- Security awareness reporting
What actually gets this resume read
- State your alert volume and tier, because a triage analyst and a detection engineer are read against different bars.
- Name the SIEM and endpoint tools you have used daily, and mention the query language you write in for each.
- Show detection work with counts: rules written, rules tuned, techniques covered or false positives removed.
- Describe one incident from alert to containment, with the clock times that show how fast you moved.
- Map your experience to a public framework such as MITRE ATT&CK or the NIST incident handling stages so scope is legible.
- Include automation you built in the platform, since analysts who reduce manual triage time are the ones who get promoted.