Write a SOC Analyst Resume That Proves You Can Triage
A SOC analyst resume example with SIEM keywords, alert triage bullets, tier-level tips and a full writing guide for security operations roles.
Example SOC Analyst summary
SOC analyst with four years on a follow-the-sun monitoring team, triaging 50 notables a shift in Splunk Enterprise Security and containing endpoints through CrowdStrike Falcon. Wrote 34 detection rules mapped to MITRE ATT&CK and led containment on a dozen business email compromise cases. GCIH certified and looking for a tier 3 detection engineering seat where I can own rule quality rather than queue depth.
Skills to list on a SOC Analyst resume
- SIEM monitoring
- Splunk Enterprise Security
- Microsoft Sentinel
- CrowdStrike Falcon
- MITRE ATT&CK mapping
- Alert triage
- Phishing analysis
- Malware analysis
- Incident response
- Log correlation
- Threat intelligence
- Network traffic analysis
- SOAR playbooks
- Python scripting
- Endpoint forensics
- Vulnerability management
What actually gets this resume read
- State your tier, the shift pattern you worked, and the alert volume you carried per shift near the top.
- Name the SIEM by product, not by category: Splunk Enterprise Security, Microsoft Sentinel, QRadar or Elastic Security.
- Map at least one bullet to MITRE ATT&CK so the hiring manager sees you speak the detection language.
- Show a full case you owned end to end: alert, investigation, containment, eradication, and what you wrote up afterward.
- Put Security+, GCIH or the CrowdStrike and Splunk product certifications in their own block above your work history.
- Include the EDR, the ticketing system and the case volume, because those three details set your resume apart from every generic security summary.