🏆 US-Registered Digital Marketing Agency Trusted by 200+ brands · USA · UK · Canada · AUS
HomeResume BuilderExamples › SOC Analyst

SOC Analyst Resume Example

Security operations resumes are judged on triage quality, not tool logos. A hiring manager wants to see the volume you handled, how you separated a real intrusion from noise, and whether you left the detection set better than you found it.

📄 Shown in the Professional template 🔎 Written for Technology & Engineering hiring 🔓 Free — no signup 🖨 PDF, Word or image
Tobias Nkemelu
Tier 2 SOC Analyst
Tampa, FL tobias.nkemelu@example.com +1 555 018 2299 linkedin.com/in/tobias-nkemelu

Summary

SOC analyst with 4 years in a 24/7 operation covering 9,000 endpoints. Escalation point for identity and endpoint alerts, and author of 40 production detection rules that reduced the shift queue rather than adding to it.

Experience

Tier 2 SOC AnalystHalbrook Managed Security Feb 2023 – Present
  • Triaged roughly 90 alerts per shift and owned escalation for a client estate of 9,000 endpoints across three time zones
  • Tuned 12 chronically noisy Splunk correlation searches, removing about 400 false positives a week from the tier 1 queue
  • Identified a credential-stuffing campaign from an anomalous impossible-travel pattern and drove containment within 35 minutes of first alert
Tier 1 SOC AnalystFairmount Cyber Operations Sep 2021 – Jan 2023
  • Handled first-line triage on a rotating shift pattern, meeting a 15-minute acknowledgement target on over 98% of priority alerts
  • Wrote 30 playbook entries that cut average tier 1 handling time on phishing reports from 22 to 9 minutes

Skills

SplunkMicrosoft SentinelEDR triageMITRE ATT&CKPhishing analysisLog analysisNetwork forensicsSOARPowerShellThreat intelligence

Education

BS CybersecurityUniversity of South Florida 2017 – 2021

Certifications

  • CompTIA Security+
  • GIAC Certified Intrusion Analyst (GCIA)
  • Splunk Core Certified Power User
  • Microsoft Certified: Security Operations Analyst Associate
Advertisement

The example above is a working resume, not a screenshot. What follows is what changes when you write your own, and what technical reviewers in this field actually do with the page.

Writing bullets an engineer will believe

Every bullet should survive the question "and then what happened". Latency, throughput, error rate, build time, cost, incident count — technical work generates numbers constantly, and a resume without them reads as work you watched rather than work you did. Name the technology inside the bullet rather than leaving it to the skills list, so the achievement and the tool arrive together.

What gets read first

The first pass is a match check rather than an assessment. A technical reviewer holds the posting beside your resume and looks for whether the stack lines up; anything that has to be inferred from a job title usually is not. That is why the top third of the page has to carry the match instead of leaving it buried in a bullet halfway down.

Mistakes that cost soc analyst candidates interviews

  • Writing "monitored security alerts" with no volume, tier or outcome, which describes every SOC analyst alive
  • Claiming incident response experience when your role ended at escalation — say what you owned
  • Skipping the tuning and detection work because it feels like housekeeping; it is what promotes you

How this role is actually hired

Expect a scenario walk-through: here is an alert, talk me through your triage. Interviewers listen for a structured process, sensible pivots and a clear escalation threshold rather than a memorised tool answer. Shift availability is discussed early and is often decisive, because coverage rotas are the constraint the team is hiring against. Be direct about what you triaged versus what you escalated; overstating this is caught quickly in the scenario round.

Certifications: what counts and what does not

Certification matters more at entry here than in most technical fields. Security+ is a common minimum on job descriptions, and GCIA or GCIH genuinely differentiate at tier 2. Home labs and detection-writing projects substitute credibly for experience at tier 1. Clearance requirements vary by employer and are non-negotiable where they apply.

The summary line

Three lines at most: your discipline, the depth of your experience, and the single system or result you would most want to be asked about. Technical readers skim the summary looking for a reason to keep reading, and "passionate about technology" is not one. Name the stack in the summary if the posting names it, because the first keyword match happens here.

Matching the posting without keyword stuffing

Technical postings are written by someone with a specific gap to fill. Read for the gap, not the wish list: the three or four things repeated across the responsibilities are what the role is really about. Mirror those in your own words and drop what does not apply. Our free ATS checker will show you what a parser extracts from your file before a recruiter sees it.

Advertisement
FAQ

SOC Analyst Resume Questions

What should an SOC analyst resume include?

A summary naming your discipline and your depth, a skills block a reader can find without hunting, experience bullets that each end in something measurable, education, and links to anything public you have shipped. Certifications only where the role is explicitly tied to a platform.

How does hiring for SOC analyst roles actually work?

The resume is the shortest part of the process in this field. It exists to earn the first call and to give a technical interviewer something concrete to open with, which is why a vague bullet is worse than no bullet — it becomes the question you answer badly.

Do certifications help for an SOC analyst role?

Rarely, and never as a substitute for shipped work. They count most when a role is explicitly tied to one vendor platform; otherwise reviewers weight what you built and can discuss in detail far above what you passed an exam in.

What do hiring managers look at first on an SOC analyst resume?

The stack, and how fast it can be found. A technical reviewer checks your languages, frameworks and platforms against the posting before reading a single achievement, which is why they belong in the summary and the skills block rather than only inside your job history.

What are the most important keywords for an SOC analyst resume?

Terms that commonly appear in postings for this role include: SIEM, alert triage, MITRE ATT&CK, EDR, incident escalation, log correlation, phishing analysis, threat hunting. Include a term only where you have genuinely done the work behind it, and write it the way the posting writes it rather than the way your last employer did.

How long should this resume be?

One page under roughly ten years of experience, two pages beyond that. A two-page resume where every line earns its place beats a padded one-page resume, so cut duties before you cut measurable achievements.

Can I use this example as a template?

Use the structure and the way each achievement is phrased, but write your own content. The names and employers here are fictional, and a resume describing work you did not do will not survive an interview.

Build Your SOC Analyst Resume

Start from this layout, edit in a live preview with an ATS score as you type, and download as PDF, Word or image — free.

Use This Example — Free
Arb Digital assistant

👋 Hey! Want to grow your business? Ask me anything — a free marketing proposal is on the table!