Cybersecurity Analyst Job Description
A complete cybersecurity analyst job description template, the ATS keywords SOC teams screen for, and why CISSP often isn't the real bar.
"Cybersecurity Analyst" covers several different jobs under one title: Tier 1 alert triage in a security operations center, vulnerability management, governance and compliance work, threat intelligence. The day-to-day for each looks almost nothing alike, and a posting that does not say which one it means is not being vague by accident — it usually means the team hasn't fully separated the work yet.
The most common mismatch in these postings is CISSP listed as a requirement for what is clearly a Tier 1 or Tier 2 analyst role. ISC2's own rules require five years of paid, full-time experience across the security domains before someone can even sit for the exam unsupervised — a candidate who clears that bar is arguably over-qualified to spend their day triaging phishing reports. Seeing CISSP on a mid-level analyst listing is a better signal that the posting was copied from a more senior requisition than that the company genuinely needs it. CompTIA Security+ is the certification that actually maps to this level of work.
It's also worth knowing where analysts come from: most did not start here. The typical path runs through IT support or systems administration first, because reading logs and spotting what's abnormal is a lot easier once you already know what normal looks like across an organization's systems. Direct-entry SOC analyst jobs exist, but they're the exception, not the on-ramp.
Ormsbury · Denver, CO
Full-time · Hybrid
$85,000 – $115,000
About the role
Ormsbury verifies identity and detects fraud for banks and fintech platforms during account opening and high-risk transactions. We handle sensitive applicant data for customers who cannot afford a breach, and our security team is a large part of the reason they trust us with it. We're hiring a Cybersecurity Analyst to join a five-person security operations team responsible for monitoring, triage and initial response across our production environment.
You'll share a rotating on-call schedule with the rest of the team, escalate confirmed incidents to our senior engineers, and spend a meaningful share of your week on work that doesn't make headlines: closing out false positives, tuning detection rules, and keeping the vulnerability backlog from growing faster than we can patch it.
What you'll do
- Monitor SIEM alerts and triage them against known indicators and prior incidents.
- Investigate suspicious login activity, phishing reports and endpoint alerts, and decide what needs escalation.
- Run weekly vulnerability scans across production and internal systems, and track remediation to closure.
- Support incident response: contain, document, and help write the after-action report.
- Tune SIEM detection rules to cut false positives without losing real signal.
- Maintain security awareness content and run phishing simulation campaigns.
- Assist with SOC 2 evidence collection and customer security questionnaires.
- Share an on-call rotation for after-hours alerts, roughly one week in five.
What we're looking for
- 2+ years in a security operations, IT support or systems administration role that touched security tooling.
- Working knowledge of SIEM platforms and how to write or tune a detection rule.
- Understanding of common attack patterns: phishing, credential stuffing, lateral movement.
- Comfort reading logs across Windows, Linux and cloud audit trails.
- Clear written communication — a fair amount of this job is explaining what happened to people who weren't watching.
- Ability to stay methodical when several alerts fire at once.
Nice to have
- CompTIA Security+ or an equivalent foundational certification.
- Scripting ability in Python or PowerShell for automating repetitive triage steps.
- Exposure to a cloud provider's native security tooling (AWS GuardDuty, Microsoft Defender, or similar).
- Prior experience in a regulated industry: financial services, healthcare or payments.
- CISSP is welcome but not expected at this level — we'd rather see judgment under pressure than a certification.
Benefits
- Medical, dental and vision coverage, with employee premiums covered in full.
- 401(k) with a 4% company match.
- Hybrid schedule: two days a week in the Denver office, flexible on which two.
- $1,500 annual budget for security training, conferences or certification exams.
- Twenty days of paid time off plus company holidays.
Salary range
As posted for this sample role. Real pay varies by employer, location and experience.
$85,000–$115,000/ yr
ATS keywords for this role
The applicant tracking system (ATS) — the recruiting software a hiring team searches and filters applicants with — will screen for these. Weight shows how central each one is to this specific posting.
Required and central (4)
Important (8)
Mentioned in passing (6)
Frequently asked questions
Do I need a CISSP to apply for a cybersecurity analyst role?
Almost never, whatever the listing says. ISC2 requires five years of paid security experience before you can sit for the exam unsupervised, which makes it a strange ask for a mid-level analyst opening. CompTIA Security+ or equivalent foundational knowledge is the realistic bar at this level — treat a CISSP requirement on a listing like this one as inherited from a more senior template, not a genuine filter.
What's the difference between a cybersecurity analyst and a SOC analyst?
Usually nothing — 'SOC analyst' is more common at managed security providers and larger enterprises with a formally named security operations center, while 'cybersecurity analyst' is a broader umbrella that can include governance and compliance work with little live alerting at all. Read the responsibilities list rather than the title.
Is this a good first security job, or do I need IT experience first?
Most people land an analyst role after a year or more in IT support, helpdesk or systems administration, not straight out of a course or bootcamp. That path exists for a reason: recognizing an abnormal login is a lot easier once you already know what a normal one looks like. Direct-entry SOC roles exist but are more competitive.
This was a sample. Your resume should be tailored to the real thing.
Rezi Ninja reads an actual job posting and rewrites your resume to match it, with a Ninja Score so you know it lands before you hit send. Free to start, with the AI usage included.
