← All job descriptionsIT & Security

Cybersecurity Analyst Job Description

A complete cybersecurity analyst job description template, the ATS keywords SOC teams screen for, and why CISSP often isn't the real bar.

Mid levelInformation TechnologyHybrid

"Cybersecurity Analyst" covers several different jobs under one title: Tier 1 alert triage in a security operations center, vulnerability management, governance and compliance work, threat intelligence. The day-to-day for each looks almost nothing alike, and a posting that does not say which one it means is not being vague by accident — it usually means the team hasn't fully separated the work yet.

The most common mismatch in these postings is CISSP listed as a requirement for what is clearly a Tier 1 or Tier 2 analyst role. ISC2's own rules require five years of paid, full-time experience across the security domains before someone can even sit for the exam unsupervised — a candidate who clears that bar is arguably over-qualified to spend their day triaging phishing reports. Seeing CISSP on a mid-level analyst listing is a better signal that the posting was copied from a more senior requisition than that the company genuinely needs it. CompTIA Security+ is the certification that actually maps to this level of work.

It's also worth knowing where analysts come from: most did not start here. The typical path runs through IT support or systems administration first, because reading logs and spotting what's abnormal is a lot easier once you already know what normal looks like across an organization's systems. Direct-entry SOC analyst jobs exist, but they're the exception, not the on-ramp.

Sample job description — not a live opening

Ormsbury · Denver, CO

Full-time · Hybrid

$85,000 – $115,000

About the role

Ormsbury verifies identity and detects fraud for banks and fintech platforms during account opening and high-risk transactions. We handle sensitive applicant data for customers who cannot afford a breach, and our security team is a large part of the reason they trust us with it. We're hiring a Cybersecurity Analyst to join a five-person security operations team responsible for monitoring, triage and initial response across our production environment.

You'll share a rotating on-call schedule with the rest of the team, escalate confirmed incidents to our senior engineers, and spend a meaningful share of your week on work that doesn't make headlines: closing out false positives, tuning detection rules, and keeping the vulnerability backlog from growing faster than we can patch it.

What you'll do

  • Monitor SIEM alerts and triage them against known indicators and prior incidents.
  • Investigate suspicious login activity, phishing reports and endpoint alerts, and decide what needs escalation.
  • Run weekly vulnerability scans across production and internal systems, and track remediation to closure.
  • Support incident response: contain, document, and help write the after-action report.
  • Tune SIEM detection rules to cut false positives without losing real signal.
  • Maintain security awareness content and run phishing simulation campaigns.
  • Assist with SOC 2 evidence collection and customer security questionnaires.
  • Share an on-call rotation for after-hours alerts, roughly one week in five.

What we're looking for

  • 2+ years in a security operations, IT support or systems administration role that touched security tooling.
  • Working knowledge of SIEM platforms and how to write or tune a detection rule.
  • Understanding of common attack patterns: phishing, credential stuffing, lateral movement.
  • Comfort reading logs across Windows, Linux and cloud audit trails.
  • Clear written communication — a fair amount of this job is explaining what happened to people who weren't watching.
  • Ability to stay methodical when several alerts fire at once.

Nice to have

  • CompTIA Security+ or an equivalent foundational certification.
  • Scripting ability in Python or PowerShell for automating repetitive triage steps.
  • Exposure to a cloud provider's native security tooling (AWS GuardDuty, Microsoft Defender, or similar).
  • Prior experience in a regulated industry: financial services, healthcare or payments.
  • CISSP is welcome but not expected at this level — we'd rather see judgment under pressure than a certification.

Benefits

  • Medical, dental and vision coverage, with employee premiums covered in full.
  • 401(k) with a 4% company match.
  • Hybrid schedule: two days a week in the Denver office, flexible on which two.
  • $1,500 annual budget for security training, conferences or certification exams.
  • Twenty days of paid time off plus company holidays.

Salary range

As posted for this sample role. Real pay varies by employer, location and experience.

$85,000$115,000/ yr

What gets you noticed

ATS keywords for this role

The applicant tracking system (ATS) — the recruiting software a hiring team searches and filters applicants with — will screen for these. Weight shows how central each one is to this specific posting.

Required and central (4)

SIEMincident responsevulnerability managementsecurity operations

Important (8)

log analysisSplunkendpoint detection and responseNIST Cybersecurity Frameworkrisk assessmentSecurity+phishing analysisattention to detail

Mentioned in passing (6)

CrowdStrikePythonCISSPMITRE ATT&CKdocumentationcross-functional communication

Frequently asked questions

Do I need a CISSP to apply for a cybersecurity analyst role?

Almost never, whatever the listing says. ISC2 requires five years of paid security experience before you can sit for the exam unsupervised, which makes it a strange ask for a mid-level analyst opening. CompTIA Security+ or equivalent foundational knowledge is the realistic bar at this level — treat a CISSP requirement on a listing like this one as inherited from a more senior template, not a genuine filter.

What's the difference between a cybersecurity analyst and a SOC analyst?

Usually nothing — 'SOC analyst' is more common at managed security providers and larger enterprises with a formally named security operations center, while 'cybersecurity analyst' is a broader umbrella that can include governance and compliance work with little live alerting at all. Read the responsibilities list rather than the title.

Is this a good first security job, or do I need IT experience first?

Most people land an analyst role after a year or more in IT support, helpdesk or systems administration, not straight out of a course or bootcamp. That path exists for a reason: recognizing an abnormal login is a lot easier once you already know what a normal one looks like. Direct-entry SOC roles exist but are more competitive.

Tailor it to a real posting

This was a sample. Your resume should be tailored to the real thing.

Rezi Ninja reads an actual job posting and rewrites your resume to match it, with a Ninja Score so you know it lands before you hit send. Free to start, with the AI usage included.

We use privacy-conscious analytics to see how the site is used — no ads, no selling data. Read our Privacy Policy.