Cyber Security Analyst resume example for Fresher (0 to 1 years), ai-era template, showing professional summary, work experience, projects, skills, education and certifications

Cyber Security Analyst Resume Format, with 3 Full Samples

A cyber security analyst is hired on evidence of threats caught, incidents contained and alerts triaged down to the ones that mattered, yet most resumes list every tool and framework the person has read about and forget the intrusion they actually stopped. Below are three complete resumes, one for a Security-Plus-certified fresher who ran a home SOC, one for a mid-level SOC analyst doing real incident response, and one for a senior analyst who leads detection engineering and threat hunting. After the samples come the format rules, the difference between listing SIEM and proving it, the terms a parser matches literally, and the mistakes that end a screening before a human reads the page.

Build my resume

Updated 17 August 2026 · 21 min read · 3 full examples

Cyber Security Analyst resume example for Fresher (0 to 1 years), ai-era template, showing professional summary, work experience, projects, skills, education and certifications

Fresher (0 to 1 years) Cyber Security Analyst

ai-era template
Read it
Cyber Security Analyst resume example for Mid-level (4 years), professional template, showing professional summary, work experience, skills, education and certifications

Mid-level (4 years) Cyber Security Analyst

professional template
Read it
Cyber Security Analyst resume example for Senior (9 years), header-band template, showing professional summary, work experience, skills, education and certifications

Senior (9 years) Cyber Security Analyst

header-band template
Read it
Cyber Security Analyst resume example for Fresher (0 to 1 years), ai-era template, showing professional summary, work experience, projects, skills, education and certifications

Fresher (0 to 1 years) Cyber Security Analyst

ai-era template
Read it
Cyber Security Analyst resume example for Mid-level (4 years), professional template, showing professional summary, work experience, skills, education and certifications

Mid-level (4 years) Cyber Security Analyst

professional template
Read it
Cyber Security Analyst resume example for Senior (9 years), header-band template, showing professional summary, work experience, skills, education and certifications

Senior (9 years) Cyber Security Analyst

header-band template
Read it

Cyber Security Analyst resume example, Fresher (0 to 1 years)

ai-era template
Cyber Security Analyst resume example for Fresher (0 to 1 years), ai-era template, showing professional summary, work experience, projects, skills, education and certifications
Fresher (0 to 1 years) ai-era template

Is your resume good enough?

Upload the resume you have now and see what an applicant tracking system reads before a cyber security analyst recruiter ever does.

Free to run. Sign in with your mobile number to see your score.

Cyber Security Analyst resume example, Mid-level (4 years)

professional template
Cyber Security Analyst resume example for Mid-level (4 years), professional template, showing professional summary, work experience, skills, education and certifications
Mid-level (4 years) professional template

Want this structure with your own details? Build it in the resume builder.

Cyber Security Analyst resume example, Senior (9 years)

header-band template
Cyber Security Analyst resume example for Senior (9 years), header-band template, showing professional summary, work experience, skills, education and certifications
Senior (9 years) header-band template

The format that works for cyber security analyst resumes in India

Reverse chronological is the only layout worth using. Put the most recent role first, work backwards, and let the dates sit in plain view. Functional resumes that group everything under Skills and quietly drop the dates read as an attempt to hide a gap, and security reviewers, who assess trust for a living, treat them that way. A gap is better explained in one honest line than buried. Length is decided by evidence. One page holds everything a fresher and most analysts up to roughly five years have to say. Past that, a second page is fine when it carries real security work, incidents handled, detections built, hunts run, rather than a longer tool and framework list. A page two built from a declaration paragraph and a hobbies line is a padded one-page resume. Four things belong nowhere on a technical resume here: a photograph, date of birth, marital status and father's name. They survive from an older template that circulated through campus placement cells. Nobody screening a security analyst is looking for them, and every line they occupy is a line an incident or a detection metric could have used. Send a PDF unless the posting asks for DOCX, and name the file with your own name and the target role rather than resume_final_v4. Use a single column all the way down, because two-column layouts parse unpredictably when a sidebar sits beside the experience. The table below sets out the section order.

SectionWhere it goesWhy
Name and headlineTop, above everythingThe headline is the role you want: SOC analyst, cyber security analyst, detection engineer. Recruiters match on it.
Professional summaryDirectly under the headerThree lines. Domain, years, and the single strongest incident or detection result.
Work experienceNext, for anyone with a jobMost recent first. Newest role gets the most bullets.
Projects or home labAbove experience for freshers, below it after thatFor a fresher a real home SOC and CTF record is the evidence. For an experienced analyst, skip unless it shows something new.
SkillsBelow experienceGrouped: SIEM and tools, frameworks, security domains. Not a 40-item wall.
EducationBottom, unless you are a fresherDegree, institution, years. Drop the percentage after your first job.
CertificationsAfter education, or beside skills; prominent in securityName, issuing body, year. Security+, CySA+, OSCP and GIAC certs earn a visible place.

Listing SIEM is not the same as proving you ran it

The single most common security analyst resume failure is a skills line that reads Splunk, QRadar, ArcSight, Sentinel, Wireshark, Nessus, Metasploit, Burp Suite, Nmap, CrowdStrike, MITRE ATT&CK, NIST, ISO 27001, incident response, threat hunting, malware analysis with no bullet anywhere that shows any of it stopping real activity. A parser matches those terms, but a human reviewer reads the wall and assumes it is padded, then goes looking for the one incident you can actually walk through. The fix is to let the experience prove the work. If you write threat hunting on the skills line, at least one bullet should describe a hunt you ran and what it found. If you write Splunk, a bullet should name a detection you wrote in it and the activity it caught. The mid-level sample lists incident response, detection engineering and MITRE ATT&CK precisely because the bullets show a contained business-email-compromise, twenty-two mapped detections and a cut in response time. The skills line and the experience agree, which is what makes both believable. Be specific about what you did, not what your team owned. Security resumes suffer more than most from the passive team voice: monitored, assisted, supported. Name your part: the rule you wrote, the incident you led, the false positives you cut. A SOC analyst who can describe one intrusion they investigated end to end beats one who lists ten tools they watched dashboards in. Do not list offensive tools you ran once in a course if the role is defensive, or claim malware reverse-engineering off one tutorial. An interviewer in security probes claimed skills hard, because the cost of a wrong hire is high, and a shallow claim collapses in the first specific question.

For every tool and framework on your skills line, ask: is there a bullet that proves I used it on a real alert or incident. If not, either add the bullet or cut it. A wall of unproven security tools helps the parser and fails the interview fast.

Writing a summary a hiring manager actually reads

The block under your name is the part you can be reasonably sure gets read, so it should carry three facts: what you defend, how long you have been defending it, and the strongest thing that happened because of your work. Three or four lines, no adjectives that cannot be checked. The old objective line, seeking a challenging position in the field of cyber security in a reputed organisation, tells the reader nothing they did not assume from the application. Replace it with a summary. An objective describes what you want, a summary describes what you have already defended, and only one is evidence. Freshers often believe they have nothing to summarise. Look at the fresher sample: it names the SIEM, states the internship triage volume, and points at a home SOC where real attacks were detected. That is a genuine summary built from one internship and serious self-directed practice. What it avoids is "passionate about cyber security", a phrase so common on graduate resumes it now carries no information, and worse, so common in security that reviewers actively discount it. A practical test: read your summary and ask whether a classmate with the same certification could paste it onto their resume unchanged. If they could, it describes the certificate, not you. Add the specific incident, the specific number and the specific ownership until it stops being transferable.

Professional summary, mid-level analyst
Weak

Passionate and motivated cyber security analyst with 4+ years of experience in SIEM, incident response and various security tools seeking a challenging role in a reputed organisation.

Strong

Security analyst with four years in a fintech SOC, owning incident response and detection tuning for a platform under constant automated attack. Cut mean time to respond by more than half and contained a business-email-compromise before any funds moved.

The rewrite trades a tool list and self-description for a domain, an ownership scope and two verifiable results, one of them a real handled incident.

Experience bullets: verb, threat, consequence

Every strong bullet in the samples follows the same shape. It opens with an action verb, names the specific detection or incident you worked, and closes with what measurably moved. The verb establishes that you did it. The threat or detection tells a reviewer whether the work is relevant. The number does the persuading. Start with the outcome and work backwards. Analysts usually write the task first, then struggle to attach a number, which produces bullets like "monitored security alerts and responded to incidents". Instead ask what was different after you acted: an intrusion was contained, response time dropped, false positives fell, coverage of an attack technique rose, a threat was found that automation missed. Then write the sentence that ends in that fact. Vary the metric. Six alert-count numbers in a row read as one trick repeated. Across a real role you can honestly reach for mean time to respond, dwell time, false-positive reduction, detection coverage, incidents handled, phishing pull-time and alert-volume cut. The mid-level sample uses several metric types across its bullets, which reads as range. Where you lack a number, describe the incident in outcome terms. "Led the containment of a business-email-compromise attempt, blocking the payment change before any funds moved" carries weight without a percentage, because the outcome is the point. Handle the confidentiality question by keeping specifics generic: name the technique and the outcome, never a client name or exact data. Allocate bullets by recency. Current role gets five or six, the previous role four or five, anything older two or three.

LevelWhat bullets must proveTypical metric
FresherYou can triage an alert and tell true from false positiveAlerts triaged, false positives cut, detection rule written, CTF rank
1 to 3 yearsYou investigate and document incidents without supervisionIncidents handled, false positives cut, alerts per shift, enrichment automated
4 to 6 yearsYou lead incident response and tune detections end to endMTTR, incident contained, detections built, alert-volume cut
7 years and upYou set detection strategy and run threat huntingDwell time, ATT&CK coverage, hunts finding gaps, standards set
Experience bullet, SOC role
Weak

Responsible for monitoring security alerts and responding to incidents as per the SOC process and escalation matrix.

Strong

Cut mean time to respond on real incidents from 48 minutes to 19 by rewriting the triage runbooks and reducing alert volume 45 percent through tuning over-broad rules.

"Responsible for" describes a job description; the rewrite names the change made and the response-time and alert-volume it moved.

Experience bullet, incident response
Weak

Worked on incident response activities and handled various security incidents to protect the organisation from threats.

Strong

Led the containment of a business-email-compromise attempt, isolating the account and blocking the payment change before any funds moved, then wrote the post-incident review.

Turns a vague protection claim into one specific incident, the action taken, the outcome, and the follow-through a reviewer can ask about.

If a bullet would read identically on a teammate's resume, it is describing the SOC, not you. Rewrite it until it only fits the incident or detection you actually worked.

The skills section: grouped, honest, and short enough to defend

A security analyst resume's skills section has two audiences with opposite preferences. The parser wants literal terms it can match, Splunk and MITRE ATT&CK and incident response. A human wants a short, organised list that signals what kind of analyst you are. Grouping satisfies both. Group by function rather than one long line. SIEM and tools, frameworks and standards, security domains, and scripting is a grouping that works for almost every analyst. The exact headings matter less than the fact that structure exists. Write names the way the industry writes them: MITRE ATT&CK not Mitre Attack, Splunk not splunk, Wireshark not Wire Shark. A parser matches on strings. Twelve to sixteen skills is the working range. Below eight the section looks thin. Above twenty it stops being a signal, and security resumes are especially prone to buzzword padding: naming NIST, ISO 27001, PCI DSS, SOC 2, GDPR, HIPAA and CIS as seven items when you have worked to one of them. The list is a contract in a field where the interview probes hard: every item is a question you have agreed to answer, and a wrong answer costs more here than an unchecked box was worth. Do not include a proficiency bar. Star ratings invite an argument you cannot win, and nobody agrees on what four stars in malware analysis means. Let the experience prove the depth instead, which security interviews will demand anyway.

GroupWhat goes in itHow many
SIEM and toolsSplunk, QRadar, Sentinel, Wireshark, Nessus, CrowdStrike3 to 5
FrameworksMITRE ATT&CK, NIST, Cyber Kill Chain, ISO 270012 to 4
Security domainsIncident response, threat hunting, vulnerability management, EDR3 to 5
ScriptingPython, PowerShell, Bash, regex1 to 3
Cloud and networkAWS security, network security, cloud logging1 to 3
Skills section
Weak

Skills: Splunk, QRadar, ArcSight, Sentinel, LogRhythm, Wireshark, Nessus, Qualys, Metasploit, Burp Suite, Nmap, CrowdStrike, Carbon Black, MITRE ATT&CK, NIST, ISO 27001, PCI DSS, SOC 2, GDPR, HIPAA, incident response, threat hunting, malware analysis, forensics, penetration testing, Python, MS Office

Strong

SIEM and tools: Splunk, QRadar, Wireshark, Nessus, CrowdStrike. Frameworks: MITRE ATT&CK, NIST, Cyber Kill Chain. Domains: incident response, detection engineering, threat hunting, EDR. Scripting: Python, PowerShell.

Cuts the tools and standards you touched once, collapses the compliance and tool walls to what you can defend in an interview, and groups the rest so a human reads it in one pass.

Home labs, CTFs and projects: what to include and how to describe it

For a fresher moving into security, a home lab and a capture-the-flag record are the resume. They sit above experience, they get real space, and they are where a reviewer decides whether you can actually do the work or only pass exams about it. Security is unusually welcoming of self-taught evidence, because the field grew that way. For an experienced analyst, drop projects unless one shows something the day job never exposed you to. The common failure is describing the setup instead of the skill. "Built a home lab with Security Onion" tells a reviewer nothing. Describe what you can do in it and what was genuinely hard. The home SOC in the fresher sample is a strong entry because it names the full loop that separates a defender from a reader: launch a real attack technique, find it in the SIEM, write a detection so it fires reliably. That loop is the job in miniature. Pick work that shows the security disciplines rather than three tutorials followed to completion. One that proves you can detect, a home SOC with real attacks caught, one that proves you can analyse, phishing or malware triage with extracted indicators, and one that proves you can assess, a vulnerability scan triaged by real exploitability rather than raw CVSS, is a stronger set than a list of courses. A capture-the-flag ranking is a legitimate, verifiable signal that a fresher can point to. Keep it honest and legal. Describe attacks only against your own lab or authorised targets, never a system you did not have permission to test, because a security team reads an unauthorised claim as a red flag about judgement, which is exactly what they are screening for.

Project description, fresher resume
Weak

Home Lab: set up a home lab with Security Onion and Kali Linux to learn about cyber security and practise attacks.

Strong

Home SOC on Security Onion monitoring a vulnerable network: launched real attack techniques with Kali, detected them from the logs, and wrote or tuned a detection for each so it fires reliably, documented against MITRE ATT&CK.

Swaps a vague learning setup for the full detect-and-respond loop that actually signals a defender, mapped to the framework a SOC uses.

Where education and certifications belong

Education goes at the bottom for anyone with a full-time job, and near the top for a fresher, who has nothing stronger to lead with. Degree, institution, years. That is the whole entry for most people. CGPA or percentage is worth keeping while you are a fresher and it is decent, roughly 7 out of 10 and above, because campus and early-career screening still filters on it. Once you have your first full-time role, drop it. A number from years ago competes for space with incidents you actually handled, which is far more predictive. Security is a field where certifications carry unusual weight and belong prominently, sometimes near the top for a fresher, because they are a recognised proxy for skill in a domain that is hard to assess from a degree. The ladder is well understood: CompTIA Security+ as the entry signal, CySA+ or the EC-Council SOC analyst certification for blue-team roles, the OSCP as a respected hands-on offensive credential, and the GIAC family, GCIH, GCDA, GCFA, as the senior blue-team standard. For cloud, the AWS or Azure security specialty matters as estates move. Write the full name, the issuing body and the year. Certifications with an expiry, which most security ones have, must be kept current or dated honestly. An expired OSCP or a GIAC past renewal listed as current is exactly the kind of small dishonesty a security screen is built to catch, so keep the dates accurate.

Getting through the applicant tracking system

An applicant tracking system is a parser and a search index, not a judge. It reads your file, tries to break it into name, dates, employers, titles and skills, and stores the result so a recruiter can search across candidates. Almost every ATS problem is a parsing problem, and parsing problems come from layout, not wording. The layout rules are short. One column. Standard section headings, so use Work Experience rather than My Journey, and Skills rather than My Arsenal. No text inside images, because a badge wall of certification logos reads as empty space, and security candidates love a badge wall. No critical information in the header or footer region, which some parsers drop. Avoid text boxes and nested tables in the resume body. On wording, mirror the language of the job description where it is honest. If the posting says SOC analyst, write SOC analyst. If it says incident response, write incident response rather than just IR, or write both. Include the expansion alongside an acronym at least once, for example "SIEM (security information and event management)", so both searches find you, and security is acronym-heavy enough that this matters more than in most fields. Keyword stuffing does not work, and security resumes are a common offender with a hidden block of every framework and tool in white text. Recruiters find it quickly, and in a trust-focused field the outcome is worse than being filtered. Write real bullets that naturally contain the right terms, because a bullet describing a detection you built in Splunk contains the word Splunk in a context that survives human review too. Save as PDF from a tool that embeds real text, then open the file and confirm you can select and copy a sentence. If you cannot select the text, neither can the parser.

Section heading
Weak

My Security Arsenal

Strong

Skills

Parsers look for standard headings; a creative one can push the entire block into an unclassified bucket the recruiter never searches, and the security field is especially fond of theatrical headings.

Test your own file before you send it. Copy the text out of the PDF into a plain text editor. Whatever you can read there is roughly what the parser sees, and anything scrambled is a real risk.

What gets cyber security analyst resumes rejected

Most rejections at the resume stage are not close calls. They come from a small set of recurring problems, and all of them are fixable in an afternoon. The list below covers what reviewers of Indian security analyst resumes see most often, in rough order of how much damage each one does.

  • A wall of tools, frameworks and compliance standards with no bullet proving you used any of it on a real alert or incident. Every item is a question a security interview will ask.
  • No incident anywhere. A security analyst who cannot point to one threat they investigated or contained end to end has not shown the core of the job.
  • Job duties copied from the job description instead of what you defended. "Responsible for monitoring" is the tell, and the passive SOC voice is worse here than in most fields.
  • No numbers anywhere. Response time, dwell time, false positives cut, incidents handled, coverage. Pick whichever is honest for the work.
  • Claiming offensive skills like penetration testing or reverse engineering off one course for a defensive role, which collapses in the first specific question.
  • A badge wall of certification logos as images, which parses as empty space and reads as compensating for thin experience.
  • A photo, date of birth, marital status or father's name. None of it belongs on a technical resume, and it takes an incident's space.
  • A generic 'passionate about cyber security' objective. Replace it with a summary that states domain, years and one incident or detection result.
  • Describing attacks against systems you had no authorisation to test, which a security team reads as a judgement red flag, the exact thing they screen for.
  • Inflated titles, dates or expired certifications presented as current. Background verification and cert checks are standard in security, and a mismatch ends the process.

Read your resume aloud once before sending it. In security especially, anything you would not want to defend in detail to an interviewer's face is a line to cut or rewrite.

Skills to put on a cyber security analyst resume

Technical

  • SIEM Operation and Tuning
  • Incident Response
  • Detection Engineering
  • Threat Hunting
  • MITRE ATT&CK Framework
  • Endpoint Detection and Response (EDR)
  • Malware Analysis
  • Vulnerability Management
  • Network Security
  • Log Analysis
  • Digital Forensics
  • Threat Intelligence
  • Cloud Security (AWS, Azure)
  • Phishing Investigation

Tools and platforms

  • Splunk
  • QRadar
  • Microsoft Sentinel
  • Wireshark
  • Nessus
  • CrowdStrike
  • Security Onion
  • Nmap
  • Metasploit
  • Python
  • PowerShell
  • VirusTotal

Working skills

  • Incident triage under pressure
  • Clear written incident reporting
  • Analytical thinking
  • Attention to detail
  • Escalation judgement
  • Cross-team collaboration
  • Stakeholder communication
  • Mentoring junior analysts
  • Discretion and integrity

Certifications worth listing as a cyber security analyst

CertificationFull nameWorth it for
Security+CompTIA Security+The standard entry-level signal for a security analyst, worth it for any fresher or career switcher because it proves broad security fundamentals and clears the certification filter many SOC job postings apply. Most valuable early, and often worth putting near the top of a fresher resume. Once you have real SOC experience it becomes a baseline rather than a highlight.
CySA+CompTIA Cybersecurity AnalystThe blue-team next step after Security+, focused on threat detection and analysis, and worth it for SOC analysts who want a defensive credential above the entry level. Fits the one-to-four-year range well and maps closely to actual SOC work. A practical mid-tier signal for analysts staying on the defensive side.
CSAEC-Council Certified SOC AnalystA SOC-specific certification aimed squarely at L1 and L2 analyst roles, covering SIEM, triage and incident basics. Worth it for someone targeting SOC positions who wants a role-specific credential. Useful early career, though many hiring managers weight Security+ and CySA+ and hands-on evidence more heavily.
OSCPOffensive Security Certified ProfessionalThe most respected hands-on offensive certification, a 24-hour practical exam that is hard to fake, and a strong differentiator even for defensive analysts because it proves you understand how attacks actually work. Worth the significant effort for anyone serious about security, and a genuine signal at any level. Overkill only if your path is purely governance or compliance.
GCIHGIAC Certified Incident HandlerA senior blue-team standard focused on incident handling and response, and worth it for mid-to-senior analysts leading real incident response. The GIAC family, GCIH, GCDA, GCFA, carries strong weight but is expensive, so it is usually employer-sponsored. A clear signal of depth for incident-response and detection roles.
AWS SecurityAWS Certified Security, SpecialtyWorth it for analysts defending cloud estates, since so much of the attack surface has moved to AWS and cloud security skills are in short supply. Backs the cloud-security keyword with a recognised, specialised credential. Pick it once you actually work security in AWS rather than as a first certification.

Keywords an ATS scans for in a cyber security analyst resume

These are the literal terms a parser matches against the job description. Use the ones that are true of you, in the sentences where you did the work, not as a list at the bottom.

  • cyber security analyst
  • soc analyst
  • incident response
  • SIEM
  • splunk
  • qradar
  • threat hunting
  • MITRE ATT&CK
  • detection engineering
  • EDR
  • malware analysis
  • vulnerability management
  • threat intelligence
  • network security
  • log analysis
  • phishing
  • cloud security
  • digital forensics
  • NIST
  • security operations

Cyber Security Analyst resume FAQ

What salary can a cyber security analyst expect in India?

A fresher or L1 SOC analyst typically starts around 3.5 to 6.5 LPA, higher in product companies and for candidates with strong hands-on evidence or an OSCP. A security analyst with four to six years doing real incident response and detection usually sits in the 9 to 20 LPA band. Senior analysts, detection engineers and threat hunters with nine years and above commonly earn 22 to 45 LPA and more, and specialised skills like cloud security, malware analysis or a GIAC credential push the top of every band upward, because deep defensive skill is genuinely scarce.

How long should a cyber security analyst resume be?

One page up to about five years of experience, two pages after that only if the second page carries real security work, incidents handled, detections built, hunts run, rather than a longer tool and framework list. Nobody has been rejected for a resume that was too easy to read. If you are struggling to fit one page, cut the oldest role to a single line, trim the certification list to the ones that count, and remove any tool you would not want probed in an interview.

Do certifications matter a lot in cyber security?

More than in almost any other IT field, because a degree alone is a weak proxy for security skill and the industry has standardised on a well-understood certification ladder. Security+ is the entry filter many postings apply, CySA+ and the EC-Council SOC analyst certification suit blue-team roles, the OSCP is a respected hands-on credential, and the GIAC family is the senior standard. They matter most while you have less real experience to point at. That said, one contained incident on your resume still outweighs a wall of badges, so pair the certifications with evidence.

How does a fresher get into a SOC with no experience?

Lead with a real home lab and a capture-the-flag record, then any internship, then education and certifications. Security welcomes self-taught evidence more than most fields, so build a home SOC, attack it in a legal lab, detect the attacks, and describe that full loop. Add checkable facts: a Security+ certification, a CTF ranking, a public write-up. "Passionate about cyber security" is discounted on sight, but "detected a real attack technique in my own SIEM and wrote a detection for it" is exactly the signal a SOC hires on.

Should I put my TryHackMe or HackTheBox rank on my resume?

Yes, if it is genuinely strong, because a capture-the-flag ranking is a verifiable, hands-on signal that a fresher or junior analyst can point to and a recruiter can check. Name the platform and the standing, for example a top-percentile rank or a completed SOC learning path. It carries real weight early in a career because it demonstrates practical skill that a certificate exam does not. Once you have real incident-response experience, it moves below your work and shrinks to a line.

What is the single most important thing on a security analyst resume?

Evidence of a real threat handled. A wall of tools and frameworks is easy to list and easy to discount, but an analyst who can point to one incident they triaged, investigated or contained end to end has shown the core of the job. Put an incident or a detection outcome in the summary and back it in a bullet: a contained business-email-compromise, a detection that caught a real intrusion, a response time cut in half. Keep the specifics generic to respect confidentiality, but the outcome must be concrete.

Does an ATS reject resumes with two columns or badge images?

Two columns are not rejected outright, but some parsers read them out of order and interleave your sidebar with your experience, which is why all three samples use a single column. Certification badge images are a bigger risk specific to security resumes: a parser reads an image as empty space, so a wall of certification logos contributes nothing to the search and can look like it is compensating for thin experience. List certifications as text with the issuing body and year, and test your file by copying the PDF text into a plain editor.

How do I write security experience without breaking confidentiality?

Describe the technique and the outcome, never the client, the data or anything that identifies the target. "Contained a business-email-compromise attempt before any funds moved" states a real, impressive outcome without naming an organisation or exposing anything sensitive. Use categories rather than specifics: a phishing campaign, a ransomware precursor, a credential-stuffing attempt. Recruiters and hiring managers in security understand this constraint and expect it, so a well-anonymised incident reads as professional, not evasive.

Should offensive and defensive skills go on the same resume?

List both only if you genuinely have both, and lead with whichever matches the role. For a SOC or detection role, foreground the defensive work, incident response, detection engineering, threat hunting, and mention offensive skills like an OSCP as evidence you understand the attacker, which strengthens a defender. Do not pad a defensive resume with penetration-testing tools you ran once in a course, because a security interview probes hard and a shallow offensive claim collapses fast and damages your credibility on the rest of the page.

Related resume examples and guides

Build your own in any of these formats

Start from a blank resume or upload the one you have. Goodspace renders it in 24 templates and flags the SIEM, incident response and threat detection keywords an applicant tracking system will look for, and the padding it will not credit.

Build my resume