Updated by
Hi, I'm Jack, the owner of Cybersecurity Jobs List, and co-founder of Himalayas (himalayas.app) and Cavuno (cavuno.com). Across all my platforms, I work with application security daily: dependency vulnerability scanning, secure authentication, API security, and data protection across hundreds of thousands of users. My technical background is in computer science (UNSW), where he studied security engineering and computer networks, and worked as a research assistant on VR experiments that were published in the Journal of Experimental Psychology. I also work with cybersecurity hiring data every day, tracking which companies are posting, what certifications actually appear in listings, how salaries differ by sub-discipline and clearance level, and where the talent gaps are widest. That combination of security practice, engineering at scale, and daily immersion in the hiring data is what shapes the content on this site. I'm currently based in Sydney, Australia.

A cybersecurity resume should make it easy to see what work you can do and what supports that claim. Choose a target role, put your most relevant evidence near the top, and describe your contribution clearly. A SOC application needs different examples from a governance, risk and compliance application.
The three examples below show how to do that when you're starting out, moving from IT support, or bringing audit and operations experience into GRC. Each includes a sample summary, work or project bullets, and notes on what to adapt.
All names, organizations, projects and achievements in these examples are fictional. They're teaching examples, not resumes from successful applicants. Replace the details with your own experience, and only use a bullet you can explain in an interview.
Choose the example closest to your experience
Start with the work you can demonstrate:
- Entry-level cybersecurity resume: your strongest evidence comes from education, a home lab or a substantial project.
- IT support to SOC analyst resume: you already troubleshoot systems, handle access requests or escalate security concerns at work.
- GRC career-change resume: you have experience with controls, evidence, audits, suppliers or documented processes.
Use the job description to choose what comes first. Our SOC career guide and GRC career guide explain the work if you're still choosing a direction.
Entry-level cybersecurity resume example
Put relevant projects before unrelated employment when they provide your clearest evidence. Keep the employment section: it can show reliability, communication and experience working with other people.
Sample resume: project-led applicant
Alex Morgan
City, country | Your email | Your phone | Your portfolio link
Summary
IT graduate applying for junior security analyst roles. Built a Windows event-log lab and documented investigations of simulated account activity. Brings customer-facing work experience and clear technical documentation.
Projects
Windows sign-in investigation lab | Independent project | June–August 2026
- Collected Windows security events from two test machines and used saved searches to compare failed and successful sign-ins by account and time.
- Wrote four investigation notes covering the observed activity, supporting events, alternative explanations and recommended next checks.
- Added a repeatable setup guide and documented a logging gap that prevented one scenario from being assessed fully.
Experience
Customer service assistant | Example Retail | February 2024–present
- Documented unresolved customer cases for the next shift, recording the issue, checks completed and promised follow-up.
- Followed identity-check procedures before changing customer account details and referred exceptions to a supervisor.
Skills
Windows event logs and basic log queries, demonstrated in the project above; TCP/IP and DNS fundamentals; technical note writing; customer communication.
Education
Bachelor of Information Technology | Example University | Completed 2026
Relevant coursework: networking, operating systems and information security.
What to adapt
The project has a clear setting: two test machines. It doesn't imply responsibility for an employer's network. The investigation notes give the reader something concrete to ask about, while the logging gap shows that the applicant understood a limitation.
If you followed a tutorial, say so. For example: “Completed a guided sign-in monitoring lab, then added a separate scenario and documented how its event pattern differed.” Name your extension only if you built it. A course completion badge alone doesn't establish that you can investigate independently.
You don't need to fill every possible section. Add a certification if you've earned one, and remove the education example if it doesn't describe your background. A self-taught applicant can lead with substantial projects and relevant training without inventing a degree.
For the portfolio, include the problem, environment, your contribution and what the results do and don't establish. Use test data you can share. Don't publish workplace logs, account identifiers or internal screenshots to make a project look more convincing.
IT support to SOC analyst resume example
Keep your real job title and describe the security-related work within it. Access administration, careful escalation and troubleshooting can be relevant without calling a support role a SOC role.
Sample resume: support professional moving into security
Sam Patel
City, country | Your email | Your phone | Your professional profile
Summary
IT support analyst with two years of experience handling account access, endpoint issues and ticket escalation. Investigates reported issues within support procedures and prepares clear handoffs to specialist teams. Developing security monitoring skills through a separate home lab.
Experience
IT support analyst | Example Services | September 2024–present
- Processed approved joiner and leaver requests in Microsoft Entra ID, recording the authorizing request and escalating access exceptions to the identity team.
- Gathered message details and user-reported symptoms for suspected phishing tickets, then escalated them through the security team's reporting process.
- Rewrote an endpoint troubleshooting guide to include required diagnostic information before escalation; the support lead adopted it for the team knowledge base.
Projects
Security monitoring lab | Independent project | May–August 2026
- Used a test log dataset in Microsoft Sentinel to write and review queries for repeated sign-in failures.
- Documented a benign explanation for one alert pattern and the additional evidence needed before treating it as suspicious.
Skills
At work: Microsoft Entra ID account administration, ticket documentation, Windows troubleshooting and escalation.
In a lab: Microsoft Sentinel queries and sign-in event analysis.
Education and training
Diploma in Information Technology | Example College | Completed 2024
List any additional relevant course or earned certification with its real completion date.
Why the distinction matters
This applicant describes gathering evidence and escalating a suspected phishing report. They don't claim they contained an incident or decided whether the message was malicious unless that was their responsibility.
Separating workplace and lab skills also makes the summary easier to defend. Someone who has queried a small test dataset can explain that useful experience without implying they've operated a production SIEM.
If you're already a SOC analyst, lead with that work instead. A suitable fictional bullet might be: “Investigated an endpoint alert by correlating process activity with sign-in events, recorded the evidence for escalation, and handed the case to the incident lead under the response procedure.” Replace it with your actual scope, tools and decisions. Only claim containment or remediation actions you performed or directly coordinated.
GRC career-change resume example
Cyber GRC applications benefit from evidence of organized assessment work: understanding a requirement, collecting relevant records, identifying exceptions and following them through to an owner. Keep the difference between administrative support, control testing and decision-making clear.
Sample resume: operations and audit background
Jordan Lee
City, country | Your email | Your phone | Your portfolio link
Summary
Operations coordinator moving into cyber GRC after supporting supplier reviews and internal audit preparation. Experienced in tracking evidence requests, documenting exceptions and following up with control owners. Built a sample access-review assessment to develop security-specific assessment skills.
Experience
Operations coordinator | Example Logistics | March 2023–present
- Maintained an evidence-request register for an internal audit, tracking the requested period, document owner and review status.
- Identified missing approvals in a sample of supplier onboarding records and referred the exceptions to the procurement manager for review.
- Coordinated follow-up on outstanding actions and retained the closure evidence for the audit lead's assessment.
Projects
Access-review assessment | Independent exercise using fictional data | July 2026
- Defined a sample control requiring managers to review access to a fictional business application each quarter.
- Compared a fictional user-access list with review records and documented missing reviews separately from confirmed access exceptions.
- Wrote a short finding with the condition, supporting evidence, potential consequence and proposed follow-up; left risk acceptance to the designated owner in the scenario.
Skills
Evidence tracking, spreadsheet analysis, exception documentation, stakeholder follow-up and access-control concepts. Specify the frameworks and assessment tools you've used, with their context.
Education and training
Bachelor of Business | Example University | Completed 2022
Add relevant security or risk training you've completed, keeping it separate from certifications you hold.
What makes this a cyber GRC application
The employment bullets establish transferable work. The access-review exercise adds a security-specific example. Neither says the applicant led an external audit, certified an organization or accepted business risk.
Describe the assessment basis precisely when you have relevant experience. “Collected access-review evidence for the audit team” and “tested the access-review control against the agreed procedure” describe different contributions. Choose the one you performed.
You can build a more substantial example using the project in our guide to becoming a GRC analyst. Keep invented organizations and records clearly labeled in your portfolio too.
Write bullet points that show your contribution
A useful starting structure is action + scope + output or supported result. Add the tool when it helps explain the work. Harvard's resume guidance recommends specific, active and fact-based language, including quantities and qualifications where possible.
These rewrites are fictional examples. Use the reasoning, not the achievements.
Replace a tool list with work
Before: “Used Splunk and Python.”
After: “Wrote a Python script to standardize timestamps in a test dataset, then used Splunk searches to compare the event sequence across two sources.”
The rewrite explains the task and the relationship between the tools. Be ready to describe how you checked that the timestamps were interpreted correctly.
Use a concrete output when you have no impact metric
Before: “Improved incident response.”
After: “Updated the escalation checklist to include the affected host, observed activity and checks already completed; the shift lead approved it for team use.”
An adopted checklist is an outcome. You don't need to invent a percentage reduction in response time. If the checklist was only proposed, use “proposed” and remove the adoption claim.
Separate team results from your part
Before: “Reduced the vulnerability backlog by 40%.”
After: “Coordinated owner follow-up and retest evidence during a team remediation project that reduced the tracked overdue findings from 50 to 30 over one quarter.”
The second version still needs records supporting the figures and a consistent definition of “overdue.” It makes the applicant's contribution clear without claiming they personally remediated every finding. If you can't verify the numbers or share them, describe the scope and work instead.
Keep a private evidence note for each strong bullet: what happened, your role, how you know the outcome, and what you can discuss. Respect confidentiality. You can describe an assessment method or your decision process without exposing a client's identity or internal weaknesses.
Tailor the resume to a specific job
Read the duties and required qualifications before editing your summary. NIST's NICE Framework distinguishes tasks from the knowledge and skills needed to perform them. That is a useful way to assess a vacancy: identify the work, then find evidence that you can do it.
Make a small worksheet like this. These requirements are illustrative, not a quotation from a live vacancy.
| Job asks for | Evidence you could use | Where it belongs |
|---|---|---|
| Investigate and escalate security alerts | A workplace case within your responsibility, or a clearly labeled lab investigation | Experience or projects |
| Coordinate audit evidence | Requests tracked, exceptions documented and evidence submitted for review | Experience |
| Communicate with technical and business teams | A handoff, finding or explanation written for a specific audience | A bullet alongside the relevant task |
Use the employer's terminology when it accurately describes your experience. Spell out an unfamiliar abbreviation on first use, such as security information and event management (SIEM). Don't add a tool because it appears in the advert if you've never used it.
A missing requirement is a gap to assess. If a role requires production incident response and you have only lab work, the lab doesn't become production experience through a rewrite. You can still decide whether to apply, but make that decision with the gap visible.
Compare the requirements in SOC analyst jobs or GRC analyst jobs, then choose one suitable vacancy to tailor against. Read the employer's full requirements, including location and experience, before investing time in the application.
List skills and certifications accurately
Keep the skills section short enough that you can explain every item. Group related skills and connect important ones to a project or work bullet. “Python: parsed and normalized test log files” communicates more than a self-assigned proficiency bar.
List an earned certification by its official name, issuer and relevant date. Put ongoing study under training and describe its status honestly. An exam you hope to take is not an earned credential.
ISC2 makes an explicit distinction: Associates of ISC2 are not certified and may only use the Associate of ISC2 designation under its member policies. Don't describe that status as being CISSP-certified. Check the issuer's current wording whenever you're unsure how to represent a credential.
Use a readable format and a copyable structure
We recommend a straightforward single-column document with ordinary section headings. Put your contact details in the body of the document and use text that can be selected and copied.
Greenhouse documents parsing problems with image resumes, complex tables, columns, and contact details placed in headers, footers or text boxes. That supports keeping the layout simple. It doesn't establish a universal ATS score or mean that every parsing problem automatically rejects an application.
Copy this structure into your document editor and replace the bracketed text:
[Your name]
[City and country] | [Email] | [Phone] | [Relevant profile or portfolio]
Summary
[Your background and target work, supported by one or two specific strengths.]
Experience
[Actual job title] | [Employer] | [Month/year–month/year]
- [Action, scope and supported output or result.]
- [Another relevant contribution you can explain.]
Projects
[Project name] | [Independent, course, volunteer or other accurate context] | [Dates]
- [What you did, what you produced and any relevant limitation.]
Skills
[Relevant skills, with context where needed.]
Education and certifications
[Qualification, institution or issuer, completion date and accurate status.]
Move projects above experience if they are more relevant. Keep entries within a section in reverse chronological order. Remove unused sections and all placeholders before submitting.
For an early-career private-sector application, start with one page and use a second when relevant experience needs the space. That's an editing recommendation, not a universal rule. Follow the employer's file type, length and application instructions.
US federal applications have specific requirements. USAJOBS currently limits resumes to two pages and asks for details such as the month and year of employment and hours worked per week. Read the announcement and current instructions rather than reusing an older long federal resume.
Check the resume before sending it
Open the exported file, not just the editable document. Copy its text into a plain-text editor and check the reading order. This catches obvious problems; it doesn't reproduce every employer's screening system.
- Check that your contact details and portfolio links work.
- Make the distinction between paid work, projects and training visible.
- Verify dates, certification status, numbers and your role in shared outcomes.
- Remove client information, confidential records and unsupported claims.
- Compare the finished resume with the vacancy's required qualifications.
- Read each bullet aloud and practice explaining one concrete example behind it.
For a SOC application, use our interview questions and sample answers to practice that explanation. Keep a master record of your work, then return to it for each application so your next resume starts with evidence you already trust.


