Back to all articles
Resume WritingCareer AdviceJob SearchCybersecurityExamples

Cybersecurity Analyst Resume: Examples & Skills to Include (2026)

Write a cybersecurity resume that lands interviews. Resume examples, technical skills tables, certification guidance, and bullet point formulas for SOC analysts, pen testers, security engineers, and GRC roles.

Cybersecurity Analyst Resume: Examples & Skills to Include (2026)

The cybersecurity talent gap is staggering. According to ISC2's 2024 Cybersecurity Workforce Study, there are roughly 3.5 million unfilled cybersecurity positions worldwide, a number that has grown year over year for over a decade. Organisations are desperate for qualified security professionals, and the demand shows no sign of slowing down.

But here's the catch: a talent shortage does not mean employers are lowering the bar. In security, a bad hire doesn't just waste a salary. It can lead to a data breach costing millions, regulatory penalties, and irreparable reputation damage. Hiring managers in cybersecurity are, if anything, more selective than those in other tech fields. They need to trust that you can actually defend their infrastructure, not just list tools on a page.

The result? Your resume carries enormous weight. It needs to demonstrate technical depth, real-world incident experience, and a clear understanding of the threat landscape. Most cybersecurity resumes I review list certifications and tools without ever answering the critical question: what did you actually protect, detect, or prevent?

This guide shows you how to write a cybersecurity resume that answers that question convincingly. I'll walk through real examples, a bullet point formula that works across security roles, and the specific details that separate candidates who get interviews from those who get filtered out.


What Security Hiring Managers Look For

Before you write a single word, it helps to understand how your resume will be evaluated. Cybersecurity hiring differs from general IT hiring in several important ways.

1. Demonstrated Incident Experience

Theory matters far less than practice in security. Hiring managers want to see evidence that you have handled real incidents: phishing campaigns, malware outbreaks, insider threats, ransomware attempts. They want to know what you detected, how you responded, and what the outcome was. A candidate who has triaged 200 alerts per day in a SOC is infinitely more credible than one who simply lists "incident response" as a skill.

2. Defence in Depth Thinking

Strong candidates show an understanding of layered security, not just individual tools. Mentioning that you configured a WAF is fine. Mentioning that you designed a defence-in-depth strategy spanning network segmentation, endpoint detection, SIEM correlation rules, and user awareness training tells a much more compelling story. Hiring managers look for evidence that you think in systems, not silos.

3. Measurable Risk Reduction

Security is fundamentally about reducing risk, and the best resumes quantify that. Did you reduce mean time to detect (MTTD) by 60%? Cut false positive rates from 40% to 12%? Achieve a 98% compliance audit score? These numbers give hiring managers confidence that your work had a real impact. Without metrics, your claims are indistinguishable from any other applicant's.

4. Certifications That Match Your Level

Unlike many tech fields, cybersecurity places significant weight on certifications. But the specific certs matter. A SOC analyst listing CISSP looks odd (that's a management-level cert). A senior security architect without CISSP raises questions. Hiring managers look for certifications that are appropriate for your experience level and target role. More on this in the certifications section below.

5. Communication and Documentation Skills

Security professionals need to write incident reports, present risk assessments to executives, and create security policies that non-technical staff can follow. Any evidence of this on your resume (briefing leadership, authoring runbooks, training staff) signals maturity that hiring managers actively seek.


Real Example: Cybersecurity Analyst Resume

Let's look at a real cybersecurity resume that demonstrates what works for mid-level security roles.

What Makes This Resume Work

Grace's resume works because it leads with incident scale and measurable outcomes. At Salesforce, she handled "50+ critical security incidents" and "reduced average resolution time by 25%." These are the numbers security hiring managers care about: how many incidents, how fast, how much risk was reduced.

The skills section is organized into four categories that mirror how SOC teams operate: Security Tools (Splunk, QRadar, CrowdStrike), Threat Intelligence (SIEM, EDR, MITRE ATT&CK), Incident Response (forensics, handling), and Programming (Python, Bash). This tells a hiring manager exactly where Grace fits in their team structure.

Her education is a strong differentiator: a Master's in Cybersecurity from UC Berkeley with a capstone on AI-driven anomaly detection. For mid-level roles, this combination of academic depth and hands-on incident experience is compelling.

Section-by-Section Breakdown

Here is what Grace's resume contains, drawn from the real template above.

Experience

Her Salesforce role demonstrates leadership and technical depth:

SALESFORCE (Senior Cyber Security Analyst, 2021 - Present)
- Led incident response efforts for over 50 critical security
  incidents, reducing average resolution time by 25% for
  high-severity alerts
- Developed and implemented automated threat hunting playbooks
  using Python, improving early detection capabilities by 30%
  for persistent threats
- Managed vulnerability management program across 1,000+
  production servers

Every bullet follows the pattern: Action + Scale + Security Outcome. No vague claims about "enhancing security posture."

Skills

Four clean categories: Security Tools (Splunk ES, QRadar, Wireshark, Nmap, Nessus, CrowdStrike Falcon, Palo Alto Firewalls), Threat Intelligence (SIEM Monitoring, EDR, IDS/IPS, Malware Analysis, MITRE ATT&CK), Incident Response, and Programming. This is the format ATS systems parse most reliably.

Education

MS in Cybersecurity from UC Berkeley with a capstone on AI-driven anomaly detection achieving 95% accuracy. For security roles, demonstrating research capability alongside operational skills sets you apart.

If you want to use this as your starting point, hit "Remix with AI" on the template above.


Professional Summary Examples

Your summary is the first thing a human reader sees after your name. It needs to communicate your level, specialisation, and value proposition in 3-4 sentences. For more examples across different fields, see our resume summary examples guide.

Entry-Level / SOC Analyst (0-2 Years)

Security-focused IT professional with a BSc in Cybersecurity and CompTIA Security+ certification. Completed a 6-month SOC analyst internship at [Company] where I triaged 150+ daily alerts in Microsoft Sentinel, escalating confirmed threats with a 96% accuracy rate. Hands-on experience with Wireshark, Nessus, and Python scripting for log analysis. Eager to contribute to a security operations team protecting critical infrastructure.

Mid-Level Security Engineer (3-5 Years)

Cybersecurity engineer with 4 years of experience designing and implementing security architectures across cloud and on-premises environments. At [Company], led a zero-trust network migration that reduced the attack surface by 40% across 3,000 endpoints. Proficient in AWS security services, Palo Alto firewalls, and SIEM platform administration. CEH and AWS Security Specialty certified, with a track record of reducing vulnerability exposure windows from 30 days to under 7 days.

Senior / CISO-Track (6+ Years)

Senior cybersecurity leader with 9 years of experience spanning incident response, security architecture, and governance across regulated industries. As Head of Security at [Company], built and managed an 8-person security team that achieved SOC 2 Type II certification in 10 months and maintained zero critical breaches over 3 years. CISSP and CISM certified. Experienced in presenting risk assessments to board-level stakeholders and aligning security investment with business objectives. Published speaker on threat intelligence automation at BSides and SANS conferences.


Experience Bullets: The Cybersecurity Achievement Formula

This is where most cybersecurity resumes fall flat. Candidates list responsibilities and tools without ever answering the critical question: what did you protect, detect, or prevent?

The Formula

Use this structure for every bullet point:

Action verb + [What you secured, detected, or built] + [Technical approach/tools] + [Measurable outcome]

This formula forces you to connect your technical work to a tangible security outcome. Here are examples across different cybersecurity domains.

Incident Response

Contained a ransomware incident affecting 45 workstations within 90 minutes by isolating compromised segments via CrowdStrike network containment and executing pre-built response playbooks, preventing lateral movement to production servers holding 2.3M customer records.

Led incident response for 12 confirmed security events over 18 months, achieving a mean time to contain (MTTC) of 35 minutes, well below the 60-minute SLA, and producing post-incident reports that informed 8 new detection rules.

Vulnerability Assessments

Conducted quarterly vulnerability assessments across 2,500 endpoints using Rapid7 InsightVM, identifying and prioritising 3,200 findings by CVSS score, and driving remediation that reduced critical vulnerabilities by 87% within 30 days.

Designed a risk-based vulnerability management programme that replaced scan-and-fix with continuous monitoring, decreasing the average remediation window from 28 days to 6 days and achieving a 96% SLA compliance rate.

SIEM Management and Threat Detection

Engineered 40+ custom Splunk correlation rules mapped to MITRE ATT&CK techniques, improving detection coverage from 35% to 78% across the kill chain and reducing mean time to detect (MTTD) from 42 minutes to 9 minutes.

Integrated 6 threat intelligence feeds into Microsoft Sentinel, enriching alert context and reducing analyst investigation time per alert by 30%, equivalent to saving 15 hours of SOC analyst time per week.

Penetration Testing

Performed internal and external penetration tests across 4 business units, identifying 18 critical and 47 high-severity vulnerabilities including a privilege escalation path from guest Wi-Fi to the domain controller, and delivered executive-level risk briefings that secured £120K in remediation funding.

Conducted web application security assessments for 12 customer-facing platforms using Burp Suite and custom Python scripts, discovering and responsibly disclosing 6 OWASP Top 10 vulnerabilities before production release.

Compliance and Audits

Coordinated the organisation's first SOC 2 Type II audit, managing evidence collection across 14 control domains and 6 departments, achieving certification with zero critical findings and 2 minor observations.

Led GDPR compliance remediation for a data processing operation handling 4M EU resident records, implementing data mapping, consent management, and breach notification workflows that passed regulatory review without corrective action.

Security Architecture

Designed and implemented a zero-trust network architecture for a 3,000-user enterprise, deploying micro-segmentation via VMware NSX and identity-aware proxies, reducing the blast radius of potential breaches by an estimated 65%.

Migrated legacy VPN infrastructure to a SASE platform (Zscaler), improving remote worker security posture scores by 40% while reducing network latency by 25% and cutting annual infrastructure costs by £85K.

Threat Hunting

Proactively hunted for advanced persistent threats across 10TB of endpoint and network telemetry using Elastic SIEM and YARA rules, identifying 3 previously undetected command-and-control beacons that had been active for an estimated 60 days.

Developed a weekly threat hunting programme using hypothesis-driven analysis mapped to MITRE ATT&CK, uncovering 14 confirmed threats over 12 months that had bypassed automated detection, and converting each finding into a new detection rule.

For more guidance on choosing the right verbs for your bullets, see our action verbs guide.


Technical Skills Table

Cybersecurity hiring managers and ATS systems both scan your skills section heavily. A categorised format works best because it shows breadth across security domains at a glance. Only list tools you can confidently discuss in a technical interview.

CategoryTools and Technologies
SIEM & MonitoringSplunk, Microsoft Sentinel, IBM QRadar, Elastic SIEM, LogRhythm, Wazuh
Firewalls & Network SecurityPalo Alto Networks, Fortinet FortiGate, Cisco ASA, pfSense, Checkpoint
IDS/IPSSnort, Suricata, Zeek (Bro), Cisco Firepower
Endpoint Detection & ResponseCrowdStrike Falcon, SentinelOne, Carbon Black, Microsoft Defender for Endpoint
Vulnerability ManagementNessus, Qualys, Rapid7 InsightVM, OpenVAS, Burp Suite
Cloud SecurityAWS (GuardDuty, Security Hub, IAM, CloudTrail), Azure (Defender for Cloud, Sentinel), GCP (Security Command Centre)
Scripting & AutomationPython, Bash, PowerShell, SOAR platforms (Splunk SOAR, Cortex XSOAR)
Forensics & Malware AnalysisVolatility, Autopsy, FTK, YARA, VirusTotal, Any.Run
Compliance FrameworksISO 27001, SOC 2, NIST CSF, NIST 800-53, CIS Controls, GDPR, PCI DSS, HIPAA
Threat IntelligenceMITRE ATT&CK, STIX/TAXII, AlienVault OTX, Recorded Future, VirusTotal
Identity & AccessActive Directory, Azure AD / Entra ID, Okta, CyberArk, MFA platforms

Must-Have Skills by Experience Level

Skill AreaJunior (0-2 years)Mid-Level (3-5 years)Senior (6+ years)
SIEMLog review, basic queriesCustom correlation rules, tuningSIEM architecture, detection engineering
NetworkWireshark, basic firewall rulesFirewall policy design, IDS tuningNetwork architecture, micro-segmentation
EndpointEDR alert triageEDR deployment and tuningEndpoint strategy, MDR evaluation
CloudBasic IAM, security groupsGuardDuty/Defender, cloud SIEMMulti-cloud security architecture
ScriptingBasic Python/BashAutomation scripts, API integrationsSOAR playbook development, tool building
ComplianceAwareness of frameworksAudit evidence preparationProgramme ownership, framework selection
Incident ResponseAlert triage, escalationContainment, forensic analysisIR programme design, tabletop exercises

For more guidance on structuring your skills section effectively, see our resume skills guide.


Certifications That Actually Matter

Certifications carry more weight in cybersecurity than in almost any other tech field. Many job postings list them as hard requirements, especially in government and defence contracting. But the specific certifications you list should match your experience level and target role. For a broader look at how to present certifications, see our guide on how to list certifications on your resume.

Certification Breakdown by Level

CertificationBest ForPrerequisitesTypical Salary Impact
CompTIA Security+ (SY0-701)Entry-level, career changersNone (2+ years recommended)Baseline for most security roles
Certified Ethical Hacker (CEH)SOC analysts, aspiring pen testersNone (2 years experience recommended)Validates offensive security fundamentals
CISSPSenior analysts, managers, architects5 years in 2+ CISSP domainsOften required for senior and leadership roles
CISMSecurity managers, GRC leads5 years in information security managementGovernance and management focus
OSCPPenetration testers, red teamersStrong technical skills requiredGold standard for hands-on offensive security
AWS Security SpecialtyCloud security engineersAWS experience, Associate-level cert recommendedHigh demand as cloud adoption grows
GIAC Certifications (GSEC, GCIH, GPEN)Varies by specific certNone (SANS training recommended)Highly respected in enterprise environments

Certification Placement Tips

Weak: Burying certifications at the bottom of a two-page resume where they may not be seen.

Strong: Listing certifications in a dedicated section immediately after Technical Skills, or including key certs in your professional summary when they are specifically required by the job posting.

If you hold certifications that are in progress, list them as "expected [month/year]" rather than omitting them entirely. A candidate actively pursuing CISSP signals ambition and commitment, even before passing.

Certifications vs. Experience

A common question: should you prioritise getting certified or gaining hands-on experience? The honest answer is both, but experience wins if you have to choose. A Security+ holder with a home lab, CTF competition results, and an internship will outperform a candidate with three certifications and no practical experience. Certifications open doors. Experience keeps you in the room.


Cybersecurity Resume by Role

Cybersecurity is not a single role. The skills, tools, and metrics that matter vary significantly depending on whether you are in a defensive operations role, an offensive testing role, or a governance position. Here is how to tailor your resume for each.

SOC Analyst

SOC analysts are the front line of defence. Your resume should emphasise speed, accuracy, and volume of alert handling.

Key metrics to include:

  • Daily alert volume triaged (e.g., "triaged 400+ daily alerts")
  • False positive reduction percentages
  • Mean time to detect (MTTD) and mean time to respond (MTTR)
  • Number of incidents escalated and confirmed true positives
  • Playbooks authored or improved

Weak: Monitored security alerts and escalated incidents to senior analysts.

Strong: Triaged 400+ daily SIEM alerts across Splunk and Microsoft Sentinel, reducing false positive escalations by 38% through custom correlation tuning and achieving a mean time to escalate of 7 minutes for confirmed threats.

Tools to highlight: Splunk, Microsoft Sentinel, QRadar, CrowdStrike, Wireshark, SOAR platforms.

Recommended certifications: CompTIA Security+, CompTIA CySA+, GIAC GSEC.

Penetration Tester

Pen testing resumes should showcase your ability to find vulnerabilities that others miss and communicate risk clearly.

Key metrics to include:

  • Number of engagements completed (internal, external, web app, social engineering)
  • Critical/high findings per engagement
  • Unique attack paths discovered
  • Remediation verification results
  • Reports delivered and executive briefings conducted

Weak: Performed penetration tests and wrote reports on findings.

Strong: Executed 24 penetration testing engagements across external network, web application, and social engineering vectors over 12 months, identifying an average of 4 critical and 11 high-severity findings per engagement, and delivering executive risk briefings that secured remediation funding in 100% of cases.

Tools to highlight: Burp Suite, Metasploit, Nmap, Cobalt Strike, BloodHound, Kali Linux, custom Python/Bash scripts.

Recommended certifications: OSCP (gold standard), CEH, GIAC GPEN, CREST CRT/CCT.

Security Engineer

Security engineers build and maintain the systems that protect organisations. Your resume should show architecture decisions, automation, and measurable improvements to security posture.

Key metrics to include:

  • Infrastructure protected (endpoints, users, cloud workloads)
  • Reduction in attack surface (percentage or absolute)
  • Automation achievements (hours saved, manual processes eliminated)
  • Uptime and availability of security systems
  • Cost savings from platform consolidation or tool migration

Weak: Managed firewall rules and security tools for the organisation.

Strong: Designed and deployed a zero-trust network architecture spanning 4,500 endpoints and 3 cloud environments, implementing micro-segmentation and identity-aware access policies that reduced the exploitable attack surface by 52% and eliminated 3 legacy VPN concentrators, saving £95K annually.

Tools to highlight: Palo Alto, Fortinet, Zscaler, Terraform, Ansible, AWS/Azure security services, Kubernetes security.

Recommended certifications: CISSP, AWS Security Specialty, Azure Security Engineer Associate, CCNP Security.

GRC / Compliance Analyst

Governance, Risk, and Compliance (GRC) roles require a different emphasis. Your resume should highlight frameworks, audit outcomes, and risk management rather than deep technical tool experience.

Key metrics to include:

  • Compliance audit scores and certification outcomes
  • Number of controls managed or gaps remediated
  • Risk register size and reduction trends
  • Policies authored or updated
  • Training programmes delivered and participation rates

Weak: Assisted with compliance activities and policy documentation.

Strong: Led the organisation's ISO 27001 certification programme across 6 departments, managing a 142-control assessment, remediating 31 identified gaps, and achieving certification on the first attempt with zero major non-conformities.

Tools to highlight: GRC platforms (ServiceNow GRC, OneTrust, Archer), risk assessment frameworks, audit management tools, policy management systems.

Recommended certifications: CISM, CISA, CRISC, ISO 27001 Lead Auditor, CISSP.

For more role-specific guidance on tech resumes in general, see our guide on CVs for tech applications.


Entry-Level and Career Changers Breaking into Cybersecurity

Cybersecurity is one of the most accessible tech fields for career changers, precisely because the talent gap is so severe. But you still need to present a compelling case on your resume. Here is how.

Transferable Skills That Hiring Managers Value

You may already have relevant experience without realising it. These backgrounds translate well:

  • IT support / helpdesk: You understand endpoints, Active Directory, and user behaviour. Emphasise troubleshooting, access management, and any security-adjacent tasks.
  • Software development: You understand code, APIs, and application architecture. Emphasise secure coding practices, code review, and any experience with SAST/DAST tools.
  • Network administration: You understand infrastructure, routing, and firewall basics. Emphasise network monitoring, access control lists, and segmentation.
  • Military / law enforcement: You understand threat analysis, procedures under pressure, and classified information handling. Emphasise analytical thinking, incident handling, and clearance levels.
  • Compliance / audit (non-IT): You understand frameworks, evidence collection, and risk assessment. Emphasise transferable governance skills and any familiarity with security standards.

Building Your Security Resume Without Professional Experience

If you are transitioning into cybersecurity, your resume needs to show practical capability even without professional security titles. Here is what to include.

Home lab projects. Build a virtualised security lab using tools like Security Onion, Wazuh, or Splunk Free. Document what you built, what attacks you simulated, and what you detected. This demonstrates initiative and hands-on skills.

CTF competitions and platforms. Mention platforms like TryHackMe, HackTheBox, or PicoCTF. List specific achievements: "Completed 45 TryHackMe rooms including the SOC Level 1 learning path" is far more credible than "familiar with security concepts."

Open-source contributions. Contributions to security tools, detection rules, or documentation show both technical ability and community engagement.

CompTIA Security+ certification. This is the single most impactful step for career changers. It is the baseline certification that most employers require for entry-level security roles, and it demonstrates foundational knowledge across the field.

Entry-Level Summary Example

Career-changing IT professional with 3 years of helpdesk experience and a CompTIA Security+ certification, transitioning into cybersecurity operations. Built a home lab SOC environment using Security Onion and Wazuh, simulating and detecting 20+ MITRE ATT&CK techniques. Completed the TryHackMe SOC Level 1 and Cyber Defence learning paths. Strong foundation in Active Directory administration, endpoint troubleshooting, and user access management from supporting 500+ users in an enterprise environment.

Common Mistakes Career Changers Make

Weak: Listing your entire IT career history without connecting it to security.

Strong: Reframing existing experience through a security lens. Instead of "managed user accounts in Active Directory," write "administered Active Directory for 500+ users, enforcing group policy security baselines and investigating 12 account compromise incidents."

The key is showing that you already think about security, even if your title did not include the word.


Common Mistakes on Cybersecurity Resumes

After reviewing hundreds of security resumes, these are the mistakes I see most often. Avoiding them puts you ahead of most applicants.

1. Listing Every Tool You Have Ever Touched

Including 40+ tools on your resume is not impressive. It is suspicious. Hiring managers know that nobody is proficient in every SIEM, every EDR platform, and every cloud security service. Curate your list to the tools you can discuss confidently in a technical interview. Quality over quantity.

Weak: Splunk, QRadar, Sentinel, LogRhythm, Elastic, Wazuh, Graylog, ArcSight, Sumo Logic, Exabeam, Securonix...

Strong: Splunk (primary, 3 years including SPL query development and correlation rule engineering), Microsoft Sentinel (1 year, cloud-native SOC deployment), Elastic SIEM (home lab for threat hunting exercises).

2. Ignoring the ATS Entirely

Many cybersecurity job postings include specific keywords that ATS systems scan for. If the posting mentions "NIST 800-53" and your resume says "NIST framework" without specifying which one, you may be filtered out before a human ever sees your application. Mirror the exact terminology from the job description. For a deep dive on this, see our ATS-friendly resume guide.

3. Vague Incident Response Claims

"Responded to security incidents" is the cybersecurity equivalent of "responsible for things." Every security professional responds to incidents. What matters is the specifics: what type of incident, how many, what tools you used, how quickly you contained it, and what the outcome was.

4. Certifications Without Context

Listing "CISSP" on a resume with 2 years of experience raises more questions than it answers. If you have certifications above your current experience level, provide context for how you earned them and how you apply that knowledge. Conversely, if you are senior without industry-standard certs, address it proactively in your summary or be prepared for the question in interviews.

5. No Evidence of Staying Current

Cybersecurity evolves faster than almost any other field. If your resume only references tools and techniques from 5 years ago with no evidence of recent learning, it signals stagnation. Mention recent training, conference attendance, CTF participation, or adoption of newer tools and frameworks.

6. Neglecting Soft Skills Entirely

Security is a team sport. Incident response requires coordination. Vulnerability management requires persuading developers to prioritise fixes. Compliance requires working with legal and business units. If your resume reads like a purely technical document with no evidence of communication, collaboration, or leadership, you are missing a dimension that hiring managers actively seek.

7. Using a Generic Resume for Every Application

A SOC analyst role and a penetration testing role require fundamentally different skill emphasis, even though both fall under "cybersecurity." Tailoring your resume to each specific role is not optional. It is the single highest-impact change you can make. JobSprout can help you tailor your resume to specific job descriptions quickly, ensuring that the right skills and experience are emphasised for each application.


Formatting and ATS Tips for Security Resumes

A few formatting considerations specific to cybersecurity resumes.

Use a clean, single-column layout. Security clearance roles and government positions often use older ATS systems that struggle with multi-column designs, graphics, and unusual formatting. Keep it simple.

Put certifications near the top. Many security job postings list certifications as hard requirements. If a recruiter is scanning for "CISSP" or "Security+," make it easy to find. A dedicated certifications section after your skills section works well.

Include a link to your GitHub or blog. Security professionals who share tools, write-ups, or detection rules publicly demonstrate expertise and community engagement. If you have a security-focused GitHub repository, a blog covering CTF walkthroughs, or contributions to open-source security tools, link to them prominently.

Match the job description terminology exactly. If the posting says "CrowdStrike Falcon," write "CrowdStrike Falcon," not just "CrowdStrike." If it says "NIST 800-171," do not write "NIST framework." ATS keyword matching is often literal, and cybersecurity postings are unusually specific about tool names and framework versions.

For a comprehensive guide to getting past ATS systems, see our ATS-friendly resume guide.


Pulling It All Together

Cybersecurity is one of the few fields where demand genuinely outstrips supply. But that advantage only helps you if your resume clearly demonstrates what you can do. The candidates who stand out are the ones who show real incident experience, quantify their impact with security-specific metrics, present certifications that match their level, and tailor their content to the specific role they are targeting.

Use the examples and formula from this guide as your starting point. Focus on answering "what did I protect, detect, or prevent?" for every bullet point, and you will be ahead of the vast majority of applicants.