Information Technology
Cybersecurity Analyst Job Description
Cybersecurity Analysts monitor, detect, and respond to threats targeting an organization's networks, systems, and data. They triage security alerts, investigate incidents, run vulnerability scans, and implement controls that reduce risk, working inside security operations centers, embedded IT teams, or dedicated security functions at organizations of every size. The U.S. Bureau of Labor Statistics tracks the closest occupation, information security analysts, and puts 2025 median pay at $129,180. BLS projects much faster than average growth for the occupation, giving analysts steady work and a clear path toward senior, specialist, and leadership roles.
Last updated
Role at a glance
- Typical education
- Bachelor's degree in cybersecurity, computer science, or a related field is typical; certifications plus an associate degree or military training are accepted at many employers.
- Typical experience
- Entry-level SOC roles need 0 to 1 years; mid-level is 2 to 4 years; senior and lead roles expect 5 or more years.
- Key certifications
- CompTIA Security+, CompTIA CySA+, GIAC GCIH, GIAC GCIA, CISSP.
- Top employer types
- Healthcare systems, financial services, energy companies, government agencies, and managed security service providers.
- Growth outlook
- BLS projects 21% employment growth for information security analysts from 2025 to 2035, much faster than average, adding about 14,100 openings a year.
- AI impact (through 2030)
- AI is used on both sides: attackers scale phishing and malware creation, while analysts use AI to triage alert volume; ISC2's 2026 research finds this is also increasing the need for human oversight of AI output.
Duties and responsibilities
- Monitor SIEM dashboards and security alerts to identify suspicious activity, policy violations, and network intrusions
- Investigate security incidents by analyzing system logs, network traffic, endpoint data, and threat intelligence feeds
- Run vulnerability scans and work with IT teams to prioritize and track remediation of identified security gaps
- Review and triage phishing reports, malware detections, and unauthorized access alerts from users and tools
- Assess new systems, applications, and third-party vendor services for security risk before deployment or integration
- Tune SIEM rules, alert thresholds, and detection logic to cut false positives and improve signal quality
- Write and update incident response playbooks covering ransomware, phishing, and credential compromise attack scenarios in detail
- Collect evidence for SOC 2, ISO 27001, PCI DSS, and HIPAA audits and track remediation of audit findings
- Prepare security metrics reports for management covering incident volume, vulnerability status, and overall patching compliance levels
- Participate in tabletop exercises and red team or blue team drills to test incident response readiness
Overview
A Cybersecurity Analyst protects an organization's networks, systems, and data by watching for threats, investigating incidents, and closing the gaps attackers would otherwise use to get in. The role sits between the tools that generate alerts and the leadership that decides how to respond. NIST's Workforce Framework for Cybersecurity describes this work through defined work roles and tasks, and earlier editions grouped much of it under "Protect and Defend" and "Analyze" categories, which is a useful map of the job even at organizations that never mention the framework by name.
In a Security Operations Center, the daily rhythm is set by alerts. Firewalls, endpoint detection tools, email security filters, and cloud access logs generate a steady stream of events, and most of them are benign. A skilled analyst triages quickly, separating true positives that need investigation from false positives tied to well-understood activity. When an alert does warrant a closer look, the analyst pulls logs, reviews network traffic, checks the endpoint, and works through a structured process to determine whether an attack actually occurred and how far it reached.
Vulnerability management is the other major piece of the role. Analysts run regular scans of the organization's network and systems to find unpatched software, misconfigured services, and exposed credentials. The results need prioritization, since not everything can be fixed at once, and the analyst works with system owners and IT teams to get the highest-risk issues closed first.
Compliance support is also part of the job at many organizations. SOC 2, PCI DSS, HIPAA, and ISO 27001 audits all require security evidence: log retention records, access control reviews, vulnerability scan results, and incident documentation. Analysts who understand what auditors need and can pull that evidence quickly save their organizations real audit-preparation time.
The most demanding part of the job is threat hunting: proactively and continuously searching for attacker activity that has already slipped past automated detection tools. That means thinking like an attacker: knowing which MITRE ATT&CK techniques show up most often in the wild, identifying the data sources that would carry evidence of those techniques, and building queries that surface anomalies in that data. Analysts who build threat hunting skill get access to some of the most technical roles in the field, and many now work alongside AI-assisted tooling, reviewing and correcting what an AI-assisted query surfaces rather than building every query from scratch.
Qualifications
Employers hiring for this role look at a mix of formal education, industry certifications, and hands-on technical skill, and few candidates arrive with all three fully built out. Certifications tend to carry the most weight early in a career, since they signal specific, verifiable knowledge that a resume alone cannot.
Education:
- Bachelor's degree in cybersecurity, computer science, information systems, or a related field is the most common path, matching BLS's stated typical entry-level education for information security analysts.
- An associate degree or military technical training plus certifications is accepted at many employers, especially for entry-level SOC roles.
- Relevant certifications can substitute for a degree in practice at many employers, particularly managed security service providers.
Certifications:
- CompTIA Security+: the industry baseline, approved for many DoD 8140 cyber workforce roles, and a strong starting point for any security career.
- CompTIA CySA+: built specifically for the analyst role, covering threat detection, incident response, and vulnerability management.
- GIAC GCIH (Incident Handler): well regarded by SOC teams for incident response depth.
- GIAC GCIA (Intrusion Analyst): valued for network-focused analyst roles.
- CISSP: the senior-level credential, typically expecting several years of experience, and often requested for senior and principal roles.
- CEH (Certified Ethical Hacker): common in government environments, though some security teams weight it less than the GIAC and CompTIA credentials above.
Technical skills:
- SIEM platforms: Splunk, Microsoft Sentinel, IBM QRadar, Elastic SIEM.
- Endpoint detection: CrowdStrike Falcon, Microsoft Defender for Endpoint, Carbon Black.
- Threat intelligence: the MITRE ATT&CK framework, indicator-of-compromise analysis, VirusTotal, OSINT techniques.
- Network analysis: Wireshark, Zeek, NetFlow analysis.
- Scripting: Python or PowerShell for alert triage automation and log analysis.
- Vulnerability management: Tenable Nessus, Qualys, Rapid7 InsightVM.
Experience path:
- Entry: SOC Tier 1, junior security analyst, or an IT help desk or sysadmin role with security responsibilities.
- Mid-level: two to four years of SOC experience with documented incident investigation and containment work.
- Senior: five or more years, moving into threat hunting, incident response leadership, or cloud security specialization.
Career changers coming from network administration, software development, or military IT roles can move through this path quickly, since they arrive with the underlying systems knowledge and only need to layer security-specific tools and certifications on top of it. Hiring managers at managed security service providers, in particular, often value demonstrated hands-on skill, such as a home lab or capture-the-flag record, alongside or in place of a specific degree.
Career outlook
Cybersecurity analyst work remains one of the stronger career bets in technology, though the growth numbers have cooled from the peak projections of a few years ago. The Bureau of Labor Statistics now projects employment of information security analysts, the closest tracked occupation, to grow 21 percent from 2025 to 2035, taking the field from about 192,900 jobs to roughly 233,400 and adding around 14,100 openings a year from growth and turnover combined. That is still much faster than the average for all occupations, even though it is a step down from the 29 to 33 percent figures BLS published in earlier projection cycles.
The underlying driver is straightforward: organizations run more systems, cloud services, and connected devices, and each one is something an attacker can target, from ransomware to supply chain attacks. Healthcare, financial services, and energy face regulatory requirements for security controls, which makes security work less discretionary than some other IT spending. Government agencies at the federal, state, and local level also hire security analysts, and benefits and pension value belong in any comparison of public and private sector offers.
AI is reshaping the role from both directions. ISC2's 2026 research on AI's impact on cybersecurity found that professionals already using AI tools see them changing workflows and decision-making across the field, alongside a growing need for human oversight of what those tools produce. On the attacker side, generative tools are being used to scale phishing campaigns and speed up malware variant creation. Analysts are well placed when they understand both halves of that dynamic: how AI-assisted attacks are built, and how AI-assisted detection can be tuned, and checked, well enough to catch them.
Career advancement from Cybersecurity Analyst runs in several directions. Senior Analyst and Threat Hunter roles bring more pay and technical depth. Incident Response Analyst and Digital Forensics Analyst are specialized paths that build deep investigative skill and often lead to consulting or leadership work. Security Engineering and Cloud Security roles push toward a more technical, less alert-driven track. For analysts with management interest, the path runs through SOC Manager and Security Manager toward CISO. At large organizations, the CISO role is a realistic outcome from an analyst starting point over a long career spent building both technical depth and people-management experience.
Sample cover letter
Dear Hiring Manager,
I'm applying for the Cybersecurity Analyst position at [Company]. I've spent two years as a Tier 1 and Tier 2 SOC analyst at a managed security service provider, monitoring and investigating alerts across roughly 30 client environments ranging from healthcare organizations to financial services firms.
The incident I found most technically interesting was a credential harvesting campaign targeting one of our healthcare clients. The initial alert was a login from an unfamiliar IP address, a pattern we see often and usually clear quickly as a VPN or travel scenario. What made this one different was that when I checked the user's activity over the prior three days, I found a series of off-hours logins with small, targeted file access that looked like reconnaissance rather than normal work. The IP had no history with the client and came back clean on our threat intel feeds, but the behavior pattern was wrong.
I escalated to our incident response team, and we found that the user's credentials had been harvested through a targeted phishing email two weeks earlier. The attacker had been running slow, low-volume reconnaissance specifically to avoid tripping our rate-based alerts. We contained the account and worked with the client to confirm what data had actually been accessed.
I work primarily in Splunk and Microsoft Sentinel and hold CompTIA Security+ and CySA+. I'm currently studying for the GIAC GCIH exam, and I've been using AI-assisted query tools in my current role while staying deliberate about verifying what they surface rather than taking the output at face value. I'm particularly interested in [Company]'s threat hunting program and would welcome the chance to discuss the role.
Thank you for your time.
[Your Name]
Frequently asked questions
- What does a Cybersecurity Analyst do?
- Cybersecurity Analysts monitor, detect, and respond to threats targeting an organization's networks, systems, and data. They triage security alerts, investigate incidents, run vulnerability scans, and implement controls that reduce risk, working inside security operations centers, embedded IT teams, or dedicated security functions at organizations of every size. The U.S. Bureau of Labor Statistics tracks the closest occupation, information security analysts, and puts 2025 median pay at $129,180. BLS projects much faster than average growth for the occupation, giving analysts steady work and a clear path toward senior, specialist, and leadership roles.
- What are the main duties of a Cybersecurity Analyst?
- Core duties include: monitor SIEM dashboards and security alerts to identify suspicious activity, policy violations, and network intrusions; investigate security incidents by analyzing system logs, network traffic, endpoint data, and threat intelligence feeds; and run vulnerability scans and work with IT teams to prioritize and track remediation of identified security gaps.
- What certifications are most valuable for a Cybersecurity Analyst?
- CompTIA Security+ is the standard entry-level credential and is approved for many roles under the DoD 8140 cyber workforce rules. CompTIA CySA+ is built specifically for the analyst role and covers detection and incident response in depth. CISSP is a common senior-level credential once an analyst has several years of experience, and GIAC's GCIH and GCIA carry particular weight for SOC and intrusion-analysis work.
- What does working in a Security Operations Center look like day to day?
- SOC analysts work shifts monitoring a continuous stream of alerts from SIEM platforms, endpoint detection tools, and network sensors. Tier 1 analysts triage incoming alerts and escalate anything that looks like a real threat, while Tier 2 analysts dig into escalated incidents across logs and endpoints. Junior SOC work involves real repetition, but the exposure to live attack patterns builds practical security skill.
- How technical does a Cybersecurity Analyst need to be?
- Moderately to highly technical depending on the role. Analysts need working knowledge of networking, operating system fundamentals such as Windows event logs and the Linux command line, and enough scripting to automate alert triage. Analysts moving into threat hunting or incident response also need malware analysis and memory forensics skills, organized around the shared vocabulary of the MITRE ATT&CK framework.
- How do you break into cybersecurity without direct experience?
- The most reliable path combines a certification such as Security+, hands-on lab practice, and a starting role in adjacent IT work like help desk or systems administration that exposes you to the infrastructure you would later secure. Capture-the-flag platforms such as TryHackMe and HackTheBox build practical skill that hiring managers notice. SOC analyst openings at managed security service providers are a common entry point for candidates with limited prior experience.
- How is AI changing the work of a Cybersecurity Analyst?
- ISC2's 2026 research on AI's impact on cybersecurity roles found that professionals already using AI tools see the technology reshaping workflows and decision-making, while increasing the need for human oversight of what those tools produce. Attackers are using the same generative tools to scale phishing and speed up malware development. Analysts who understand how an AI tool reached its conclusion, not just how to run it, are best placed to catch a wrong or manipulated result.
Sources
Salary figures and role details on this page were checked against the following sources. Dates show when each was last reviewed.
- Information Security Analysts, Occupational Outlook Handbook, U.S. Bureau of Labor Statistics (2025)Checked Sep 21, 2026
- Information Security Analysts, Occupational Employment and Wage Statistics, U.S. Bureau of Labor Statistics (May 2025)Checked Sep 21, 2026
- Workforce Framework for Cybersecurity (NICE Framework), NIST Special Publication 800-181r1Checked Sep 21, 2026
- ISC2 Research Finds AI Is Reshaping Cybersecurity Roles and Increasing Human Oversight, ISC2 (2026)Checked Sep 21, 2026
Related job descriptions
See all Information Technology jobs →- Cybersecurity Engineer$100K–$165K
Cybersecurity Engineers design, build, and maintain the technical systems that protect an organization's infrastructure and data. Unlike analysts who monitor and respond, engineers focus on constructing the defensive architecture—firewalls, identity systems, detection pipelines, encryption implementations, and security automation—that determines how exposed an organization is to attack in the first place.
- Cybersecurity Manager$120K–$185K
Cybersecurity Managers lead security teams and programs that protect an organization's systems, data, and infrastructure. They set strategy, manage staff, govern risk, and interface with executive leadership on security posture—translating technical risk into business terms while ensuring their teams have the tools, training, and direction to operate effectively.
- Cybersecurity Specialist$75K–$200K
Cybersecurity Specialists handle a broad slice of an organization's day-to-day security work: threat monitoring, incident response, vulnerability remediation, and access control, usually inside a lean team where nobody covers just one domain. The title is common in government, healthcare, and defense contracting, and its seniority varies by employer: some treat it as an entry point toward an analyst role, others use it for mid-to-senior practitioners holding Security+ or CISSP. AI tools now assist with routine triage, and ISC2 research shows most practitioners now spend more time deciding when to trust automated recommendations and validating their output.
- Grid Cybersecurity Engineer$105K–$175K
Grid Cybersecurity Engineers protect electric utility infrastructure — generation facilities, transmission substations, distribution control systems, and energy management systems — from cyber threats. They design and operate security controls that meet NERC CIP regulatory standards while keeping operational technology (OT) systems available and reliable. The role sits at the intersection of information security, industrial control systems engineering, and federal energy regulation.
- Information Security Analyst$75K–$200K
Information Security Analysts design, implement, and monitor the controls that protect an organization's networks, systems, and data from unauthorized access, breaches, and cyberattacks. They sit between IT operations and risk management, running vulnerability scans, investigating alerts, and translating technical findings into guidance for engineering teams and leadership. The U.S. Bureau of Labor Statistics projects the occupation to grow 21 percent from 2025 to 2035, far faster than average. Many security tools now include AI-assisted detection, and analysts are expected to validate automated alerts rather than accept them as given.
- SAP Security Consultant$75K–$200K
An SAP Security Consultant sets the access rules for every user in a company's SAP landscape. The job covers building PFCG roles, assigning them to users, catching segregation-of-duties conflicts, running emergency access, and handing auditors clean evidence that access matches job duties. Consultants work for SAP partners, audit and advisory firms, or inside the IT and internal controls teams of companies that run SAP ERP or S/4HANA. BLS does not track the title on its own; the closest occupation, information security analysts, paid a median of $129,180 in May 2025, with the 10th to 90th percentile running from $75,090 to $199,850.