Information Technology
Information Security Analyst Job Description
Information Security Analysts design, implement, and monitor the controls that protect an organization's networks, systems, and data from unauthorized access, breaches, and cyberattacks. They sit between IT operations and risk management, running vulnerability scans, investigating alerts, and translating technical findings into guidance for engineering teams and leadership. The U.S. Bureau of Labor Statistics projects the occupation to grow 21 percent from 2025 to 2035, far faster than average. Many security tools now include AI-assisted detection, and analysts are expected to validate automated alerts rather than accept them as given.
Last updated
Role at a glance
- Typical education
- Bachelor's degree in a computer science field is typical per BLS, though certifications plus network admin or help desk experience are a common entry path.
- Typical experience
- Entry-level (0-2 years) through mid-career; senior analyst and architect tracks generally expect 5+ years.
- Key certifications
- CompTIA Security+, CISSP, CEH, GIAC GSEC.
- Top employer types
- SOCs, enterprise IT, government and defense, cloud service providers, regulated industries such as finance and healthcare.
- Growth outlook
- 21% employment growth projected 2025-2035 (BLS), about 14,100 annual openings.
- AI impact (through 2030)
- ISC2's 2026 survey found 63% of AI-using professionals spend more time validating AI outputs and 89% have seen an AI recommendation produce a wrong result; respondents were split on whether AI is reducing or creating entry-level roles.
Duties and responsibilities
- Monitor SIEM and XDR alerts for indicators of compromise, triaging and escalating confirmed incidents according to documented runbook procedures.
- Run vulnerability scans with Tenable Nessus, Qualys, or Rapid7 and prioritize remediation with system owners using CVSS scoring.
- Hunt for attacker activity across endpoint, network, and cloud logs that automated detection rules and AI-assisted triage missed.
- Investigate phishing reports and malicious email campaigns, analyzing headers, attachments, and links to assess scope and containment.
- Develop and maintain security policies, standards, and procedures aligned to NIST CSF, ISO 27001, or CIS Controls frameworks.
- Coordinate penetration testing engagements with internal red teams or third-party vendors and track remediation of findings.
- Assess third-party vendor security posture through questionnaires, SOC 2 Type II reviews, and contractual security requirements.
- Support audit and compliance work for PCI DSS, HIPAA, SOX, or FedRAMP by gathering evidence and answering auditor questions.
- Tune endpoint detection and response tools, firewall rules, and cloud security group policies to shrink the attack surface.
- Write clear reports summarizing vulnerability findings, incident timelines, and risk recommendations for technical and executive audiences.
Overview
Information Security Analysts are responsible for making sure an organization's systems, data, and infrastructure don't get compromised, and for limiting damage when they do. The job is part detective work, part systems administration, part risk management, and part written communication. On a given day, the work might move from investigating a suspicious PowerShell process flagged by an EDR tool, to reviewing a vendor's SOC 2 report before a procurement decision, to writing a plain-language memo explaining a new phishing campaign to the help desk team.
In organizations large enough to run a security operations center, analysts typically start there: monitoring alerts, triaging events, and handling Tier 1 and Tier 2 incidents. The discipline built in that environment is foundational. It means learning to move fast without jumping to conclusions, telling a genuine compromise apart from a noisy detection rule, and documenting an incident timeline clearly enough that a forensics team can reconstruct what happened months later.
Vulnerability management is the other core responsibility that touches most analyst roles. That means running regular scans, interpreting the output, and then, the hard part, working with application owners and infrastructure teams to close findings on a timeline that reflects actual risk instead of IT backlog priorities. Analysts who can make that case persuasively get findings remediated. Analysts who just forward scan reports do not.
Compliance work runs parallel to the technical track in most enterprise environments. PCI DSS, HIPAA, SOX, and FedRAMP all require documented security controls, audit evidence, and periodic assessments. Analysts are typically the people who gather that evidence, respond to auditor questions, and identify gaps between the current state and what the framework requires.
NIST's Workforce Framework for Cybersecurity groups this work under the Protection and Defense category, which is a useful way to see how the job connects to the wider cybersecurity workforce: it sits between detection, incident response, and governance rather than owning any one of them exclusively.
The role demands a specific mindset: adversarial thinking paired with methodical documentation. The question is not just whether a control exists, it is whether an attacker who already has a foothold on one endpoint can use that control's gaps to move laterally, escalate privileges, and reach data that actually matters. Analysts who think that way, rather than checking compliance boxes, are the ones organizations trust to lead incident response when something serious happens. That also means knowing when to trust an AI-generated alert or recommendation and when to second-guess it.
Qualifications
Education
- A bachelor's degree in a computer science field is the typical path employers list, per the BLS Occupational Outlook Handbook, usually paired with related work experience.
- Many analysts arrive by way of network administration or help desk roles rather than a straight line from school.
- Candidates without a four-year degree do get hired, especially with a strong home lab, CTF history, or a SOC internship behind relevant certifications.
Certifications by career stage
- Entry level: CompTIA Security+, CompTIA CySA+, Google Cybersecurity Certificate
- Mid-career: CEH, GIAC GSEC, GCIA, GCIH, AWS Security Specialty, Microsoft SC-200
- Senior: CISSP, CISM, OSCP for analysts with offensive security duties, CISA for audit-facing roles
- Government and cleared roles: DoD 8570/8140 baseline requirements commonly include Security+ or CASP+, depending on the position level
Technical skills
- SIEM platforms: Splunk, Microsoft Sentinel, IBM QRadar, Elastic Security
- EDR tools: CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne
- Vulnerability management: Tenable Nessus, Qualys VMDR, Rapid7 InsightVM
- Network analysis: Wireshark, Zeek, Suricata, plus familiarity with packet capture and flow analysis
- Cloud security: AWS Security Hub, Microsoft Defender for Cloud, GCP Security Command Center
- Scripting: Python or PowerShell to automate repetitive analysis and reporting tasks
- Frameworks: NIST CSF, MITRE ATT&CK, CIS Controls, ISO 27001
Working with AI-assisted tools Many major SIEM and XDR platforms ship built-in AI triage and correlation features. Analysts are expected to know how to evaluate an AI-generated alert or recommendation rather than accept it automatically, since AI outputs can be wrong. The skill can come up in interviews as a direct question: walk me through a time an automated detection got it wrong and what you did next.
Soft skills that differentiate
- Writing a clear, concise incident report that a non-technical executive can act on
- Staying comfortable in ambiguous situations where the runbook does not have an answer
- Keeping attention on log detail without losing track of what the attacker was actually trying to do
- Pushing back, with evidence, when an automated system's output looks wrong
Career outlook
The Bureau of Labor Statistics projects employment of information security analysts to grow 21 percent from 2025 to 2035, far faster than the average for all occupations, with about 14,100 openings expected per year over the decade, most from workers leaving the field or retiring. Demand comes from the ongoing need to protect networks and data from cyberattacks, from data-protection rules, and from the security work that comes with moving systems to the cloud.
Skills matter as much as headcount. SANS Institute's 2026 Cybersecurity Workforce Research Report focuses on skills gaps within existing security teams, including the skills needed to handle AI-driven attacks and work with AI-assisted defense. Analysts who can already work alongside AI tooling start with an advantage over those who would need to learn it on the job.
ISC2's 2026 survey of working AI users in cybersecurity found respondents split on entry-level demand. More than half of respondents, 56 percent, said AI has reduced demand for entry-level positions, while 53 percent believe AI is creating new entry-level opportunities.
The specialization paths from this title are well established. Analysts who lean technical tend to move toward incident response, penetration testing, or detection engineering, writing the SIEM rules and EDR behavioral detections that the next generation of analysts will work from. Analysts who lean toward governance move into GRC, security architecture, or eventually CISO-track leadership. Both paths can lead toward the upper end of the salary range for people who keep their skills current.
Cloud security is a major specialization inside the field. The move of enterprise workloads to AWS, Azure, and GCP rewards analysts who understand on-premise security and can also assess IAM configurations, storage bucket policies, and container security posture. Building cloud-native security skills widens the range of roles an analyst can pursue, from cloud security engineering to security architecture for organizations that run workloads across more than one cloud provider.
AI is also changing the entry point to the field. Tier 1 functions such as alert triage and basic phishing analysis often run through automated playbooks, which puts more weight on analytical judgment in junior roles. Per ISC2, 89 percent of surveyed professionals have already seen an AI recommendation produce an incorrect outcome, which is why human validation of that output is an expected part of the job rather than an afterthought.
Sample cover letter
Dear Hiring Manager,
I'm applying for the Information Security Analyst position at [Company]. I've spent the past three years as a Tier 2 SOC analyst at [Company], where I handle escalated alerts from our Splunk environment, lead initial incident response on confirmed compromises, and own vulnerability management across roughly 2,400 endpoints.
The work I'm most proud of is detection tuning. When I joined, our Splunk instance was generating about 340 alerts per day, and the team spent the first two hours of every shift clearing obvious false positives. I spent six weeks building suppression logic for the highest-volume, low-fidelity rules and replacing them with behavioral detections mapped to the MITRE ATT&CK techniques we'd actually seen in our environment, mainly lateral movement and credential access. Alert volume dropped to under 80 per day, and the mean time to investigate a real event fell from 47 minutes to 19.
I hold CompTIA Security+ and CySA+, and I'm currently in the GCIH exam pipeline. I've also spent the past year reviewing Defender for Cloud findings and tuning conditional access policies as [Company] finished its move to Azure, including learning where our AI-assisted alert triage gets things wrong so I know when to override it rather than trust it by default.
Your posting mentioned this role supports PCI DSS scope for the card processing environment. That's an area I want to grow into. I've supported two QSA audits by gathering evidence, and I'm looking for a position where I help drive the compliance program rather than just feed it data.
I'd welcome the chance to talk through how my background fits what your team needs.
[Your Name]
Frequently asked questions
- What does an Information Security Analyst do?
- Information Security Analysts design, implement, and monitor the controls that protect an organization's networks, systems, and data from unauthorized access, breaches, and cyberattacks. They sit between IT operations and risk management, running vulnerability scans, investigating alerts, and translating technical findings into guidance for engineering teams and leadership. The U.S. Bureau of Labor Statistics projects the occupation to grow 21 percent from 2025 to 2035, far faster than average. Many security tools now include AI-assisted detection, and analysts are expected to validate automated alerts rather than accept them as given.
- What are the main duties of an Information Security Analyst?
- Core duties include: monitor SIEM and XDR alerts for indicators of compromise, triaging and escalating confirmed incidents according to documented runbook procedures; run vulnerability scans with Tenable Nessus, Qualys, or Rapid7 and prioritize remediation with system owners using CVSS scoring; and hunt for attacker activity across endpoint, network, and cloud logs that automated detection rules and AI-assisted triage missed.
- What certifications do employers expect from an Information Security Analyst?
- CompTIA Security+ remains the baseline many employers require, including DoD contractor roles under the 8570/8140 directives. Mid-career analysts typically add CEH, GIAC GSEC or GCIA, or CISSP, and cloud certifications like AWS Security Specialty or Microsoft SC-200 are common asks for cloud-focused roles.
- Is a four-year computer science degree required to break into the field?
- No. The BLS Occupational Outlook Handbook lists a bachelor's degree in a computer science field with related experience as typical, but also notes that candidates enter with a high school diploma plus relevant certifications and prior network administration experience. Hands-on skills often matter more to hiring managers than the degree itself.
- How does a SOC analyst role differ from a broader security analyst position?
- A SOC analyst role is a specific function: real-time alert monitoring, triage, and initial response, usually organized into Tier 1 through Tier 3 by complexity. NIST's NICE Framework groups this work under its Protection and Defense category, which also covers vulnerability analysis and incident response work that a broader analyst title often carries.
- How is AI changing day-to-day work for security analysts?
- ISC2's May 2026 survey of 856 cybersecurity professionals using AI found 63% now spend more time reviewing or validating AI-generated outputs, and 89% had seen an AI recommendation produce an incorrect outcome. Just over half, 56%, believe AI has reduced demand for entry-level positions, while 53% believe AI is creating new entry-level opportunities.
- Does this role require a security clearance?
- It depends on the employer. Federal agencies, defense contractors, and intelligence community vendors require clearances ranging from Secret to TS/SCI for most analyst roles, while commercial employers generally do not, though regulated industries run thorough background checks. An active clearance makes a candidate more competitive for federal and DoD contract work.
Sources
Salary figures and role details on this page were checked against the following sources. Dates show when each was last reviewed.
- Information Security Analysts, BLS Occupational Employment and Wage Statistics (May 2025)Checked Sep 21, 2026
- Information Security Analysts, BLS Occupational Outlook Handbook (2025-35 projections)Checked Sep 21, 2026
- ISC2 Research Finds AI Is Reshaping Cybersecurity Roles and Increasing Human Oversight, ISC2 (July 2026)Checked Sep 21, 2026
- Workforce Framework for Cybersecurity (NICE Framework), NIST Special Publication 800-181 Revision 1Checked Sep 21, 2026
- 2026 Cybersecurity Workforce Research Report, SANS Institute and GIAC (March 2026)Checked Sep 21, 2026
Related job descriptions
See all Information Technology jobs →- Senior Information Security Analyst$105K–$155K
Senior Information Security Analysts protect organizations from cyber threats by monitoring security systems, investigating incidents, assessing vulnerabilities, and driving security improvements across the technology environment. They lead security operations activities, mentor junior analysts, contribute to security architecture decisions, and serve as the technical escalation point for complex security incidents and risk assessments.
- Information Security Analyst$80K–$125K
Information Security Analysts at sports organizations protect the digital infrastructure that runs modern professional franchises — ticketing systems, player data platforms, broadcast technology, financial systems, and the growing internet-connected hardware throughout smart stadiums. They identify vulnerabilities, respond to incidents, and build the security posture that keeps fan data, competitive information, and business operations safe.
- NBA Information Security Analyst$85K–$135K
An NBA Information Security Analyst protects the franchise's digital infrastructure, player data, proprietary analytics, and business systems against unauthorized access and cybersecurity threats. They monitor network activity, manage security tools, respond to incidents, and implement security controls across a sports organization that holds sensitive player medical data, financial information, and proprietary competitive intelligence.
- Director of Information Security$145K–$225K
A Director of Information Security leads an organization's cybersecurity strategy, program management, and risk governance across enterprise IT and OT environments. Reporting to the CISO or CIO, they own security architecture, incident response capability, compliance posture, and a team of analysts, engineers, and architects. The role sits at the intersection of technical depth and executive communication — translating threat intelligence and vulnerability data into business risk decisions that boards and leadership teams can act on.
- Information Security Engineer$95K–$155K
Information Security Engineers design, implement, and maintain the technical controls that protect an organization's networks, systems, and data from compromise. They sit at the intersection of engineering and defense — building security architecture, running vulnerability programs, responding to incidents, and translating threat intelligence into hardened configurations. The role demands hands-on technical depth across identity, network, endpoint, and cloud domains.
- Information Security Manager$105K–$165K
Information Security Managers lead an organization's efforts to protect information systems, networks, and data from unauthorized access, breaches, and compliance failures. They own the security program — setting policy, managing a team of analysts and engineers, coordinating incident response, and translating technical risk into business language for senior leadership. The role sits at the intersection of technical depth and organizational authority.