Skip to main content
JobDescription.orgSearch

Information Technology

Information Security Analyst Job Description

Information Security Analysts design, implement, and monitor the controls that protect an organization's networks, systems, and data from unauthorized access, breaches, and cyberattacks. They sit between IT operations and risk management, running vulnerability scans, investigating alerts, and translating technical findings into guidance for engineering teams and leadership. The U.S. Bureau of Labor Statistics projects the occupation to grow 21 percent from 2025 to 2035, far faster than average. Many security tools now include AI-assisted detection, and analysts are expected to validate automated alerts rather than accept them as given.

Last updated

Role at a glance

Typical education
Bachelor's degree in a computer science field is typical per BLS, though certifications plus network admin or help desk experience are a common entry path.
Typical experience
Entry-level (0-2 years) through mid-career; senior analyst and architect tracks generally expect 5+ years.
Key certifications
CompTIA Security+, CISSP, CEH, GIAC GSEC.
Top employer types
SOCs, enterprise IT, government and defense, cloud service providers, regulated industries such as finance and healthcare.
Growth outlook
21% employment growth projected 2025-2035 (BLS), about 14,100 annual openings.
AI impact (through 2030)
ISC2's 2026 survey found 63% of AI-using professionals spend more time validating AI outputs and 89% have seen an AI recommendation produce a wrong result; respondents were split on whether AI is reducing or creating entry-level roles.

Duties and responsibilities

  • Monitor SIEM and XDR alerts for indicators of compromise, triaging and escalating confirmed incidents according to documented runbook procedures.
  • Run vulnerability scans with Tenable Nessus, Qualys, or Rapid7 and prioritize remediation with system owners using CVSS scoring.
  • Hunt for attacker activity across endpoint, network, and cloud logs that automated detection rules and AI-assisted triage missed.
  • Investigate phishing reports and malicious email campaigns, analyzing headers, attachments, and links to assess scope and containment.
  • Develop and maintain security policies, standards, and procedures aligned to NIST CSF, ISO 27001, or CIS Controls frameworks.
  • Coordinate penetration testing engagements with internal red teams or third-party vendors and track remediation of findings.
  • Assess third-party vendor security posture through questionnaires, SOC 2 Type II reviews, and contractual security requirements.
  • Support audit and compliance work for PCI DSS, HIPAA, SOX, or FedRAMP by gathering evidence and answering auditor questions.
  • Tune endpoint detection and response tools, firewall rules, and cloud security group policies to shrink the attack surface.
  • Write clear reports summarizing vulnerability findings, incident timelines, and risk recommendations for technical and executive audiences.

Overview

Information Security Analysts are responsible for making sure an organization's systems, data, and infrastructure don't get compromised, and for limiting damage when they do. The job is part detective work, part systems administration, part risk management, and part written communication. On a given day, the work might move from investigating a suspicious PowerShell process flagged by an EDR tool, to reviewing a vendor's SOC 2 report before a procurement decision, to writing a plain-language memo explaining a new phishing campaign to the help desk team.

In organizations large enough to run a security operations center, analysts typically start there: monitoring alerts, triaging events, and handling Tier 1 and Tier 2 incidents. The discipline built in that environment is foundational. It means learning to move fast without jumping to conclusions, telling a genuine compromise apart from a noisy detection rule, and documenting an incident timeline clearly enough that a forensics team can reconstruct what happened months later.

Vulnerability management is the other core responsibility that touches most analyst roles. That means running regular scans, interpreting the output, and then, the hard part, working with application owners and infrastructure teams to close findings on a timeline that reflects actual risk instead of IT backlog priorities. Analysts who can make that case persuasively get findings remediated. Analysts who just forward scan reports do not.

Compliance work runs parallel to the technical track in most enterprise environments. PCI DSS, HIPAA, SOX, and FedRAMP all require documented security controls, audit evidence, and periodic assessments. Analysts are typically the people who gather that evidence, respond to auditor questions, and identify gaps between the current state and what the framework requires.

NIST's Workforce Framework for Cybersecurity groups this work under the Protection and Defense category, which is a useful way to see how the job connects to the wider cybersecurity workforce: it sits between detection, incident response, and governance rather than owning any one of them exclusively.

The role demands a specific mindset: adversarial thinking paired with methodical documentation. The question is not just whether a control exists, it is whether an attacker who already has a foothold on one endpoint can use that control's gaps to move laterally, escalate privileges, and reach data that actually matters. Analysts who think that way, rather than checking compliance boxes, are the ones organizations trust to lead incident response when something serious happens. That also means knowing when to trust an AI-generated alert or recommendation and when to second-guess it.

Qualifications

Education

  • A bachelor's degree in a computer science field is the typical path employers list, per the BLS Occupational Outlook Handbook, usually paired with related work experience.
  • Many analysts arrive by way of network administration or help desk roles rather than a straight line from school.
  • Candidates without a four-year degree do get hired, especially with a strong home lab, CTF history, or a SOC internship behind relevant certifications.

Certifications by career stage

  • Entry level: CompTIA Security+, CompTIA CySA+, Google Cybersecurity Certificate
  • Mid-career: CEH, GIAC GSEC, GCIA, GCIH, AWS Security Specialty, Microsoft SC-200
  • Senior: CISSP, CISM, OSCP for analysts with offensive security duties, CISA for audit-facing roles
  • Government and cleared roles: DoD 8570/8140 baseline requirements commonly include Security+ or CASP+, depending on the position level

Technical skills

  • SIEM platforms: Splunk, Microsoft Sentinel, IBM QRadar, Elastic Security
  • EDR tools: CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne
  • Vulnerability management: Tenable Nessus, Qualys VMDR, Rapid7 InsightVM
  • Network analysis: Wireshark, Zeek, Suricata, plus familiarity with packet capture and flow analysis
  • Cloud security: AWS Security Hub, Microsoft Defender for Cloud, GCP Security Command Center
  • Scripting: Python or PowerShell to automate repetitive analysis and reporting tasks
  • Frameworks: NIST CSF, MITRE ATT&CK, CIS Controls, ISO 27001

Working with AI-assisted tools Many major SIEM and XDR platforms ship built-in AI triage and correlation features. Analysts are expected to know how to evaluate an AI-generated alert or recommendation rather than accept it automatically, since AI outputs can be wrong. The skill can come up in interviews as a direct question: walk me through a time an automated detection got it wrong and what you did next.

Soft skills that differentiate

  • Writing a clear, concise incident report that a non-technical executive can act on
  • Staying comfortable in ambiguous situations where the runbook does not have an answer
  • Keeping attention on log detail without losing track of what the attacker was actually trying to do
  • Pushing back, with evidence, when an automated system's output looks wrong

Career outlook

The Bureau of Labor Statistics projects employment of information security analysts to grow 21 percent from 2025 to 2035, far faster than the average for all occupations, with about 14,100 openings expected per year over the decade, most from workers leaving the field or retiring. Demand comes from the ongoing need to protect networks and data from cyberattacks, from data-protection rules, and from the security work that comes with moving systems to the cloud.

Skills matter as much as headcount. SANS Institute's 2026 Cybersecurity Workforce Research Report focuses on skills gaps within existing security teams, including the skills needed to handle AI-driven attacks and work with AI-assisted defense. Analysts who can already work alongside AI tooling start with an advantage over those who would need to learn it on the job.

ISC2's 2026 survey of working AI users in cybersecurity found respondents split on entry-level demand. More than half of respondents, 56 percent, said AI has reduced demand for entry-level positions, while 53 percent believe AI is creating new entry-level opportunities.

The specialization paths from this title are well established. Analysts who lean technical tend to move toward incident response, penetration testing, or detection engineering, writing the SIEM rules and EDR behavioral detections that the next generation of analysts will work from. Analysts who lean toward governance move into GRC, security architecture, or eventually CISO-track leadership. Both paths can lead toward the upper end of the salary range for people who keep their skills current.

Cloud security is a major specialization inside the field. The move of enterprise workloads to AWS, Azure, and GCP rewards analysts who understand on-premise security and can also assess IAM configurations, storage bucket policies, and container security posture. Building cloud-native security skills widens the range of roles an analyst can pursue, from cloud security engineering to security architecture for organizations that run workloads across more than one cloud provider.

AI is also changing the entry point to the field. Tier 1 functions such as alert triage and basic phishing analysis often run through automated playbooks, which puts more weight on analytical judgment in junior roles. Per ISC2, 89 percent of surveyed professionals have already seen an AI recommendation produce an incorrect outcome, which is why human validation of that output is an expected part of the job rather than an afterthought.

Sample cover letter

Dear Hiring Manager,

I'm applying for the Information Security Analyst position at [Company]. I've spent the past three years as a Tier 2 SOC analyst at [Company], where I handle escalated alerts from our Splunk environment, lead initial incident response on confirmed compromises, and own vulnerability management across roughly 2,400 endpoints.

The work I'm most proud of is detection tuning. When I joined, our Splunk instance was generating about 340 alerts per day, and the team spent the first two hours of every shift clearing obvious false positives. I spent six weeks building suppression logic for the highest-volume, low-fidelity rules and replacing them with behavioral detections mapped to the MITRE ATT&CK techniques we'd actually seen in our environment, mainly lateral movement and credential access. Alert volume dropped to under 80 per day, and the mean time to investigate a real event fell from 47 minutes to 19.

I hold CompTIA Security+ and CySA+, and I'm currently in the GCIH exam pipeline. I've also spent the past year reviewing Defender for Cloud findings and tuning conditional access policies as [Company] finished its move to Azure, including learning where our AI-assisted alert triage gets things wrong so I know when to override it rather than trust it by default.

Your posting mentioned this role supports PCI DSS scope for the card processing environment. That's an area I want to grow into. I've supported two QSA audits by gathering evidence, and I'm looking for a position where I help drive the compliance program rather than just feed it data.

I'd welcome the chance to talk through how my background fits what your team needs.

[Your Name]

Frequently asked questions

What does an Information Security Analyst do?
Information Security Analysts design, implement, and monitor the controls that protect an organization's networks, systems, and data from unauthorized access, breaches, and cyberattacks. They sit between IT operations and risk management, running vulnerability scans, investigating alerts, and translating technical findings into guidance for engineering teams and leadership. The U.S. Bureau of Labor Statistics projects the occupation to grow 21 percent from 2025 to 2035, far faster than average. Many security tools now include AI-assisted detection, and analysts are expected to validate automated alerts rather than accept them as given.
What are the main duties of an Information Security Analyst?
Core duties include: monitor SIEM and XDR alerts for indicators of compromise, triaging and escalating confirmed incidents according to documented runbook procedures; run vulnerability scans with Tenable Nessus, Qualys, or Rapid7 and prioritize remediation with system owners using CVSS scoring; and hunt for attacker activity across endpoint, network, and cloud logs that automated detection rules and AI-assisted triage missed.
What certifications do employers expect from an Information Security Analyst?
CompTIA Security+ remains the baseline many employers require, including DoD contractor roles under the 8570/8140 directives. Mid-career analysts typically add CEH, GIAC GSEC or GCIA, or CISSP, and cloud certifications like AWS Security Specialty or Microsoft SC-200 are common asks for cloud-focused roles.
Is a four-year computer science degree required to break into the field?
No. The BLS Occupational Outlook Handbook lists a bachelor's degree in a computer science field with related experience as typical, but also notes that candidates enter with a high school diploma plus relevant certifications and prior network administration experience. Hands-on skills often matter more to hiring managers than the degree itself.
How does a SOC analyst role differ from a broader security analyst position?
A SOC analyst role is a specific function: real-time alert monitoring, triage, and initial response, usually organized into Tier 1 through Tier 3 by complexity. NIST's NICE Framework groups this work under its Protection and Defense category, which also covers vulnerability analysis and incident response work that a broader analyst title often carries.
How is AI changing day-to-day work for security analysts?
ISC2's May 2026 survey of 856 cybersecurity professionals using AI found 63% now spend more time reviewing or validating AI-generated outputs, and 89% had seen an AI recommendation produce an incorrect outcome. Just over half, 56%, believe AI has reduced demand for entry-level positions, while 53% believe AI is creating new entry-level opportunities.
Does this role require a security clearance?
It depends on the employer. Federal agencies, defense contractors, and intelligence community vendors require clearances ranging from Secret to TS/SCI for most analyst roles, while commercial employers generally do not, though regulated industries run thorough background checks. An active clearance makes a candidate more competitive for federal and DoD contract work.

Sources

Salary figures and role details on this page were checked against the following sources. Dates show when each was last reviewed.

  1. Information Security Analysts, BLS Occupational Employment and Wage Statistics (May 2025)Checked Sep 21, 2026
  2. Information Security Analysts, BLS Occupational Outlook Handbook (2025-35 projections)Checked Sep 21, 2026
  3. ISC2 Research Finds AI Is Reshaping Cybersecurity Roles and Increasing Human Oversight, ISC2 (July 2026)Checked Sep 21, 2026
  4. Workforce Framework for Cybersecurity (NICE Framework), NIST Special Publication 800-181 Revision 1Checked Sep 21, 2026
  5. 2026 Cybersecurity Workforce Research Report, SANS Institute and GIAC (March 2026)Checked Sep 21, 2026