Cybersecurity Analyst career guide
Detect, investigate and respond to security threats.
What does a cybersecurity analyst do?
A cybersecurity analyst protects an organisation's systems and data by monitoring for threats, investigating alerts and responding to incidents. Many start in a Security Operations Centre (SOC).
The work rewards curiosity and careful investigation: understanding how attacks work, reading logs, and documenting what happened and how to prevent it.
Typical responsibilities
- Monitor security alerts and investigate suspicious activity
- Triage and respond to security incidents
- Analyse logs from systems, networks and applications
- Run vulnerability scans and track fixes
- Document incidents and write reports
- Help improve security policies and awareness
Skills you need
Technical skills
- Networking (TCP/IP, ports, protocols)
- Operating systems: Windows and Linux
- Log analysis and SIEM tools
- Common attack techniques (for example the MITRE ATT&CK framework)
- Vulnerability assessment
- Incident response process
- Scripting for automation
Soft skills
- Investigative thinking
- Attention to detail
- Clear incident writing
- Composure under pressure
Tools and technologies
- A SIEM (for example Splunk or Microsoft Sentinel)
- Wireshark
- Nmap
- A vulnerability scanner (for example Nessus)
- Endpoint detection and response tools
- Linux command line
Certifications
- ISC2 Certified in Cybersecurity (CC)BeginnerISC2
- CompTIA Security+BeginnerCompTIA
- CompTIA Cybersecurity Analyst (CySA+)IntermediateCompTIA
- Certified Ethical Hacker (CEH)IntermediateEC-Council
- Certified Information Systems Security Professional (CISSP)AdvancedISC2 · Requires security work experience
Certifications are optional for most roles; skills and projects matter more. Providers retire and rename exams regularly, so check the provider's website before you register. Last reviewed October 2026.
Cybersecurity Analyst salary
Career path
- Step 1SOC Analyst (L1)
- Step 2Security Analyst (L2)
- Step 3Senior Security Analyst or Incident Responder
- Step 4Security Engineer, Architect or SOC Manager
- Step 5Chief Information Security Officer
Titles and the time between steps vary by company and individual.
Your first 90 days of learning
Networking and systems
- Learn TCP/IP, common ports and protocols
- Practise Windows and Linux administration basics
- Capture and read traffic with Wireshark
Threats and detection
- Study common attacks and the MITRE ATT&CK framework
- Practise investigating alerts in a SIEM lab
- Run a vulnerability scan on a lab machine and prioritise the findings
Incident response and certification
- Work through incident-response scenarios in a lab environment
- Write an incident report for one investigation
- Prepare for Security+ or ISC2 CC
Interview preparation
Common topics to prepare for cybersecurity analyst interviews. These are preparation areas, not questions from a specific company's interview.
- Networking fundamentals and common ports
- Walking through an incident response
- Investigating a phishing alert
- Common attack types and how to detect them
- Vulnerability vs threat vs risk
- Reading and interpreting logs
Resume guidance
- List labs and practice platforms you completed, accurately
- Describe investigations: what you found and what you did
- Name the tools you used (SIEM, scanners, EDR)
- Show certifications and the year earned
Is your resume ready for cybersecurity analyst roles?
Upload your resume to check ATS readiness, matched keywords and what to improve.