BrainRank
Career guide

Cybersecurity Analyst career guide

Detect, investigate and respond to security threats.

What does a cybersecurity analyst do?

A cybersecurity analyst protects an organisation's systems and data by monitoring for threats, investigating alerts and responding to incidents. Many start in a Security Operations Centre (SOC).

The work rewards curiosity and careful investigation: understanding how attacks work, reading logs, and documenting what happened and how to prevent it.

Typical responsibilities

  • Monitor security alerts and investigate suspicious activity
  • Triage and respond to security incidents
  • Analyse logs from systems, networks and applications
  • Run vulnerability scans and track fixes
  • Document incidents and write reports
  • Help improve security policies and awareness

Skills you need

Technical skills

  • Networking (TCP/IP, ports, protocols)
  • Operating systems: Windows and Linux
  • Log analysis and SIEM tools
  • Common attack techniques (for example the MITRE ATT&CK framework)
  • Vulnerability assessment
  • Incident response process
  • Scripting for automation

Soft skills

  • Investigative thinking
  • Attention to detail
  • Clear incident writing
  • Composure under pressure

Tools and technologies

  • A SIEM (for example Splunk or Microsoft Sentinel)
  • Wireshark
  • Nmap
  • A vulnerability scanner (for example Nessus)
  • Endpoint detection and response tools
  • Linux command line

Certifications

  • ISC2 Certified in Cybersecurity (CC)Beginner
    ISC2
  • CompTIA Security+Beginner
    CompTIA
  • CompTIA Cybersecurity Analyst (CySA+)Intermediate
    CompTIA
  • Certified Ethical Hacker (CEH)Intermediate
    EC-Council
  • Certified Information Systems Security Professional (CISSP)Advanced
    ISC2 · Requires security work experience

Certifications are optional for most roles; skills and projects matter more. Providers retire and rename exams regularly, so check the provider's website before you register. Last reviewed October 2026.

Cybersecurity Analyst salary

We only publish salary ranges based on verified data, and we don't have a reliable source for this role yet. Meanwhile, if you have an offer or a target CTC, work out what you would actually take home.

Career path

  1. Step 1
    SOC Analyst (L1)
  2. Step 2
    Security Analyst (L2)
  3. Step 3
    Senior Security Analyst or Incident Responder
  4. Step 4
    Security Engineer, Architect or SOC Manager
  5. Step 5
    Chief Information Security Officer

Titles and the time between steps vary by company and individual.

Your first 90 days of learning

First 30 days

Networking and systems

  • Learn TCP/IP, common ports and protocols
  • Practise Windows and Linux administration basics
  • Capture and read traffic with Wireshark
Days 31-60

Threats and detection

  • Study common attacks and the MITRE ATT&CK framework
  • Practise investigating alerts in a SIEM lab
  • Run a vulnerability scan on a lab machine and prioritise the findings
Days 61-90

Incident response and certification

  • Work through incident-response scenarios in a lab environment
  • Write an incident report for one investigation
  • Prepare for Security+ or ISC2 CC

Interview preparation

Common topics to prepare for cybersecurity analyst interviews. These are preparation areas, not questions from a specific company's interview.

  • Networking fundamentals and common ports
  • Walking through an incident response
  • Investigating a phishing alert
  • Common attack types and how to detect them
  • Vulnerability vs threat vs risk
  • Reading and interpreting logs

Resume guidance

  • List labs and practice platforms you completed, accurately
  • Describe investigations: what you found and what you did
  • Name the tools you used (SIEM, scanners, EDR)
  • Show certifications and the year earned

Is your resume ready for cybersecurity analyst roles?

Upload your resume to check ATS readiness, matched keywords and what to improve.

Keep going