About the Security Analyst role
A Security Analyst protects an organization's systems and data. They monitor networks and applications for suspicious activity, investigate alerts, respond to incidents, and assess vulnerabilities before attackers can exploit them. They are often the first line of defense when something goes wrong.
The role blends technical depth with judgment under pressure. A strong analyst can read logs and network traffic, separate real threats from noise, and document findings clearly enough to support both remediation and compliance audits. Many analysts also run phishing simulations, manage vulnerability scans, tune detection rules, and help teams across the company follow security policies without slowing them down.
In your posting, describe your environment and where the role sits: SOC monitoring, incident response, vulnerability management, or a generalist mix. Name the tools you use, such as your SIEM and EDR platforms, and mention any compliance frameworks like SOC 2 or ISO 27001 the analyst will support.
Security Analyst job description template
Job brief
We are looking for a Security Analyst to monitor, investigate, and strengthen the security of our systems and data. You will triage alerts, respond to incidents, run vulnerability assessments, and work with engineering teams to close gaps before they become breaches. To succeed in this role, you should combine hands-on technical skills with calm judgment during incidents and the ability to communicate risk clearly to non-security audiences.
Responsibilities
- Monitor security alerts and events across networks, endpoints, and cloud environments
- Triage and investigate potential incidents, escalating and containing threats when needed
- Conduct vulnerability scans, prioritize findings by risk, and track remediation with system owners
- Tune SIEM detection rules to reduce false positives and improve coverage
- Perform log analysis and forensics to determine the scope and root cause of incidents
- Document incidents, findings, and response actions for internal review and compliance audits
- Support security awareness efforts, including phishing simulations and employee training
- Assess the security posture of new tools, vendors, and system changes
- Help maintain compliance with frameworks such as SOC 2, ISO 27001, or GDPR
Requirements and skills
- Proven working experience as a Security Analyst, SOC Analyst, or in a similar security role
- Hands-on experience with SIEM platforms such as Splunk, Microsoft Sentinel, or Elastic Security
- Solid understanding of network protocols, firewalls, and common attack techniques such as phishing, malware, and lateral movement
- Experience with vulnerability management tools such as Nessus or Qualys
- Familiarity with endpoint detection and response tools
- Working knowledge of at least one scripting language such as Python or PowerShell for automation
- Clear written communication for incident reports and audit documentation
- BSc in Computer Science, Cybersecurity, or a related field, or equivalent experience
Nice to have
- Certifications such as Security+, CySA+, GCIH, or CISSP
- Experience securing cloud environments on AWS, Azure, or GCP
- Familiarity with threat intelligence platforms and the MITRE ATT&CK framework
- Experience supporting SOC 2 or ISO 27001 audits
Generate a custom Security Analyst job description
Need a version tailored to your company, seniority level, or industry? Describe the role and our AI job description generator will draft one in seconds.
