Home / Military to civilian jobs / Information Security Analyst

Military to civilian resume exampleArmy 25D

Information security analyst resume example (military to civilian)

This is an information security analyst resume for someone leaving the military with about ten years in network defense. Brandon is a fictional Army 25D Cyber Network Defender, a Staff Sergeant who ran a watch floor. Every line on his page came from real 25D work. If you sat in a security operations center, hunted threats, or ran endpoint security in any branch, this is the shape your resume can take. Under it you get the lines that changed, the words the job posts use, and a free score on your own resume.

The example

Fictional sample. The person, the units, and the numbers are illustrative. Rendered by BMR's Classic template, the same one a user's resume prints on.

Brandon Pierce
[email protected] | (555) 019-3382 | Augusta, GA | LinkedIn | Clearance: Secret
Professional Summary

Information security analyst with 10 years defending Army enterprise networks. Led an 11-analyst security operations center watch covering 24,000 endpoints, ran response on 62 confirmed incidents, and cut false-positive alerts 38% by rewriting SIEM correlation rules. Works daily in Splunk, ArcSight, endpoint security tooling, and Tenable Nessus vulnerability management. CompTIA Security+ and CySA+. Active Secret clearance.

Experience
Cyber Defense Operations Supervisor (Staff Sergeant)Apr 2022 - Aug 2025
United States Army, Cyber Protection Brigade, Fort Eisenhower, GA

Ran the day watch in a security operations center defending an enterprise network of 24,000 endpoints. Supervised 11 analysts and owned alert triage, incident response, vulnerability reporting, and the daily risk brief leadership used to make decisions.

Monitored 24,000 endpoints in a SIEM (Splunk and ArcSight), triaging 300 alerts a day and closing every confirmed incident inside a 4-hour response standard.

Cut false-positive alerts 38% by rewriting 45 correlation rules against observed attacker behavior, returning about 12 analyst hours a week to real work.

Led response on 62 confirmed incidents, containing each one, tracing the root cause, and writing the after-action report that closed the gap.

Supervised and certified 11 analysts on triage and escalation procedures, moving 6 of them through the CompTIA CySA+ exam in one year.

Cyber Network Defender (Sergeant)Feb 2019 - Mar 2022
United States Army, 4th Infantry Division, Fort Carson, CO

Network defense analyst for a division network of 9,000 users. Hunted for threats in host and network data, ran the endpoint security platform, and tracked the vulnerabilities system owners had to fix.

Ran weekly threat hunts across 9,000 endpoints using host and network log data, finding 14 compromises that automated alerting had missed.

Administered the endpoint security platform (HBSS), pushing policy and signature updates to every host and holding 99% agent coverage.

Scanned the network monthly with Tenable Nessus, ranked findings by real risk, and drove a 41% cut in high and critical vulnerabilities over 18 months.

Wrote the incident and vulnerability reports read by the division chief information officer, turning technical findings into plain risk language.

Information Technology Specialist (Specialist)Oct 2015 - Jan 2019
United States Army, 7th Infantry Division, Joint Base Lewis-McChord, WA

Help desk and systems support for a 4,000-user network. Built and maintained accounts, workstations, and servers, and handled the security side of every account action.

Resolved 2,400 help desk tickets over three years, meeting the response deadline on every priority ticket.

Administered accounts and access permissions for 4,000 users, removing access the same day a user departed.

Imaged and patched 600 workstations to the published security baseline, with zero failed compliance checks in two annual inspections.

Education

Associate of Applied Science, Cyber SecurityCentral Texas College | May 2023

Cyber Network Defender CourseU.S. Army Cyber School, Fort Eisenhower, GA | Jan 2019

Certifications

CompTIA CySA+ (Cybersecurity Analyst)CompTIA | Issued: 2022

CompTIA Security+ (DoD 8140 baseline)CompTIA | Issued: 2016

Skills

Detection & ResponseSIEM monitoring & log correlation · Incident response & containment · Threat hunting

Tools & PlatformsSplunk & ArcSight · Endpoint security (HBSS) · Tenable Nessus scanning

Risk & VulnerabilitiesVulnerability management · Risk-ranked remediation · Continuous monitoring

Leadership & ReportingTeam supervision (11 analysts) · Analyst training & certification · Executive incident reporting

Open the PDF (1 page, as the engine prints it).

Already have a resume? Get it graded straight.

Upload it and get a number in about a minute, plus the information security analyst lines a civilian hiring manager will not follow and what to write instead. No account.

Free. Your file is never stored.

Score my resume free

Why this example works

  1. The summary says the civilian job in the first three words.

    "Information security analyst." A manager filling a SOC seat knows in one second that this page is for them. Rank and MOS come later, where they belong.

  2. Staying in security? Most of your words already work.

    SIEM. Threat hunting. Incident response. Vulnerability management. A commercial security team posts for all four in the same words you use. The job here is to add your tools and your numbers, not to hide the field.

  3. The tool names are on the page.

    Splunk. ArcSight. Tenable Nessus. Security teams screen on tools, and a recruiter searching for "Splunk" has to find the word. HBSS gets plain English next to it, because that is the one name a civilian shop will not know.

  4. Every bullet has a number a manager can picture.

    24,000 endpoints. 300 alerts a day. 62 incidents. 38% fewer false positives. 11 analysts. Nobody has to guess how big the job was.

  5. The first bullet of each job is the one the post cares about most.

    Monitoring and triage under the top job, threat hunting under the second, accounts and access under the third. Read only the first bullet of each block and you still get the story.

  6. Tuning is written as a result, not a chore.

    "Cut false positives 38% by rewriting 45 correlation rules" tells the reader what happened. "Responsible for SIEM content management" tells them nothing.

  7. The skills block is grouped, not a pile.

    Four short headings, three skills each. A recruiter can scan it in a few seconds, and a keyword scan finds "SIEM," "incident response," and "vulnerability management" without hunting.

  8. One page, on purpose.

    Ten years, three jobs, twelve skills, two certs, two schools, and it still fits. A civilian resume for a mid-career NCO rarely needs page two.

The translation, line by line

How most 25Ds write itWhat a security hiring manager reads
Performed DCO on a Secret enclaveEnterprise threat monitoring and incident response across 24,000 endpoints
SIEM / Big Data Platform analystSecurity analytics and log correlation in Splunk and ArcSight
Tier 1 and Tier 2 watch floor NCOICSOC shift supervisor; led an 11-analyst triage and escalation team
Responded to incidents on DoD networksManaged and remediated 62 incidents on critical systems
Conducted threat hunting on the enclaveProactive threat hunting; found 14 compromises alerting had missed
HBSS administrator for the divisionEndpoint security platform administration, 99% agent coverage
Ran ACAS scans per the tasking orderMonthly enterprise vulnerability scanning with risk-ranked remediation
RMF continuous monitoring, held the ATOOngoing compliance monitoring against NIST 800-53 controls
Briefed the G6 on network statusReported incidents and open risk to the chief information officer
Held the 8140 baseline certCompTIA Security+, the Department of Defense baseline certification
25D producing course, Cyber SchoolCyber Network Defender Course, U.S. Army Cyber School

The words the job posts use

The words information security analyst job posts use, and what the numbers look like right now.

Titles you will see

  • Information Security Analyst
  • Security Analyst
  • Information Systems Security Analyst
  • Information Systems Security Officer (ISSO)
  • IT Security Analyst
  • Network Security Analyst

Work the posts describe

  • Develop plans to safeguard computer files against accidental or unauthorized modification, destruction, or disclosure
  • Perform risk assessments and execute tests of data processing systems to ensure security measures are working
  • Monitor current reports of computer viruses to determine when to update virus protection systems
  • Encrypt data transmissions and erect firewalls to conceal confidential information as it is transmitted
  • Review violations of computer security procedures and discuss them with the people involved
  • Document computer security and emergency measures policies, procedures, and tests

Credentials that get named

  • CompTIA Security+
  • CompTIA CySA+
  • GIAC Certified Incident Handler (GCIH)
  • CISSP (ISC2)
  • DoD 8140 baseline certification

BLS Occupational Outlook Handbook, May 2025 data: median pay for information security analysts $129,180 a year, across 192,900 jobs. Employment is projected to grow 21 percent from 2025 to 2035, much faster than average. Typical entry-level education is a bachelor's degree.

Sources: O*NET 15-1212.00 Information Security Analysts (tasks, reported job titles) and the BLS Occupational Outlook Handbook, Information Security Analysts. Both read 2026-09-09.

Frequently asked questions

Do I need a degree to get hired as an information security analyst?

BLS says most of these jobs ask for a bachelor's degree. Plenty of veterans get hired without one. What moves a hiring manager is proof: certifications, a clearance, and years of real detection work. Brandon's page shows the common NCO path, an associate degree plus Security+ and CySA+. Apply first to the posts that say "or equivalent experience," and finish the degree after you are working.

Should I put ArcSight and HBSS on my resume, or the commercial tool names?

Write down what you actually ran, then say what it is. "Endpoint security platform (HBSS)" works for both readers. Splunk, ArcSight, and Nessus need no help at all, because commercial teams use the same three. Never swap in a tool you have not touched. One tools question in the first interview ends that.

How long should a military-to-civilian resume be?

For about ten years of service, one page usually does it. That is what this example is. If you have 20 years and several very different jobs, two pages can be fine. Length matters less than this: the top third of page one says the civilian job you want and proves it with numbers.

Build your information security analyst resume the same way

BMR writes your network defense experience the way this page reads, tailored to the job you pick. Free to start, 2 tailored resumes included.

Build this resume freeFree to start. 71,892 resumes built for the military community.