Information Security Analyst sits at a different intersection than the pure SOC analyst or penetration tester: it spans technical security controls, risk management, compliance frameworks, and the translation of security findings into business decisions. At most organisations, the role owns the information security management system (ISMS), manages risk registers, coordinates audits, runs third-party security assessments, and reports security posture to the CISO or board. The CV problem this creates is a framing one: candidates who lead with technical tool experience (SIEM monitoring, vulnerability scanning) without showing risk governance, policy ownership, or compliance delivery are positioning themselves as junior analysts when they may be operating at a programme management level. The reverse also happens — GRC-heavy CVs with no technical signal struggle for roles that require hands-on control management. The strongest information security analyst CVs show both layers: the technical understanding of controls and the governance capability to manage the programme around them. This guide covers the ATS keywords, structure, and bullet patterns that position an information security analyst CV correctly.
What Information Security Analyst Job Descriptions Require in 2026
Information security analyst JDs at regulated organisations — financial services, healthcare, critical infrastructure, and large enterprises with compliance obligations — have become significantly more framework-specific in 2026. Hiring managers screen for the specific framework(s) their organisation operates under before evaluating technical skills.
Requirements that appear consistently across information security analyst JDs:
- Security framework ownership — ISO 27001 (dominant in UK, EU, and global enterprise), SOC 2 Type II (US tech companies and SaaS), NIST Cybersecurity Framework (US government and defence supply chain), PCI DSS (payment card environments), or Cyber Essentials/CE+ (UK public sector and SMB). JDs name the specific framework. Your CV should match the framework to the organisations you've worked in.
- Risk management — maintaining a risk register, conducting risk assessments, and communicating risk to non-technical stakeholders. Risk quantification (expressing security risk in financial impact terms) is increasingly expected at senior levels. FAIR methodology appears in sophisticated JDs.
- Audit and compliance management — coordinating internal and external security audits, managing non-conformities, and maintaining the evidence base for certification. ISO 27001 surveillance audit experience and SOC 2 readiness are explicit JD requirements at organisations that hold these certifications.
- Third-party and vendor risk — assessing the security posture of suppliers, contractors, and cloud vendors. Third-party risk management programmes are now a standard InfoSec accountability, driven by supply chain incident frequency and contractual requirements from enterprise customers.
- Security awareness and policy — developing and delivering security awareness training, maintaining security policies and procedures, and managing phishing simulation programmes. These are operational InfoSec responsibilities that appear across all seniority levels.
- Technical security oversight — not necessarily hands-on tooling, but the ability to manage vulnerability management programmes, review penetration test reports, and engage with technical teams on control implementation.
Information security analyst salaries in 2026: £45K–£75K UK; £70K–£100K for senior analyst and InfoSec manager roles. US: $80K–$120K; senior/manager $110K–$160K.
ATS Keywords for an Information Security Analyst Resume
Information security ATS filtering is framework-specific and certification-specific. "ISO 27001" as an exact string triggers matches that "security compliance" does not.
Essential ATS terms for an information security analyst resume:
- Title variants: Information Security Analyst, InfoSec Analyst, Information Security Officer, Security Risk Analyst, GRC Analyst, Cyber Risk Analyst
- Frameworks: ISO 27001, ISMS, SOC 2, NIST CSF, PCI DSS, Cyber Essentials, CIS Controls, GDPR, data protection, DPIA
- Risk management: risk assessment, risk register, risk quantification, FAIR, threat modelling, business impact analysis, BIA
- Audit and compliance: internal audit, external audit, surveillance audit, audit management, non-conformity, corrective action, evidence management, security controls
- Third-party risk: vendor risk assessment, third-party risk management, TPRM, supplier security, due diligence
- Security programme: security awareness training, phishing simulation, security policy, information security policy, acceptable use policy, access control review
- Technical security: vulnerability management, penetration testing, Nessus, Qualys, SIEM, Splunk, DLP, endpoint security
- Certifications: CISSP, CISM, CRISC, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, CompTIA Security+, CISA
- Long-tail phrases: information security analyst resume examples, how to write an InfoSec analyst resume, ISO 27001 analyst cv, GRC analyst resume, cybersecurity risk analyst resume
Placement: Your primary framework (ISO 27001, SOC 2, NIST) and your highest certification (CISSP, CISM) in the headline. Skills section should lead with frameworks and risk management, then technical security tools — the governance layer comes before the execution layer on an InfoSec analyst CV.
Information Security Analyst CV Structure and Bullets That Show Programme Ownership
Section order:
- Headline — "Information Security Analyst | ISO 27001 · CISSP · Risk Management · SOC 2 · GDPR"
- Certifications — CISSP, CISM, ISO 27001 Lead Implementer, CRISC; near the top
- Skills — Security Frameworks / Risk Management / Audit & Compliance / Third-Party Risk / Technical Security / Tools
- Experience — 4–5 bullets per role; risk register size, audit outcomes, third-party programme scope, and phishing metrics are the evidence
- Education — CS, information systems, or law/business degree; bottom
Two pages for 4+ years. GRC-heavy candidates should include quantified compliance programme outcomes, not just framework names; technical-heavy candidates should include at least one governance or risk bullet to show breadth.
Three elements make an information security analyst bullet convincing: the programme scope (assets, users, vendors, framework), the action or ownership (audit coordinated, risk register managed, training delivered), and the outcome (certification maintained, risk reduced, audit passed). Three examples:
- Maintained ISO 27001 certification for a 600-person organisation — managed the ISMS across 18 control domains, coordinated annual surveillance audits in 2024 and 2025 with zero non-conformities, and maintained the risk register of 88 documented risks reviewed quarterly with the CISO
- Implemented a third-party vendor risk programme covering 140 suppliers — assessed all critical vendors against a 62-control security framework, identified 11 high-risk suppliers requiring remediation plans, and negotiated security improvement commitments with 8; programme satisfied SOC 2 Type II third-party requirement within 6 months of launch
- Delivered a security awareness training programme to 800 employees — phishing simulation click rate fell from 23% to 4% over 12 months; produced monthly security metrics dashboard for CISO and quarterly board reporting pack covering risk posture, incident trends, and compliance status
Information security interviews at senior levels test risk judgement: "we have limited budget — walk me through how you'd prioritise the security roadmap for this organisation" or "a supplier has failed your security assessment — what do you do?" Your CV's evidence of programme ownership and business-facing communication determines the seniority of the discussion.
Three Information Security Analyst CV Mistakes That Misrepresent the Role
Framework named but no programme outcome. "Experience with ISO 27001" appears on every information security analyst CV. The question it leaves unanswered is: what did you do with it? Maintained the certification through an audit? Implemented it from scratch? Managed the ISMS for 50 users or 5,000? The framework name without context is a claim without evidence. Add what you owned (the ISMS, the risk register, the audit process), at what scale (users, assets, control domains), and what the outcome was (certification maintained, audit passed, non-conformity remediated). "Maintained ISO 27001 ISMS for 600-user organisation, coordinating 2 consecutive surveillance audits with zero non-conformities" is evidence. "ISO 27001 experience" is not.
Mixing SOC and GRC without a clear positioning. An information security analyst CV that leads with SIEM monitoring bullets, then pivots to ISO 27001 audit coordination, then mentions penetration testing support, then lists GDPR policy work, tells a fragmented story. Hiring managers for information security roles are typically hiring for a specific type — a GRC-focused analyst for a compliance-heavy organisation, or a more technically-rounded analyst for a smaller company where the role covers more ground. Lead with your dominant domain, provide supporting context for adjacent skills, and write a headline that signals clearly where your primary value is.
Risk management described without a risk register. "Conducted risk assessments" and "managed security risk" appear on many information security CVs. The question they don't answer is: to what methodology, at what scale, and with what output? A risk register with 88 documented risks reviewed quarterly by the CISO is a programme. A spreadsheet with 12 risks that was last updated 18 months ago is not. If you own a risk register, say so: the number of risks documented, the review cadence, who consumes the output, and what decisions it informs. That specificity is the difference between a compliance administrator and a security risk professional.
If you are applying to information security analyst or GRC roles and want your CV rebuilt around the specific ISO 27001, CISSP, and risk management requirements in a target job description, Resumegpt generates your information security analyst CV from your work history in under 60 seconds — framework evidence surfaced, programme ownership evidenced, ATS-optimised, and exported as a PDF ready to submit.