These are the ATS keywords, credentials, and software terms that recur across current information security analyst job descriptions — organized so you can scan for what your resume is missing. Placement matters as much as presence: an ATS keyword buried in a skills list ranks lower than the same term used in context inside an experience bullet.
Title variants
- Information Security Analyst
- InfoSec Analyst
- Information Security Officer
- Security Risk Analyst
- GRC Analyst
- Cyber Risk Analyst
Frameworks
- ISO 27001
- ISMS
- SOC 2
- NIST CSF
- PCI DSS
- Cyber Essentials
- CIS Controls
- GDPR
- data protection
- DPIA
Risk management
- risk assessment
- risk register
- risk quantification
- FAIR
- threat modelling
- business impact analysis
- BIA
Audit and compliance
- internal audit
- external audit
- surveillance audit
- audit management
- non-conformity
- corrective action
- evidence management
- security controls
Third-party risk
- vendor risk assessment
- third-party risk management
- TPRM
- supplier security
- due diligence
Security programme
- security awareness training
- phishing simulation
- security policy
- information security policy
- acceptable use policy
- access control review
Technical security
- vulnerability management
- penetration testing
- Nessus
- Qualys
- SIEM
- Splunk
- DLP
- endpoint security
Certifications
- CISSP
- CISM
- CRISC
- ISO 27001 Lead Implementer
- ISO 27001 Lead Auditor
- CompTIA Security+
- CISA
Long-tail phrases
- information security analyst resume examples
- how to write an InfoSec analyst resume
- ISO 27001 analyst cv
- GRC analyst resume
- cybersecurity risk analyst resume
Pasting these terms into your resume verbatim without matching context can read as keyword stuffing to a human reviewer, even if it passes the ATS. The full Information Security Analyst resume guide shows where each category belongs and how to work it into real experience bullets.