Templates

Cybersecurity analyst job description template: SOC, incident response or GRC, shifts, clearances and certifications

On this page
  1. Pick one security seat
  2. The cybersecurity analyst job description template
  3. Citizenship, certifications, hours and classification
  4. From must-haves to screening questions and scorecard rows
  5. Common mistakes in cybersecurity analyst job descriptions
  6. Before you publish
  7. Questions people ask

Cybersecurity analyst postings often ask for everything at once: monitor the SIEM, respond to incidents, run vulnerability scans, write policies, lead audits, hunt threats and harden the cloud, with CISSP, five years of experience and an entry-level salary. That describes three or four jobs, and strong candidates recognize it immediately. The useful posting names one seat, the hours (shifts or business days), what the analyst can do on their own authority, and any clearance or contract requirement. Below is a copy-ready cybersecurity analyst job description template, the citizenship, certification and classification lines checked against primary sources, screening questions and scorecard rows, and the mistakes that cost security teams their best applicants. The general method is in how to write a job description that screens.

Pick one security seat

SeatWhat fills the shift or weekMust-have that separates it
SOC analyst (tier 1 or 2)Alert triage, investigation, escalation, ticket notes, shift handoverHas triaged real alerts and can explain a true positive they found
Incident responderContainment, forensic collection, timelines, post-incident reportsHas worked an incident from detection to closure
Vulnerability managementScanning, prioritizing findings, chasing remediation with system ownersHas reduced an open-vulnerability backlog by working with owners
GRC analystControl testing, policies, audit evidence, vendor risk reviewsHas prepared evidence for an external audit or framework assessment
Cloud security analystCloud configuration reviews, identity and access findings, guardrailsHas found and fixed misconfigurations in a production cloud account

Then decide the conditions: shift pattern (follow-the-sun, 24/7 rotation or business hours), on-call duties, authority to isolate a host or disable an account without approval, the tools in use, and whether a government contract sets clearance or qualification requirements. Each of these changes who will apply.

The cybersecurity analyst job description template

Cybersecurity Analyst [I / II], [SOC / Incident Response / GRC]
[Company], [city] — [On-site / Hybrid: days / Remote within: states]
Pay: $[min]–$[max] per year [plus shift differential, if any].
[Benefits summary, if required.] [Exempt / overtime-eligible, after
review.]

SUMMARY
You will [monitor and investigate alerts / respond to incidents /
run control assessments] for [environment: N employees, N endpoints,
cloud and on-premises systems]. You will work [shift pattern / business
hours] in a team of [N], using [SIEM / EDR / GRC tool], and report to
[title]. You can [isolate hosts / disable accounts / open priority
tickets] on your own authority.

WHAT YOU WILL DO
- [SOC: triage alerts, investigate with logs and endpoint data, and
  escalate with clear notes.]
- [Response: contain incidents, collect evidence and write timelines
  and lessons learned.]
- [GRC: test controls, collect audit evidence and track remediation
  with system owners.]
- Tune detections or controls that create noise or miss activity.
- Write findings that system owners understand and can act on.

YOU MUST HAVE
- [Seat-specific experience from the table above.]
- Investigated a security event using logs or endpoint data and
  reached a defensible conclusion.
- Written up findings for a non-security audience.
- [Scripting in [language] to automate a repeated task.]

NICE TO HAVE
- CompTIA Security+ or CySA+; [CISSP for senior seats].
- Experience with [SIEM], [EDR], [cloud provider], [framework].
If you meet the must-haves and none of these, please apply.

FIXED CONDITIONS
- Schedule: [shift pattern, weekends, holidays]; on-call [details].
- [Only if a contract requires it: U.S. citizenship and the ability
  to obtain and keep a [level] security clearance are required by
  [contract or regulation].]
- [Qualification required by contract within [N] days of start.]

HOW WE HIRE
[Recruiter screen; conversation with [title]; a 60-minute exercise
reviewing sample logs or a control finding; meeting the team.]

[EEO STATEMENT]
For accessibility or adjustments, contact [address].

Citizenship, certifications, hours and classification

Not legal advice. These points were checked against the Justice Department, the Department of Labor, the Department of Defense and the certification issuers as of October 2026. Confirm contract requirements with your contracts team and classification with counsel.

Citizenship and clearances. The Justice Department says an employer "may restrict hiring to U.S. citizen only if a law, regulation, executive order, or government contract requires the employer to do so" (DOJ Immigrant and Employee Rights Section). Put the requirement under fixed conditions only for seats that need it, and name the source. "U.S. citizens only" on a commercial SOC posting is a risk, not a precaution.

Defense contracts. Department of Defense cyber roles fall under DoD Manual 8140.03, whose qualification program combines foundational qualification (through education, training or personnel certification) with resident training and continuous professional development (DoDM 8140.03). Ask the contracting officer what the contract requires instead of copying a certification list from an old posting.

Certifications. CompTIA Security+ is valid for three years and can be renewed with 50 continuing education units (CompTIA). CompTIA says a new Security+ version is expected on or around November 17, 2026, and that CySA+ V3 is retiring in favor of V4 (CompTIA Security+, CompTIA CySA+), so ask for an active certification rather than a named version. CISSP requires at least five years of cumulative paid work in two or more of the eight domains, with up to one year waived for a qualifying degree or credential; people who pass without the experience become an Associate of ISC2 (ISC2). That puts CISSP in senior postings, not analyst I.

Hours and classification. BLS notes that information security analysts sometimes have to be on call outside business hours (BLS, last modified August 27, 2026). The computer employee exemption requires at least $684 a week on a salary basis or $27.63 an hour and a primary duty of systems analysis, design, development, testing or modification of systems (DOL Fact Sheet 17E). A tier 1 analyst working a fixed playbook on shifts is the case to review carefully. Post the approved pay range (see pay transparency laws by state) and close with your EEO statement.

From must-haves to screening questions and scorecard rows

Must-haveScreening questionScorecard competencyEvidence of a strong answer
Investigating events"Tell me about an alert that turned out to be real. What did you look at, in what order?"Investigation methodSpecific data sources, a hypothesis tested, a clear conclusion and escalation
False positives"Which alert wasted the most of your team's time, and what did you change?"Detection tuningFound why it fired, tuned or suppressed it with a record, checked nothing was lost
Writing findings"How did you explain your last finding to the system owner?"Risk communicationPlain impact, a specific fix, and follow-up until it was done
Working under pressure (response seats)"Walk me through the first hour of an incident you worked."Incident handlingContained before investigating deeply, preserved evidence, kept a timeline
Audit evidence (GRC seats)"What control was hardest to evidence in your last audit, and why?"Control assessmentUnderstands the control's purpose, found a real gap and tracked remediation

The full first-round call, with red flags, is in cybersecurity analyst screening questions. To find candidates, start from the Boolean search strings for cybersecurity roles. If the seat leans toward firewalls and network design, compare network engineer screening questions.

Common mistakes in cybersecurity analyst job descriptions

Senior requirements, junior title

CISSP plus five years for an analyst I seat contradicts itself and drives away both groups. Match certifications and years to the level.

Hidden shifts

A 24/7 SOC means nights, weekends and holidays for someone. State the pattern and any differential.

Blanket citizenship lines

Use citizenship or clearance requirements only where a contract or law requires them, and say so.

A tool wall

Requiring experience with your exact SIEM and EDR products shrinks the pool for skills that transfer within weeks. Require the investigation skill; name the tools as environment.

No authority

If analysts must wait for approval to isolate a compromised laptop, say so. Candidates judge the maturity of the team by it.

Before you publish

  • One seat, the environment and the analyst's authority are in the summary.
  • The schedule, on-call and any shift differential are stated.
  • Citizenship, clearance and qualification lines appear only where a contract or law requires them.
  • Certifications match the level and accept any current version.
  • Classification is reviewed, and an approved pay range, the EEO statement and an accommodation contact close the posting.

Questions people ask

Can a cybersecurity analyst posting require U.S. citizenship?

Only when a law, regulation, executive order or government contract requires it, according to the Justice Department's Immigrant and Employee Rights Section. Requiring citizenship for an ordinary commercial security job risks citizenship status discrimination. If a contract or clearance requires it, say that in the posting and keep the wording tied to the requirement.

Should a cybersecurity analyst job description require CISSP?

Not for most analyst seats. ISC2 requires at least five years of cumulative paid work in two or more of the eight CISSP domains, with up to one year waived for a qualifying degree or credential, so it marks experienced practitioners. Security+ or CySA+ fit analyst levels better, and many good analysts hold neither. List certifications as preferred unless a contract requires them.

What is the difference between a SOC analyst and a GRC analyst posting?

A SOC analyst monitors alerts, investigates suspicious activity and escalates incidents, often on shifts. A governance, risk and compliance analyst runs control assessments, policies, audits and vendor risk reviews on a business schedule. The skills, hours and candidate pools are different, so write separate postings.

Is a cybersecurity analyst exempt from overtime?

It depends on the duties and pay. Security engineers who design or modify systems often fit the computer employee exemption, which requires at least $684 a week on a salary basis or $27.63 an hour. An entry-level analyst who follows a fixed triage playbook needs a closer review. Shift roles are often classified as overtime-eligible.