Occupation · SOC 15-1212
Information Security Analysts
Plan, implement, upgrade, or monitor security measures for the protection of computer networks and information. Assess system vulnerabilities for security risks and propose and implement risk mitigation strategies. May ensure appropriate security controls are in place that will safeguard digital files and vital electronic infrastructure. May respond to computer security breaches and viruses.
Median wage
$124,910
$69,660–$186,420
Projected growth
+28.5%
Faster than average
Annual openings
5,210
per year
Employed (US)
179,430
Job Zone 4
Typical preparation
Considerable preparation
Stackable credential programs
2,210 mapped
Core skills
Reading ComprehensionCritical ThinkingComplex Problem SolvingActive ListeningSpeakingWritingSystems AnalysisMonitoringJudgment and Decision MakingActive LearningTime ManagementSystems EvaluationQuality Control AnalysisOperations MonitoringCoordinationService OrientationManagement of Personnel ResourcesLearning StrategiesInstructingSocial PerceptivenessProgrammingPersuasionNegotiationOperations AnalysisMathematicsTroubleshootingTechnology DesignScienceOperation and ControlManagement of Material ResourcesManagement of Financial ResourcesEquipment SelectionRepairingEquipment MaintenanceInstallation
Knowledge areas
Computers and ElectronicsEnglish LanguageAdministration and ManagementTelecommunicationsEngineering and TechnologyCustomer and Personal ServicePublic Safety and SecurityEducation and TrainingMathematicsCommunications and MediaLaw and GovernmentAdministrativePersonnel and Human ResourcesProduction and ProcessingDesignEconomics and AccountingPsychologySociology and AnthropologyMechanicalTransportationGeographySales and MarketingPhysicsBuilding and ConstructionForeign LanguageChemistryPhilosophy and TheologyHistory and ArcheologyTherapy and CounselingMedicine and DentistryBiologyFood ProductionFine Arts
Technology & tools
3M Post-it AppAJAXAccess management softwareAccessData FTKActive directory softwareAdobe ActionScriptAdvanced business application programming ABAPAmazon DynamoDBAmazon Elastic Compute Cloud EC2Amazon RedshiftAmazon Simple Storage Service S3Amazon Web Services AWS CloudFormationAmazon Web Services AWS softwareAnsible softwareAnti-Trojan softwareAnti-phishing softwareAnti-spyware softwareApache AntApache CassandraApache GroovyApache HTTP ServerApache HadoopApache HiveApache KafkaApache MavenApache PigApache SolrApache SparkApache StrutsApache Subversion SVNApache TomcatApple macOSArcSight Enterprise Threat and Risk ManagementAtlassian BambooAtlassian ConfluenceAtlassian JIRAAutomated audit trail analysis softwareAutomated installation softwareAutomated media tracking softwareBackup and archival software
Representative tasks
Working with ComputersGetting InformationIdentifying Objects, Actions, and EventsEvaluating Information to Determine Compliance with StandardsProcessing InformationAnalyzing Data or InformationUpdating and Using Relevant KnowledgeDocumenting/Recording InformationCommunicating with Supervisors, Peers, or SubordinatesMaking Decisions and Solving ProblemsMonitoring Processes, Materials, or SurroundingsInterpreting the Meaning of Information for OthersOrganizing, Planning, and Prioritizing WorkThinking CreativelyEstablishing and Maintaining Interpersonal RelationshipsPerforming Administrative ActivitiesDeveloping Objectives and StrategiesEstimating the Quantifiable Characteristics of Products, Events, or InformationCommunicating with People Outside the OrganizationJudging the Qualities of Objects, Services, or PeopleProviding Consultation and Advice to OthersCoordinating the Work and Activities of OthersDeveloping and Building TeamsTraining and Teaching OthersCoaching and Developing OthersScheduling Work and ActivitiesResolving Conflicts and Negotiating with OthersMonitoring and Controlling ResourcesRepairing and Maintaining Electronic EquipmentInspecting Equipment, Structures, or MaterialsGuiding, Directing, and Motivating SubordinatesSelling or Influencing OthersStaffing Organizational UnitsDrafting, Laying Out, and Specifying Technical Devices, Parts, and EquipmentControlling Machines and ProcessesPerforming for or Working Directly with the PublicHandling and Moving ObjectsAssisting and Caring for OthersPerforming General Physical ActivitiesRepairing and Maintaining Mechanical Equipment
Competency framework
Skill expectations by proficiency level.
emerging
SIEM alert triage (Splunk, Sentinel, Chronicle) — investigate per runbook under a senior analyst's review.Phishing analysis and email-threat investigations — work the queue on a tier-1 rotation.Vulnerability-scan output (Nessus, Qualys, Wiz) — interpret and prioritize routine findings.Standard runbooks for common alerts — execute correctly and document outcomes.Tickets and case-tracking in the ITSM platform — log accurately for downstream investigation.Endpoint-detection tools (CrowdStrike, SentinelOne) — interpret detections on a standard threat profile.Common attack frameworks (MITRE ATT&CK) — recognize techniques in alerts at the tactic level.Authentication and identity basics (SSO, MFA, SAML, OIDC) — explain and apply correctly.Network-traffic analysis basics (firewall logs, DNS, NetFlow) — read and pattern-match on routine sessions.Compliance frameworks (SOC 2, ISO 27001 high-level) — recognize control families in audit prep.
developing
Multi-source alert investigations — correlate across SIEM, EDR, identity, and network with reduced oversight.Routine incident response — execute tier-2 containment and eradication on familiar threat types.Vulnerability prioritization — assess CVSS, exploitability, and asset context to drive patching decisions.Threat-intel ingestion and operationalization — turn IOCs and TTPs into detection rules.Cloud-security configuration (AWS, Azure, GCP IAM and network controls) — review and remediate in routine cases.Detection engineering (basic SIEM queries, custom rules) — write and tune for the SOC's standard threats.Junior analysts on alert triage — coach during their first 90 days.On-call shifts in the SOC rotation — handle independently with senior backstop.Compliance audit evidence collection — produce for SOC 2 / ISO 27001 cycles without manager involvement.Tabletop exercises — participate substantively in SOC and broader-IR drills.
proficient
Complex incident response — lead investigation, containment, eradication, and recovery on owned incidents.Adversary-simulation findings (red-team, pentest) — translate into detection and prevention improvements.Security-tool selection and deployment — own a category (EDR, SIEM, CSPM) end-to-end.Risk assessments and threat models for new systems — produce credibly with engineering teams.Detection engineering at scale — design and tune across a comprehensive rule set.On-call leadership — manage the SOC rotation, training, and escalation across a quarter.Mentorship across the analyst team — provide on technique, tools, and career development.Cross-functional partnerships (engineering, legal, privacy) — collaborate substantively on security initiatives.Compliance and audit findings — represent the security team in audit closure discussions.Security-awareness program contributions — design content and measure effectiveness.
advanced
Security strategy and roadmap — set, communicate, and execute across the organization.Major incident response — lead through containment, executive comms, and regulator notification on a real breach.Security architecture at organization scale — design, evolve, and defend across the enterprise.Security-team hiring, leveling, and development — shape across the org over multi-year horizons.Vendor and tooling strategy — set the framework and trade-offs at scale.Board and executive reporting on security posture — represent credibly across regulatory and stakeholder contexts.Industry presence (BSides, BlackHat, ISACs) — engage at expert level across a specialty.Threat-intelligence program — own at organization or sector level.Crisis leadership (regulator inquiry, public breach, ransomware) — lead the organization through with composure.Security culture and practices — shape through standards, rituals, and partnerships across the enterprise.
Also known as
87 alternate job titles map to this occupation.
AI Security Specialist (Artificial Intelligence Security Specialist)All-Source AnalystApplication Security AnalystApplications Security AnalystAutomatic Data Processing Systems Security Specialist (ADP Systems Security)Blue Team MemberCertified Information Systems Security Professional (CISSP)Cloud Security ArchitectCloud Security EngineerComputer Security CoordinatorComputer Security Information SpecialistComputer Security SpecialistComputer Systems Security AnalystCounterespionage AnalystCryptological TechnicianCryptologistCyber Defense AnalystCyber Defense Forensics AnalystCyber Incident ResponderCyber Information Security AnalystCyber Intel PlannerCyber Intelligence SpecialistCyber Operations Planner (Cyber Ops Planner)Cyber Operations SpecialistCyber OperatorCyber Policy and Strategy PlannerCyber Security AnalystCyber Security SpecialistCyber Security Support TechnicianCybersecurity All-Source AnalystCybersecurity AnalystCybersecurity EngineerCybersecurity Exploitation AnalystCybersecurity Incident Response AnalystCybersecurity Multi-Disciplined Language AnalystCybersecurity Partner Integration PlannerCybersecurity SpecialistCybersecurity Target DeveloperCybersecurity Target Network AnalystCybersecurity Threat Analyst