Occupation · SOC 15-1212

Information Security Analysts

Plan, implement, upgrade, or monitor security measures for the protection of computer networks and information. Assess system vulnerabilities for security risks and propose and implement risk mitigation strategies. May ensure appropriate security controls are in place that will safeguard digital files and vital electronic infrastructure. May respond to computer security breaches and viruses.

Median wage
$124,910
$69,660–$186,420
Projected growth
+28.5%
Faster than average
Annual openings
5,210
per year
Employed (US)
179,430
Job Zone 4
Typical preparation
Considerable preparation
Stackable credential programs
2,210 mapped

Core skills

Reading ComprehensionCritical ThinkingActive ListeningComplex Problem SolvingSpeakingWritingSystems AnalysisMonitoring

Knowledge areas

Computers and ElectronicsEnglish LanguageAdministration and ManagementTelecommunicationsEngineering and Technology

Technology & tools

Word processing softwareAccess softwareNetwork monitoring softwareInternet directory services softwareDevelopment environment software

Representative tasks

Develop plans to safeguard computer files against accidental or unauthorized modification, destruction, or disclosure and to meet emergency data processing needs.Monitor current reports of computer viruses to determine when to update virus protection systems.Encrypt data transmissions and erect firewalls to conceal confidential information as it is being transmitted and to keep out tainted digital transfers.Perform risk assessments and execute tests of data processing system to ensure functioning of data processing activities and security measures.Modify computer security files to incorporate new software, correct errors, or change individual access status.Review violations of computer security procedures and discuss procedures with violators to ensure violations are not repeated.Confer with users to discuss issues such as computer data access needs, security violations, and programming changes.Document computer security and emergency measures policies, procedures, and tests.Monitor use of data files and regulate access to safeguard information in computer files.Coordinate implementation of computer system plan with establishment personnel and outside vendors.Train users and promote security awareness to ensure system security and to improve server and network efficiency.

Competency framework

Skill expectations by proficiency level.

emerging
SIEM alert triage (Splunk, Sentinel, Chronicle) — investigate per runbook under a senior analyst's review.Phishing analysis and email-threat investigations — work the queue on a tier-1 rotation.Vulnerability-scan output (Nessus, Qualys, Wiz) — interpret and prioritize routine findings.Standard runbooks for common alerts — execute correctly and document outcomes.Tickets and case-tracking in the ITSM platform — log accurately for downstream investigation.Endpoint-detection tools (CrowdStrike, SentinelOne) — interpret detections on a standard threat profile.Common attack frameworks (MITRE ATT&CK) — recognize techniques in alerts at the tactic level.Authentication and identity basics (SSO, MFA, SAML, OIDC) — explain and apply correctly.Network-traffic analysis basics (firewall logs, DNS, NetFlow) — read and pattern-match on routine sessions.Compliance frameworks (SOC 2, ISO 27001 high-level) — recognize control families in audit prep.
developing
Multi-source alert investigations — correlate across SIEM, EDR, identity, and network with reduced oversight.Routine incident response — execute tier-2 containment and eradication on familiar threat types.Vulnerability prioritization — assess CVSS, exploitability, and asset context to drive patching decisions.Threat-intel ingestion and operationalization — turn IOCs and TTPs into detection rules.Cloud-security configuration (AWS, Azure, GCP IAM and network controls) — review and remediate in routine cases.Detection engineering (basic SIEM queries, custom rules) — write and tune for the SOC's standard threats.Junior analysts on alert triage — coach during their first 90 days.On-call shifts in the SOC rotation — handle independently with senior backstop.Compliance audit evidence collection — produce for SOC 2 / ISO 27001 cycles without manager involvement.Tabletop exercises — participate substantively in SOC and broader-IR drills.
proficient
Complex incident response — lead investigation, containment, eradication, and recovery on owned incidents.Adversary-simulation findings (red-team, pentest) — translate into detection and prevention improvements.Security-tool selection and deployment — own a category (EDR, SIEM, CSPM) end-to-end.Risk assessments and threat models for new systems — produce credibly with engineering teams.Detection engineering at scale — design and tune across a comprehensive rule set.On-call leadership — manage the SOC rotation, training, and escalation across a quarter.Mentorship across the analyst team — provide on technique, tools, and career development.Cross-functional partnerships (engineering, legal, privacy) — collaborate substantively on security initiatives.Compliance and audit findings — represent the security team in audit closure discussions.Security-awareness program contributions — design content and measure effectiveness.
advanced
Security strategy and roadmap — set, communicate, and execute across the organization.Major incident response — lead through containment, executive comms, and regulator notification on a real breach.Security architecture at organization scale — design, evolve, and defend across the enterprise.Security-team hiring, leveling, and development — shape across the org over multi-year horizons.Vendor and tooling strategy — set the framework and trade-offs at scale.Board and executive reporting on security posture — represent credibly across regulatory and stakeholder contexts.Industry presence (BSides, BlackHat, ISACs) — engage at expert level across a specialty.Threat-intelligence program — own at organization or sector level.Crisis leadership (regulator inquiry, public breach, ransomware) — lead the organization through with composure.Security culture and practices — shape through standards, rituals, and partnerships across the enterprise.

Also known as

362 alternate job titles map to this occupation.

Cybersecurity Partner Integration PlannerCommand, Control, Communications, Computers and Intelligence (C4I) Officer (Marine Corps 8858)Cyber Capabilities Development Officer (Army 17D)Cyberspace Effects Operations, General (if Prefix P) (Air Force 17S1W)Cyber Operations Planner (Cyber Ops Planner)Surface Cryptologic Carry-On Program (CCOP) Installer (Navy C38B)Cyber Security Support TechnicianCyber Intelligence Craftsman (Air Force 1N471)Cloud Security EngineerInformation Security OfficerCyberspace Effects Operations, Defensive Cyberspace Operator (Air Force 17S2B)Information Systems Security SpecialistInformation Systems Administrator (Navy 746A)Cybersecurity Exploitation AnalystCyberspace Effects Operations, Software Development (Air Force 17S2S)Data Operations Warrant Officer (Army 255A)Communication Watch Officer (Navy 9525)Technology AnalystCloud Security ArchitectAutomatic Logistics Information System (ALIS) Administrator (Navy H40A)Warfighter Communications Operations, Network Operations (Air Force 17D2A)Information Systems Security Officer (ISSO)Cryptologic Warfare Officer (National) (Navy 9826)Warfighter Communications Operations, General (Air Force 17D2Y)Incident Response ManagerAssistant Cryptologic Resource Coordinator (ACRC) (Navy C12A)Cyberspace Warfare Development Officer (Marine Corps 1705)Cyberspace Effects Operations, Capabilities Development (Air Force 17S3C)Surface Cryptologic Carry-On Program (CCOP) Director (Navy C38C)Warfighter Communications Operations, Capabilities Development (Air Force 17D1C)Incident Response AnalystExploitation AnalystCyber Intelligence SpecialistCybersecurity Incident Response AnalystCyberspace Effects Operations, Bomber (Air Force 17S2R)Defensive Cyberspace Warfare Officer (Marine Corps 1720)Communications System Center Director (Navy 9510)Systems AnalystSecurity Assistant (Navy 791A)Cryptologic Infrastructure Maintenance Supervisor (Navy C37B)
← All occupationsEmployer demand by state →