NSXNational Skills ExchangeSign in
Back to Framework

Information Security Analysts

SOC 15-1212.00Job Zone 4 · Considerable Preparation

Plan, implement, upgrade, or monitor security measures for the protection of computer networks and information. Assess system vulnerabilities for security risks and propose and implement risk mitigation strategies. May ensure appropriate security controls are in place that will safeguard digital files and vital electronic infrastructure. May respond to computer security breaches and viruses.

Context coveredEnterprise security operations, application security, GRC, threat intel, incident response, and security engineering across financial services, healthcare, tech, and government.

Emerging
Entry / Apprentice
  1. SIEM alert triage (Splunk, Sentinel, Chronicle)investigate per runbook under a senior analyst's review.
  2. Phishing analysis and email-threat investigationswork the queue on a tier-1 rotation.
  3. Vulnerability-scan output (Nessus, Qualys, Wiz)interpret and prioritize routine findings.
  4. Standard runbooks for common alertsexecute correctly and document outcomes.
  5. Tickets and case-tracking in the ITSM platformlog accurately for downstream investigation.
  6. Endpoint-detection tools (CrowdStrike, SentinelOne)interpret detections on a standard threat profile.
  7. Common attack frameworks (MITRE ATT&CK)recognize techniques in alerts at the tactic level.
  8. Authentication and identity basics (SSO, MFA, SAML, OIDC)explain and apply correctly.
  9. Network-traffic analysis basics (firewall logs, DNS, NetFlow)read and pattern-match on routine sessions.
  10. Compliance frameworks (SOC 2, ISO 27001 high-level)recognize control families in audit prep.
Developing
Mid-level / Established
  1. Multi-source alert investigationscorrelate across SIEM, EDR, identity, and network with reduced oversight.
  2. Routine incident responseexecute tier-2 containment and eradication on familiar threat types.
  3. Vulnerability prioritizationassess CVSS, exploitability, and asset context to drive patching decisions.
  4. Threat-intel ingestion and operationalizationturn IOCs and TTPs into detection rules.
  5. Cloud-security configuration (AWS, Azure, GCP IAM and network controls)review and remediate in routine cases.
  6. Detection engineering (basic SIEM queries, custom rules)write and tune for the SOC's standard threats.
  7. Junior analysts on alert triagecoach during their first 90 days.
  8. On-call shifts in the SOC rotationhandle independently with senior backstop.
  9. Compliance audit evidence collectionproduce for SOC 2 / ISO 27001 cycles without manager involvement.
  10. Tabletop exercisesparticipate substantively in SOC and broader-IR drills.
Proficient
Senior / Expert IC
  1. Complex incident responselead investigation, containment, eradication, and recovery on owned incidents.
  2. Adversary-simulation findings (red-team, pentest)translate into detection and prevention improvements.
  3. Security-tool selection and deploymentown a category (EDR, SIEM, CSPM) end-to-end.
  4. Risk assessments and threat models for new systemsproduce credibly with engineering teams.
  5. Detection engineering at scaledesign and tune across a comprehensive rule set.
  6. On-call leadershipmanage the SOC rotation, training, and escalation across a quarter.
  7. Mentorship across the analyst teamprovide on technique, tools, and career development.
  8. Cross-functional partnerships (engineering, legal, privacy)collaborate substantively on security initiatives.
  9. Compliance and audit findingsrepresent the security team in audit closure discussions.
  10. Security-awareness program contributionsdesign content and measure effectiveness.
Advanced
Lead / Principal / Executive
  1. Security strategy and roadmapset, communicate, and execute across the organization.
  2. Major incident responselead through containment, executive comms, and regulator notification on a real breach.
  3. Security architecture at organization scaledesign, evolve, and defend across the enterprise.
  4. Security-team hiring, leveling, and developmentshape across the org over multi-year horizons.
  5. Vendor and tooling strategyset the framework and trade-offs at scale.
  6. Board and executive reporting on security posturerepresent credibly across regulatory and stakeholder contexts.
  7. Industry presence (BSides, BlackHat, ISACs)engage at expert level across a specialty.
  8. Threat-intelligence programown at organization or sector level.
  9. Crisis leadership (regulator inquiry, public breach, ransomware)lead the organization through with composure.
  10. Security culture and practicesshape through standards, rituals, and partnerships across the enterprise.

AI-at-Work Competency Framework

A 4-level framework describing how a worker at each mastery level uses, directs, and evaluates AI tools in this occupation. Each statement cites its evidence inline. Subscribe for $19.99/mo to read the full framework — or sign in if you have a subscription.

  1. Emerging
  2. Developing
  3. Proficient
  4. Advanced
Monthly subscription · Stripe-hosted · unlocks AI-at-Work and Pathsmith Durable Skills across the full library

Ten durable-skill domains mapped to four proficiency levels for this occupation. Subscribe to unlock the full Pathsmith Durable Skills Framework across all 1,016 occupations.

Monthly subscription · Stripe-hosted · unlocks AI-at-Work and Pathsmith Durable Skills across the full library
Show O*NET source anchors57 anchors · skillscrosswalk.com

O*NET enrichment · skillscrosswalk.com

Suggest an O*NET correction

Source anchors that ground each statement

Related titles
Cybersecurity Technician · AI Security Specialist (Artificial Intelligence Security Specialist) · All-Source Analyst · Application Security Analyst · Applications Security Analyst · Automatic Data Processing Systems Security Specialist (ADP Systems Security) · Blue Team Member · Certified Information Systems Security Professional (CISSP) · Cloud Security Architect · Cloud Security Engineer · Computer Security Coordinator · Computer Security Information Specialist
RAPIDS apprenticeships
0220 · Cybersecurity Technician
O*NET skills
Reading ComprehensionCritical ThinkingActive ListeningComplex Problem SolvingSpeakingWritingSystems AnalysisMonitoringJudgment and Decision MakingActive LearningTime ManagementSystems EvaluationQuality Control AnalysisCoordinationOperations Monitoring
Knowledge domains
Computers and ElectronicsEnglish LanguageAdministration and ManagementTelecommunicationsEngineering and TechnologyCustomer and Personal ServicePublic Safety and SecurityEducation and Training
Abilities
Deductive ReasoningProblem SensitivityWritten ComprehensionInductive ReasoningOral ComprehensionInformation OrderingWritten ExpressionNear VisionOral ExpressionCategory Flexibility
Work styles
Attention to DetailIntegrityCautiousnessDependabilityIntellectual CuriosityInnovation
Technology
Word processing softwareAccess softwareNetwork monitoring softwareInternet directory services softwareDevelopment environment softwareObject or component oriented development softwareWeb platform development softwareData base management system softwareData base user interface and query softwareStorage networking software
Tasks · seed anchors for statements
  1. Develop plans to safeguard computer files against accidental or unauthorized modification, destruction, or disclosure and to meet emergency data processing needs.
  2. Monitor current reports of computer viruses to determine when to update virus protection systems.
  3. Encrypt data transmissions and erect firewalls to conceal confidential information as it is being transmitted and to keep out tainted digital transfers.
  4. Perform risk assessments and execute tests of data processing system to ensure functioning of data processing activities and security measures.
  5. Modify computer security files to incorporate new software, correct errors, or change individual access status.
  6. Review violations of computer security procedures and discuss procedures with violators to ensure violations are not repeated.
  7. Document computer security and emergency measures policies, procedures, and tests.
  8. Confer with users to discuss issues such as computer data access needs, security violations, and programming changes.
CIP education codes
11.010311.070111.090111.100111.100211.100311.100543.040351.0723

Sources: O*NET v30.2 (CC BY 4.0), SkillsCrosswalk.com, LER.me®, Anthropic Economic Index, SAFI (Jadhav & Danve, 2026), WEF Skills Taxonomy 2021, Pathsmith Durable Skills Framework. © 2026 EBSCOed.