Information Security Analysts
Plan, implement, upgrade, or monitor security measures for the protection of computer networks and information. Assess system vulnerabilities for security risks and propose and implement risk mitigation strategies. May ensure appropriate security controls are in place that will safeguard digital files and vital electronic infrastructure. May respond to computer security breaches and viruses.
Context coveredEnterprise security operations, application security, GRC, threat intel, incident response, and security engineering across financial services, healthcare, tech, and government.
- SIEM alert triage (Splunk, Sentinel, Chronicle) — investigate per runbook under a senior analyst's review.
- Phishing analysis and email-threat investigations — work the queue on a tier-1 rotation.
- Vulnerability-scan output (Nessus, Qualys, Wiz) — interpret and prioritize routine findings.
- Standard runbooks for common alerts — execute correctly and document outcomes.
- Tickets and case-tracking in the ITSM platform — log accurately for downstream investigation.
- Endpoint-detection tools (CrowdStrike, SentinelOne) — interpret detections on a standard threat profile.
- Common attack frameworks (MITRE ATT&CK) — recognize techniques in alerts at the tactic level.
- Authentication and identity basics (SSO, MFA, SAML, OIDC) — explain and apply correctly.
- Network-traffic analysis basics (firewall logs, DNS, NetFlow) — read and pattern-match on routine sessions.
- Compliance frameworks (SOC 2, ISO 27001 high-level) — recognize control families in audit prep.
- Multi-source alert investigations — correlate across SIEM, EDR, identity, and network with reduced oversight.
- Routine incident response — execute tier-2 containment and eradication on familiar threat types.
- Vulnerability prioritization — assess CVSS, exploitability, and asset context to drive patching decisions.
- Threat-intel ingestion and operationalization — turn IOCs and TTPs into detection rules.
- Cloud-security configuration (AWS, Azure, GCP IAM and network controls) — review and remediate in routine cases.
- Detection engineering (basic SIEM queries, custom rules) — write and tune for the SOC's standard threats.
- Junior analysts on alert triage — coach during their first 90 days.
- On-call shifts in the SOC rotation — handle independently with senior backstop.
- Compliance audit evidence collection — produce for SOC 2 / ISO 27001 cycles without manager involvement.
- Tabletop exercises — participate substantively in SOC and broader-IR drills.
- Complex incident response — lead investigation, containment, eradication, and recovery on owned incidents.
- Adversary-simulation findings (red-team, pentest) — translate into detection and prevention improvements.
- Security-tool selection and deployment — own a category (EDR, SIEM, CSPM) end-to-end.
- Risk assessments and threat models for new systems — produce credibly with engineering teams.
- Detection engineering at scale — design and tune across a comprehensive rule set.
- On-call leadership — manage the SOC rotation, training, and escalation across a quarter.
- Mentorship across the analyst team — provide on technique, tools, and career development.
- Cross-functional partnerships (engineering, legal, privacy) — collaborate substantively on security initiatives.
- Compliance and audit findings — represent the security team in audit closure discussions.
- Security-awareness program contributions — design content and measure effectiveness.
- Security strategy and roadmap — set, communicate, and execute across the organization.
- Major incident response — lead through containment, executive comms, and regulator notification on a real breach.
- Security architecture at organization scale — design, evolve, and defend across the enterprise.
- Security-team hiring, leveling, and development — shape across the org over multi-year horizons.
- Vendor and tooling strategy — set the framework and trade-offs at scale.
- Board and executive reporting on security posture — represent credibly across regulatory and stakeholder contexts.
- Industry presence (BSides, BlackHat, ISACs) — engage at expert level across a specialty.
- Threat-intelligence program — own at organization or sector level.
- Crisis leadership (regulator inquiry, public breach, ransomware) — lead the organization through with composure.
- Security culture and practices — shape through standards, rituals, and partnerships across the enterprise.
AI-at-Work Competency Framework
A 4-level framework describing how a worker at each mastery level uses, directs, and evaluates AI tools in this occupation. Each statement cites its evidence inline. Subscribe for $19.99/mo to read the full framework — or sign in if you have a subscription.
- Emerging
- Developing
- Proficient
- Advanced
Pathsmith™ Durable Skills Framework
Pathsmith™ Durable Skills Framework
Ten durable-skill domains mapped to four proficiency levels for this occupation. Subscribe to unlock the full Pathsmith™ Durable Skills Framework across all 1,016 occupations.
Show O*NET source anchors57 anchors · skillscrosswalk.com
O*NET enrichment · skillscrosswalk.com
Suggest an O*NET correctionSource anchors that ground each statement
- Develop plans to safeguard computer files against accidental or unauthorized modification, destruction, or disclosure and to meet emergency data processing needs.
- Monitor current reports of computer viruses to determine when to update virus protection systems.
- Encrypt data transmissions and erect firewalls to conceal confidential information as it is being transmitted and to keep out tainted digital transfers.
- Perform risk assessments and execute tests of data processing system to ensure functioning of data processing activities and security measures.
- Modify computer security files to incorporate new software, correct errors, or change individual access status.
- Review violations of computer security procedures and discuss procedures with violators to ensure violations are not repeated.
- Document computer security and emergency measures policies, procedures, and tests.
- Confer with users to discuss issues such as computer data access needs, security violations, and programming changes.
Sources: O*NET v30.2 (CC BY 4.0), SkillsCrosswalk.com, LER.me®, Anthropic Economic Index, SAFI (Jadhav & Danve, 2026), WEF Skills Taxonomy 2021, Pathsmith™ Durable Skills Framework. © 2026 EBSCOed.