How to write a Cybersecurity CV

The conventions below are the ones this field actually uses. They are what the builder applies when you pick Cybersecurity, and what the rating checks a finished CV against.

What it must contain

Leave any of these out and the CV reads as incomplete to someone who hires in this field:

  • Security Skills
  • Work experience — Scope matters: estate size, incidents handled, mean time to detect, findings closed.
  • Security Certifications — OSCP, CISSP, CEH, Security+ and their dates. These are screened on before anything else.

The order to put them in

Order is not cosmetic. What sits at the top is what gets read before someone decides whether to keep reading.

  1. Professional summary
  2. Security Skills
  3. Security Certifications
  4. Work experience
  5. Projects
  6. Education
  7. Achievements
  8. Languages
  9. Licences & registrations
  10. Publications

Section by section

  • Projects — CTF placings, CVEs credited to you, and public write-ups all count as evidence.

What to put numbers on

The single most common reason a CV in this field reads as weak is that nothing in it is measured. These are the figures that mean something here:

mean time to detect · incidents handled · endpoints · findings closed · CVSS · phishing click rate

Verbs that carry weight

Openers like “responsible for” and “worked on” describe a job description rather than a person. In this field these do the work instead:

Hardened · Detected · Contained · Audited · Patched · Simulated · Reduced

Length

1 to 2 pages is normal for this field.

Free, no account, and nothing is uploaded — the builder runs in your browser and the CV never leaves it.

Related fields

Data · IT Support · Product Management · Software