Skip to content
Cyber Recrut

The cybersecurity CV that makes recruiters call you

Structure, proven skills, certifications, ATS keywords and LinkedIn: how to write a clear, credible cybersecurity CV that actually gets you interviews.

Published on 7 min read

Many cybersecurity CVs look alike: a column of tools, a list of certifications, vague job titles. Yet whoever reads it, recruiter or practitioner, is looking for one thing: proof that you can do the job. Here is how to build a CV that shows capabilities rather than keywords, without breaching your former employers' confidentiality.

The structure that works

A busy reader scans your CV in a few seconds before deciding whether to read it properly. Make that easy with a predictable structure.

  1. Header: name, city (or region), mobility and remote preferences, email, phone, LinkedIn link, and a GitHub or technical blog if you have one.
  2. Two or three line summary: the target role, your specialty and what sets you apart. "Tier 2 SOC analyst specialising in detection on Microsoft environments, looking to move into incident response."
  3. Key skills: four to six grouped areas, not a cloud of logos.
  4. Professional experience: most recent first, with concrete achievements under each role.
  5. Projects and practice: home lab, CTFs, open source contributions, published research.
  6. Certifications and education.
  7. Languages: in France, your level of English matters, since much of the documentation and many teams work in English. If you are applying in France, say whether you work comfortably in French too.

Two pages at most for an experienced profile, one page if you are starting out. A clean, readable layout, exported as PDF.

Skills you demonstrate, not skills you claim

"Proficient in Splunk, Wireshark, Burp Suite, Nmap" says nothing about your level. What convinces is a capability tied to evidence. For each important skill, ask yourself three questions: what did I do, in what context, with what result?

Sources of evidence

  • Your experience: incidents handled, detection rules written, audits led, hardening carried out.
  • Your personal projects: a home lab with Active Directory, a SIEM and simulated attacks is often worth more than a line of tools. Our guide to becoming a SOC analyst explains how to build one.
  • CTFs and training platforms: name the categories (web, forensics, Active Directory) and what you took from them, rather than just a ranking.
  • Your writing: write-ups, articles, meetup talks. A link beats a claim.

Talking about incidents without breaching confidentiality

You may not reveal a client's name, an unpatched vulnerability or the details of a compromise. You can, however, describe the nature of the work:

  • Anonymise the context: "a healthcare organisation", "an estate of several thousand endpoints".
  • Describe your method and your role rather than the sensitive facts.
  • Never include exploitable technical detail about a system still in production.

Hold the same line in interviews. A serious recruiter will value your discretion: it is a skill in itself.

Before and after: rewriting your experience bullets

BeforeAfter
Monitoring SIEM alertsHandled tier 1 and tier 2 alerts on a SIEM covering endpoints, servers and email, with documented escalation to the incident response team
Performing pentestsPenetration tests of internal web applications and APIs, report writing and debriefs with development teams
Vulnerability managementSet up a monthly scanning cycle and remediation tracking prioritised by severity and exposure, shared with operations teams
User awarenessDesigned and ran simulated phishing campaigns, followed by targeted workshops for the most exposed departments
AWS cloud knowledgeReviewed AWS account configurations (IAM, logging, exposed storage) and fixed the gaps with the platform teams

The right-hand version starts with an action verb, sets the scope and shows your role. If you have a real, shareable figure (number of rules written, improved handling time), add it. If not, don't invent one: a dubious number does not survive the first question.

Where to put certifications

Certifications reassure readers and get you through filters, but they don't replace practice. Put them in a dedicated section with the year obtained, and mention the most relevant one in your summary if the role expects it (for example a recognised offensive certification for a pentester role).

  • Remove expired ones and those unrelated to the target role.
  • Don't write "in progress" without a planned exam date.
  • Practical certifications, which require passing a hands-on exam, carry more weight with practitioners.

To see which ones really count for each role, read our article on cybersecurity certifications and hiring.

If you are changing careers

System and network administrators, developers, operations engineers: you often already have part of the skill set. Your CV has to make it visible.

  • Translate your experience into security terms: access management, hardening, backups, logging, code review, patch management.
  • Put practice first: a "Security projects" section above your experience, if that is your strongest asset.
  • Own the transition in your summary: "Linux systems administrator for six years, moving into defensive security, with a home lab and ongoing training."

Our employer-side article on career changers explains what companies look for in these profiles.

ATS keywords, without stuffing

Many companies filter applications with an applicant tracking system (ATS). These tools compare your CV with the job ad.

  • Reuse the job ad's vocabulary where it truly describes what you do: "incident response", "EDR", "ISO 27001", "penetration testing".
  • Write the full term and the acronym once: "identity and access management (IAM)".
  • Put keywords inside your achievements, not in a hidden block or a list of fifty tools.
  • Avoid complex layouts: multiple columns, tables, text inside images; some ATS parse them poorly.

Stuffing is obvious as soon as a human takes over. And in a technical interview, every word on your CV can become a question. Our guide to passing a cybersecurity technical interview helps you prepare.

What to remove

  • Tools you only saw once during a course.
  • Skill bars and star ratings: they mean nothing.
  • Unnecessary personal details (an unrequested photo, date of birth, marital status).
  • Confidential details about clients or incidents.
  • Old roles unrelated to the target job, summarised in a single line.
  • Empty phrases such as "passionate", "detail-oriented", "proactive", unless something proves them.

Aligning LinkedIn with your CV

Recruiters and managers almost always check your LinkedIn profile. Mismatched dates or titles create needless doubt.

  • Same titles, same dates, same employers.
  • An explicit headline: role and specialty, rather than "open to opportunities".
  • An "About" section that expands on your CV summary.
  • Your projects, write-ups and certifications featured.
  • Care with what you post: reveal nothing sensitive about your employers or their systems.

The checklist before you send it

  • The summary clearly states the target role and your specialty.
  • Every role includes at least one concrete achievement.
  • I can talk for five minutes about every tool I list.
  • No confidential information about a client or an incident.
  • Certifications are dated and relevant.
  • The job ad's keywords appear wherever they are true.
  • The CV fits on one or two pages, as a readable PDF.
  • LinkedIn is consistent with the CV.
  • Someone else has proofread it, ideally a practitioner.

In short

A good cybersecurity CV doesn't try to say everything: it shows, with evidence, that you can do the target job. Fewer logos, more achievements; fewer adjectives, more context. And if your background is unusual, demonstrable practice becomes your best argument.

That is exactly how we work. At Cyber Recrut, we introduce you to companies for your real skills, not for your CV layout: our shortlisted candidates prove their skills on hands-on labs. Join the network for free and see how we work.

Related articles