Rewriting Your CV for a Cybersecurity Career Change
How to reframe a non-security background into a CV that gets you interviews for entry-level cybersecurity roles.
Most career changers make the same mistake on their CV: they either bury their old job titles at the top like they don't matter, or they try to force-fit unrelated experience into security language that reads as desperate. Neither works. Hiring managers scanning fifty applications for a SOC analyst role want to see two things fast: proof you can actually do the work, and proof you understand what the work is.
Lead with a skills summary, not a job history
Drop the objective statement nobody reads. Instead, put a 3-4 line summary right under your name that names the specific area you're targeting — SOC analyst, GRC, appsec, whatever it is — and lists two or three concrete things you've done that relate. If you completed a home lab where you set up Splunk to ingest Sysmon logs and wrote detection rules for common attack patterns, say that in the summary, not just buried in a projects section three pages down.
Recruiters and hiring managers spend seconds on first pass. If the top third of the page doesn't signal "this person understands security work," the rest of the CV often doesn't get read.
Translate your old job, don't hide it
If you were a network admin, an accountant, a teacher, or worked IT helpdesk, that experience has real value and pretending it doesn't exist is a mistake. A network admin already knows subnetting, firewall rules, and troubleshooting under pressure — all directly relevant to security operations. An accountant understands controls, audit trails, and regulatory pressure, which maps well onto GRC and compliance work. A helpdesk tech has already dealt with phishing reports and password reset social engineering firsthand.
Write your old bullet points using the verbs and outcomes that matter in security. Instead of "Managed company network infrastructure," write "Administered firewall rules and VPN access for 200+ endpoints, including incident response for suspicious login attempts." Same job, framed for the audience reading it now.
Projects matter more than certifications early on
Certifications like Security+ or the free tier of TryHackMe/HTB paths signal you've studied. But a hiring manager for an entry-level SOC or blue team role wants evidence you've touched tools, not just passed a multiple-choice exam. List 2-3 projects with specifics:
- Built a home SOC lab using Security Onion, generated traffic with a Kali VM, and documented detection of an Nmap scan and a Metasploit exploit attempt in Kibana
- Completed 15+ rooms on TryHackMe's SOC Level 1 path, including log analysis and phishing email triage
- Wrote a Python script using the
pandaslibrary to parse and flag anomalous entries in a sample Apache access log
Each of these takes one line but shows a hiring manager exactly what you can do without them having to guess.
Cut the fluff bullet points
Delete anything that says "team player," "detail-oriented," or "fast learner" with no evidence attached. Every bullet should have a number, a tool, or an outcome. "Reduced ticket resolution time by 30% by creating a shared troubleshooting wiki" tells a story. "Strong communication skills" tells nothing.
If you're short on quantifiable security metrics because you're new to the field, borrow numbers from your prior career and phrase them to highlight transferable traits: scale ("supported 500 end users"), risk handling ("resolved P1 incidents within SLA 95% of the time"), or process improvement.
Keep it to one page if you have under 5 years total experience across all careers combined, two pages max otherwise. Recruiters in security hiring pipelines, especially at larger companies, are often moving fast through applicant tracking systems, and a bloated CV with irrelevant detail from a decade-old job gets skimmed past.
Tailor for the specific job posting
Pull the exact tool names and requirements from the job description and mirror them where honest. If the posting says "experience with SIEM tools (Splunk, QRadar, or Sentinel)" and you've used Splunk in a lab, say Splunk specifically rather than a vague "SIEM experience." ATS keyword matching is real, and specificity also just reads better to a human reviewer.
A cover letter, when required, is the place to explain the career change story in one or two sentences — why security, why now — so the CV itself can stay focused entirely on capability.
If you want to build the kind of hands-on experience that actually fills out a CV like this, Korra Studio's Breaking In and Blue Team tracks walk through building a home lab, working through log analysis exercises, and picking a specialization that matches what you're already good at.
Written with AI assistance, reviewed and published by Michal Pilch (CISSP), Korra Studio.
This is one note from the Korra Studio knowledge base — the platform pairs every topic with 1-to-1 mentoring.
Get started freearrow_forward