Home › HRMS › Job roles › Information Technology › Security Analyst
Information Technology · Mid level

Security Analyst job description

A Security Analyst protects a company's systems and data by monitoring for threats, investigating alerts and closing security gaps. They review logs and alerts from security tools, respond to incidents, run vulnerability scans and help teams fix weaknesses before attackers use them. A good analyst tells a real threat from noise, acts quickly during an incident, and helps the business meet its security and compliance obligations. The role sits in the information security or IT team and reports to a security lead or manager.

DetailFor this role
DepartmentInformation Technology
LevelMid level
Reports toInformation Security Manager
Direct reportsNone
Experience2 to 5 years in a security operations or IT security role

Security Analyst job description template

Copy this job description, replace the text in square brackets and post it on your careers page or a job portal.

Job title: Security Analyst

Department: Information Technology

Reports to: Information Security Manager

Location: [City], [office, branch or site]

About the role

A Security Analyst protects a company's systems and data by monitoring for threats, investigating alerts and closing security gaps. They review logs and alerts from security tools, respond to incidents, run vulnerability scans and help teams fix weaknesses before attackers use them. A good analyst tells a real threat from noise, acts quickly during an incident, and helps the business meet its security and compliance obligations. The role sits in the information security or IT team and reports to a security lead or manager.

Key responsibilities

  • Monitor security alerts from the SIEM, endpoint and network tools, and triage them by real risk.
  • Investigate suspected incidents, gather evidence, contain the threat and document the timeline.
  • Run vulnerability scans, prioritise findings by severity and track fixes with the owning teams.
  • Review firewall, access and identity logs for unusual activity and follow up on anomalies.
  • Manage user access reviews and flag excessive or dormant privileges for cleanup.
  • Test phishing awareness, run security drills and help train staff on safe practices.
  • Maintain security documentation, runbooks and evidence for audits and certifications.
  • Apply and verify security patches and configuration hardening across servers and endpoints.
  • Support compliance work by mapping controls to standards and closing gaps.
  • Report the security posture, open risks and incident trends to the security manager.

Requirements

  • Graduate in computer science, IT or a related field
  • Security certification such as CompTIA Security+ or CEH
  • Knowledge of a SIEM and endpoint protection tools
  • 2 to 5 years in a security operations or IT security role

KRAs and KPIs for a Security Analyst

Key result areas for the appraisal form, each with a KPI you can measure every month or quarter.

Key result areaHow to measure it
Alert triagePriority alerts triaged within the agreed time, with false positives tracked and reduced
Incident responseConfirmed incidents contained within the response time set by policy
Vulnerability closureCritical vulnerabilities remediated within the agreed patch window
Access hygieneAccess reviews completed on schedule with excess privileges removed
AwarenessPhishing simulation failure rate reduced quarter on quarter
Audit readinessSecurity evidence produced for audits with no major findings

Skills and tools

SIEM monitoringIncident responseVulnerability managementLog and network analysisIdentity and access reviewEndpoint securitySecurity frameworks awarenessAnalytical thinkingCalm under pressure

Tools used day to day: SIEM platform, EDR tools, Nessus, Wireshark, Firewall consoles, Ticketing system.

Reporting line and career path

Information SecurityManagerSecurity Analyst
Moves up from: SOC Analyst, IT Support Engineer, Network Engineer
Next roles: Senior Security Analyst, Incident Response Lead, Security Engineer

Interview questions for a Security Analyst

  1. Walk me through how you triage a suspicious login alert from first look to closure.
  2. How do you tell a false positive from a real threat in the SIEM?
  3. What are your first actions when you suspect a compromised endpoint?
  4. How do you prioritise vulnerabilities when the fix list is long?
  5. Explain how phishing works and how you reduce the risk from it.
  6. Describe an incident you handled and what you changed afterwards.

Managing a Security Analyst in ZeniaHR

Hire and manage your information technology team in one place

Post the role, onboard the new hire, and track attendance, leave and KRAs in ZeniaHR. Free for your first 50 employees.

Book a free demoSee pricing

Frequently asked questions

What does a security analyst do?

A security analyst monitors a company's systems for threats, investigates alerts, responds to incidents and closes security gaps. They watch logs and security tools, run vulnerability scans, review access and help staff work safely. The goal is to catch and contain attacks early and keep data and systems protected.

What is the difference between a security analyst and a SOC analyst?

A SOC analyst usually works inside a security operations centre, watching alerts around the clock and escalating incidents by tier. A security analyst covers a wider scope: monitoring plus vulnerability management, access reviews, awareness and audit support. In small companies one person does both, while larger firms separate the roles.

What qualifications do you need to become a security analyst?

Most security analysts hold a computer science or IT degree and a certification such as CompTIA Security+ or CEH. Employers value hands on knowledge of a SIEM, endpoint tools and networking more than the paper alone. Many start in IT support or a SOC and move up as they build incident and investigation experience.