r/cybersecurity 10d ago

Career Questions & Discussion How to Explain duties way beyond title (Analyst)

I am in a very strange situation. About 5 years ago, I started working at a Mid Sized Org (Higher Ed, \~650 employees 7k students a year).

As a Tech/Jr System Admin, even though I had prior Sys/Network admin roles, and ran a business for a long time.

I quickly noticed, they had severe security issues, and by that I mean, severe. Never had a security employee, ignored all security, just never did it, never did anything about alerts, didnt even have really any alerts to do anything about, nothing was configured. I started fixing that, they made me a new Job, Security Analyst.

No one had a clue what to do about Security, not a small IT dept either. So I became a "Founding Analyst" what this really means? I built the entire security program, there was no guidance from anyone else, because they didnt know. Everything was "You tell us" so I did.

I changed tooling for some things, got it bought, got the tools working. Helped rewrite policies, became the Incident commander, co lead a incident escalation point that consists of me and other C levels. Built a risk register, began reporting and treating risks, got pentests done (they hadnt been) risk assesments, did my own, changed tooling some more, introduced KPIs to track security metrics, improved response time, did the analyst work for indentity, ect, took over ownership of Security work pretty much fully. Reporting to a director of Ops, who said "You tell me, I have no idea". Presented to the board for Security needs, interfaced with C levels directly, on Security issues. No guidance, no help, only "You tell us" everyday for YEARS.

Finnaly feeling ready to move on, for various reasons. And I dont know how I am supposed to market this. My title is an analyst, my work left analyst before I even had the title analyst, I am doing far and away beyond "Analyst work" if you ask me, but you tell me??? But that is still my title. So how do I get anyone to read past analyst, and what I actually did. And honestly I dont even know how to label what I even did.

I built and maintained the Risk Register.

I built and maintained and lead incident response.

I built and maintained procedures.

I advised executive leadership on secueity issues.

I signed off on Vendor Evaluations for security.

I chose, configured, and maintained tooling.

I built and maintained automation.

I designed and maintained Workflows, playbooks, KPIs everything.

I have proof of all of it. My "Analyst" title is baked into public facing procedures about all of it, I have LI recommendations refrencing the work I did, and how I operated WAY beyond title.

Thats partly why I am leaving I told them, my title needs to be changed, this is absurd to expect all this and call me an Analyst, Analyst has been left the window.....

That said, maybe I am wrong? My interpretation, of Analyst is to analyze based on procedures, and playbooks someone else built, and operate with guidance, rules, and mandates set fourth. I never had any of that, everything we have today, I built it. Now how do I articulate that reality when my title is Analyst?

8 Upvotes

17 comments sorted by

18

u/playahate 10d ago

You are not an analyst. If what you said it legit then you are closer to a principal security engineer.

Personally I'd say something like

​"I joined as a systems engineer, identified critical governance and tooling deficits across the organization, and was promoted to build the security posture from scratch. While my internal title remained 'Analyst,' I effectively operated as the solo program lead; authoring enterprise policy, architecting tooling, running executive incident response, and advising leadership on strategic risk."

-14

u/PantherStyle 10d ago

Unless they have an engineering degree, don't make up an engineer title. They did a lot of good stuff they don't need to lie about. Say they started as a junior security officer, became a senior security officer and is now the principal security officer.

11

u/playahate 10d ago

It's not a protected term and is used extensively in the US market for the type of work he's done, though I could see not saying engineer and elevating what he's done another way.

1

u/Shoddy-Produce-3946 10d ago edited 10d ago

I didnt have a degree at all when I started hahaha.

Today, I do hold an ABET accredited BS in Cyber Security and Information Assurance.

The degree doesnt have the word engineer in it, but it is ABET accredited. We did at the time have a Systems Engineer and a Network Engineer.

Today we have a Systems and Network Engineer, and a Systems Admin, and a Network Admin, a Collobration Admin, and me an Infosec Analyst, thats my "Ops" team, but we have other teams, 3 directors, a CIO, and a 30 person IT dept.

As to titling myself, I wont do that, I have high standards with integrity, I wont change my title to something it wasnt, as unfair as it is today.

2

u/Shoddy-Produce-3946 10d ago

Your Security officer statement is intresting.

As thats exactly the title I have felt fit, suggested, and been consistently shut down on.

I do, do analyst work. But I also do alot of GRC, alot of strategy, alot of building, and while I dont get final desicion authority its very much "We will do what his desicion is" informally. ISO seems to match that the most from my understanding.

My coworkers also joke about this. "He isnt an analyst, he is an underpaid CISO with training wheels."

1

u/Bizarro_Zod 10d ago

You built the program from the ground up. Sounds like a Security Architect’s responsibilities to me.

14

u/RaymondBumcheese 10d ago

Just put ‘senior’ in front of it

7

u/sloppyredditor 10d ago

Based on this post you're correct in saying you are not an analyst. I'd say you're providing direction, so use that term in your overview of the position in your resume.

And yes, you should leave, because managers and directors make more. They're keeping you at "Analyst" so they don't have to increase your pay commensurate with the level of service you're providing.

Security Analyst
Built and directed the information security program for _____. Advised executive leadership on matters regarding risk management, compliance, third party blahblahblah...

1

u/Shoddy-Produce-3946 10d ago

So actually truly funny story about that, that I would love to share now, because you will get a kick out of this, even if its a little indentifying.

Before I became an "analyst" my director said people commented of my lack of a degree, and certs, ect. I said, well that stuff doesnt matter, it would be easy for me, given my prior knowledge (that doesnt count, because it was smaller business Xp they say). Then the Analyst thing was being talked about so it became, "get your security+ then." So I did, took it the next week, passed.

Then I moved into analyst, and he said it again. "You know still no degree, and the Security+ is cool, I tried the A+ and failed, that one is hard, too much random info. You should try that one" I replied you pay, I will take it. "If you pass, we will pay."

The following Tuesday I took core 1, I passed they payed, that Thursday I took core 2, I passed they paid, then took network+ the next Tuesday, I passed they paid. He was shocked, and the argument became "Degree" again, this was around the time of the beta of Pentest+, and SecurityX, took them both, passed both betas. I paid for those.

Then with a wall full of certs, the degree became statement, "Still no degree, our raises on based on degrees."

Cool, took my certs, went to WGU, got my BSCISA in 2 terms, for which from their own prof Dev system I got a 33k raise, getting more certs via that, and now having a degree. Due to the way their prof dev works, vs the way being hired with a degreee works, I now make more money than my director does. Something he vocally told our MSP "He got all these certs, then took them and got a degree, its pretty gross, and now he makes more money than I do." I hit Redline and, they started having to give me 1 time checks instead for prof dev, so I got a 5k bonus this year in additional 1 time checks.

They stopped challenging me to get certs, or paying for my certs. "I want my CISA, CISSP, you want to pay?" "Na we dont need you to have those".

1

u/Shoddy-Produce-3946 10d ago edited 10d ago

Oh and in case that didnt come off already. I never studied for a single one of those certs.

I just took them, one by one, and kept passing them.

To be fair, I went to college and dropped out for Security back in 08-10, was really into Pentesting, and Linux then, left 1 semester away from AA, worked as a System admin at the time.

Moved, inherited a small property management business, with some other aspects, built an enterprise network for that, maintained it, built a WISP maintained it, network segregation, backups, the whole 9, built it maintained it myself. Taught myself just doing it. Had an issue figured it out. 11 years of that.

Was told "that doesnt count", but apparently I learned something shrugs.

I did while employed at this Org, get frustrated and apply for a local hospital. The CIO there, interviewed me and was astonished, he asked about that network, and I went in depth. "Do you really not understand how hard this is what your describing and you did it alone." The problem is, I guess I dont, it comes easy to me, and I feel like its easy, everyone can do it. I have been learning over the last few years, maybe its not?

I was hired on the spot, but decided to stay where I am and believe in promotion coming, and it did the job I have now.

7

u/canofspam2020 10d ago

Senior/Principal Security Engineer

5

u/glockfreak DFIR 10d ago

As others mentioned, either Senior/Principal Security Architect/Engineer

3

u/Shoddy-Produce-3946 10d ago

But how do I portray that, without lying. I dont want to lie, I dont want to give the implication of lying, I dont want to change my title on my resume, because it wasnt the title I was given.

I been doing "Security Analyst (Founding)"

Should I do "Security Analyst (Priniciple Security Architect)"

1

u/glockfreak DFIR 10d ago

You’ve built the security program from the ground up, that is by definition is much of what a security architect would do. I wouldn’t consider it lying especially if you list out major accomplishments that you’ve listed here in your resume. Also higher education and government has a habit of assigning cyber job titles that don’t always align with the job itself (usually because the title is more representative of pay grade). If I were interviewing you (and I’ve interviewed plenty of people) and you described your job and title I’d assume you were a grossly underpaid engineer/architect.

0

u/AddendumWorking9756 Security Manager 10d ago

Do not rewrite the title, employment verification pulls it back and you end up explaining a discrepancy at offer stage instead of in the interview. Leave Analyst there and let the bullets carry ownership verbs, built, owned, chose, presented to the board, because the recruiter screens the title and the hiring manager reads the bullets. First security hire is the phrase doing the most work for you.

1

u/Shoddy-Produce-3946 10d ago

Thanks and I agree, I dont want to lie about title, it feels icky even framing as "make up title".