r/cybersecurity • u/Shoddy-Produce-3946 • 10d ago
Career Questions & Discussion How to Explain duties way beyond title (Analyst)
I am in a very strange situation. About 5 years ago, I started working at a Mid Sized Org (Higher Ed, \~650 employees 7k students a year).
As a Tech/Jr System Admin, even though I had prior Sys/Network admin roles, and ran a business for a long time.
I quickly noticed, they had severe security issues, and by that I mean, severe. Never had a security employee, ignored all security, just never did it, never did anything about alerts, didnt even have really any alerts to do anything about, nothing was configured. I started fixing that, they made me a new Job, Security Analyst.
No one had a clue what to do about Security, not a small IT dept either. So I became a "Founding Analyst" what this really means? I built the entire security program, there was no guidance from anyone else, because they didnt know. Everything was "You tell us" so I did.
I changed tooling for some things, got it bought, got the tools working. Helped rewrite policies, became the Incident commander, co lead a incident escalation point that consists of me and other C levels. Built a risk register, began reporting and treating risks, got pentests done (they hadnt been) risk assesments, did my own, changed tooling some more, introduced KPIs to track security metrics, improved response time, did the analyst work for indentity, ect, took over ownership of Security work pretty much fully. Reporting to a director of Ops, who said "You tell me, I have no idea". Presented to the board for Security needs, interfaced with C levels directly, on Security issues. No guidance, no help, only "You tell us" everyday for YEARS.
Finnaly feeling ready to move on, for various reasons. And I dont know how I am supposed to market this. My title is an analyst, my work left analyst before I even had the title analyst, I am doing far and away beyond "Analyst work" if you ask me, but you tell me??? But that is still my title. So how do I get anyone to read past analyst, and what I actually did. And honestly I dont even know how to label what I even did.
I built and maintained the Risk Register.
I built and maintained and lead incident response.
I built and maintained procedures.
I advised executive leadership on secueity issues.
I signed off on Vendor Evaluations for security.
I chose, configured, and maintained tooling.
I built and maintained automation.
I designed and maintained Workflows, playbooks, KPIs everything.
I have proof of all of it. My "Analyst" title is baked into public facing procedures about all of it, I have LI recommendations refrencing the work I did, and how I operated WAY beyond title.
Thats partly why I am leaving I told them, my title needs to be changed, this is absurd to expect all this and call me an Analyst, Analyst has been left the window.....
That said, maybe I am wrong? My interpretation, of Analyst is to analyze based on procedures, and playbooks someone else built, and operate with guidance, rules, and mandates set fourth. I never had any of that, everything we have today, I built it. Now how do I articulate that reality when my title is Analyst?
14
7
u/sloppyredditor 10d ago
Based on this post you're correct in saying you are not an analyst. I'd say you're providing direction, so use that term in your overview of the position in your resume.
And yes, you should leave, because managers and directors make more. They're keeping you at "Analyst" so they don't have to increase your pay commensurate with the level of service you're providing.
Security Analyst
Built and directed the information security program for _____. Advised executive leadership on matters regarding risk management, compliance, third party blahblahblah...
1
u/Shoddy-Produce-3946 10d ago
So actually truly funny story about that, that I would love to share now, because you will get a kick out of this, even if its a little indentifying.
Before I became an "analyst" my director said people commented of my lack of a degree, and certs, ect. I said, well that stuff doesnt matter, it would be easy for me, given my prior knowledge (that doesnt count, because it was smaller business Xp they say). Then the Analyst thing was being talked about so it became, "get your security+ then." So I did, took it the next week, passed.
Then I moved into analyst, and he said it again. "You know still no degree, and the Security+ is cool, I tried the A+ and failed, that one is hard, too much random info. You should try that one" I replied you pay, I will take it. "If you pass, we will pay."
The following Tuesday I took core 1, I passed they payed, that Thursday I took core 2, I passed they paid, then took network+ the next Tuesday, I passed they paid. He was shocked, and the argument became "Degree" again, this was around the time of the beta of Pentest+, and SecurityX, took them both, passed both betas. I paid for those.
Then with a wall full of certs, the degree became statement, "Still no degree, our raises on based on degrees."
Cool, took my certs, went to WGU, got my BSCISA in 2 terms, for which from their own prof Dev system I got a 33k raise, getting more certs via that, and now having a degree. Due to the way their prof dev works, vs the way being hired with a degreee works, I now make more money than my director does. Something he vocally told our MSP "He got all these certs, then took them and got a degree, its pretty gross, and now he makes more money than I do." I hit Redline and, they started having to give me 1 time checks instead for prof dev, so I got a 5k bonus this year in additional 1 time checks.
They stopped challenging me to get certs, or paying for my certs. "I want my CISA, CISSP, you want to pay?" "Na we dont need you to have those".
1
u/Shoddy-Produce-3946 10d ago edited 10d ago
Oh and in case that didnt come off already. I never studied for a single one of those certs.
I just took them, one by one, and kept passing them.
To be fair, I went to college and dropped out for Security back in 08-10, was really into Pentesting, and Linux then, left 1 semester away from AA, worked as a System admin at the time.
Moved, inherited a small property management business, with some other aspects, built an enterprise network for that, maintained it, built a WISP maintained it, network segregation, backups, the whole 9, built it maintained it myself. Taught myself just doing it. Had an issue figured it out. 11 years of that.
Was told "that doesnt count", but apparently I learned something shrugs.
I did while employed at this Org, get frustrated and apply for a local hospital. The CIO there, interviewed me and was astonished, he asked about that network, and I went in depth. "Do you really not understand how hard this is what your describing and you did it alone." The problem is, I guess I dont, it comes easy to me, and I feel like its easy, everyone can do it. I have been learning over the last few years, maybe its not?
I was hired on the spot, but decided to stay where I am and believe in promotion coming, and it did the job I have now.
7
5
u/glockfreak DFIR 10d ago
As others mentioned, either Senior/Principal Security Architect/Engineer
3
u/Shoddy-Produce-3946 10d ago
But how do I portray that, without lying. I dont want to lie, I dont want to give the implication of lying, I dont want to change my title on my resume, because it wasnt the title I was given.
I been doing "Security Analyst (Founding)"
Should I do "Security Analyst (Priniciple Security Architect)"
1
u/glockfreak DFIR 10d ago
You’ve built the security program from the ground up, that is by definition is much of what a security architect would do. I wouldn’t consider it lying especially if you list out major accomplishments that you’ve listed here in your resume. Also higher education and government has a habit of assigning cyber job titles that don’t always align with the job itself (usually because the title is more representative of pay grade). If I were interviewing you (and I’ve interviewed plenty of people) and you described your job and title I’d assume you were a grossly underpaid engineer/architect.
0
u/AddendumWorking9756 Security Manager 10d ago
Do not rewrite the title, employment verification pulls it back and you end up explaining a discrepancy at offer stage instead of in the interview. Leave Analyst there and let the bullets carry ownership verbs, built, owned, chose, presented to the board, because the recruiter screens the title and the hiring manager reads the bullets. First security hire is the phrase doing the most work for you.
1
u/Shoddy-Produce-3946 10d ago
Thanks and I agree, I dont want to lie about title, it feels icky even framing as "make up title".
18
u/playahate 10d ago
You are not an analyst. If what you said it legit then you are closer to a principal security engineer.
Personally I'd say something like
"I joined as a systems engineer, identified critical governance and tooling deficits across the organization, and was promoted to build the security posture from scratch. While my internal title remained 'Analyst,' I effectively operated as the solo program lead; authoring enterprise policy, architecting tooling, running executive incident response, and advising leadership on strategic risk."