Skip to content
Breaking into cybersecurity

How to write a cybersecurity CV with no experience (with a sample)

Writing a cybersecurity resume with no experience? Show lab work, transferable skills and study honestly. Includes a full sample CV for a career switcher.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 8 min read

A cybersecurity CV with no experience works when it swaps job titles for evidence: things you have built, broken in a lab, written up and can talk about in an interview. Hiring managers for junior roles know you have not worked in security yet. What they want to see is that you can learn on your own, that you can explain your work clearly, and that what you did before carries over.

This guide covers what goes on the page, in what order, and how to word it. At the end there’s a full two-page sample CV for a fictional career switcher in British format. Some people search for a cybersecurity résumé rather than a CV. For most junior roles the advice is the same. The conventions differ a little by country, and we flag that below.

What do employers look for on a junior cybersecurity CV?

When a team lead skims thirty applications for a junior SOC analyst or graduate security role, they are usually checking four things quickly:

  1. Can this person do the basics? That means networking, Linux and Windows, how logs work, and common attacks.
  2. Is there proof, or just claims? “Familiar with SIEM” means little. “Built a Wazuh lab, wrote three detection rules and documented the false positives” means a lot.
  3. Can they write? Security work produces tickets, incident notes and reports. Your CV is the first writing sample you send.
  4. Will they fit the role? Shift work, customer contact, regulated environments. Previous jobs often answer this better than any course.

The NICE Workforce Framework from NIST breaks security work into roles and the knowledge and skills each one needs. Look up the role you are targeting and borrow its vocabulary where it honestly describes what you have done.

The structure that works (British CV conventions)

In the UK and many other markets, a CV for a career starter is one to two A4 pages, in reverse chronological order, with these sections:

Section What goes in it Common mistake
Header Name, town or city, phone, email, LinkedIn, GitHub or blog link Full home address, date of birth, photo
Personal profile 3–4 lines: who you are, what you are targeting, your strongest evidence Clichés like “passionate self-starter” with nothing behind them
Key skills 8–12 specific, honest skills, grouped A list of 40 tools you’ve opened once
Projects and lab work Your main evidence, with outcomes “Completed rooms on a training platform” with no detail
Certifications and training Exam-based certifications, then courses Listing a course certificate as if it were a certification
Employment history Reverse chronological, with security-relevant achievements Copying the job description
Education Degree, diploma or school results, briefly Taking half a page

Leave out your photo, date of birth, marital status, religion, state of origin and national ID numbers. UK employers don’t expect them, and including them can raise discrimination concerns. Nigerian CVs often include some of these by habit, so remove them when you apply internationally. “References available on request” is optional. Most UK recruiters assume it, so you can use the line for something more useful.

If you need sponsorship or already have the right to work in the country, say so in one line in the header or profile. It saves everyone time.

How do you write a CV when you have no cybersecurity experience?

You turn learning into evidence and translate your old job. Three techniques do most of the work.

1. Lead with projects, not courses

A project entry should answer: what did you build or test, how, and what did you find or learn? Use this pattern:

Action + tool/technique + scope + result you can measure or describe

Weak: “Used Nmap and Wireshark.” Strong: “Scanned a 6-host home lab network with Nmap, identified an outdated SMB service on a Windows Server VM, patched it and confirmed the fix with a rescan; wrote up the process on my blog.”

If you don’t have a lab yet, building one is the fastest way to create CV material. Our guide to setting up a cybersecurity home lab walks through free and low-cost options. Write up each exercise as you go, because a public write-up is something an interviewer can actually read.

A quick reminder for anything offensive you put on your CV: only test systems you own or have written permission to test. “I scanned my employer’s network to practise” is a red flag, not an achievement.

2. Translate your previous job

Most careers contain security-adjacent work. Pull it out with specific verbs:

Previous role Security-relevant work to highlight
Bank customer service or operations Fraud flags, KYC checks, handling account-takeover complaints, following escalation procedures
IT support / help desk Password resets and identity checks, endpoint setup, patching, phishing reports from users
Audit, compliance, legal Evidence gathering, control testing, policy writing, regulatory reporting
Teaching or training Explaining technical topics, writing materials, awareness sessions
Logistics, retail management Incident handling under pressure, shift handovers, process documentation

Quantify only what you can stand behind: “handled around 40 customer queries a day” is fine if true. Don’t invent figures. Interviewers ask about them.

3. Be precise about certifications

A certificate shows you completed a course. A certification is an exam-based credential from a certifying body, such as CompTIA. Put them under clear labels and never blur the two. If you’re studying for an exam, write it honestly:

  • CompTIA Security+ (SY0-701): in progress, exam booked for [month year]

Only write “booked” if it is. “In progress” with a target month is fine too. Check CompTIA’s Security+ page for current exam details before you name a version, because CompTIA says Security+ V8 is expected on or around 17 November 2026, and SY0-701 is still available.

Tailoring for ATS and humans

Many employers run CVs through an applicant tracking system before a human sees them. Keep the file friendly to both:

  • Use a single-column layout, standard headings (“Employment history”, not “My journey”), and a .docx or text-based PDF.
  • Mirror the job advert’s wording where it is true. If the advert says “SIEM triage”, and you triaged alerts in Wazuh, write “SIEM alert triage (Wazuh)”.
  • Skip skill bars and star ratings. “Python ★★★☆☆” tells a reader nothing and confuses parsers.
  • Name the file sensibly: Firstname-Lastname-CV-SOC-Analyst.pdf.

Keep a master CV with everything on it, then trim a copy for each application. A SOC analyst version leads with log analysis and detection work. A GRC version leads with policy, audit and risk work.

Sample cybersecurity CV for a career switcher

Illustrative example, not a real person. The details below are invented to show structure and wording. Replace every placeholder with your own true information.


[YOUR NAME] Lagos, Nigeria (open to remote and relocation) · +234 [number] · [name]@example.com linkedin.com/in/[profile] · github.com/[username] · [yourblog].example.com

Personal profile Former retail-banking operations officer moving into security operations. Five years handling fraud alerts, KYC checks and customer account-compromise cases under strict escalation procedures. Over the past nine months I have built a home SOC lab, written detection rules for common Windows attacks and published write-ups of each exercise. Studying for CompTIA Security+ and looking for a junior SOC analyst role.

Key skills

  • Security operations: SIEM alert triage (Wazuh, Splunk Free), Windows event log analysis (4624, 4625, 4688, 4720), phishing email analysis, basic incident documentation
  • Networking and systems: TCP/IP, DNS, HTTP; Nmap; Wireshark; Linux command line (Ubuntu, Kali); Windows Server and Active Directory basics
  • Scripting: Python and Bash for log parsing and small automation tasks
  • Professional: written reporting, escalation handling, working to regulatory procedures, shift handovers

Projects and lab work Home SOC lab | Jan 2026 – present

  • Built a 5-VM lab (Windows Server domain controller, two Windows 10 clients, Ubuntu server, Kali) on VirtualBox with an isolated host-only network.
  • Deployed Wazuh and forwarded Sysmon and Windows Security logs; wrote 4 custom rules for brute-force logons, new local admin accounts and suspicious PowerShell.
  • Simulated password spraying from Kali against my own domain controller, detected it in Wazuh and documented the detection logic and the false positives I tuned out.

Phishing analysis write-ups | Mar 2026 – present

  • Analysed 10 phishing samples from public training sets: header analysis, URL and attachment checks in a sandbox VM, and IOC extraction.
  • Published each analysis with a standard template (summary, indicators, verdict, recommended action).

Python log parser | May 2026

  • Wrote a script that parses Linux auth.log for failed SSH logons and outputs the top source IPs and usernames to CSV; code and README on GitHub.

Certifications and training

  • CompTIA Security+ (SY0-701): in progress, exam planned for [month year]
  • [Course name], [provider]: course certificate, [month year]
  • Hands-on labs on [training platform]: SOC and blue-team learning paths

Employment history Operations Officer, Retail Banking | [Bank name], Lagos | 2021 – present

  • Reviewed daily fraud-monitoring alerts and escalated suspicious transactions according to bank procedure.
  • Handled customer reports of account compromise: verified identity, froze access, logged cases and coordinated with the fraud team.
  • Wrote step-by-step guides for new staff on KYC document checks; adopted across the branch team.
  • Ran short sessions for colleagues on recognising phishing calls and messages.

Customer Service Representative | [Company name], Lagos | 2019 – 2021

  • Resolved account and payment queries by phone and email; trained in data-protection handling of customer records.

Education B.Sc. Economics, [University], 2019

Additional

  • Right to work: Nigeria. Open to relocation; would require visa sponsorship for UK roles.
  • Interests: CTF events (blue-team categories), writing technical explainers.

Look at what this sample does. The profile names a target role. Each project bullet starts with a verb and ends with something concrete. The banking bullets are chosen because they show escalation, identity checks and fraud handling. Nothing claims more than the person has done.

Common mistakes to avoid

  • A skills section with tools you can’t demonstrate. Expect interviewers to pick any item and ask, “Walk me through the last time you used that.”
  • Claiming a certification you haven’t passed. Employers can verify CompTIA certifications, and a false claim ends the process.
  • Leaving out your previous career. Five years of regulated work is an asset; don’t shrink it to one line.
  • Generic objective statements. “Seeking a challenging role in a dynamic organisation” can go.
  • Spelling and formatting errors. In a field that values attention to detail, they cost more than in most.

For UK-facing roles, the NCSC’s cyber skills pages explain the skills routes and frameworks UK employers recognise. For the wider question of how to get your first role, read how to get into cybersecurity with no experience.

Questions

Should my cybersecurity CV be one page or two?

Two A4 pages at most for UK-style CVs. One strong page beats two padded ones. US entry-level applications often aim for a single page.

Do I need a degree to get shortlisted?

Not always. Many junior roles weigh certifications, lab evidence and transferable experience. See [how to get into cybersecurity without a degree](/blog/get-into-cybersecurity-without-a-degree).

Should I include a cover letter?

If the application allows one, yes. Keep it short. Name the role, link your best write-up, and explain the career switch in two or three sentences.

Can I list training-platform badges?

Yes, under training, but describe what you did. A badge alone doesn't tell the reader much.

Is it fine to put my home lab on my CV?

Yes. For career switchers it is often the strongest section, as long as you can talk about it in detail.