Security postings are dense with terminology, and reviewers use that terminology to gauge whether you've done the work or just read about it. The goal of a security resume isn't to list every acronym you recognize — it's to show, honestly, where you have hands-on evidence and where you have working familiarity. Those are different claims, and conflating them is easy to catch in an interview.
The signals reviewers scan for
Most security roles cluster around a few recurring areas. Knowing the vocabulary lets you map your experience to a posting's language:
- SOC — detection and response. Working in or with a Security Operations Center: triaging alerts, investigating incidents, escalation, and the response lifecycle. Look for terms like incident response, threat detection, and on-call rotation.
- SIEM tooling. The platforms that aggregate and correlate logs — Splunk, Microsoft Sentinel, Elastic, QRadar, Chronicle. Postings often name a specific one.
- Zero Trust. An architectural concept: never trust by default, verify every request, enforce least privilege, segment the network. Related terms include microsegmentation and continuous verification.
- IAM. Identity and access management — SSO, MFA, role-based access control, privileged access management, joiner/mover/leaver processes.
- Vulnerability management. Scanning, prioritization, and remediation tracking, often with tools like Nessus, Qualys, or Tenable, and CVSS-based triage.
- Frameworks. NIST CSF and 800-53 for controls, MITRE ATT&CK for adversary techniques, plus CIS Controls, ISO 27001, and compliance regimes relevant to the role.
Hands-on evidence vs. familiarity
A reviewer wants to know what you can actually do on day one. Draw the line clearly on the page. Hands-on evidence sounds like: "Wrote Splunk correlation searches to detect lateral movement" or "Led response on a phishing incident from detection through containment and post-mortem." Familiarity sounds like: "Exposure to Zero Trust principles through an IAM migration project." Both are legitimate — the harm is dressing up familiarity as depth.
When you reference a framework, tie it to something concrete. "Mapped detection coverage to MITRE ATT&CK techniques" shows use; "familiar with MITRE ATT&CK" shows reading. If all you have is the reading, say the smaller true thing. A hiring team that lives in ATT&CK will know within one question which it is.
Aligning to a specific posting
Security roles vary widely under similar titles — a "Security Analyst" job might be SOC alert triage, GRC audit work, or vulnerability management, and each rewards different evidence. Read the posting for which cluster it actually centers on, then lead with the matching work rather than a generic security summary. If the role is SIEM-heavy and your depth is in IAM, be honest about that shape: show your real strength, and name the SIEM experience at the level you truly have it.
Keeping a record of your actual security work — the incidents you handled, the tools you operated, the controls you implemented — makes this alignment fast; a Memory Board of that evidence lets you match a posting against real cases instead of guessing. FilterProof is built around working that way, but the discipline matters more than any tool.
One note on tone: you don't need to inflate threats or write like a breach is imminent to sound credible. Calm, specific descriptions of what you detected, investigated, and fixed carry more weight with a security team than dramatic language. Show the work honestly, name the gaps plainly, and let the evidence speak.