Most cyber security CVs read like a tools list with a name stapled to the top. SIEM, ISO 27001, a wall of acronyms, and not one line that shows the person can actually defend a network.
Hiring managers in security screen for judgement, not vocabulary. The CVs that earn interviews prove you can spot a risk, respond to an incident, and explain it to someone non-technical, and knowing how to write a CV that does that matters most when you are breaking in without a security title yet.

Key takeaways
- Break in on evidence, not job titles. Lead with a home lab, a TryHackMe or CTF record, and any framework you can name.
- UK cyber security work is mostly hybrid or on-site, so put your location and any clearance eligibility near the top.
- Name the tools and frameworks employers list: ISO 27001, SIEM, cloud security, NIST, incident response, and vulnerability management.
- Open your personal statement with one concrete thing you have secured, monitored, or investigated.
- Two pages, reverse chronological once you have roles, sent as a PDF unless the advert asks for Word.
- List your certifications, including any in progress. CompTIA Security+ or an equivalent signals you are on the path.
Writing a cyber security CV with no experience
Cyber security has a real skills shortage, yet most UK postings still ask for prior experience. So your first CV has to manufacture evidence the role can trust.
Use a skills-based CV: personal statement, then skills and hands-on projects, then education and certifications, with any unrelated work history lower down.
The biggest lever you have is practical, documented practice. A home lab is the clearest proof you can do the work before anyone has paid you to.
Build evidence a hiring manager can picture:
- A home SOC lab: a SIEM such as Wazuh or Splunk Free, a firewall like pfSense, and a couple of vulnerable virtual machines to attack and defend.
- TryHackMe or Hack The Box progress, with your rank and the number of rooms or machines completed.
- Capture the Flag events, solo or with a team, and what you solved.
- A small project with a write-up: detection rules you wrote, a Python script that parses logs, or a network you segmented and hardened.
Write those in security language, the way an advert would. "Built a home SOC with Wazuh, ingested logs from three VMs, and wrote rules that flagged simulated brute-force attacks" is a security bullet that happened on your own kit.
Mine your existing work too. IT support, helpdesk, networking, and sysadmin roles all carry security-adjacent duties: patching, access management, MFA rollouts, incident tickets, and backups. If you are writing one of your first CVs, look at CV examples for a first job, and volunteering on a CV, such as securing a charity's systems, counts as real experience here.
Rewrite those duties in security terms. "Reset user accounts and managed access permissions" becomes "administered access control and enforced least-privilege permissions across 200-plus user accounts". Same task, framed for the role you want.
Community involvement reads well too. A local security meet-up, a blog where you document a vulnerability you researched, or an open-source security tool you contributed to all show initiative that a classroom cannot.
Free and low-cost training gives you more to list: TryHackMe and Hack The Box learning paths, the Google Cybersecurity Certificate, and Microsoft's SC-900 fundamentals. Each one is a dated, verifiable entry that fills a thin CV with real learning.
One line moves a no-experience CV up the pile: "CompTIA Security+ certified" or "studying for Security+". It tells a hiring manager you are already on the path, not just curious.
Pick a direction early, even loosely. Blue-team defence, penetration testing, and governance and risk each reward different projects, and a CV aimed at one specialism reads far stronger than a generalist one stretched across all three.
Group all of this under a clear "Projects" or "Practical experience" heading so a hiring manager reads your evidence first. That single structural choice is what turns "no experience" into "here is what I can already do".
What the UK cyber security market looks like
Knowing what employers actually ask for tells you which words belong near the top of your CV. Here is the current picture.
| What | UK cyber security roles |
|---|---|
| Most-requested skills | ISO 27001, SIEM, and cloud security top the list (across 141 UK cyber security postings in the last ~30 days, Enhancv's internal job feed) |
| Where the work happens | Hybrid 60% and on-site 40% (same 141 postings, last ~30 days, Enhancv's internal job feed) |
| Salary | No single verified UK figure. Pay varies widely by specialism, certifications, and clearance, so research the specific role. |
Two of those shape your CV directly.
Cyber security work is mostly hybrid or on-site, so a recruiter needs to see where you are and whether you can get to an office. Put your location near the top, and note any security clearance you hold or are eligible for.
The recurring frameworks and tools are your CV keywords. Name ISO 27001, SIEM, and cloud security exactly where they are true of you, because both the screening software and the hiring manager scan for them.
The market also leans towards experienced hires. Entry-level roles were fewer than 1 in 20 of those 141 postings, which is why the no-experience route above has to lead with hands-on proof rather than hope. Target the openings actually pitched at newcomers, a junior SOC analyst seat, a graduate scheme, or an apprenticeship, rather than firing the same CV at senior listings that will screen you out.
A lot of UK security work sits in regulated sectors like finance, defence, and the public sector, where clearance and framework knowledge matter. If you are eligible for SC or DV clearance, say so, because it widens the roles you can be considered for.
On pay, there is no single reliable UK figure for cyber security, so treat any headline salary with caution and check the specific role, specialism, and clearance level.
Formatting your cyber security CV
For a first security CV, use a skills-led structure so your projects and certifications come before a thin work history. Once you have security roles behind you, switch to reverse chronological, the format most UK employers expect.
Keep it to two pages, one column, standard headings, and a readable font. A security hire is a technical read, so make the scan easy.
Use the header a security employer expects: name, location, phone, a professional email, and links to your LinkedIn and any GitHub, write-ups, or security blog. A tidy GitHub of lab work does more than another line of adjectives.
Send a PDF for direct applications so the layout holds, and keep a Word copy for agencies that reformat CVs into their own template. If the advert names a file type, follow it.
Security applications almost always pass through screening software, so keep the layout clean and the headings standard for an ATS-friendly CV. Build it from a tested CV format rather than a blank page, and Enhancv's CV templates export to a clean PDF.
Writing your cyber security personal statement
Three or four sentences at the top: who you are, the security work you can already do, one concrete piece of evidence, and the role you want. Keep it specific. For more openings, see these CV personal statement examples.
Tailor it to the specialism in the advert, so a detection role sees SIEM triage and incident response, and a governance role sees frameworks and audit work.
Skip the adjective soup every other CV uses. "Passionate, driven cyber security enthusiast" tells a hiring manager nothing they can verify.
Lead with evidence instead:
Cyber security CV personal statement example (no experience)
Recent BSc Computer Science graduate with a home SOC lab and CompTIA Security+ in progress. Comfortable with SIEM triage in Wazuh, vulnerability scanning in Nessus, and mapping controls to ISO 27001. Ranked in the top 5% on TryHackMe across 60-plus rooms, and looking to bring hands-on detection and a methodical approach to a junior SOC analyst role in Manchester.
Compare that with the version that says everything and proves nothing:
What to avoid
Passionate and highly motivated cyber security enthusiast seeking a challenging role in a dynamic organisation where I can leverage my skills, grow professionally, and make a real impact.
When someone applies for their first security role, I am not looking for a job title they do not have yet. I want proof they have done the work: a home lab they can talk through, a TryHackMe rank, one incident they investigated and what they took from it. A candidate who can walk me through a detection rule they wrote beats a page of certifications with nothing behind them. Show the hands-on evidence first, then let the certifications confirm it.
Writing your cyber security experience section
Whether it is paid, a placement, or a documented project, write each entry the same way: a dated heading, then bullets that show what you did and what changed. For the mechanics, see work experience on a CV.
Security work is measurable more often than people think: alerts triaged, vulnerabilities closed, mean time to detect, phishing click-rates, systems patched. Those numbers are your CV achievements, so put them in.
Lead each bullet with a strong action verb, and let a project stand in for a job if that is what you have. A home lab entry, dated and detailed, is a legitimate experience block for a first security CV.
Keep each bullet to one action and one result. "Investigated 40-plus phishing reports a week and escalated confirmed threats, cutting average response time by a third" says more than three lines of listed responsibilities.
If your numbers come from an IT or support role, keep them: tickets resolved, uptime maintained, accounts onboarded, patches deployed. Reframed around the security outcome they protected, they still count on a security CV.
Then tailor every application. Pull the frameworks and tools from the advert and mirror the ones you can genuinely back. Enhancv's CV tailoring feature reads the advert and suggests the matching edits, which saves rewriting from scratch each time.
- Built a home security operations centre with Wazuh and pfSense across four virtual machines, feeding endpoint and firewall logs into a single dashboard
- Wrote detection rules that flagged simulated brute-force and privilege-escalation attacks, cutting the time to spot each test from minutes to seconds
- Ran monthly vulnerability scans with Nessus and OpenVAS, then patched and re-tested to close over 30 findings across the lab
- Reached the top 4% on TryHackMe across 60-plus rooms covering SIEM triage, network forensics, and web exploitation

PRO TIP
Cyber adverts name frameworks and tools exactly: ISO 27001, NIST, SIEM, SOAR, MITRE ATT&CK. Mirror the ones you have actually used, spelled the way the advert spells them, so both the screening software and the hiring manager can find them. Never claim a tool you cannot discuss in an interview.
Skills to put on a cyber security CV
Read a dozen live cyber security adverts and the same demands repeat. They are specific and technical, not generic. ISO 27001, SIEM, cloud security, vulnerability management, incident response, and NIST come up again and again, so list your hard skills in the words the adverts use.
The soft skills that matter here are real and checkable: analytical thinking, clear communication, and attention to detail. Prove each one in a bullet, because "communicated a phishing risk to non-technical staff and cut click-rates" beats the word "communication" on its own.
Group your hard skills so a reader can scan them, with security frameworks, tooling, cloud, and scripting each in their own cluster rather than one long list. For example: Frameworks (ISO 27001, NIST), Tooling (Splunk, Wazuh, Nessus), Cloud (AWS, Azure), and Scripting (Python, Bash).
List only what you can stand behind, and do not keyword-stuff. A recruiter can tell the difference between a tool you have used and one you pasted in, and the interview will expose it. For the wider picture, see how to build the skills section of a CV and which IT skills support a security move.
Top skills for your cyber security CV:
ISO 27001
SIEM (Splunk, Wazuh)
Vulnerability management
Incident response
NIST Cybersecurity Framework
Cloud security (AWS, Azure)
Network security
Python scripting
Analytical thinking
Communication
Attention to detail
Problem solving
Teamwork
Certifications for a cyber security CV
Certifications carry unusual weight in security because they map to skills employers can verify. List them where you have them, and list the ones in progress too.
Early on, CompTIA Security+ is the common baseline, with Network+ and CySA+ close behind. Cloud roles look for AWS or Azure security certifications, and senior roles start asking for CISSP or CISM. Put these in your education section or a dedicated certifications block, and name any certificates on your CV exactly as the awarding body writes them.
Order them by relevance to the advert, not by how hard they were to earn. A role asking for cloud security should see your AWS or Azure certification first, even if your CISSP looks more impressive on paper.
Keep them current and dated. Several security certifications expire, so show the year you earned each one and, where a renewal is due, that it is in hand.
A degree or apprenticeship helps but does not gate the field. Plenty of people move in from IT with a strong set of qualifications built from certifications and hands-on projects rather than a security degree.
Conclusion
Lead with evidence you can defend, name the frameworks and tools employers screen for, and keep the format clean and technical.
Pair the CV with a short cover letter that says why security and why now, and a first application without a security job behind it becomes a credible one.

Author's take - the Enhancv team
When someone applies for their first security role, I am not looking for a job title they do not have yet. I want proof they have done the work: a home lab they can talk through, a TryHackMe rank, one incident they investigated and what they took from it. A candidate who can walk me through a detection rule they wrote beats a page of certifications with nothing behind them. Show the hands-on evidence first, then let the certifications confirm it.



















