Cybersecurity Analyst

Cybersecurity Analyst carries out client-facing actions and record updates using 20 task templates that map daily work. The tasks show common collaborators, typical durations, and basic verification steps. Each one shows where we found it, and comes with an AI prompt you can copy and use straight away.

20evidenced tasks
20ready prompts
8tools of the trade
15-1212.00O*NET-SOC code
190,650hold this job (US, BLS 2025)
$129,180median pay/yr (US)
Open Cybersecurity Analyst in the interactive atlas →

What it pays

Government survey numbers — not estimates, not ads.

Half of all Information Security Analysts in the U.S. earn more than $129,180 a year — the middle 80% land between $75,090 and $199,850. About 190,650 people in the U.S. do this work. Figures are for the U.S. occupation group “Information Security Analysts”. (U.S. Bureau of Labor Statistics survey, published 2025.) In India, Professionals earn about ₹38,298 a month on average — around ₹4.6 lakh a year (government PLFS survey via ILOSTAT, occupation-family figure).
$129,180typical pay / year
190,650people in this work
$199,850+top 10% earn
₹4.6 lakha year in India (family avg)
Think you get this job?Six quick questions on how it really works — with a hint and the reason behind every answer.
Test yourself →

The work, task by task

These are the real jobs-to-be-done, not a wish list. Each task shows where we found it, and the prompt underneath is written for that exact task.

Keeping the record4

Ensure compliance with relevant laws and standards

+
Confirm our controls map covers GDPR, PCI-DSS, and NIST 800-53 for the payments platform, list gaps with…
Confirm our controls map covers GDPR, PCI-DSS, and NIST 800-53 for the payments platform, list gaps with evidence and legal citation, and prepare a one-page remediation plan for the CISO by next Wednesday.
The tools that do the workAnsiblejob descriptionsWikipedia

Train staff on security awareness and best practices

+
Create a two-hour security awareness session for all trading desk staff covering phishing, credential…
Create a two-hour security awareness session for all trading desk staff covering phishing, credential handling, and secure remote access, include a phishing simulation and a one-page cheat sheet to distribute before Friday.
The tools that do the workApache KafkaO*NETWikipedia

Design and implement security policies

+
Draft and publish a role-based security policy that limits trading-data access to the analytics team, include…
Draft and publish a role-based security policy that limits trading-data access to the analytics team, include audit requirements and breach response steps, circulate to Legal and Compliance for sign-off by Thursday, and update the access control matrix.
The tools that do the workApache HiveApache Mavenjob descriptionsWikipedia

Conduct security assessments and audits

+
Run a full security audit of the market-data pipeline, validate permissions, check for orphaned accounts and…
Run a full security audit of the market-data pipeline, validate permissions, check for orphaned accounts and misconfigured shards, produce a remediation plan with timelines, and present findings to the CISO next Tuesday.
The tools that do the workApache HadoopApache CassandraO*NETWikipedia
Fixing2

Implement security measures to protect data

+
Harden the data access layer by enforcing least-privilege for the finance ingest pipeline, rotate keys that…
Harden the data access layer by enforcing least-privilege for the finance ingest pipeline, rotate keys that are older than 90 days, deploy the approved firewall ruleset to the staging environment, and open a change request for production deployment on Friday.
The tools that do the workAnsibleAmazon Web Services AWSjob descriptionsO*NETWikipedia

Monitor networks for security breaches

+
Continuously inspect network flows for unusual lateral movement and authenticate anomalies, escalate…
Continuously inspect network flows for unusual lateral movement and authenticate anomalies, escalate confirmed incidents to Priya in SOC, add signatures for the new threat indicators, and produce a daily summary for the CTO before 09:00.
The tools that do the workApache KafkaAmazon Web Services AWSjob descriptionsWikipedia
The daily work14

Analyse financial risk

+
Run a systemic analysis of our exposure to market-driven cyber fraud over the past 12 months: pull…
Run a systemic analysis of our exposure to market-driven cyber fraud over the past 12 months: pull traded-instrument transaction logs, map breaches to dollar losses per quarter, quantify likely tail losses under a 1-in-100 shock, and produce an executive one-page risk brief for Friday.
The tools that do the workAmazon RedshiftESCOsee the evidence ↗

Stock market

+
Produce a market surveillance report correlating unusual login and trade patterns with price movements for…
Produce a market surveillance report correlating unusual login and trade patterns with price movements for the last six months: extract trades, user session anomalies, compute abnormal return windows, flag top five suspicious tickers with suggested containment actions by Wednesday.
The tools that do the workApache KafkaESCOsee the evidence ↗

Monitor current reports of computer viruses to determine when to update virus protection systems.

+
Scan current threat feeds and internal incident logs for new malware indicators, assess which protection…
Scan current threat feeds and internal incident logs for new malware indicators, assess which protection signatures and heuristics need updating, and schedule the timed push to endpoints after confirming no false positives on Thursday evening.
The tools that do the workApache KafkaO*NET

Coordinate implementation of computer system plan with establishment personnel and outside vendors.

+
Arrange and lead the implementation meeting with facilities IT, procurement lead Sarah Ortiz, and vendor…
Arrange and lead the implementation meeting with facilities IT, procurement lead Sarah Ortiz, and vendor SecureWave next Tuesday, agree deployment windows, device access, rollback plan, and who will validate each milestone.
The tools that do the workAnsibleO*NET

Research latest IT security trends

+
Gather the past six months of security advisories, exploit reports, and vendor roadmaps, summarise the top…
Gather the past six months of security advisories, exploit reports, and vendor roadmaps, summarise the top five emerging threats and suggested mitigations in a one-page briefing for the CISO by Monday.
The tools that do the workApache Hadoopjob descriptions

Manage vulnerabilities and system hardening

+
Run the vulnerability scan results, prioritise remediation by risk and exploitability, apply system hardening…
Run the vulnerability scan results, prioritise remediation by risk and exploitability, apply system hardening templates to high-risk hosts, and record configuration baselines for audit before Friday close.
The tools that do the workAnsiblejob descriptions

Help users install and learn security products

+
Prepare step-by-step install guides and host three 45-minute training sessions next Wednesday for staff to…
Prepare step-by-step install guides and host three 45-minute training sessions next Wednesday for staff to walk through the new endpoint protection features, capture common questions and follow-up actions.
The tools that do the workApache Hivejob descriptions

Collaborate with technical and business teams

+
Set up a cross-functional sync with network, devops, and finance lead Martin Cole for Thursday to align…
Set up a cross-functional sync with network, devops, and finance lead Martin Cole for Thursday to align security priorities with business risk, agree on sprint tasks, and document who owns each action.
The tools that do the workApache Kafkajob descriptions

Reduce the probability of data breaches

+
Reduce our chance of a data breach by mapping the crown-jewel datasets, prioritising controls for the top…
Reduce our chance of a data breach by mapping the crown-jewel datasets, prioritising controls for the top three high-risk assets, deploy multi-factor authentication and network segmentation, and produce a one-page residual risk memo for the board by Wednesday.
The tools that do the workAnsibleWikipedia

Develop and enforce password policies

+
Create and enforce a corporate password policy that sets minimum length, complexity, rotation cadence,…
Create and enforce a corporate password policy that sets minimum length, complexity, rotation cadence, account lockout thresholds and reuse rules, roll it out to all business units with enforcement on privileged accounts and a 30-day compliance report to IT leadership.
The tools that do the workAnsibleWikipedia

Develop incident response plans

+
Draft an incident response plan that assigns roles for containment, eradication and recovery, defines…
Draft an incident response plan that assigns roles for containment, eradication and recovery, defines escalation to legal and finance, lists contact details for forensics and regulators, and run a tabletop exercise with the SOC next Friday to validate it.
The tools that do the workAnsibleWikipedia

Perform research activities to gather and analyse financial, legal and economic information

+
Research and compile a dossier of financial, legal and economic intelligence on the target company: collect…
Research and compile a dossier of financial, legal and economic intelligence on the target company: collect recent filings, sanctions watchlist hits, market movements and legal proceedings, summarise implications for our exposure, and deliver a risk brief to the investigations team by Monday.
The tools that do the workApache HiveESCO

Interpret data on the price, stability and future investment trends in a certain economic area

+
Interpret price, stability and forward-investment trends for the Southeast Asia payments sector: ingest last…
Interpret price, stability and forward-investment trends for the Southeast Asia payments sector: ingest last five years of price series, flag volatility episodes, calculate forward-looking risk metrics, and produce a two-page advisory for the trading desk by Thursday.
The tools that do the workApache HadoopESCO

Make recommendations and forecasts to business clients

+
Prepare actionable recommendations and three- and twelve-month forecasts for our corporate clients: evaluate…
Prepare actionable recommendations and three- and twelve-month forecasts for our corporate clients: evaluate current exposures, stress-test scenarios against market moves, list recommended hedges or mitigations, and send the advisory deck to client services by Friday noon.
The tools that do the workAmazon RedshiftESCO

Says who?

These are the pages we read to build this. Open any of them and check us.

The logs, files & records this job keeps

Shared with other careers — the same record means something different in each.

Related careers

Same family of work — each with its own tasks and prompts.

The LLOS Work Atlas is the world's largest evidenced task library — a map of human work, with a ready prompt behind every task. 1,774 careers · every task named by the sources that witnessed it — O*NET, ESCO, real job descriptions, Wikipedia — and the deepest tasks by several at once. And it is honest about limits: where AI cannot help, the map says so.

The rest of the map

Same library, five ways in.

Copyright © LLOS.ai · 2026 — original pedagogy, voice, and design — all rights reserved.
Built on public evidence: O*NET®, ESCO, Wikipedia, U.S. Bureau of Labor Statistics, ILOSTAT. All sources & licenses