Information Security Analysis in the United States: Evidence from 100 Current Vacancies

The report and public evidence package are archived at Zenodo DOI 10.5281/zenodo.22712242. Download the research report PDF.

MTF Institute Research Report
Research geography: United States
Vacancy retrieval date: 11 September 2026
Permanent identifier: https://doi.org/10.5281/zenodo.22712242
Proposed programme: Professional Certificate in Information Security Analysis: Monitoring, Triage and Incident Handoff

Executive summary

This report examines the advertised work of defensive information-security analysts in the United States. The evidence base is a structured purposive sample of exactly 100 current, unique U.S. vacancy records from 62 employers. Ninety-four records came from first-party employer sites or applicant-tracking systems, while six remained clearly labelled public fallback sources.

The results show a role organized around evidence and controlled decisions. Escalation or handoff appeared as an explicit duty in 81 records, triage or prioritization in 78, case or findings documentation in 73, investigation in 68, bounded containment or remediation in 66, and monitoring in 62. The most common method signals were evidence correlation (70), incident-response lifecycle work (66), scripting or automation (64), SIEM search or query (62), cloud or SaaS telemetry (61), endpoint analysis (57) and network analysis (50).

These findings do not describe an unrestricted “cybersecurity expert.” The recurring professional contribution is narrower: receive an alert, exposure or suspicious event; collect appropriate evidence; form a qualified judgment; take only a pre-authorized action; preserve a defensible record; and transfer ownership when scope, impact or authority exceeds the analyst's boundary.

The sample also shows why a course must distinguish an accessible foundation from employer hiring rules. Prior experience was stated in 84 records, an explicit entry pathway in 16, and clearance or citizenship constraints in 28. A course-completion certificate can build demonstrable capability, but it cannot replace employer-specific experience, clearance, sector or legal requirements.

1. Research question and role boundary

The study asked: What responsibilities, outputs, skills, tools, interfaces and authority boundaries are visible in a diverse sample of current U.S. defensive information-security analyst vacancies?

The target role is an individual contributor who supports the protection of organizational information and systems through authorized monitoring, triage, investigation, exposure review, incident documentation and escalation. The unit of work is an alert, vulnerability, suspicious event or bounded incident question. A valid output is a triage verdict, investigation record, evidence package, recommendation, controlled detection change, vulnerability work item or context-rich handoff.

The scope includes security operations, information-security analysis, incident response, vulnerability and exposure workflows, and selected detection or threat-hunting contexts. It excludes work primarily centered on offensive testing, exploitation, credential attacks, malware deployment, persistence, evasion, destructive testing or unauthorized access. Specialist forensics, malware analysis, threat hunting, incident command and detection engineering are useful boundary cases but do not define every entry analyst position.

2. Method

2.1 Sampling and source controls

The study used a structured purposive sample designed for role breadth, not statistical representativeness. Public vacancies were collected across multiple defensive title families. A record was accepted only when it had current-status evidence, a public HTTPS source, U.S. location or explicit U.S. eligibility, a retrievable date of 11 September 2026, and material relevance to defensive analyst work.

Collection produced 110 candidate records. Normalization by employer ATS domain and requisition or job identity found 102 unique source identities. Eight cross-batch duplicates and two lower-scoring overflow records were excluded, leaving exactly 100 accepted records. All 100 had structured duties or requirements and passed geography, required-field and short-excerpt checks.

The source mix was deliberately visible: 94 first-party employer or ATS records and six fallback recruiter or aggregator records. Fallback records were retained only where the structured evidence remained attributable and role-relevant; they do not carry unsupported employer-specific claims.

2.2 Coding

The frozen codebook separated:

  • duties and responsibilities;
  • work outputs;
  • hard skills and methods;
  • observable professional behavior;
  • tools and system categories;
  • education, certification, experience, clearance and entry signals;
  • shift, on-call and reporting cadence;
  • interfaces with technical, business and external stakeholders; and
  • decision authority and escalation boundaries.

Coding recorded explicit structured signals. A missing item remained unknown and was never converted into zero. Counts describe the collected records, not all U.S. employers or actual time spent on a task.

A deterministic 20-record second implementation tested code robustness using the structured detail fields. Mean Jaccard similarity was 0.968. This is a conservative implementation check performed by one research workflow, not independent human inter-rater reliability.

3. Sample composition

The accepted records span six role families:

Role family Records
Security operations / SOC 36
Information-security analysis 32
Incident response 17
Vulnerability and exposure 8
Detection and threat hunting 6
Other defensive analysis 1
Total 100

This mix improves boundary coverage but is not proportional to the national labor market. Leidos accounts for 13 records, creating a material employer concentration. Government and contractor work also contributes to the 28 clearance or citizenship signals. Those requirements must not be generalized to every analyst role.

4. Findings

4.1 The role begins with prioritization and ends with accountable transfer

Escalation or handoff was the most frequent duty signal, appearing in 81 records. Triage or prioritization appeared in 78. An explicit escalation boundary appeared in 82. Together, these signals frame analyst work as a sequence of bounded decisions rather than unlimited technical autonomy.

A useful handoff does more than forward an alert. It communicates the trigger, verified evidence, current hypothesis, confidence, possible business effect, action already taken, remaining uncertainty, next owner and requested decision. This preserves continuity across shifts, specialist teams and business functions.

4.2 Investigation quality depends on evidence, not alert volume

Investigation appeared in 68 records, multi-source correlation in 59, and log, packet or artifact analysis in 53. Seventy records contained explicit evidence-reasoning signals. SIEM search or query appeared in 62, cloud or SaaS telemetry in 61, endpoint analysis in 57, network analysis in 50 and identity analysis in 37.

These patterns support a practical definition of investigation: form a testable hypothesis, collect relevant evidence, normalize time and identity, connect events across systems, record both positive and negative findings, and state what the evidence does not establish. A single indicator, risk score or successful sign-in cannot carry more certainty than its source supports.

4.3 Documentation is a core technical output

Case, timeline or findings documentation appeared as a duty in 73 records, and an investigation or incident record appeared as an output in 74. Evidence packages or timelines were explicit in 26, reports or briefings in 41, and playbooks or procedures in 42.

Documentation is not administrative residue. It enables review, shift continuity, stakeholder decisions, lessons learned and safe reuse of historical cases by detection or AI-assisted systems. A defensible record identifies the source, query or check; shows the result; distinguishes observation from inference; records the decision and authority; and preserves open questions.

4.4 Response is bounded and verification-based

Bounded containment or remediation appeared in 66 records, while 42 explicitly signaled bounded containment authority and 38 described recommendation without execution. Incident-response lifecycle knowledge appeared in 66. These overlapping signals show that employers expect response fluency, but not identical authority.

An analyst should confirm the target, scope and business context before action; use only an approved procedure; preserve necessary evidence; verify the action's actual outcome; and record rollback or follow-up needs. Major business interruption, legal notification, public disclosure, production control changes and broad account actions belong to named owners unless a narrowly defined action was pre-authorized and audited.

4.5 Detection, exposure and automation are connected workflows

Detection tuning or engineering appeared as a duty and output in 58 records. Vulnerability or exposure analysis appeared in 25 duty signals, vulnerability prioritization in 34 method signals, and a vulnerability finding or work item in 69 outputs. Scripting or automation appeared in 64 method signals.

These counts do not make every analyst a detection engineer or vulnerability researcher. They do support the ability to explain a detection hypothesis, data dependency, test case and expected noise; validate whether a public vulnerability is actually present and reachable in the local environment; and use small, reviewable automation with input constraints, logs and a rollback path.

4.6 Communication is part of risk control

Stakeholder communication or briefing appeared in 90 records. Interfaces with incident-response, threat-intelligence or detection teams appeared in 88; business, leadership or customer interfaces in 78; IT, infrastructure or engineering in 64.

The analyst must translate technical observations into decision-ready language: what happened, what is known, what remains uncertain, what could be affected, what action is proposed, what authority is required and what happens next. This is not legal advice or a compliance certification. It is evidence-qualified operational communication.

4.7 Operational cadence shapes the work

Shift or 24x7 language appeared in 39 records and on-call or after-hours work in 36. Recurring reporting or review appeared in 27. These are sample signals, not universal schedule requirements. They do, however, reinforce the importance of concise records, honest status, priority preservation and confirmed receipt across handoffs.

5. Qualifications and entry implications

Only 14 records explicitly stated a degree, and four stated a degree-or-equivalent formulation. Certifications were required in seven records and preferred in eight. Prior experience appeared in 84, while 16 contained an explicit entry-path signal.

The evidence supports a practical course that develops observable work products and helps a learner demonstrate disciplined analyst reasoning. It does not support a universal education rule, certification substitution or hiring guarantee. Senior, clearance-restricted and specialist vacancies were retained to show role boundaries and progression; they must not define the minimum learner promise.

6. Implications for programme design

The evidence supports six capability families: monitoring and triage; reproducible investigation; bounded incident handling; detection and vulnerability workflow; case documentation and stakeholder handoff; and responsible supervision of automation. Assessment should require observable artifacts and decisions, not terminology recall alone.

All practice must use synthetic data and isolated, provider-owned or explicitly authorized environments. Learners should never use real credentials, secrets, personal data or confidential incident material in exercises or public AI tools. The programme must not teach live third-party scanning, phishing execution, credential attacks, persistence, evasion, malware deployment, destructive testing or weaponized exploitation.

7. Portfolio position

The proposed programme is intentionally distinct from the existing MTF course Cybersecurity GRC Analyst: Governance, Risk and Compliance Operations. GRC owns governance, control assurance, risk registers, compliance operations and audit-oriented evidence. Information Security Analysis owns defensive monitoring, triage, investigation, evidence-qualified decision making and incident handoff.

The public title is also narrower than the existing Udemy title Information Security Professional Certification. The phrase “Professional Certificate” describes a non-degree course-completion award; it does not confer a regulated designation or make a learner a “certified information security analyst.”

8. Limitations

This is a purposive public-vacancy sample, not a representative U.S. survey or employer census. Public listings can change or close. Lexical coding finds explicit language but cannot measure actual frequency, proficiency or causal importance. The 13-record Leidos concentration and 28 clearance/citizenship signals reflect a material government-contractor presence. Six fallback sources carry greater provenance uncertainty than first-party pages. Quality checking used two deterministic implementations rather than independent human coders.

No claim in this report establishes national prevalence, employer recognition, accreditation, licensure, exam equivalency, salary, hiring or career outcomes.

Rights and professional-boundary statement

This report is original analysis based on derived facts, public metadata and short necessary excerpts. It does not reproduce job descriptions, proprietary standards, certification curricula, detection rules, vendor code, screenshots, tables or graphics. Employer and product names identify evidence sources only and do not imply endorsement.

The report provides general professional education, not legal, regulatory, privacy, compliance, incident-response or safety advice. Organization-specific policy, written authorization and qualified owners govern real systems and consequential decisions.