Get shortlisted for security roles, not filtered out
HRLens builds your CV around what security hiring teams scan for: certifications up front, the stack you actually ran, incidents described without breaking NDA.

Why strong security people write weak CVs
Most of your best work is the stuff you cannot describe. You contained a breach at a client you signed an NDA with, you tuned detections nobody outside the SOC will ever see, and you spent a quarter closing findings from an audit that is still confidential. So you fall back on safe, empty phrasing: "handled security incidents", "experience with security tools". A screener reads that and learns nothing.
There is a way to be specific and still discreet. Name the sector and the scale instead of the client. Name the products you touched, because Splunk, Microsoft Sentinel, CrowdStrike Falcon and Tenable are not secrets, they are your stack. Describe an incident by what you detected, what you did and what changed afterwards. That reads as operational experience without exposing a single detail you are obliged to protect.
The second problem is placement. Security hiring runs on certifications, and the person doing the first pass is often screening for CISSP, OSCP, CySA+, CISM or a cloud security cert before anything else. If those acronyms sit at the bottom of page two under "Additional information", they may as well not be there. HRLens moves them into a certification line under your name and checks that the file parses cleanly on the way out.
Built for how security CVs are actually read
Certifications a screener spots fast
Security+, CySA+, OSCP, CISSP, CISM, AZ-500. Acronym first, year in brackets, sitting under your name where the eye lands.
Your stack, by name
The builder pushes back when you write "security tools" and asks which SIEM, which EDR, which cloud, which scanner.
Incidents you can put in writing
Scope, action, outcome. Enough detail to prove you ran the response, nothing that identifies a client or a system.
Duties mapped to real frameworks
Detection work tied to MITRE ATT&CK, governance work to ISO 27001, NIST CSF or CIS Controls. Reviewers recognise both.
Parsing that holds up
One column, standard headings, text-based PDF. No tables or icons that turn your experience into an unreadable blob.
Tailored per job ad
Paste the posting and the builder rewrites your summary and bullets around the stack and certifications that ad asks for.
From job ad to tailored CV
Five steps, roughly twenty minutes
1. Strip the job ad for its stack
Pull out every named product, framework and certification in the posting. That list is your keyword set, and you are not guessing at it.
2. Put certifications in the top third
Name, title, contact, then a single certification line. Nobody should scroll to find out you hold an OSCP.
3. Write each incident as scope, action, outcome
What you detected, what you did about it, what changed. Response times and containment beat adjectives every time.
4. Split the stack into categories
SIEM, EDR, cloud, vulnerability management, identity. Grouped like that, a hiring manager checks their must-haves in seconds.
5. Check the parse before you send
Run the finished file through the ATS check, then fix whatever comes back thin or missing.

Same experience, two very different CVs
| Section | What most security CVs say | What gets you the call |
|---|---|---|
| Certifications | Bottom of page two under "Other" | A line under your name: CISSP (2023), OSCP (2021) |
| Tooling | "Experience with security tools" | "Splunk ES, CrowdStrike Falcon, Tenable Nessus" |
| Incident work | "Handled security incidents" | "Led containment on phishing and credential theft cases, then rewrote the playbook" |
| Frameworks | "Familiar with compliance standards" | "Detections mapped to MITRE ATT&CK techniques; ISO 27001 controls evidenced for audit" |
| Cloud | "Cloud security experience" | "AWS: GuardDuty, Security Hub, IAM policy review" |
| Confidentiality | Client names and ticket IDs in the bullets | Sector and scale only: "a mid-size fintech, hybrid estate" |
| File | Designed in a graphics tool, exported as an image | Text-based PDF, one column, standard section headings |
Your certifications are solid. Make the CV prove it.
Paste the job ad, answer a few questions about your stack and your incidents, and walk away with a security CV that parses cleanly.
Questions security candidates ask us
Where should certifications go on a cybersecurity CV?
Put them in the top third of page one, either on a single line under your name or in a short block beside your summary. Lead with the acronym, add the year you earned it, and note the expiry if it is close. Certifications drive the first screen in security hiring, so burying them under "Additional information" costs you interviews.
How do I describe SOC and incident response work without breaching confidentiality?
Swap identifying detail for context. Instead of the client name, give the sector and rough scale. Instead of ticket IDs, give the attack type and severity tier. Then write what you detected, what you did and what changed: containment time, a tuned detection, a rewritten playbook. That proves you ran the response while keeping every protected detail off the page.
Should I spell out certification acronyms for the ATS?
Write both once, in the form "CISSP (Certified Information Systems Security Professional)". Recruiters search either way, and parsers match plain text rather than guessing at abbreviations. After that first mention, the acronym alone is fine. Do the same for frameworks a non-technical screener may not know, and skip it for things everyone spells the same way, like AWS.
Do homelabs, CTFs and bug bounties belong on a security CV?
Yes, if you are junior, changing careers, or moving into offensive security. Give them a short "Projects" section with what you built or found, the tooling involved and what you learned. Once you have a few years of paid incident, engineering or governance work behind you, cut it back to one or two lines so it does not crowd out your operational experience.
How do I move from IT support or sysadmin work into a security role?
Rewrite what you already did through a security lens. Patching becomes vulnerability management, account clean-up becomes identity and access work, log triage becomes detection. Keep the job titles honest, then add a certification such as Security+ or CySA+ and a projects section. Recruiters hire IT people into SOC roles constantly, but only when the CV translates the experience for them.