What a Cybersecurity Analyst at 1–3 years can own
Scope: incident investigation, vulnerability management and security controls for a defined set of systems.
Supervision
Works from a weekly priority list rather than daily instructions. Needs guidance on trade-offs and on anything cross-team, not on the craft itself.
Typical titles
Executive, Engineer / Developer, Analyst or Senior Associate
Typical responsibilities at this level
- Investigate and contain incidents end to end
- Run VAPT on web apps and APIs
- Tune SIEM rules to cut false positives
- Collect evidence for ISO 27001 or SOC 2 audits
Skills and tools to screen for
The skills are the same across bands — the depth is what changes. At 1–3 years, screen for working inside an unfamiliar codebase and owning a feature end to end.
Core skills
- Networking fundamentals
- SIEM monitoring
- Vulnerability assessment
- OWASP Top 10
- Incident handling
Common tools
- Splunk / Sentinel
- Burp Suite
- Nessus / Qualys
- Wireshark
How to assess a 1–3 years candidate
This is the band where titles are least reliable. Ask for specifics — what they personally owned, shipped or closed — and test that ownership in a practical exercise rather than trusting the résumé wording.
Practical exercise
A lab web app with known flaws: find and report two, with severity, evidence and remediation.
Red flag at this band: Two years of experience that turns out to be the same support ticket queue, with no feature they can describe owning.
Indicative cybersecurity analyst salary by experience (India)
| Experience | Indicative CTC | Level |
|---|---|---|
| 0–1 year | ₹3.5–6 LPA | Entry level |
| 1–3 years | ₹6–12 LPA | Early career |
| 3–5 years | ₹10–20 LPA | Mid-level |
Indicative market ranges for India, rounded, for guidance only — not MyInternships.in platform data. Metros and funded product companies tend to pay toward the top; tier-2 cities and services firms toward the bottom. Always benchmark against the candidate’s current CTC.
Interview questions for 1–3 years of experience
- How do you respond to a phished user account?
- A detection fires 200 times a day — how do you tune it?
- Explain IDOR and how you test for it.
- Which part of your current system would you redesign, and why has nobody done it yet?
Notice period and ramp-up
Commonly 30–60 days; in IT services 60–90 days is normal. Counter-offers from the current employer are frequent at this band, so keep the candidate warm through the notice period.
Productive on real work in two to four weeks once they have access and context.
Job description template
Job title: Cybersecurity Analyst (1–3 years experience)
About the role: We are hiring a Cybersecurity Analyst with 1–3 years of experience who can own incident investigation, vulnerability management and security controls for a defined set of systems. You will work with our team on investigate and contain incidents end to end and grow into broader ownership over time.
Responsibilities
- Investigate and contain incidents end to end
- Run VAPT on web apps and APIs
- Tune SIEM rules to cut false positives
- Collect evidence for ISO 27001 or SOC 2 audits
Requirements
- 1–3 years in a comparable role
- Working knowledge of Networking fundamentals, SIEM monitoring, Vulnerability assessment
- Comfort with OWASP Top 10 and Incident handling
- Clear written and spoken communication in English
Nice to have
- Hands-on use of Burp Suite and Nessus / Qualys
- Experience in a similar industry or product type
CTC: ₹6–12 LPA (indicative — set your own band; stating it in the post improves response)
Copy it, edit it, and paste it into the posting chat — or let the AI assistant write one for you.
Where to find 1–3 years cybersecurity analyst candidates
Most candidates at this band come from B.E./B.Tech, BCA/MCA and B.Sc (CS/IT) graduates, plus bootcamp graduates with public project work.
- Write the stack and the actual problems into the job title and first line — engineers at this band filter hard on stack match.
- Say whether the role is product or services work; it changes who applies more than salary does.
Post your Cybersecurity Analyst role free
Tell us the role, experience band, city and CTC in a two-minute chat. Your listing reaches 63,000+ registered candidates, including 12,000+ from the 2026 batch.
Post a job freeFrequently asked questions
What can a cybersecurity analyst with 1–3 years of experience handle?
Incident investigation, vulnerability management and security controls for a defined set of systems. Typical work at this band includes investigate and contain incidents end to end; run VAPT on web apps and APIs; tune SIEM rules to cut false positives. Works from a weekly priority list rather than daily instructions. Needs guidance on trade-offs and on anything cross-team, not on the craft itself.
What is the salary of a cybersecurity analyst with 1–3 years of experience in India?
As an indicative market range, ₹6–12 LPA CTC — roughly ₹50,000 to ₹1,00,000 a month before deductions. Pay varies with city, company size, industry and the candidate’s current CTC; metros and funded product companies usually pay towards the top of the range. This is a guide, not MyInternships.in platform data.
How should I assess a cybersecurity analyst at the 1–3 years level?
Focus on working inside an unfamiliar codebase and owning a feature end to end. A practical that works well: a lab web app with known flaws: find and report two, with severity, evidence and remediation. This is the band where titles are least reliable. Ask for specifics — what they personally owned, shipped or closed — and test that ownership in a practical exercise rather than trusting the résumé wording.
How long is the notice period for a cybersecurity analyst with 1–3 years of experience?
Commonly 30–60 days; in IT services 60–90 days is normal. Counter-offers from the current employer are frequent at this band, so keep the candidate warm through the notice period. Productive on real work in two to four weeks once they have access and context.
Where can I find cybersecurity analyst candidates with 1–3 years of experience?
Most come from B.E./B.Tech, BCA/MCA and B.Sc (CS/IT) graduates, plus bootcamp graduates with public project work. Write the stack and the actual problems into the job title and first line — engineers at this band filter hard on stack match. On MyInternships.in you can post the role free and reach 63,000+ registered candidates and 45,000+ resumes on file; the platform is strongest at the entry and early-career end.
Is 1–3 years enough, or should I hire a cybersecurity analyst with 3–5 years?
Hire at 1–3 years when the work is well defined and someone senior can set direction; hire at 3–5 years when the person must own decisions, design the approach and guide others. At 3–5 years the indicative range rises to ₹10–20 LPA, so be clear about which of those you actually need.
Same role, other experience levels
More cybersecurity analyst hiring pages
Hire by city
Other software & it roles at 1–3 years
Browse every role and band in the hire-by-experience directory or go back to Hire Talent.
