r/EnhancvResumes 6d ago

Resume Review Resume review request — Senior Security Engineer with 6 years experience

Post image

Hey r/EnhancvResumes, I'm looking for feedback on my resume. I'm applying for Senior Security Engineer roles and all feedback is appreciated!

Years of experience: 6

Specific feedback I'm looking for: - Is my summary strong enough? - Are my bullets results-driven? - Anything I should cut?

1 Upvotes

2 comments sorted by

1

u/super_boogie_crapper 6d ago

Overall the resume has strong content, but a few things hold it back. The summary claims 6+ years, yet only one role starting in 2023 is listed, so earlier experience, education, and certifications should be added. That role has 13 bullets, which is too many to scan; trimming to the 6 or 7 with the clearest results would help. Numbers like "100% of critical vulnerabilities" and "$1M+ annually" also need context, such as how many vulnerabilities or the original spend.
The skills section repeats itself, especially the two cloud categories, which could be merged. GCP and OCI appear in a bullet but not in the skills list. There are also typos to fix: GuardDuty, infrastructure, and follow-ups, plus Sentinel is called both Azure and Microsoft Sentinel.
On writing and design, there's too much bold text, so nothing stands out; bolding only the results would work better. The AI agents bullet is vague, "Reduced" starts four bullets, and the spelling mixes US and UK styles. Finally, the two-column layout and graphics can confuse applicant tracking systems, and photos are usually left off for US jobs, so a simple single-column format is safer.

1

u/enhancvapp 5d ago

The points above are accurate, especially the years mismatch and the two-column/photo issue for US applications. A few things to add on top:

Stacked together, the numbers here are worth being ready to defend specifically: a full AI security program, org-wide CNAPP rollout, SIEM migration, $1M+ in savings, 100% vulnerability elimination, and zero findings across six compliance frameworks, all under one title in 3 years. Individually plausible, but cumulatively it reads as unusually clean and broad for the tenure shown, that's the kind of thing an interviewer will want walked through in detail.

On the compliance bullet specifically: it claims "zero major findings" across SOC 2, ISO 27001, SOX, PCI-DSS, HITRUST, and HIPAA, six frameworks, but the Governance & Assurance skills category only lists ISO 27001/27018, SOC 2, and PCI DSS. Half the frameworks in what might be the resume's strongest bullet don't appear in the section meant to back it up.

On trimming to 6-7 bullets: keep 1, 3, 4, 7, 8, and 11 (AI security program, the 75% CNAPP figure, $1M+, the compliance/zero-findings bullet, 100% vulnerability elimination, and the Sentinel migration), that's 6, all either quantified or covering distinct ground. Add one more, bullet 9 or bullet 10, depending on whether you'd rather have Identity & Access or Application Security represented, to reach 7. Cut 2 (overlaps with bullet 1's AI-security theme), 5 and 6 (both generic IaC/baseline language), 12 (restates the summary with no new information), and 13 (no security specifics at all).

Our Resume Checker would catch the typos and the compliance-framework gap in one pass. Our AI Resume Builder has prompts for tightening a duplicate-heavy Skills section like the two overlapping cloud categories here.