Home / Learn / How to Build a Cybersecurity Portfolio That Actually Gets You Hired (Not Just GitHub Repos)

How to Build a Cybersecurity Portfolio That Actually Gets You Hired (Not Just GitHub Repos)

By Gaurav Malhotra · 2026-09-10 · 14 min read

Here's the uncomfortable truth about cybersecurity portfolios: 90% of them are useless.

Not because the candidates aren't smart. But because they've been told "build a GitHub" and end up with 20 half-finished repos that say "learning Python" in the readme. Hiring managers see this 50 times a week. They close the tab in 30 seconds.

The portfolios that actually get interviews are artifact-first. They don't show code - they show deliverables that mirror the actual work. A risk register. An incident playbook. A detection rule with business context. A gap assessment with remediation priorities.

This guide shows you the five portfolio pieces every SOC and GRC candidate needs, with specific tools and frameworks to build them in a weekend.

The "Artifact-First" Portfolio Philosophy

Think like a hiring manager. When they interview a GRC analyst, they don't ask "can you write Python?" They ask:

  • "Walk me through a risk assessment you've done"
  • "How would you prioritize remediation for these 20 findings?"
  • "Draft a work-from-home security policy"

Your portfolio should answer these questions before they ask. Show them the document you'd produce on day one of the job.

For SOC analysts it's similar:

  • "How would you triage this alert?"
  • "Write a detection for lateral movement"
  • "Walk me through your investigation of this incident"

The artifact proves you can think like a practitioner. A cert proves you passed a test.

The Five Portfolio Pieces Every Candidate Needs

1. A Risk Register (GRC) or Threat Model (SOC)

For GRC: Pick a fictional small business (e.g., "Acme Legal, a 30-person law firm"). Identify 15-20 risks. For each, document:

  • Asset at risk (client data, reputation, revenue)
  • Threat actor and vector
  • Likelihood (1-5) and impact (1-5)
  • Risk score and current controls
  • Residual risk and recommended treatment (accept, mitigate, transfer, avoid)

For SOC: Pick the same company and write a threat model. What are the top 10 threats? Which MITRE ATT&CK techniques map to each? What detections would you build?

Why this works: It shows you can think about risk in business terms, not just security jargon. Law firms care about "client confidentiality breach" not "SQL injection CVE-2024-XXXX."

Tool to use: Risk Register Generator - generate the structure, then add your analysis and commentary.

2. A Security Policy Document

Pick one: acceptable use, remote work, incident response, or data classification. Write a 2-3 page policy that includes:

  • Purpose and scope: Who does this apply to?
  • Policy statements: Clear, enforceable rules
  • Roles and responsibilities: Who does what?
  • Enforcement and exceptions: What happens if violated?
  • Review cadence: When is this updated?

Why this works: Every company has policies. Most are terrible. A well-written policy shows you understand the balance between security and usability, legal requirements, and human behavior.

Tool to use: Security Policy Generator - generate a base, then customize with your own examples and rationale.

Portfolio tip: Add a 500-word commentary explaining your design decisions. "I chose 'should' over 'must' for personal devices because..."

3. A SIEM Detection Rule + Business Justification

For SOC candidates. Pick one attack technique from MITRE ATT&CK (e.g., T1078 - Valid Accounts). Write:

  • The attack: How would an adversary use valid accounts?
  • The detection: Splunk SPL, Elastic KQL, or Sentinel KQL query
  • The tuning: What false positives would you expect? How would you allow-list legitimate activity?
  • The playbook: When this alert fires, what does the Tier 1 analyst do?

Why this works: Detection engineering is the highest-leverage skill in a SOC. A well-documented detection shows you think about attacker behavior, data sources, false positives, and analyst workflow - all in one artifact.

Pro tip: Build the detection in a free home lab (ELK + Sysmon, or Splunk Free Tier) and include screenshots of it actually firing on a simulated attack. That's portfolio gold.

4. An ISO 27001 Gap Assessment

For GRC candidates. Pick the same fictional company from piece #1. Run through Annex A controls (A.5-A.18 in ISO 27001:2022) and document:

  • Which controls are fully implemented
  • Which are partially implemented
  • Which are missing
  • Priority ranking based on risk
  • 90-day remediation roadmap

Why this works: Gap assessments are what GRC consultants actually do. This artifact shows you understand the framework, can identify gaps, and can prioritize remediation based on business impact - not just control coverage.

Tool to use: ISO 27001 Gap Assessment - generate the checklist, then fill it in with your fictional company context and add your analysis.

5. A CTF or Lab Write-Up

For all candidates. Pick one room from TryHackMe or one box from HackTheBox. Write a 1000-1500 word walkthrough that includes:

  • Approach: How did you think about the problem?
  • Methodology: Enumeration → foothold → privilege escalation → flags
  • Key commands: Not every command, just the ones that were interesting or taught you something
  • Lessons learned: What would you do differently?
  • Real-world relevance: How does this relate to actual threats?

Why this works: This is the one "GitHub-style" piece that actually matters. But it's not a raw walkthrough - it's a reflective analysis that shows you think about attacker tradecraft and defensive implications.

How to Present Your Portfolio

Where you host matters less than how you present. Here are the options, ranked:

Best: Personal Website (GitHub Pages, Vercel, or Notion)

One clean page with your name, 1-paragraph bio, and 5 artifact cards. Each card links to a detailed write-up. Takes 2 hours to set up.

Pros: Professional, customizable, shows you can ship a project.

Cons: Slight learning curve.

Good: Notion Page

Free, looks clean, easy to update. Share the public link on your resume.

Pros: Zero setup, looks professional.

Cons: Less customizable, can feel "student-ish."

Avoid: Just GitHub Repos

Hiring managers won't read your code. They want to see documents, write-ups, and artifacts. A GitHub repo with a readme is not a portfolio.

How to Present Portfolio Pieces in Interviews

When an interviewer asks "tell me about a risk assessment you've done," you say:

"I actually built a risk register for a fictional 30-person law firm as part of my portfolio. The biggest risk I identified was client data exposure via unencrypted laptops. I scored it as 4x5=20 (critical) because likelihood was high (lawyers travel constantly) and impact was high (client confidentiality breach = malpractice lawsuits). I recommended full-disk encryption + MDM, with a 30-day implementation timeline."

Then you hand them the printed artifact or share the link.

This does three things:

  1. Answers their question specifically
  2. Shows you think in risk scores and business impact
  3. Proves you can produce deliverables on day one

That's a hire. Every time.

The Bottom Line

A great cybersecurity portfolio has five pieces: risk register, policy, detection rule, gap assessment, and CTF write-up. Each is an artifact that mirrors real work, not a tutorial or code sample.

You can build all five in a weekend using the free tools on this site. Then document your reasoning in 500-word commentaries for each.

When you walk into an interview with a printed risk register and a written detection rule, you're not a candidate who "wants to learn cybersecurity." You're a practitioner who already thinks like one. And that's who gets hired.

Want the complete playbook?

AI Workflows for Cybersecurity Professionals

AI workflows for building portfolio pieces that hiring managers actually notice.

Get the Guide →

Frequently asked questions

Do I need a portfolio for cybersecurity jobs?

For entry-level and career-changers, yes. A portfolio demonstrates practical skills when you lack work experience. Mid-career professionals can rely on work history, but a portfolio still differentiates you.

Should my portfolio be on GitHub?

GitHub is fine for technical roles (SOC, pentesting), but GRC portfolios work better on a personal website or Notion page. The artifact matters more than the platform - hiring managers want to see documents, not just code repos.

How many portfolio pieces do I need?

Three to five high-quality pieces beat twenty shallow ones. One risk register, one policy, one detection rule, and one CTF writeup is enough to get interviews. Quality of reasoning matters more than quantity.

Can I use tools from this site in my portfolio?

Absolutely - that's exactly what they're designed for. Generate a risk register with our tool, then write a 500-word explanation of your methodology and risk acceptance rationale. That's portfolio gold.

Can you explain this in an interview?

CyberVerse AI asks you this topic out loud and grades your answer like a hiring manager.

Practice with CyberVerse AI →