Select your current position

Pick a role and level — we'll show the growth path, skills and gap analysis.

Development path

Junior

0-2 years

Current

Responsibility: Setting up SAST/DAST in CI/CD. Scanning Docker images. Managing secrets. Monitoring dependency vulnerabilities.

Key skills:

JWT / OAuth2 / OIDC Need
OWASP & Application Security Need
RBAC / ABAC Authorization Need
SAST/DAST Need
Secrets Management Need
Supply Chain Security Need
Kubernetes Security Need
Cloud Security Need
Threat Modeling Need
Network Fundamentals Need
Secure Coding Practices Need
Incident Response Process Need
Network Security Need
Dependency Vulnerability Scanning Need
Vulnerability Management Need

Middle

2-5 years

Next

Responsibility: Designing security pipeline. Policy as Code (OPA/Rego). Container security. Supply chain security. Compliance automation.

Key skills:

JWT / OAuth2 / OIDC Need
OWASP & Application Security Need
RBAC / ABAC Authorization Need
SAST/DAST Need
Secrets Management Need
Supply Chain Security Need
Kubernetes Security Need
Cloud Security Need
Threat Modeling Need
Network Fundamentals Need
Secure Coding Practices Need
Incident Response Process Need
Network Security Need
Dependency Vulnerability Scanning Need
Vulnerability Management Need

Senior

5-8 years

Responsibility: DevSecOps platform architecture. Runtime security (Falco). Network policies. Secrets management at scale. Security observability.

Key skills:

Ansible Need
ArgoCD Need
AWS Need
Blue/Green Deployment Need
Canary Deployment Need
Code Review Need
Docker Need
ELK Stack Need
Feature Flags Need
Git Advanced Need
GitHub Actions / GitLab CI Need
GitHub Copilot Need
GitLab CI/CD Advanced Need
Helm Need
JWT / OAuth2 / OIDC Need
Kubernetes Advanced Need
Kubernetes Core Need
OpenTelemetry Need
OWASP & Application Security Need
Prometheus & Grafana Need
RBAC / ABAC Authorization Need
Runbook & Playbook Writing Need
SAST/DAST Need
Secrets Management Need
Security Testing Need
Supply Chain Security Need
Terraform Need
Algorithms & Complexity Need
Kubernetes Security Need
Cloud Security Need
Code Quality & Refactoring Need
Threat Modeling Need
Network Fundamentals Need
Secure Coding Practices Need
Incident Response Process Need
Network Security Need
Container Security Scanning Need
Dependency Vulnerability Scanning Need
Structured Logging Need
Data Structures Need
On-Call Management Need
Vulnerability Management Need

Lead / Staff

7-12 years

Responsibility: DevSecOps strategy. Security as Code standards. Coordination with DevOps and Security. Compliance automation platform.

Key skills:

Ansible Need
ArgoCD Need
AWS Need
Blue/Green Deployment Need
Canary Deployment Need
Code Review Need
Docker Need
ELK Stack Need
Feature Flags Need
Git Advanced Need
GitHub Actions / GitLab CI Need
GitHub Copilot Need
GitLab CI/CD Advanced Need
Helm Need
JWT / OAuth2 / OIDC Need
Kubernetes Advanced Need
Kubernetes Core Need
OpenTelemetry Need
OWASP & Application Security Need
Prometheus & Grafana Need
RBAC / ABAC Authorization Need
Runbook & Playbook Writing Need
SAST/DAST Need
Secrets Management Need
Security Testing Need
Supply Chain Security Need
Terraform Need
Algorithms & Complexity Need
Kubernetes Security Need
Cloud Security Need
Code Quality & Refactoring Need
Threat Modeling Need
Secure Coding Practices Need
Incident Response Process Need
Network Security Need
Container Security Scanning Need
Dependency Vulnerability Scanning Need
Structured Logging Need
Data Structures Need
On-Call Management Need
Vulnerability Management Need

Principal

10+ years

Responsibility: Enterprise DevSecOps. Supply chain security strategy. Zero Trust CI/CD. Industry thought leadership.

Key skills:

Ansible Need
ArgoCD Need
AWS Need
Blue/Green Deployment Need
Canary Deployment Need
Code Review Need
Docker Need
ELK Stack Need
Feature Flags Need
Git Advanced Need
GitHub Actions / GitLab CI Need
GitHub Copilot Need
GitLab CI/CD Advanced Need
Helm Need
JWT / OAuth2 / OIDC Need
Kubernetes Advanced Need
Kubernetes Core Need
OpenTelemetry Need
OWASP & Application Security Need
Prometheus & Grafana Need
RBAC / ABAC Authorization Need
Runbook & Playbook Writing Need
SAST/DAST Need
Secrets Management Need
Security Testing Need
Supply Chain Security Need
Terraform Need
Algorithms & Complexity Need
Kubernetes Security Need
Cloud Security Need
Code Quality & Refactoring Need
Threat Modeling Need
Secure Coding Practices Need
Incident Response Process Need
Network Security Need
Container Security Scanning Need
Dependency Vulnerability Scanning Need
Structured Logging Need
Data Structures Need
On-Call Management Need
Vulnerability Management Need

Gap analysis: skills to develop

To reach the next level you'll need to develop:

JWT / OAuth2 / OIDC

Implements OAuth 2.0 with PKCE for SPA and mobile applications. Configures Keycloak/Auth0 as Identity Provider with OIDC support. Introduces secure token storage (HttpOnly cookies, token rotation). Implements rate limiting and token revocation. Configures scope-based authorization.

OWASP & Application Security

Introduces OWASP ASVS as application security verification standard. Conducts code review against OWASP Top 10. Configures OWASP ZAP for automated DAST scanning in CI/CD. Applies OWASP Testing Guide for systematic web application vulnerability testing.

RBAC / ABAC Authorization

Implements hierarchical RBAC with role inheritance and permission boundaries. Introduces ABAC with Open Policy Agent (OPA) for context-dependent access decisions. Configures AWS IAM policies with conditions for ABAC. Creates access change audit system. Implements just-in-time access.

SAST/DAST

Integrates SonarQube and Semgrep into CI/CD pipelines with quality gates blocking merge on critical vulnerabilities. Configures OWASP ZAP in API scanning mode with OpenAPI specification. Writes custom Semgrep rules for project-specific vulnerability patterns.

Secrets Management

Deploys Vault in production with auto-unseal through AWS KMS. Configures AppRole and Kubernetes auth methods for applications. Implements dynamic secrets for PostgreSQL and AWS IAM. Manages Vault policies with least privilege principle. Integrates Vault with Terraform through provider.

Supply Chain Security

Applies Supply Chain Security in daily work. Conducts security code review. Uses scanning and analysis tools.

Kubernetes Security

Introduces OPA Gatekeeper with constraint templates for Policy-as-Code in cluster. Configures Falco for runtime anomaly detection in containers. Implements image signing with Cosign and verification through Kyverno. Manages Kubernetes RBAC with ClusterRoles following minimal access principle.

Cloud Security

Introduces AWS Security Hub with CIS and PCI DSS standards enabled. Configures GuardDuty for threat detection, AWS Config for continuous compliance. Implements landing zone with Control Tower and SCPs. Manages IAM through Terraform with enforced MFA and session policies.

Threat Modeling

Independently conducts threat modeling for microservices using STRIDE. Builds Data Flow Diagrams, identifies trust boundaries and attack surfaces. Applies Microsoft Threat Modeling Tool for systematic analysis. Prioritizes threats by DREAD model and creates mitigation plans.

Network Fundamentals

Designs cloud network architectures: VPC peering, Transit Gateway, PrivateLink. Configures DNS security (DNSSEC, DoH). Introduces mTLS between services. Analyzes network traffic with tcpdump and Wireshark for incident investigation. Configures VPN (WireGuard) for secure remote access.

Secure Coding Practices

Introduces secure coding practices in the team: Content Security Policy, CORS configuration, secure session handling. Configures pre-commit hooks with Semgrep for blocking insecure patterns. Conducts security review of pull requests. Implements SSRF and path traversal protection.

Incident Response Process

Independently manages incidents as Incident Commander for P2/P3 incidents. Conducts security incident investigation with log analysis (ELK). Creates runbooks for common incidents: compromised credentials, DDoS, data breach. Configures automated alerts and escalation policies in PagerDuty.

Network Security

Designs network architecture with DMZ, private subnets and NAT gateways. Configures WAF (AWS WAF / ModSecurity) with rules against OWASP Top 10. Introduces VPN (WireGuard/IPSec) for site-to-site and remote access. Monitors network anomalies through VPC Flow Logs and AWS Traffic Mirroring.

Dependency Vulnerability Scanning

Integrates Snyk into CI/CD with build-blocking policy for critical CVEs (CVSS 9+). Configures Dependabot with update grouping and scheduled runs. Manages .snyk policy files for justified exceptions. Analyzes transitive dependencies and license compliance through FOSSA.

Vulnerability Management

Introduces regular vulnerability scanning for all infrastructure through Qualys/Rapid7 InsightVM. Configures remediation SLAs: Critical 24h, High 7d, Medium 30d. Integrates scan results with Jira for automated ticket creation. Builds dashboards with vulnerability trends.