Select your current position

Pick a role and level — we'll show the growth path, skills and gap analysis.

Development path

Junior

0-2 years

Current

Responsibility: Completing tasks under the guidance of senior colleagues. Learning the codebase, standards, and team processes. Writing code to spec, fixing simple bugs, writing tests.

Key skills:

E2E Testing Need
Property-Based Testing Need
Security Testing Need
TDD & BDD Need
Unit Testing Need
Integration Testing Need
Load Testing Need
Test Pyramid & Strategy Need
Test Data Management Need
Test Environment Management Need

Middle

2-5 years

Next

Responsibility: Independently developing features from decomposition to deployment. Participating in code review. Optimizing performance. Mentoring junior developers. Taking part in architecture discussions.

Key skills:

E2E Testing Need
Property-Based Testing Need
Security Testing Need
TDD & BDD Need
Unit Testing Need
Integration Testing Need
Load Testing Need
Test Pyramid & Strategy Need
Test Data Management Need
Test Environment Management Need

Senior

5-8 years

Responsibility: Designing the architecture of components and services. Solving complex technical problems. Managing technical debt. Code review as a quality gatekeeper. Mentoring middle developers. Choosing technologies for new tasks.

Key skills:

Code Review Need
Docker Need
E2E Testing Need
ELK Stack Need
GDPR / 152-FZ Compliance Need
Git Advanced Need
GitHub Actions / GitLab CI Need
GitHub Copilot Need
JWT / OAuth2 / OIDC Need
OWASP & Application Security Need
PCI DSS Need
Prometheus & Grafana Need
Property-Based Testing Need
RBAC / ABAC Authorization Need
REST API Design Need
SAST/DAST Need
Security Testing Need
TDD & BDD Need
Unit Testing Need
Algorithms & Complexity Need
Kubernetes Security Need
Cloud Security Need
Documentation as Code Need
Integration Testing Need
Code Quality & Refactoring Need
Threat Modeling Need
Load Testing Need
Secure Coding Practices Need
OOP & SOLID Principles Need
Incident Response Process Need
Network Security Need
Container Security Scanning Need
Dependency Vulnerability Scanning Need
Structured Logging Need
Data Structures Need
API Testing Need
Test Pyramid & Strategy Need
Test Data Management Need
Test Environment Management Need
Vulnerability Management Need

Lead / Staff

7-12 years

Responsibility: Technical leadership of a team or area. Designing system architecture. Coordinating with other teams. Establishing standards and best practices. Participating in hiring. Planning the technical roadmap.

Key skills:

Code Review Need
Docker Need
E2E Testing Need
ELK Stack Need
GDPR / 152-FZ Compliance Need
Git Advanced Need
GitHub Actions / GitLab CI Need
GitHub Copilot Need
JWT / OAuth2 / OIDC Need
OWASP & Application Security Need
PCI DSS Need
Prometheus & Grafana Need
Property-Based Testing Need
RBAC / ABAC Authorization Need
REST API Design Need
SAST/DAST Need
Security Testing Need
TDD & BDD Need
Unit Testing Need
Algorithms & Complexity Need
Kubernetes Security Need
Cloud Security Need
Documentation as Code Need
Integration Testing Need
Code Quality & Refactoring Need
Threat Modeling Need
Load Testing Need
Secure Coding Practices Need
OOP & SOLID Principles Need
Incident Response Process Need
Network Security Need
Container Security Scanning Need
Dependency Vulnerability Scanning Need
Structured Logging Need
Data Structures Need
API Testing Need
Test Pyramid & Strategy Need
Test Data Management Need
Test Environment Management Need
Vulnerability Management Need

Principal

10+ years

Responsibility: Technical strategy at the company or domain level. Cross-organizational influence. Solving systemic business problems through technology. Mentoring lead engineers. Publicly representing the company.

Key skills:

Code Review Need
Docker Need
E2E Testing Need
ELK Stack Need
GDPR / 152-FZ Compliance Need
Git Advanced Need
GitHub Actions / GitLab CI Need
GitHub Copilot Need
JWT / OAuth2 / OIDC Need
OWASP & Application Security Need
PCI DSS Need
Prometheus & Grafana Need
Property-Based Testing Need
RBAC / ABAC Authorization Need
REST API Design Need
SAST/DAST Need
Security Testing Need
TDD & BDD Need
Unit Testing Need
Algorithms & Complexity Need
Kubernetes Security Need
Cloud Security Need
Documentation as Code Need
Integration Testing Need
Code Quality & Refactoring Need
Threat Modeling Need
Load Testing Need
Secure Coding Practices Need
OOP & SOLID Principles Need
Incident Response Process Need
Network Security Need
Container Security Scanning Need
Dependency Vulnerability Scanning Need
Structured Logging Need
Data Structures Need
API Testing Need
Test Pyramid & Strategy Need
Test Data Management Need
Test Environment Management Need
Vulnerability Management Need

Gap analysis: skills to develop

To reach the next level you'll need to develop:

E2E Testing

Writes E2E security tests: login/logout flows, session hijacking prevention, CSRF protection, file upload security. Uses Selenium/Playwright with security focus.

Property-Based Testing

Applies property-based testing for security: random input generation for fuzzing, invariant checking for authorization rules. Uses Hypothesis/QuickCheck for security properties.

Security Testing

Conducts security testing: OWASP Top 10 verification, vulnerability scanning (ZAP/Burp), dependency checking (Snyk). Documents findings with reproducible steps.

TDD & BDD

Applies BDD for security requirements: Gherkin scenarios for authentication, authorization rules, compliance requirements. TDD for security utility functions.

Unit Testing

Writes unit tests for security code: input validation functions, encoding/escaping, cryptographic helpers. Tests edge cases and boundary values.

Integration Testing

Writes integration tests for security: authentication flows, authorization checks across services, session management. Tests security middleware and filters.

Load Testing

Conducts security load testing: DDoS simulation, brute-force resistance testing, rate limiting verification. Uses k6/Locust for security load tests.

Test Pyramid & Strategy

Applies test pyramid for security: unit tests for validation functions, integration for auth flows, E2E for critical security paths. Balances coverage and speed.

Test Data Management

Manages test data for security: sanitized production data, synthetic PII generation, credential management for test environments. Ensures compliance in test data.

Test Environment Management

Manages security test environments: isolated environments for penetration testing, sandboxed environments for malware analysis. Configures network isolation.