Understands HTTP/HTTPS, DNS basics, TCP vs UDP. Knows what ports, IP addresses, and localhost are. Can use curl for API testing.
Roles · Application Security Engineer · Junior
What a Junior } should know
19 core skills, 54 in total. Expectations per skill, and what changes at the next level.
This page lists what a Junior } is expected to know and do, skill by skill. Core skills are the ones a manager and peers assess in a review cycle; the rest count only in self-assessment. Main areas: Cloud & Infrastructure, Security.
Core skills for a Junior
Grouped by area. The label on the right is the expected depth: Awareness, Working, Advanced or Expert.
Cloud & Infrastructure · 1
Security · 18
Understands basic Cloud Infrastructure Security concepts. Follows security guidelines. Recognizes typical code vulnerabilities.
Understands basic Dependency Vulnerability Scanning concepts. Follows security guidelines. Recognizes typical code vulnerabilities.
Understands basic Digital Forensics concepts. Follows security guidelines. Recognizes typical code vulnerabilities.
Understands basic GDPR / 152-FZ Compliance concepts. Follows security guidelines. Recognizes typical code vulnerabilities.
Understands basic Incident Response Process concepts. Follows security guidelines. Recognizes typical code vulnerabilities.
Understands basic JWT / OAuth2 / OIDC concepts. Follows security guidelines. Recognizes typical code vulnerabilities.
Understands basic Kubernetes Security concepts. Follows security guidelines. Recognizes typical code vulnerabilities.
Understands basic Network Security concepts. Follows security guidelines. Recognizes typical code vulnerabilities.
Understands basic OWASP and application security concepts. Follows security guidelines. Recognizes typical code vulnerabilities.
Understands core PCI DSS requirements for cardholder data protection. Follows secure coding guidelines aligned with PCI standards. Recognizes common application vulnerabilities that may lead to PCI compliance violations in codebases.
Understands basic RBAC / ABAC authorization concepts. Follows security guidelines. Recognizes typical code vulnerabilities.
Understands basic SAST/DAST concepts. Follows security guidelines. Recognizes typical code vulnerabilities.
Understands basic Secrets Management concepts. Follows security guidelines. Recognizes typical code vulnerabilities.
Understands basic Secure Coding Practices concepts. Follows security guidelines. Recognizes typical code vulnerabilities.
Understands basic SOC2 Compliance concepts. Follows security guidelines. Recognizes typical code vulnerabilities.
Understands basic Supply Chain Security concepts. Follows security guidelines. Recognizes typical code vulnerabilities.
Understands basic Threat Modeling concepts. Follows security guidelines. Recognizes typical code vulnerabilities.
Understands basic Vulnerability Management concepts. Follows security guidelines. Recognizes typical code vulnerabilities.
Additional skills
Not assessed by the team, but part of the self-assessment and the development plan.
What changes at Mid-level
54 skills get a higher expectation or become core when moving from Junior to Mid-level. The biggest jumps first.
- Cloud Security: Awareness → Working
- Dependency Vulnerability Scanning: Awareness → Working
- Digital Forensics Basics: Awareness → Working
- GDPR / 152-FZ Compliance: Awareness → Working
- Incident Response Process: Awareness → Working
- JWT / OAuth2 / OIDC: Awareness → Working
- Kubernetes Security: Awareness → Working
- Network Fundamentals: Awareness → Working
- Network Security: Awareness → Working
- OWASP & Application Security: Awareness → Working
} in the open competency matrix: 54 skills across 5 levels. The matrix is free for individuals and stays free.