Studies TCP/IP, DNS, HTTP/HTTPS basics, OSI model. Understands firewall, NAT, VPN operation. Uses nslookup, ping, traceroute, netstat for diagnostics. Configures Security Groups in AWS. Understands TLS handshake and X.509 certificate principles for connection security.
Roles · DevSecOps Engineer · Junior
What a Junior } should know
15 core skills, 57 in total. Expectations per skill, and what changes at the next level.
This page lists what a Junior } is expected to know and do, skill by skill. Core skills are the ones a manager and peers assess in a review cycle; the rest count only in self-assessment. Main areas: Cloud & Infrastructure, Security.
Core skills for a Junior
Grouped by area. The label on the right is the expected depth: Awareness, Working, Advanced or Expert.
Cloud & Infrastructure · 1
Security · 14
Studies AWS Security Hub, IAM best practices, S3 bucket policies. Configures MFA for root account and IAM users. Applies AWS Config rules for basic compliance. Uses ScoutSuite for automated cloud account security audit and misconfiguration detection.
Configures Snyk and Dependabot for automated project dependency scanning. Studies CVE reports, understands CVSS vulnerability scoring. Updates vulnerable dependencies through Dependabot auto-merge for patch versions. Uses npm audit and pip audit for local checks.
Studies incident response fundamentals: NIST phases (Preparation, Detection, Containment, Eradication, Recovery). Participates in on-call rotation under senior engineer mentorship. Documents incidents in tracking system. Masters basic tools: PagerDuty, OpsGenie, Slack incident bot.
Studies JWT basics: token structure (header, payload, signature), signing algorithms (HS256, RS256). Configures OAuth 2.0 Authorization Code flow for web application. Understands difference between access token and refresh token. Uses jwt.io for token debugging and validation.
Studies Kubernetes security fundamentals: RBAC, ServiceAccount, SecurityContext. Configures Pod Security Standards (Restricted). Runs Trivy for image scanning in cluster. Applies NetworkPolicies for basic pod segmentation. Understands least privilege principles for containers.
Studies network security fundamentals: firewall rules, VPN, TLS/SSL. Configures Security Groups and NACLs in AWS. Understands Defense in Depth and network segmentation principles. Uses Wireshark for basic traffic analysis. Configures HTTPS with Let's Encrypt for web applications.
Studies OWASP Top 10 vulnerabilities: SQL injections, XSS, CSRF, SSRF. Completes OWASP WebGoat and Juice Shop labs. Uses OWASP Cheat Sheets for understanding basic web application threats. Configures OWASP Dependency-Check locally for dependency analysis.
Studies access control models: RBAC (Role-Based), ABAC (Attribute-Based), DAC and MAC. Configures basic RBAC in application with admin, editor, viewer roles. Applies Kubernetes RBAC with Roles and ClusterRoles. Understands least privilege and separation of duties principles.
Runs SonarQube and Semgrep locally for static code analysis. Studies SAST reports, classifies vulnerabilities by severity. Configures basic DAST scan with OWASP ZAP against test application. Understands difference between SAST, DAST and IAST approaches to security testing.
Installs HashiCorp Vault in dev mode, studies basic operations: reading/writing secrets via CLI and API. Configures KV secrets engine v2 with versioning. Understands zero-trust principle for secrets in code. Uses Vault Agent for automated token rotation.
Studies secure coding principles: input validation, parameterized queries, proper password hashing (bcrypt/Argon2). Applies encoding for XSS prevention. Uses OWASP Secure Coding Practices Quick Reference Guide in daily development.
Understands basic SBOM concepts: software bill of materials formats (SPDX, CycloneDX), dependency tracking, and license compliance fundamentals. Follows security guidelines for reviewing dependency vulnerabilities using automated scanning tools. Recognizes common supply chain attack vectors.
Studies STRIDE and DREAD threat modeling methodologies. Participates in threat modeling sessions under senior engineer guidance. Documents identified threats in standard format. Uses OWASP Threat Dragon for visualizing DFD data flow diagrams.
Studies vulnerability management process: scanning, prioritization, patching. Runs Nessus/OpenVAS for basic infrastructure scanning. Understands CVSS scoring and vulnerability classification. Tracks CVEs in NVD. Creates tickets for vulnerability remediation with description and fix guidance.
Additional skills
Not assessed by the team, but part of the self-assessment and the development plan.
What changes at Mid-level
57 skills get a higher expectation or become core when moving from Junior to Mid-level. The biggest jumps first.
- Cloud Security: Awareness → Working
- Dependency Vulnerability Scanning: Awareness → Working
- Incident Response Process: Awareness → Working
- JWT / OAuth2 / OIDC: Awareness → Working
- Kubernetes Security: Awareness → Working
- Network Fundamentals: Awareness → Working
- Network Security: Awareness → Working
- OWASP & Application Security: Awareness → Working
- RBAC / ABAC Authorization: Awareness → Working
- SAST/DAST: Awareness → Working
} in the open competency matrix: 57 skills across 5 levels. The matrix is free for individuals and stays free.