Roles · DevSecOps Engineer · Mid-level

What a Mid-level } should know

15 core skills, 57 in total. Expectations per skill, and what changes at the next level.

This page lists what a Mid-level } is expected to know and do, skill by skill. Core skills are the ones a manager and peers assess in a review cycle; the rest count only in self-assessment. Main areas: Cloud & Infrastructure, Security.

15core skills
42additional skills
2skill areas
0%at Advanced or Expert
Assess myself as Mid-level Full role matrix

Core skills for a Mid-level

Grouped by area. The label on the right is the expected depth: Awareness, Working, Advanced or Expert.

Cloud & Infrastructure · 1

Designs cloud network architectures: VPC peering, Transit Gateway, PrivateLink. Configures DNS security (DNSSEC, DoH). Introduces mTLS between services. Analyzes network traffic with tcpdump and Wireshark for incident investigation. Configures VPN (WireGuard) for secure remote access.

Security · 14

Cloud Security Working

Introduces AWS Security Hub with CIS and PCI DSS standards enabled. Configures GuardDuty for threat detection, AWS Config for continuous compliance. Implements landing zone with Control Tower and SCPs. Manages IAM through Terraform with enforced MFA and session policies.

Integrates Snyk into CI/CD with build-blocking policy for critical CVEs (CVSS 9+). Configures Dependabot with update grouping and scheduled runs. Manages .snyk policy files for justified exceptions. Analyzes transitive dependencies and license compliance through FOSSA.

Independently manages incidents as Incident Commander for P2/P3 incidents. Conducts security incident investigation with log analysis (ELK). Creates runbooks for common incidents: compromised credentials, DDoS, data breach. Configures automated alerts and escalation policies in PagerDuty.

Implements OAuth 2.0 with PKCE for SPA and mobile applications. Configures Keycloak/Auth0 as Identity Provider with OIDC support. Introduces secure token storage (HttpOnly cookies, token rotation). Implements rate limiting and token revocation. Configures scope-based authorization.

Introduces OPA Gatekeeper with constraint templates for Policy-as-Code in cluster. Configures Falco for runtime anomaly detection in containers. Implements image signing with Cosign and verification through Kyverno. Manages Kubernetes RBAC with ClusterRoles following minimal access principle.

Designs network architecture with DMZ, private subnets and NAT gateways. Configures WAF (AWS WAF / ModSecurity) with rules against OWASP Top 10. Introduces VPN (WireGuard/IPSec) for site-to-site and remote access. Monitors network anomalies through VPC Flow Logs and AWS Traffic Mirroring.

Introduces OWASP ASVS as application security verification standard. Conducts code review against OWASP Top 10. Configures OWASP ZAP for automated DAST scanning in CI/CD. Applies OWASP Testing Guide for systematic web application vulnerability testing.

Implements hierarchical RBAC with role inheritance and permission boundaries. Introduces ABAC with Open Policy Agent (OPA) for context-dependent access decisions. Configures AWS IAM policies with conditions for ABAC. Creates access change audit system. Implements just-in-time access.

SAST/DAST Working

Integrates SonarQube and Semgrep into CI/CD pipelines with quality gates blocking merge on critical vulnerabilities. Configures OWASP ZAP in API scanning mode with OpenAPI specification. Writes custom Semgrep rules for project-specific vulnerability patterns.

Deploys Vault in production with auto-unseal through AWS KMS. Configures AppRole and Kubernetes auth methods for applications. Implements dynamic secrets for PostgreSQL and AWS IAM. Manages Vault policies with least privilege principle. Integrates Vault with Terraform through provider.

Introduces secure coding practices in the team: Content Security Policy, CORS configuration, secure session handling. Configures pre-commit hooks with Semgrep for blocking insecure patterns. Conducts security review of pull requests. Implements SSRF and path traversal protection.

Applies Supply Chain Security in daily work. Conducts security code review. Uses scanning and analysis tools.

Threat Modeling Working

Independently conducts threat modeling for microservices using STRIDE. Builds Data Flow Diagrams, identifies trust boundaries and attack surfaces. Applies Microsoft Threat Modeling Tool for systematic analysis. Prioritizes threats by DREAD model and creates mitigation plans.

Introduces regular vulnerability scanning for all infrastructure through Qualys/Rapid7 InsightVM. Configures remediation SLAs: Critical 24h, High 7d, Medium 30d. Integrates scan results with Jira for automated ticket creation. Builds dashboards with vulnerability trends.

Additional skills

Not assessed by the team, but part of the self-assessment and the development plan.

Algorithms & ComplexityAnsibleAPI DocumentationArgoCDAsync ProgrammingAWSBlue/Green DeploymentCanary DeploymentChatGPT / ClaudeCode Quality & RefactoringCode ReviewContainer Security ScanningCursor IDEData StructuresDesign PatternsDockerELK StackFeature FlagsGit AdvancedGitHub Actions / GitLab CIGitHub CopilotGitLab CI/CD AdvancedGraphQL DesignHelmIntegration TestingKubernetes AdvancedKubernetes CoreMultithreadingOn-Call ManagementOOP & SOLID PrinciplesOpenTelemetryPostgreSQLPrometheus & GrafanaPrompt Engineering for CodeRedisREST API DesignRunbook & Playbook WritingSecurity TestingStructured LoggingSystem Design FundamentalsTerraformUnit Testing

What changes at Senior

57 skills get a higher expectation or become core when moving from Mid-level to Senior. The biggest jumps first.

See the Senior page →
Run this with your whole team
Self-assessment plus manager and peer reviews against the same matrix, gap analysis and next-level readiness for every engineer. Team Pro is free for 14 days; individual tools stay free forever.
Start a team trial (14 days free) Send to my manager

} in the open competency matrix: 57 skills across 5 levels. The matrix is free for individuals and stays free.