Understands basic Cloud Infrastructure Security concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Roles · Penetration Testing Engineer · Junior
What a Junior } should know
13 core skills, 50 in total. Expectations per skill, and what changes at the next level.
This page lists what a Junior } is expected to know and do, skill by skill. Core skills are the ones a manager and peers assess in a review cycle; the rest count only in self-assessment. Main areas: Security.
Core skills for a Junior
Grouped by area. The label on the right is the expected depth: Awareness, Working, Advanced or Expert.
Security · 13
Understands basic Dependency Vulnerability Scanning concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Understands basic Digital Forensics concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Understands basic Incident Response Process concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Understands JWT/OAuth2 concepts from a security testing perspective: common JWT vulnerabilities (none algorithm, key confusion), OAuth2 redirect URI manipulation, and token leakage vectors. Recognizes insecure token storage and transmission patterns. Follows team guidelines for authentication security assessments.
Understands basic Kubernetes Security concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Understands basic network security concepts: TCP/IP model, common ports and protocols, firewall rule logic. Can run Nmap scans, read packet captures in Wireshark, and identify open services on a target host under supervision.
Understands basic OWASP and Application Security concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Understands basic RBAC / ABAC Authorization concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Understands basic SAST/DAST concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Understands basic secure coding concepts from a penetration testing perspective — recognizes injection, authentication bypass, and insecure deserialization patterns in source code. Follows security guidelines for identifying exploitable code weaknesses and understands how common vulnerabilities manifest in different programming languages.
Understands basic Threat Modeling concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Understands basic Vulnerability Management concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Additional skills
Not assessed by the team, but part of the self-assessment and the development plan.
What changes at Mid-level
50 skills get a higher expectation or become core when moving from Junior to Mid-level. The biggest jumps first.
- Cloud Security: Awareness → Working
- Dependency Vulnerability Scanning: Awareness → Working
- Digital Forensics Basics: Awareness → Working
- Incident Response Process: Awareness → Working
- JWT / OAuth2 / OIDC: Awareness → Working
- Kubernetes Security: Awareness → Working
- Network Security: Awareness → Working
- OWASP & Application Security: Awareness → Working
- RBAC / ABAC Authorization: Awareness → Working
- SAST/DAST: Awareness → Working
} in the open competency matrix: 50 skills across 5 levels. The matrix is free for individuals and stays free.