Defines algorithmic standards for security testing team: scanning algorithm selection criteria, fuzzing strategy evaluation, attack path analysis algorithm reviews. Conducts reviews of algorithmic trade-offs between testing thoroughness and operational efficiency.
Roles · Penetration Testing Engineer · Lead
What a Lead } should know
35 core skills, 50 in total. Expectations per skill, and what changes at the next level.
This page lists what a Lead } is expected to know and do, skill by skill. Core skills are the ones a manager and peers assess in a review cycle; the rest count only in self-assessment. Main areas: Programming Fundamentals, API & Integration, Cloud & Infrastructure.
Core skills for a Lead
Grouped by area. The label on the right is the expected depth: Awareness, Working, Advanced or Expert.
Programming Fundamentals · 6
Defines async programming standards for security testing team: concurrent scanning architecture guidelines, async exploit execution reviews, non-blocking assessment patterns. Establishes best practices for async patterns in security testing tools.
Defines code quality standards for penetration testing team: exploit code conventions, scanner module architecture, report automation guidelines. Conducts reviews of testing methodology and evidence collection. Establishes quality gates for tool accuracy and operational security.
Defines data structure standards for security testing team: target enumeration data models, exploit payload organization, evidence collection structures. Conducts reviews of scanning tool data architecture. Establishes team guidelines for efficient vulnerability data management.
Defines multithreading standards for penetration testing teams: establishes guidelines for concurrent scanning and assessment tool architectures, conducts reviews of parallel exploit execution designs, creates training materials on thread-safe offensive security tool development.
Defines OOP/SOLID standards for security testing team: exploit module architecture guidelines, scanner plugin interface contracts, payload framework class design. Conducts reviews of OOP decisions balancing tool extensibility with exploit development speed.
API & Integration · 5
Defines API penetration testing methodology and toolchain standards for the security team. Evaluates and integrates commercial and open-source API security tools (Burp Suite Enterprise, Nuclei, custom scanners). Coordinates API security assessments across product lines, prioritizes findings by business risk, and drives remediation with engineering leads. Builds team competency in emerging API attack vectors.
Defines GraphQL security assessment strategy across the product portfolio. Establishes standards for GraphQL threat modeling, introspection policy enforcement, and query depth governance. Conducts cross-team API security reviews and coordinates GraphQL vulnerability disclosure processes.
Defines API strategy at the product level. Establishes design standards. Conducts API design reviews. Coordinates cross-team API interaction.
Defines API security testing strategy at product level: API penetration testing standards, automated API security scanning governance, API vulnerability assessment frameworks. Conducts API security architecture reviews and establishes API security testing processes.
Defines API strategy at the product level. Establishes design standards. Conducts API design reviews. Coordinates cross-team API interaction.
Cloud & Infrastructure · 4
Defines container security assessment strategy and red team methodology. Establishes container penetration testing standards, reporting frameworks, and remediation verification processes. Coordinates offensive security exercises targeting container infrastructure.
Defines Docker strategy for security testing: ephemeral test environment standards, container security assessment governance, isolated lab architecture guidelines. Conducts architecture reviews for containerized pentest infrastructure and establishes secure container usage policies.
Defines network security assessment strategy across the organization's infrastructure. Establishes IaC standards for penetration testing lab environments and attack simulation platforms. Conducts architecture reviews of network security configurations and drives adoption of zero-trust network principles across engineering teams.
Defines infrastructure strategy with VPN and Network Isolation. Establishes IaC standards. Conducts architecture reviews. Optimizes FinOps.
Testing & QA · 1
Defines penetration testing strategy for the organization. Establishes pentest methodologies, scope guidelines, and reporting standards. Coordinates red team operations and purple team exercises. Creates attack simulation frameworks for continuous security validation. Trains pentest team on emerging attack vectors.
Security · 13
Defines offensive cloud security strategy across AWS, Azure, and GCP attack surfaces. Establishes penetration testing policies and red team engagement rules for cloud infrastructure. Coordinates response to critical cloud vulnerabilities discovered during assessments and trains teams on cloud exploitation frameworks.
Defines the penetration testing team's strategy for leveraging dependency scanning data in engagements. Establishes standard operating procedures for correlating SCA findings from Snyk, Grype, and OSV with exploitable attack paths. Coordinates red team exercises that simulate supply chain attacks targeting vulnerable dependencies. Trains pentest engineers on advanced SCA exploitation techniques, SBOM analysis, and supply chain threat intelligence.
Defines forensic capabilities within the offensive security practice. Establishes standards for evidence collection, preservation, and reporting during penetration tests and red team exercises. Coordinates with legal and compliance teams on forensic requirements and trains offensive security staff on forensic techniques.
Defines offensive security's role in the incident response process across the organization. Establishes red team/purple team exercise programs that systematically test incident response maturity. Coordinates with SOC leadership on improving detection coverage based on real-world attack simulation results.
Defines authentication security testing strategy for the organization. Establishes penetration testing methodologies for JWT/OAuth2/OIDC systems. Creates red team playbooks for identity infrastructure assessment. Coordinates authentication security testing across product teams. Trains pentest team on advanced authentication attack techniques.
Defines Kubernetes offensive security testing programs covering multi-cluster and multi-cloud environments. Establishes red team playbooks for container orchestration attacks aligned with current threat intelligence. Coordinates with platform teams on remediation priorities and drives continuous improvement of cluster security posture.
Leads the team's network penetration testing practice: defines engagement scoping for network assessments, standardizes network attack toolchains and reporting templates, and prioritizes remediation across firewall, VPN, and segmentation findings. Builds team capabilities in advanced network exploitation and coordinates purple-team exercises focused on network defense validation.
Defines penetration testing strategy and application security assessment programs across the organization. Establishes security testing policies, red team exercise frameworks, and vulnerability disclosure processes. Coordinates large-scale security assessments and trains teams on advanced attack simulation methodologies.
Defines authorization penetration testing strategy across all products and platforms. Establishes security testing policies for RBAC/ABAC implementations. Coordinates red team exercises targeting access control systems. Trains pentest engineers on advanced authorization bypass techniques.
Defines SAST/DAST integration strategy for penetration testing across all products. Establishes scanner validation policies and custom rule development standards. Coordinates offensive security efforts combining automated scanning with manual testing. Trains pentest engineers on advanced SAST/DAST usage.
Defines secure coding assessment strategy for penetration testing programs across the organization. Establishes policies for code-assisted pentesting, source code review standards, and vulnerability remediation verification. Coordinates large-scale code security assessments and trains red team members on code-level exploitation methodologies.
Defines threat-driven penetration testing strategy at team level. Establishes threat model-informed scoping and prioritization for all engagements. Coordinates red team and purple team exercises aligned with organizational threat landscape. Builds feedback loops between threat modeling outcomes, pentest findings, and security architecture decisions.
Defines vulnerability discovery strategy integrating penetration testing with continuous scanning programs. Establishes severity classification policies and validation standards for reported vulnerabilities. Coordinates red team assessments feeding into vulnerability management processes. Trains pentest engineers on systematic vulnerability analysis.
AI-Assisted Development · 1
Defines GitHub Copilot strategy for penetration testing teams: establishes ethical guidelines for AI-assisted exploit development, designs review policies for AI-generated security assessment code, drives responsible Copilot adoption with focus on confidentiality and compliance.
Observability & Monitoring · 2
Defines the offensive security team's observability strategy using ELK Stack. Establishes SLO-based approach for vulnerability management metrics: detection-to-report time, retest coverage, and finding recurrence rates. Coordinates incident management workflows between red team and blue team through shared Kibana dashboards and Elasticsearch alerting. Drives adoption of OpenSearch for cost-effective long-term storage of engagement data. Optimizes MTTD/MTTR by integrating ELK with ticketing and notification systems.
Defines observability assessment strategy for penetration testing practice: establishes SLO-based approach for security monitoring evaluation, coordinates incident response validation during assessment engagements, optimizes MTTD/MTTR measurement methodology for client organizations.
Version Control & Collaboration · 2
Defines security code review strategy for security testing team: offensive security review standards, exploit code quality governance, security tool review practices. Establishes review culture for security testing code quality.
Defines Git strategy for penetration testing teams: establishes standards for secure repository management of assessment data, designs access control and audit policies for engagement repositories, drives adoption of automated secret scanning across all team repositories.
Documentation · 1
Defines runbook strategy for the penetration testing practice: standardizes engagement methodology playbooks, establishes quality gates for runbook completeness, drives integration of runbooks with vulnerability management platforms and reporting automation.
Additional skills
Not assessed by the team, but part of the self-assessment and the development plan.
What changes at Principal
0 skills get a higher expectation or become core when moving from Lead to Principal. The biggest jumps first.
} in the open competency matrix: 50 skills across 5 levels. The matrix is free for individuals and stays free.