Applies algorithmic thinking to security testing: brute-force optimization algorithms for credential testing, graph traversal algorithms for network attack path discovery, fuzzing mutation algorithms for input generation. Designs efficient scanning algorithms that maximize coverage while minimizing detection risk.
Roles · Penetration Testing Engineer · Senior
What a Senior } should know
35 core skills, 50 in total. Expectations per skill, and what changes at the next level.
This page lists what a Senior } is expected to know and do, skill by skill. Core skills are the ones a manager and peers assess in a review cycle; the rest count only in self-assessment. Main areas: Programming Fundamentals, API & Integration, Cloud & Infrastructure.
Core skills for a Senior
Grouped by area. The label on the right is the expected depth: Awareness, Working, Advanced or Expert.
Programming Fundamentals · 6
Designs async architectures for security tools: massively concurrent scanning, async exploit chain execution, non-blocking result aggregation and analysis. Mentors team on async patterns for efficient security assessment at scale.
Designs code quality standards for security tooling and exploit code: modular vulnerability scanner architecture, reusable exploit frameworks, report generation automation. Refactors penetration testing scripts for reliability and evidence preservation. Establishes review practices for operational security and tool accuracy.
Selects optimal data structures for penetration testing tools: graph structures for attack path modeling, hash tables for credential storage and lookup, trie structures for payload pattern matching. Optimizes data structures for efficient port scanning and service fingerprinting. Designs efficient evidence storage structures for vulnerability chain documentation.
Has deep expertise in multithreading for security testing: designs high-performance concurrent scanning architectures, implements thread-safe exploit chaining and results aggregation, optimizes parallel assessment techniques for large-scale engagements. Mentors team on concurrent programming for offensive security tools.
Applies OOP/SOLID in security tool architecture: abstract scanner interfaces for pluggable vulnerability checks, strategy pattern for exploit technique selection, template method for assessment workflow standardization. Designs modular penetration testing frameworks with clean separation between reconnaissance, exploitation, and reporting.
API & Integration · 5
Leads complex API penetration testing engagements targeting GraphQL, gRPC, and WebSocket APIs alongside REST. Develops custom exploitation tools and fuzzing harnesses for API-specific vulnerabilities. Identifies business logic flaws through deep API flow analysis. Creates reusable Burp Suite automation pipelines and trains junior pentesters on advanced API attack techniques.
Designs comprehensive GraphQL security assessment methodologies for production APIs. Architects advanced attack scenarios including authorization bypass through nested resolvers, information disclosure via error messages, and resource exhaustion through query complexity manipulation. Defines remediation standards and security review processes for GraphQL schema changes.
Designs rate limiting assessment methodology for complex systems: tests distributed rate limiting consistency, evaluates race conditions in quota enforcement, and assesses API gateway throttling under concurrent attack scenarios. Mentors team on advanced bypass techniques.
Designs API security testing strategies: comprehensive API attack surface assessment, automated API security scanning integration, business logic vulnerability analysis frameworks. Defines API security testing standards and breach simulation methodologies. Mentors team on advanced API exploitation.
Designs comprehensive WebSocket security assessment programs: advanced exploitation techniques for WebSocket protocol weaknesses, automated fuzzing frameworks for message handling, and red team methodologies for real-time communication infrastructure. Creates WebSocket security testing tools and frameworks. Conducts threat modeling for WebSocket-based architectures. Mentors team on WebSocket security testing.
Cloud & Infrastructure · 4
Designs comprehensive container penetration testing methodology covering image vulnerabilities, runtime exploits, and orchestrator attacks. Develops custom container escape techniques and kernel exploitation scenarios. Mentors team on container-specific attack surfaces.
Designs Docker infrastructure for penetration testing: ephemeral attack environment architecture, container escape testing and prevention, isolated network topologies for safe testing. Implements best practices for forensic container analysis and secure evidence collection.
Designs comprehensive network security assessment methodologies for enterprise environments. Implements advanced network attack simulations including lateral movement, protocol exploitation, and encrypted traffic analysis. Optimizes penetration testing infrastructure for large-scale network assessments and implements security hardening recommendations.
Designs advanced VPN and network isolation penetration testing methodologies: crafts custom tunneling exploits, evaluates split-tunneling attack surfaces, and tests network isolation boundaries across multi-cloud environments. Implements automated security validation for VPN configurations and recommends hardening strategies.
Testing & QA · 1
Designs comprehensive penetration testing programs: red team operations, advanced exploit development, and security assessment frameworks. Implements automated vulnerability discovery pipelines. Conducts advanced attacks: cloud infrastructure exploitation, container escape, and supply chain attack simulation. Creates pentest tooling and custom exploit frameworks. Mentors team on advanced offensive security techniques.
Security · 13
Designs cloud penetration testing methodologies for complex multi-account AWS/Azure/GCP environments. Conducts threat modeling of cloud architectures to identify attack surfaces. Integrates offensive security findings into SDLC processes and mentors junior pentesters on cloud exploitation techniques.
Designs penetration testing methodologies that incorporate dependency scanning data from Snyk, Grype, and OSV to prioritize attack surfaces. Conducts threat modeling of software supply chains, identifying risks in transitive dependencies, build pipelines, and artifact registries. Integrates SCA findings with DAST and SAST results to build comprehensive exploit chains. Mentors junior pentesters on leveraging known dependency CVEs for realistic attack scenarios and proof-of-concept development.
Designs forensic-aware penetration testing methodologies that produce court-admissible evidence when needed. Conducts advanced memory forensics and malware analysis to reverse-engineer attack techniques. Mentors team on anti-forensic awareness and evidence preservation during red team engagements.
Leads purple team exercises to validate and improve incident response capabilities. Designs attack simulations that test detection and response workflows end-to-end. Integrates offensive findings into incident response playbooks and mentors the team on attacker TTPs relevant to detection engineering.
Designs comprehensive authentication security assessments: advanced JWT attack chains (key injection, header manipulation, JWE vulnerabilities), OAuth2 flow exploitation (token theft via open redirects, PKCE downgrade), and OIDC misconfiguration exploitation. Creates automated testing frameworks for authentication infrastructure. Conducts red team exercises targeting identity systems. Mentors team on authentication penetration testing methodologies.
Designs advanced Kubernetes penetration testing methodologies covering control plane attacks, etcd exploitation, and service mesh bypass techniques. Develops custom tools for Kubernetes attack simulation and validates cluster hardening against MITRE ATT&CK for Containers. Mentors team on cloud-native offensive security.
Designs complex network penetration testing methodologies: multi-stage attack chains exploiting network trust relationships, pivoting through segmented networks, and advanced IDS/IPS evasion. Mentors junior pentesters on network protocol analysis and firewall bypass techniques. Evaluates zero-trust network architectures and identifies gaps in micro-segmentation implementations.
Designs comprehensive application security assessment methodologies beyond OWASP Top 10 — identifies business logic flaws, authentication bypass chains, and complex multi-step exploitation scenarios. Conducts threat modeling for application architectures and integrates penetration testing into SDLC pipelines. Mentors team on advanced exploitation techniques and responsible disclosure.
Designs advanced penetration testing strategies targeting RBAC/ABAC authorization systems. Conducts threat modeling for complex multi-tenant access control architectures. Integrates authorization testing into security assessment pipelines. Mentors team on access control attack vectors.
Designs advanced SAST/DAST testing strategies combining automated scanning with manual exploitation techniques. Conducts threat modeling to identify gaps in scanner coverage. Integrates SAST/DAST into CI/CD security gates with custom rule sets. Mentors team on interpreting and validating scanner results.
Designs comprehensive code security assessment methodologies — identifies complex multi-step exploitation chains from source code analysis, creates custom SAST rules for organization-specific vulnerability patterns, and integrates code review findings into penetration test strategies. Conducts architecture-level threat modeling and mentors team on advanced code-level exploitation techniques.
Designs adversary simulation frameworks informed by comprehensive threat models. Maps MITRE ATT&CK kill chains to organizational assets and creates purple team exercise plans. Mentors junior testers on threat-driven penetration testing methodology. Optimizes threat model accuracy by feeding pentest findings back into organizational threat intelligence.
Designs vulnerability assessment methodologies combining automated scanning with manual exploitation. Conducts threat modeling to prioritize vulnerability discovery in high-risk areas. Integrates penetration testing results into vulnerability management workflows. Mentors team on vulnerability validation techniques.
AI-Assisted Development · 1
Designs GitHub Copilot governance for penetration testing teams: implements policies for responsible AI use in exploit development, configures content exclusion for sensitive assessment repositories, evaluates AI-assisted scripting for engagement efficiency. Mentors team on balancing AI speed with exploit reliability and ethics.
Observability & Monitoring · 2
Designs end-to-end observability architecture for offensive security operations using ELK Stack. Implements custom Elasticsearch ingest pipelines with enrichment processors for automated vulnerability scoring and asset correlation. Builds advanced Kibana Lens dashboards for executive-level penetration testing reports. Defines index lifecycle management policies for compliance-sensitive engagement data. Mentors team on writing efficient Elasticsearch DSL queries and Logstash grok patterns.
Designs observability assessment methodology for penetration testing: evaluates target logging and monitoring coverage during engagements, identifies detection blind spots through controlled exploitation, defines SLI/SLO recommendations for target organization. Mentors team on adversarial log analysis and detection evasion techniques documentation.
Version Control & Collaboration · 2
Designs security code review processes: offensive security review standards, exploit code quality checklists, security tool effectiveness review gates. Mentors team on conducting thorough security-focused code reviews from attacker perspective.
Designs Git workflows for penetration testing teams: implements repository isolation strategies for sensitive assessment data, configures automated secret detection across all repositories, designs branch-based access control for engagement confidentiality. Mentors team on forensic-grade Git history management and secure artifact handling.
Documentation · 1
Designs advanced penetration testing runbook frameworks: red team operation playbooks, social engineering campaign procedures, Active Directory attack chains documentation. Mentors junior testers on creating reusable engagement runbooks with proper evidence collection and chain-of-custody procedures.
Additional skills
Not assessed by the team, but part of the self-assessment and the development plan.
What changes at Lead
50 skills get a higher expectation or become core when moving from Senior to Lead. The biggest jumps first.
- Algorithms & Complexity: Advanced → Expert
- API Testing: Advanced → Expert
- Async Programming: Advanced → Expert
- Cloud Security: Advanced → Expert
- Code Quality & Refactoring: Advanced → Expert
- Code Review: Advanced → Expert
- Container Security Scanning: Advanced → Expert
- Data Structures: Advanced → Expert
- Dependency Vulnerability Scanning: Advanced → Expert
- Digital Forensics Basics: Advanced → Expert
} in the open competency matrix: 50 skills across 5 levels. The matrix is free for individuals and stays free.