Understands E2E testing fundamentals with security focus: authentication/authorization flow testing, HTTPS certificate validation, and security header verification in E2E scenarios. Writes E2E tests that verify security controls across the application stack. Follows team practices for security-focused E2E test case design.
Roles · QA Security Engineer · Junior
What a Junior } should know
10 core skills, 55 in total. Expectations per skill, and what changes at the next level.
This page lists what a Junior } is expected to know and do, skill by skill. Core skills are the ones a manager and peers assess in a review cycle; the rest count only in self-assessment. Main areas: Testing & QA.
Core skills for a Junior
Grouped by area. The label on the right is the expected depth: Awareness, Working, Advanced or Expert.
Testing & QA · 10
Understands basics of integration testing for security control interactions. Writes simple tests verifying authentication flow, authorization middleware, and encryption service integration. Follows team testing guidelines for security boundary validation between components.
Understands load testing basics from security perspective: stress testing authentication endpoints, testing rate limiting effectiveness, and identifying security degradation under load (bypassed validations, error message leakage). Follows team practices for security-focused load test scenario design.
Understands the fundamentals of property-based testing for security verification. Applies basic fuzzing techniques to validate input sanitization and boundary properties. Follows team guidelines for defining security invariants in tests.
Understands security QA fundamentals: security test planning, OWASP testing methodology, and security-focused test case design. Executes security test suites covering authentication, authorization, input validation, and data protection. Uses basic security testing tools (OWASP ZAP, Burp Suite Community). Follows team practices for security defect lifecycle management.
Understands TDD/BDD fundamentals applied to security testing: writing security test scenarios in BDD format, test-first approach for security validations, and security acceptance criteria in Gherkin. Follows team practices for automated security test specifications.
Understands fundamentals of test data management for security testing. Prepares basic datasets with various input patterns for vulnerability scanning. Follows team guidelines for handling sensitive test data, masking PII, and secure storage of test credentials.
Understands fundamentals of test environment management for security testing. Sets up isolated sandboxed environments for vulnerability scanning and penetration testing. Follows team guidelines for network segmentation, firewall rules, and secure access to test infrastructure.
Understands the test pyramid and how security testing integrates across its layers. Knows the difference between unit-level security checks, API security tests, and full penetration tests. Follows team guidelines for distributing security test effort across SAST, DAST, and manual security reviews.
Understands basic unit testing for security test code: test cases for security rules, assertion patterns for vulnerability detection, fixtures for security scan configurations. Follows team practices for testing security automation scripts and detection logic.
Additional skills
Not assessed by the team, but part of the self-assessment and the development plan.
What changes at Mid-level
55 skills get a higher expectation or become core when moving from Junior to Mid-level. The biggest jumps first.
- E2E Testing: Awareness → Working
- Integration Testing: Awareness → Working
- Load Testing: Awareness → Working
- Property-Based Testing: Awareness → Working
- Security Testing: Awareness → Working
- TDD & BDD: Awareness → Working
- Test Data Management: Awareness → Working
- Test Environment Management: Awareness → Working
- Test Pyramid & Strategy: Awareness → Working
- Unit Testing: Awareness → Working
} in the open competency matrix: 55 skills across 5 levels. The matrix is free for individuals and stays free.