Defines performance budgets for security tests. Reviews fuzzing and brute-force scripts with focus on algorithm efficiency. Implements optimal strategies for security scanning.
Roles · QA Security Engineer · Lead
What a Lead } should know
40 core skills, 55 in total. Expectations per skill, and what changes at the next level.
This page lists what a Lead } is expected to know and do, skill by skill. Core skills are the ones a manager and peers assess in a review cycle; the rest count only in self-assessment. Main areas: Programming Fundamentals, API & Integration, Cloud & Infrastructure.
Core skills for a Lead
Grouped by area. The label on the right is the expected depth: Awareness, Working, Advanced or Expert.
Programming Fundamentals · 4
Establishes security code quality standards: code review for test scripts, linting for security configs, coverage requirements for security tests. Implements quality gates.
Defines test data standards: structured payloads for fuzzing, immutable test fixtures for security tests. Reviews data models of vulnerability tracking systems.
Defines architectural standards for security tooling: modular scanner design, extensible frameworks for custom security rules. Trains the team on design patterns.
API & Integration · 2
Defines tooling strategy: selection and standardization of tools (Burp vs ZAP), licensing, training. Implements custom rule sets for organization-specific threats.
Defines API security testing standards: mandatory checks per endpoint, security review process for new APIs, automated regression testing. Coordinates with development teams.
Cloud & Infrastructure · 2
Defines scanning standards: mandatory scanning gates, remediation SLA, reporting requirements. Coordinates vulnerability remediation across teams.
Defines container security standards: mandatory scanning policies, base image requirements, vulnerability SLA. Coordinates container security with DevOps and development.
DevOps & CI/CD · 1
Defines CI security standards: mandatory security checks, gate policies, remediation SLA. Coordinates security tooling in CI/CD. Introduces security pipeline metrics.
Testing & QA · 10
Defines E2E security testing standards: critical path coverage, automated regression, manual testing criteria for complex attack vectors.
Defines integration testing standards for security: mandatory scenarios (auth, authz, data protection), environment requirements, CI integration.
Defines security load testing standards: mandatory DDoS resilience testing, rate limiting verification, performance budgets for security controls.
Defines property-based security testing standards: templates for typical security properties (auth, authz, input validation). Integrates into the security testing workflow.
Defines security testing standards: testing methodology, tool selection, reporting requirements. Coordinates security testing across the development lifecycle.
Defines BDD standards for security: scenario templates for OWASP categories, review process, documentation-as-tests. Implements security story mapping.
Defines test data standards for security: PII handling policy, data classification requirements, compliant test data generation. Coordinates data privacy in testing.
Defines environment standards for security testing: isolation requirements, provisioning automation, cleanup policies. Coordinates shared security testing infrastructure.
Defines security testing pyramid standards: coverage requirements per layer, automation ratios, manual testing criteria. Balances shift-left and depth.
Defines unit test standards for security: coverage requirements, test patterns, review checklist. Implements mutation testing for security-critical components.
Security · 14
Defines cloud security testing standards: mandatory assessments per account, compliance framework (SOC2, ISO 27001), reporting requirements. Coordinates with cloud engineering.
Defines dependency management standards: scanning requirements, remediation SLA by severity, approved package registries. Coordinates organization-wide vulnerability response.
Defines security strategy with GDPR/152-FZ compliance. Establishes security policies. Coordinates incident response. Trains teams.
Defines security IR standards: incident classification, escalation matrix, communication plan. Conducts tabletop exercises. Coordinates cross-team incident response.
Defines auth testing standards: mandatory tests per auth flow, OAuth security review checklist, compliance requirements. Coordinates auth security with the identity team.
Defines K8s security testing standards: mandatory checks per cluster, compliance requirements, incident response for K8s. Coordinates security hardening with platform team.
Defines network security testing standards: periodic assessment schedule, scope requirements, reporting. Coordinates with infrastructure team. Implements continuous network monitoring.
Defines OWASP testing standards: mandatory checks per release, ASVS compliance level requirements, training program. Coordinates OWASP adoption in development.
Defines PCI DSS testing strategy across all payment-related products. Establishes security QA policies ensuring continuous compliance validation. Coordinates cross-team security testing during PCI audit preparation. Trains QA engineers on PCI compliance verification methods.
Defines authorization testing standards: mandatory authorization coverage, access control review process, compliance verification. Coordinates authorization testing across teams.
Defines SAST/DAST standards: mandatory scanning gates, triage process, remediation SLA. Coordinates tooling between security and development. Evaluates tool effectiveness.
Defines organizational secure coding standards: language-specific guidelines, mandatory training, code review security checklist. Builds secure coding culture.
Defines threat modeling standards: mandatory for high-risk features, templates, review process. Trains dev teams. Coordinates threat models across teams.
Defines vulnerability management standards: SLA per severity, triage process, escalation policy. Coordinates vulnerability response. Implements vulnerability metrics and reporting.
AI-Assisted Development · 1
Implements AI tools in the security team: defines boundaries (automation scripts — yes, vulnerability assessment — review). Evaluates AI for security (AI-powered SAST, automated triage).
Observability & Monitoring · 3
Defines security logging standards: mandatory security events, retention for compliance, access control for security data. Coordinates security monitoring with SOC.
Defines security metrics standards: mandatory KPIs, dashboard templates, reporting cadence. Implements data-driven security management.
Defines security logging standards: event categories, retention requirements, compliance mapping (GDPR, PCI-DSS). Coordinates security logging across services.
Version Control & Collaboration · 3
Builds security review culture: defines checklist by categories (OWASP), SLA for security review, automated pre-review checks. Trains developers on security review skills.
Defines security documentation standards: required documents per project, templates, review process. Implements docs-as-code for security policies and procedures.
Establishes Git workflow for the security team: branching model, review requirements for security changes, CODEOWNERS for security-critical configs.
Additional skills
Not assessed by the team, but part of the self-assessment and the development plan.
What changes at Principal
0 skills get a higher expectation or become core when moving from Lead to Principal. The biggest jumps first.
} in the open competency matrix: 55 skills across 5 levels. The matrix is free for individuals and stays free.