Roles · QA Security Engineer · Lead

What a Lead } should know

40 core skills, 55 in total. Expectations per skill, and what changes at the next level.

This page lists what a Lead } is expected to know and do, skill by skill. Core skills are the ones a manager and peers assess in a review cycle; the rest count only in self-assessment. Main areas: Programming Fundamentals, API & Integration, Cloud & Infrastructure.

40core skills
15additional skills
9skill areas
100%at Advanced or Expert
Assess myself as Lead Full role matrix

Core skills for a Lead

Grouped by area. The label on the right is the expected depth: Awareness, Working, Advanced or Expert.

Programming Fundamentals · 4

Defines performance budgets for security tests. Reviews fuzzing and brute-force scripts with focus on algorithm efficiency. Implements optimal strategies for security scanning.

Establishes security code quality standards: code review for test scripts, linting for security configs, coverage requirements for security tests. Implements quality gates.

Defines test data standards: structured payloads for fuzzing, immutable test fixtures for security tests. Reviews data models of vulnerability tracking systems.

Defines architectural standards for security tooling: modular scanner design, extensible frameworks for custom security rules. Trains the team on design patterns.

API & Integration · 2

API Testing Expert

Defines tooling strategy: selection and standardization of tools (Burp vs ZAP), licensing, training. Implements custom rule sets for organization-specific threats.

Defines API security testing standards: mandatory checks per endpoint, security review process for new APIs, automated regression testing. Coordinates with development teams.

Cloud & Infrastructure · 2

Defines scanning standards: mandatory scanning gates, remediation SLA, reporting requirements. Coordinates vulnerability remediation across teams.

Docker Expert

Defines container security standards: mandatory scanning policies, base image requirements, vulnerability SLA. Coordinates container security with DevOps and development.

DevOps & CI/CD · 1

Defines CI security standards: mandatory security checks, gate policies, remediation SLA. Coordinates security tooling in CI/CD. Introduces security pipeline metrics.

Testing & QA · 10

E2E Testing Expert

Defines E2E security testing standards: critical path coverage, automated regression, manual testing criteria for complex attack vectors.

Defines integration testing standards for security: mandatory scenarios (auth, authz, data protection), environment requirements, CI integration.

Load Testing Expert

Defines security load testing standards: mandatory DDoS resilience testing, rate limiting verification, performance budgets for security controls.

Defines property-based security testing standards: templates for typical security properties (auth, authz, input validation). Integrates into the security testing workflow.

Defines security testing standards: testing methodology, tool selection, reporting requirements. Coordinates security testing across the development lifecycle.

TDD & BDD Expert

Defines BDD standards for security: scenario templates for OWASP categories, review process, documentation-as-tests. Implements security story mapping.

Defines test data standards for security: PII handling policy, data classification requirements, compliant test data generation. Coordinates data privacy in testing.

Defines environment standards for security testing: isolation requirements, provisioning automation, cleanup policies. Coordinates shared security testing infrastructure.

Defines security testing pyramid standards: coverage requirements per layer, automation ratios, manual testing criteria. Balances shift-left and depth.

Unit Testing Expert

Defines unit test standards for security: coverage requirements, test patterns, review checklist. Implements mutation testing for security-critical components.

Security · 14

Defines cloud security testing standards: mandatory assessments per account, compliance framework (SOC2, ISO 27001), reporting requirements. Coordinates with cloud engineering.

Defines dependency management standards: scanning requirements, remediation SLA by severity, approved package registries. Coordinates organization-wide vulnerability response.

Defines security strategy with GDPR/152-FZ compliance. Establishes security policies. Coordinates incident response. Trains teams.

Defines security IR standards: incident classification, escalation matrix, communication plan. Conducts tabletop exercises. Coordinates cross-team incident response.

Defines auth testing standards: mandatory tests per auth flow, OAuth security review checklist, compliance requirements. Coordinates auth security with the identity team.

Defines K8s security testing standards: mandatory checks per cluster, compliance requirements, incident response for K8s. Coordinates security hardening with platform team.

Defines network security testing standards: periodic assessment schedule, scope requirements, reporting. Coordinates with infrastructure team. Implements continuous network monitoring.

Defines OWASP testing standards: mandatory checks per release, ASVS compliance level requirements, training program. Coordinates OWASP adoption in development.

PCI DSS Expert

Defines PCI DSS testing strategy across all payment-related products. Establishes security QA policies ensuring continuous compliance validation. Coordinates cross-team security testing during PCI audit preparation. Trains QA engineers on PCI compliance verification methods.

Defines authorization testing standards: mandatory authorization coverage, access control review process, compliance verification. Coordinates authorization testing across teams.

SAST/DAST Expert

Defines SAST/DAST standards: mandatory scanning gates, triage process, remediation SLA. Coordinates tooling between security and development. Evaluates tool effectiveness.

Defines organizational secure coding standards: language-specific guidelines, mandatory training, code review security checklist. Builds secure coding culture.

Defines threat modeling standards: mandatory for high-risk features, templates, review process. Trains dev teams. Coordinates threat models across teams.

Defines vulnerability management standards: SLA per severity, triage process, escalation policy. Coordinates vulnerability response. Implements vulnerability metrics and reporting.

AI-Assisted Development · 1

Implements AI tools in the security team: defines boundaries (automation scripts — yes, vulnerability assessment — review). Evaluates AI for security (AI-powered SAST, automated triage).

Observability & Monitoring · 3

ELK Stack Expert

Defines security logging standards: mandatory security events, retention for compliance, access control for security data. Coordinates security monitoring with SOC.

Defines security metrics standards: mandatory KPIs, dashboard templates, reporting cadence. Implements data-driven security management.

Defines security logging standards: event categories, retention requirements, compliance mapping (GDPR, PCI-DSS). Coordinates security logging across services.

Version Control & Collaboration · 3

Code Review Expert

Builds security review culture: defines checklist by categories (OWASP), SLA for security review, automated pre-review checks. Trains developers on security review skills.

Defines security documentation standards: required documents per project, templates, review process. Implements docs-as-code for security policies and procedures.

Git Advanced Expert

Establishes Git workflow for the security team: branching model, review requirements for security changes, CODEOWNERS for security-critical configs.

Additional skills

Not assessed by the team, but part of the self-assessment and the development plan.

API DocumentationAsync ProgrammingAWSChatGPT / ClaudeCursor IDEDesign PatternsGraphQL DesignKubernetes CoreMultithreadingNetwork FundamentalsOpenTelemetryPostgreSQLPrompt Engineering for CodeRedisSystem Design Fundamentals

What changes at Principal

0 skills get a higher expectation or become core when moving from Lead to Principal. The biggest jumps first.

See the Principal page →
Run this with your whole team
Self-assessment plus manager and peer reviews against the same matrix, gap analysis and next-level readiness for every engineer. Team Pro is free for 14 days; individual tools stay free forever.
Start a team trial (14 days free) Send to my manager

} in the open competency matrix: 55 skills across 5 levels. The matrix is free for individuals and stays free.