Roles · QA Security Engineer · Mid-level

What a Mid-level } should know

10 core skills, 55 in total. Expectations per skill, and what changes at the next level.

This page lists what a Mid-level } is expected to know and do, skill by skill. Core skills are the ones a manager and peers assess in a review cycle; the rest count only in self-assessment. Main areas: Testing & QA.

10core skills
45additional skills
1skill areas
0%at Advanced or Expert
Assess myself as Mid-level Full role matrix

Core skills for a Mid-level

Grouped by area. The label on the right is the expected depth: Awareness, Working, Advanced or Expert.

Testing & QA · 10

E2E Testing Working

Writes E2E security tests: login/logout flows, session hijacking prevention, CSRF protection, file upload security. Uses Selenium/Playwright with security focus.

Writes integration tests for security: authentication flows, authorization checks across services, session management. Tests security middleware and filters.

Load Testing Working

Conducts security load testing: DDoS simulation, brute-force resistance testing, rate limiting verification. Uses k6/Locust for security load tests.

Applies property-based testing for security: random input generation for fuzzing, invariant checking for authorization rules. Uses Hypothesis/QuickCheck for security properties.

Conducts security testing: OWASP Top 10 verification, vulnerability scanning (ZAP/Burp), dependency checking (Snyk). Documents findings with reproducible steps.

TDD & BDD Working

Applies BDD for security requirements: Gherkin scenarios for authentication, authorization rules, compliance requirements. TDD for security utility functions.

Manages test data for security: sanitized production data, synthetic PII generation, credential management for test environments. Ensures compliance in test data.

Manages security test environments: isolated environments for penetration testing, sandboxed environments for malware analysis. Configures network isolation.

Applies test pyramid for security: unit tests for validation functions, integration for auth flows, E2E for critical security paths. Balances coverage and speed.

Unit Testing Working

Writes unit tests for security code: input validation functions, encoding/escaping, cryptographic helpers. Tests edge cases and boundary values.

Additional skills

Not assessed by the team, but part of the self-assessment and the development plan.

Algorithms & ComplexityAPI DocumentationAPI TestingAsync ProgrammingAWSChatGPT / ClaudeCloud SecurityCode Quality & RefactoringCode ReviewContainer Security ScanningCursor IDEData StructuresDependency Vulnerability ScanningDesign PatternsDockerDocumentation as CodeELK StackGDPR / 152-FZ ComplianceGit AdvancedGitHub Actions / GitLab CIGitHub CopilotGraphQL DesignIncident Response ProcessJWT / OAuth2 / OIDCKubernetes CoreKubernetes SecurityMultithreadingNetwork FundamentalsNetwork SecurityOOP & SOLID PrinciplesOpenTelemetryOWASP & Application SecurityPCI DSSPostgreSQLPrometheus & GrafanaPrompt Engineering for CodeRBAC / ABAC AuthorizationRedisREST API DesignSAST/DASTSecure Coding PracticesStructured LoggingSystem Design FundamentalsThreat ModelingVulnerability Management

What changes at Senior

55 skills get a higher expectation or become core when moving from Mid-level to Senior. The biggest jumps first.

See the Senior page →
Run this with your whole team
Self-assessment plus manager and peer reviews against the same matrix, gap analysis and next-level readiness for every engineer. Team Pro is free for 14 days; individual tools stay free forever.
Start a team trial (14 days free) Send to my manager

} in the open competency matrix: 55 skills across 5 levels. The matrix is free for individuals and stays free.