Roles · Security Analyst · Junior

What a Junior } should know

18 core skills, 51 in total. Expectations per skill, and what changes at the next level.

This page lists what a Junior } is expected to know and do, skill by skill. Core skills are the ones a manager and peers assess in a review cycle; the rest count only in self-assessment. Main areas: Security.

18core skills
33additional skills
1skill areas
0%at Advanced or Expert
Assess myself as Junior Full role matrix

Core skills for a Junior

Grouped by area. The label on the right is the expected depth: Awareness, Working, Advanced or Expert.

Security · 18

Cloud Security Awareness

Understands basic Cloud Infrastructure Security concepts. Follows security guidelines. Recognizes common code vulnerabilities.

Understands the purpose of dependency scanning tools such as Snyk, Dependabot, and OWASP Dependency-Check. Follows established SCA policies when triaging vulnerability alerts. Recognizes common CVE severity levels and can escalate critical findings to senior analysts.

Understands basic Digital Forensics concepts. Follows security guidelines. Recognizes common code vulnerabilities.

Understands basic GDPR / 152-FZ Compliance concepts. Follows security guidelines. Recognizes common code vulnerabilities.

Understands basic Incident Response Process concepts. Follows security guidelines. Recognizes common code vulnerabilities.

Understands basic JWT / OAuth2 / OIDC concepts. Follows security guidelines. Recognizes common code vulnerabilities.

Understands basic Kubernetes Security concepts. Follows security guidelines. Recognizes common code vulnerabilities.

Network Security Awareness

Understands basic Network Security concepts. Follows security guidelines. Recognizes common code vulnerabilities.

Understands basic OWASP and Application Security concepts. Follows security guidelines. Recognizes common code vulnerabilities.

PCI DSS Awareness

Understands basic PCI DSS concepts. Follows security guidelines. Recognizes common code vulnerabilities.

Understands basic RBAC / ABAC Authorization concepts. Follows security guidelines. Recognizes common code vulnerabilities.

SAST/DAST Awareness

Understands basic SAST/DAST concepts. Follows security guidelines. Recognizes common code vulnerabilities.

Secrets Management Awareness

Understands basic Secrets Management concepts. Follows security guidelines. Recognizes common code vulnerabilities.

Understands basic secure coding concepts from a security analysis perspective — recognizes injection patterns, authentication bypass indicators, and insecure data handling in application logs. Follows security guidelines for identifying vulnerability signatures in code review findings and SAST/DAST reports.

SOC2 Compliance Awareness

Understands basic SOC2 Compliance concepts. Follows security guidelines. Recognizes common code vulnerabilities.

Understands basic supply chain security concepts: SBOM generation, dependency vulnerability databases (NVD, OSV), and package provenance verification. Follows security guidelines for triaging dependency alerts and documenting component inventories. Recognizes common supply chain risks in third-party software.

Threat Modeling Awareness

Understands basic threat modeling methodologies (STRIDE, DREAD). Identifies common threats in simple systems using predefined templates. Documents threat scenarios following organizational guidelines. Assists in data flow diagram creation for threat analysis.

Understands basic Vulnerability Management concepts. Follows security guidelines. Recognizes common code vulnerabilities.

Additional skills

Not assessed by the team, but part of the self-assessment and the development plan.

Algorithms & ComplexityAPI DocumentationArchitecture Documentation: C4, arc42Async ProgrammingAWSChatGPT / ClaudeCode Quality & RefactoringCode ReviewData StructuresDesign PatternsDiagramming: Mermaid, PlantUML, D2DockerELK StackGit AdvancedGitHub Actions / GitLab CIGitHub CopilotIntegration TestingKubernetes CoreMultithreadingNetwork FundamentalsOn-Call ManagementOOP & SOLID PrinciplesPostgreSQLPrometheus & GrafanaPrompt Engineering for CodeRedisREST API DesignRunbook & Playbook WritingSecurity TestingSLI / SLO / SLAStructured LoggingSystem Design FundamentalsUnit Testing

What changes at Mid-level

51 skills get a higher expectation or become core when moving from Junior to Mid-level. The biggest jumps first.

See the Mid-level page →
Run this with your whole team
Self-assessment plus manager and peer reviews against the same matrix, gap analysis and next-level readiness for every engineer. Team Pro is free for 14 days; individual tools stay free forever.
Start a team trial (14 days free) Send to my manager

} in the open competency matrix: 51 skills across 5 levels. The matrix is free for individuals and stays free.