Defines algorithmic standards for SecOps team: threat detection algorithm selection criteria, log analysis optimization strategies, alert correlation algorithm evaluation. Conducts reviews of algorithmic decisions in SIEM performance and detection accuracy.
Roles · Security Analyst · Lead
What a Lead } should know
36 core skills, 51 in total. Expectations per skill, and what changes at the next level.
This page lists what a Lead } is expected to know and do, skill by skill. Core skills are the ones a manager and peers assess in a review cycle; the rest count only in self-assessment. Main areas: Programming Fundamentals, API & Integration, Cloud & Infrastructure.
Core skills for a Lead
Grouped by area. The label on the right is the expected depth: Awareness, Working, Advanced or Expert.
Programming Fundamentals · 3
Defines code quality standards for security operations team: SIEM rule conventions, incident response automation guidelines, threat detection code reviews. Conducts reviews of detection logic accuracy and alert quality. Establishes quality gates for security tooling reliability.
Defines data structure standards for SecOps team: SIEM index schema design, alert correlation data models, threat intelligence storage formats. Conducts reviews of security data architecture decisions. Establishes team guidelines for efficient log data structures and query optimization.
API & Integration · 1
Defines API security monitoring strategy at product level: API threat detection standards, API abuse analytics governance, API security incident response policies. Conducts API security monitoring architecture reviews and establishes API security alerting.
Cloud & Infrastructure · 2
Defines Docker strategy for security operations: containerized SOC/SIEM architecture standards, security monitoring container governance, forensic environment isolation guidelines. Conducts architecture reviews for SecOps container infrastructure and establishes container security monitoring SLAs.
Defines network security monitoring strategy across the organization's infrastructure. Establishes IaC standards for SIEM network detection rules and threat hunting playbooks. Conducts architecture reviews of network monitoring coverage and drives adoption of advanced network analytics across security operations.
Testing & QA · 1
Defines security analysis and vulnerability management strategy. Establishes vulnerability scanning policies, risk assessment frameworks, and remediation SLA requirements. Coordinates threat intelligence integration for security testing prioritization. Creates security analytics capabilities for organization-wide vulnerability visibility.
Security · 18
Defines cloud security monitoring strategy using SIEM, CloudTrail, and cloud-native detection services. Establishes cloud security policies and alert triage procedures. Coordinates cloud incident response across distributed teams and trains analysts on cloud threat intelligence and forensic investigation methods.
Defines the security analytics team's strategy for dependency vulnerability monitoring and triage at product-line scale. Establishes standardized dashboards and KPI tracking for mean-time-to-remediate across SCA tools (Snyk, Dependabot, Trivy). Coordinates cross-team incident response when critical dependency vulnerabilities emerge, ensuring consistent communication and patching timelines. Trains analysts on advanced SCA interpretation, SBOM-driven risk assessment, and license compliance monitoring.
Defines the organization's digital forensics strategy including tooling, processes, and team capabilities. Establishes forensic readiness policies ensuring systems produce investigation-quality logs and artifacts. Coordinates forensic investigations with legal counsel and law enforcement when required.
Defines GDPR/152-FZ compliance monitoring strategy: establishes data processing registers, incident classification criteria, and regulatory reporting workflows. Coordinates with legal team on cross-border data transfer assessments and supervisory authority interactions.
Defines the organization's incident response framework including team structure, escalation paths, and communication plans. Establishes incident classification standards, SLAs for response times, and post-incident review processes. Coordinates tabletop exercises and drives continuous improvement of IR capabilities.
Defines security monitoring strategy for authentication infrastructure. Establishes detection rules, incident response procedures, and compliance requirements for identity systems. Coordinates threat intelligence for authentication-related attacks. Creates security analytics dashboards for organization-wide authentication health monitoring.
Defines organization-wide Kubernetes security monitoring and incident response strategy. Establishes detection engineering standards for container runtime, orchestration events, and service mesh telemetry. Coordinates security operations coverage for multi-cluster environments and drives adoption of runtime protection platforms.
Leads the team's network security monitoring and response capabilities: defines SIEM use cases for network threat detection, establishes SLAs for network incident triage, and builds runbooks for common network attack patterns. Coordinates with SOC and infrastructure teams to ensure comprehensive network visibility and drives adoption of NDR (Network Detection and Response) solutions.
Defines security monitoring strategy for application-layer threat detection across the organization. Establishes security analysis policies, detection engineering standards, and application security incident response playbooks. Coordinates cross-team security event investigation and trains analysts on OWASP-based threat analysis.
Defines PCI DSS compliance monitoring strategy across the organization. Establishes security analytics policies for cardholder data environments. Coordinates incident response and forensic analysis for PCI breaches. Trains analysts on PCI assessment methodologies.
Defines authorization monitoring and audit strategy for RBAC/ABAC across the organization. Establishes access control review policies and compliance frameworks. Coordinates cross-team access control incident investigations. Trains security analysts on authorization risk analysis methods.
Defines SAST/DAST monitoring and reporting strategy across the organization. Establishes vulnerability management policies based on scanner data and risk classification. Coordinates cross-team remediation tracking for critical scanner findings. Trains security analysts on scan result analysis and prioritization.
Defines security monitoring strategy for secrets infrastructure. Establishes audit policies for Vault operations, compliance reporting requirements, and secret lifecycle governance. Coordinates incident response for organization-wide credential compromise. Creates threat intelligence integration for credential-based attacks.
Defines security analysis strategy integrating secure coding intelligence across monitoring operations. Establishes policies for code-informed detection engineering, vulnerability correlation workflows, and code-level threat analysis standards. Coordinates cross-team security analysis for application vulnerabilities and trains analysts on code-aware investigation techniques.
Defines SOC 2 compliance program spanning all Trust Services Criteria. Establishes control frameworks, manages audit relationships, coordinates remediation of control gaps, and trains cross-functional teams on compliance requirements.
Defines organizational supply chain security strategy: establishes SBOM compliance requirements, vulnerability SLA policies, and third-party risk assessment frameworks. Coordinates incident response for dependency compromises across teams. Trains analysts on supply chain threat intelligence and regulatory compliance.
Defines threat modeling strategy at team and product level for security operations. Establishes threat intelligence-driven modeling processes aligned with MITRE ATT&CK and industry frameworks. Coordinates threat assessments across SOC, incident response, and vulnerability management teams. Drives integration of threat models into detection engineering and monitoring strategy.
Defines vulnerability management program strategy with risk-based metrics and executive reporting. Establishes vulnerability triage policies, remediation SLAs, and exception management processes. Coordinates organization-wide vulnerability response during zero-day events. Trains security analysts on vulnerability intelligence and prioritization.
AI-Assisted Development · 1
Defines GitHub Copilot security governance at the product level: establishes security review requirements for AI-assisted development across teams, designs compliance frameworks for AI code generation tools, drives adoption of secure AI development practices in security-sensitive domains.
Observability & Monitoring · 5
Defines the product's security observability strategy built on ELK Stack. Establishes SLO-based approach for SOC operations: alert quality, detection coverage by MITRE ATT&CK matrix, and analyst response times. Coordinates incident management across security, DevOps, and engineering through unified Elasticsearch indices and Kibana spaces. Drives migration strategies between Elastic and OpenSearch based on licensing and cost analysis. Optimizes MTTD/MTTR through automated triage pipelines and Logstash enrichment workflows.
Defines on-call management strategy for security operations. Establishes SOC shift management, threat response SLA targets, and security incident escalation framework. Coordinates cross-team security incident response. Optimizes MTTD/MTTR for security events across the organization.
Defines security observability strategy at the product level with Prometheus & Grafana: establishes SLO-based approach for security monitoring effectiveness, coordinates security incident management across teams, optimizes MTTD/MTTR for threat detection.
Defines observability strategy for security operations — establishes SLO-based approach for detection and response capabilities, coordinates security incident management processes, and optimizes MTTD/MTTR for security events through tooling and automation improvements.
Defines security observability strategy at the product level: establishes SLO-based approach for security monitoring effectiveness and response times, coordinates security incident management across teams, optimizes MTTD/MTTR for threat detection through advanced correlation and automation.
Version Control & Collaboration · 2
Defines code review strategy for SecOps team: SIEM rule review standards, threat detection code review governance, security monitoring review practices. Establishes review culture for SecOps code quality and detection accuracy.
Defines Git security strategy at the product level: establishes repository audit policies and compliance frameworks, designs incident response procedures using Git forensics, drives adoption of commit signing and branch protection across all development teams.
Documentation · 3
Defines the security architecture documentation strategy at the team and product level. Establishes standards for documenting security boundaries, data flows, and threat models using C4 and arc42. Conducts security architecture reviews ensuring ADRs properly capture risk decisions, compliance rationale, and mitigation strategies. Drives adoption of security documentation practices across development teams through templates and review checklists.
Defines diagramming strategy for threat modeling, attack surface visualization, and incident response documentation. Establishes standards for security architecture diagrams, network topology maps, and compliance visuals. Conducts reviews of security diagram accuracy and completeness.
Defines runbook strategy for SOC operations at the team level: establishes playbook governance frameworks, drives SOAR-integrated automated response procedures, creates runbook effectiveness metrics tied to MTTD and MTTR improvements.
Additional skills
Not assessed by the team, but part of the self-assessment and the development plan.
What changes at Principal
0 skills get a higher expectation or become core when moving from Lead to Principal. The biggest jumps first.
} in the open competency matrix: 51 skills across 5 levels. The matrix is free for individuals and stays free.