Defines organizational algorithmic strategy for security operations: enterprise threat detection optimization standards, cross-team SIEM performance governance, security analytics computational efficiency frameworks. Makes strategic decisions on SecOps platform performance investments.
Roles · Security Analyst · Principal
What a Principal } should know
36 core skills, 51 in total. Expectations per skill, and what changes at the next level.
This page lists what a Principal } is expected to know and do, skill by skill. Core skills are the ones a manager and peers assess in a review cycle; the rest count only in self-assessment. Main areas: Programming Fundamentals, API & Integration, Cloud & Infrastructure.
Core skills for a Principal
Grouped by area. The label on the right is the expected depth: Awareness, Working, Advanced or Expert.
Programming Fundamentals · 3
Defines organizational code quality strategy for security operations: enterprise SIEM governance, cross-team detection engineering standards, security automation quality frameworks. Makes decisions on security tooling investments and shapes organization-wide SecOps code quality expectations.
Defines organizational data structure strategy for security operations: enterprise SIEM data governance, cross-team threat intelligence data standards, security metrics data frameworks. Makes strategic decisions on SecOps data platform architecture.
API & Integration · 1
Defines organizational API security monitoring strategy: enterprise API threat detection standards, cross-team API security governance, SecOps platform investment decisions for API monitoring. Designs enterprise-grade API security monitoring architecture.
Cloud & Infrastructure · 2
Defines organizational container strategy for security operations: enterprise SOC/SIEM containerization standards, cross-team security monitoring governance, container forensics frameworks. Designs enterprise-grade container infrastructure for SecOps and evaluates security platform technology investments.
Defines organizational network security monitoring strategy spanning enterprise, cloud, and hybrid environments. Evaluates multi-cloud network visibility architectures and designs enterprise-grade threat detection platforms. Establishes FinOps practices for security monitoring infrastructure and network defense investment optimization.
Testing & QA · 1
Defines enterprise security monitoring and vulnerability management strategy. Shapes organizational security analytics capabilities and risk management frameworks. Drives adoption of advanced threat detection and automated security assessment at scale. Coordinates compliance requirements and industry standards for security testing practices.
Security · 18
Defines enterprise cloud security monitoring and detection strategy across multi-cloud environments. Shapes security operations architecture including SOC modernization for cloud workloads. Coordinates compliance with industry security standards and represents the organization in cloud security threat intelligence sharing communities.
Defines the enterprise security analytics strategy for dependency vulnerability management, shaping tooling and process architecture across all organizational units. Drives adoption of SBOM-based risk quantification models and integrates SCA programs with enterprise GRC platforms for continuous compliance monitoring. Coordinates organization-wide vulnerability disclosure processes and defines escalation frameworks for supply chain incidents impacting multiple business units. Represents the organization in industry bodies (OpenSSF, FIRST) and shapes evolving standards for vulnerability scoring, SCA benchmarking, and supply chain transparency.
Defines enterprise digital forensics strategy aligned with legal, compliance, and business continuity requirements. Shapes forensic architecture across all environments ensuring investigation readiness at scale. Represents the organization in industry forensic communities and drives adoption of advanced forensic methodologies.
Defines enterprise data protection strategy aligned with GDPR/152-FZ and emerging privacy regulations. Shapes organizational compliance framework spanning multiple jurisdictions. Drives privacy-by-default culture and represents organization in regulatory community.
Defines enterprise-wide incident response strategy aligned with business risk management and regulatory requirements. Shapes the security operations architecture including SOAR, threat intelligence, and automated response capabilities. Represents the organization to regulators, partners, and industry bodies on incident management practices.
Defines enterprise security monitoring strategy for identity infrastructure. Shapes organizational SOC capabilities for authentication threat detection and response. Drives adoption of advanced security analytics for identity-based attacks. Coordinates compliance and regulatory requirements for authentication systems across the enterprise.
Defines enterprise container security strategy integrating Kubernetes security into the broader security operations framework. Shapes security architecture for cloud-native workloads at organizational scale with automated compliance and policy enforcement. Represents the organization in Kubernetes security communities and influences upstream security features.
Defines the organization's network threat intelligence and detection strategy: architects enterprise-wide network security monitoring covering on-prem, cloud, and hybrid environments. Establishes network forensics standards, drives investment in NDR and SIEM capabilities, and sets organizational benchmarks for mean-time-to-detect network-based threats. Represents the company in industry threat-sharing consortiums and shapes network security policy at the board level.
Defines enterprise security monitoring and analysis strategy spanning application, network, and cloud environments. Shapes security operations architecture integrating OWASP threat intelligence with organizational detection capabilities. Coordinates industry compliance programs and represents the organization in threat intelligence sharing communities.
Defines enterprise PCI DSS compliance and risk management strategy. Shapes security monitoring architecture for cardholder data across all business units. Coordinates with external auditors and payment networks on compliance programs. Drives industry standards adoption.
Defines enterprise access control governance strategy spanning RBAC and ABAC across all business units. Shapes authorization analytics architecture for organization-wide visibility. Coordinates with regulators on access control compliance programs. Drives authorization standards in the security community.
Defines enterprise vulnerability intelligence strategy powered by SAST/DAST data across all business units. Shapes security analytics architecture integrating scanner output with threat intelligence platforms. Coordinates compliance reporting with regulatory bodies. Drives vulnerability management standards in the industry.
Defines enterprise security monitoring strategy with secrets management as a critical component. Shapes organizational security operations center (SOC) capabilities for credential-based threat detection. Drives adoption of advanced security analytics and threat intelligence for secrets protection. Represents the organization in security industry forums and standards bodies.
Defines enterprise security analysis strategy integrating code intelligence with threat detection across application, network, and cloud environments. Shapes security operations architecture leveraging secure coding insights for advanced detection capabilities. Coordinates organizational compliance and represents the organization in threat intelligence and security analysis communities.
Defines enterprise-wide compliance strategy across SOC 2, ISO 27001, and related frameworks. Shapes organizational security architecture for multi-framework compliance, drives automation of compliance processes, and serves as executive liaison to audit firms.
Defines enterprise security strategy for software supply chain: shapes SBOM adoption across the organization, evaluates emerging standards (SLSA, VEX, OpenSSF Scorecard), and coordinates regulatory compliance. Represents the organization in the security community and influences industry supply chain practices.
Defines organizational threat modeling strategy aligned with enterprise risk management. Shapes security operations architecture through threat landscape analysis and adversary modeling at scale. Establishes cross-departmental threat assessment standards integrating MITRE ATT&CK, STRIDE, and business impact analysis. Drives industry collaboration on threat intelligence sharing and modeling frameworks.
Defines enterprise vulnerability governance strategy with board-level risk reporting and compliance alignment. Shapes vulnerability intelligence architecture integrating internal and external threat data at scale. Coordinates with regulators and industry consortiums on vulnerability management frameworks. Drives organizational resilience through proactive vulnerability programs.
AI-Assisted Development · 1
Defines organizational GitHub Copilot security governance: evaluates enterprise AI code generation compliance and risk frameworks, designs security review standards for AI-assisted development at organizational scale, establishes policies for AI tool usage in security-sensitive and regulated environments.
Observability & Monitoring · 5
Defines the organization's security observability strategy with ELK Stack as the enterprise SIEM backbone. Implements platform solutions: multi-cluster Elasticsearch with cross-cluster search for global threat visibility, centralized detection-as-code repositories with CI/CD deployment to Elasticsearch. Builds reliability culture with SLO frameworks for log ingestion latency, detection coverage by kill chain phase, and SOC analyst efficiency metrics. Establishes enterprise governance for security data classification, retention policies aligned with regulatory requirements, and Kibana RBAC across business units.
Defines organizational strategy for security operations and incident management. Implements platform SOC solutions with AI-driven threat detection and automated response. Builds security reliability culture across the organization. Establishes enterprise SLO framework for security event handling.
Defines organizational security observability strategy with Prometheus & Grafana: implements enterprise security monitoring platforms, builds security-aware reliability culture, establishes enterprise SLO framework for security detection and response effectiveness.
Defines organizational observability strategy for security operations — implements platform solutions for unified security monitoring, builds security reliability culture integrating detection SLOs with operational metrics, and establishes enterprise SLO framework for security service availability and response effectiveness.
Defines organizational observability strategy for security operations: implements enterprise security monitoring platforms and correlation infrastructure, builds security-aware reliability culture across the organization, establishes enterprise SLO framework for security detection and response effectiveness.
Version Control & Collaboration · 2
Defines organizational code review strategy for SecOps: enterprise security monitoring code review standards, cross-team SecOps review governance, review culture maturity model for security teams. Mentors leads on SecOps code review best practices.
Defines organizational Git security strategy: evaluates enterprise Git platform security configurations and compliance requirements, designs governance for repository auditing and access control at organizational scale, establishes standards for incident response and forensic analysis through version control systems.
Documentation · 3
Defines security architecture documentation strategy at the organizational level. Establishes enterprise-wide standards for documenting security architectures using C4 and arc42 aligned with compliance frameworks (SOC 2, ISO 27001, NIST). Creates cross-organizational ADR governance for security decisions ensuring traceability from threat models to implemented controls. Mentors leads and architects on integrating security documentation into the overall architecture documentation lifecycle.
Defines organization-wide diagramming strategy for enterprise threat modeling, security architecture documentation, and compliance reporting visuals. Establishes enterprise approaches to attack surface mapping and incident response diagramming. Mentors leads and architects on security visualization standards.
Defines organizational strategy for security operations runbooks: establishes enterprise-wide incident response playbook standards aligned with NIST and ISO 27001, drives cross-functional runbook integration between SOC, IT operations, and business units, creates executive communication playbooks for major security incidents.
Additional skills
Not assessed by the team, but part of the self-assessment and the development plan.
} in the open competency matrix: 51 skills across 5 levels. The matrix is free for individuals and stays free.