Roles · Security Analyst · Senior

What a Senior } should know

36 core skills, 51 in total. Expectations per skill, and what changes at the next level.

This page lists what a Senior } is expected to know and do, skill by skill. Core skills are the ones a manager and peers assess in a review cycle; the rest count only in self-assessment. Main areas: Programming Fundamentals, API & Integration, Cloud & Infrastructure.

36core skills
15additional skills
9skill areas
100%at Advanced or Expert
Assess myself as Senior Full role matrix

Core skills for a Senior

Grouped by area. The label on the right is the expected depth: Awareness, Working, Advanced or Expert.

Programming Fundamentals · 3

Applies algorithmic thinking to security operations: anomaly detection algorithms for threat identification, correlation algorithms for multi-source alert analysis, pattern matching algorithms for IOC detection in log streams. Designs efficient log analysis algorithms for real-time threat hunting at scale.

Designs code quality standards for security operations tooling: SIEM rule structure, incident response automation scripts, threat intelligence integration code. Refactors detection logic for accuracy and performance. Establishes review practices for alert quality, forensic script reliability, and chain-of-custody compliance.

Data Structures Advanced

Selects optimal data structures for security operations: log index structures for rapid threat hunting, correlation matrices for multi-source alert aggregation, timeline data models for incident reconstruction. Optimizes SIEM data structures for query performance on high-volume log streams. Designs efficient data models for threat intelligence storage and IOC matching.

API & Integration · 1

REST API Design Advanced

Designs API security monitoring architecture: API-specific threat detection rules, API abuse pattern analytics, API authentication anomaly detection. Defines API security monitoring standards and incident response procedures. Mentors team on API threat intelligence and analysis.

Cloud & Infrastructure · 2

Docker Advanced

Designs Docker infrastructure for security operations: containerized SIEM/SOC architecture, hardened monitoring containers, isolated forensic analysis environments. Implements best practices for container runtime security, log collection from containerized services, and threat detection in container environments.

Designs network security monitoring architectures for enterprise environments. Implements advanced threat detection through network behavior analysis, encrypted traffic inspection, and ML-based anomaly detection. Optimizes SIEM network correlation rules and implements security hardening for network infrastructure.

Testing & QA · 1

Security Testing Advanced

Designs security analytics for vulnerability management: automated vulnerability correlation across scanning tools, risk-based prioritization models, and executive reporting dashboards. Implements continuous security monitoring for application portfolio. Conducts organizational threat modeling and risk assessments. Mentors team on advanced security analysis techniques.

Security · 18

Cloud Security Advanced

Designs cloud threat detection strategies using advanced SIEM correlation rules and CloudTrail analytics. Conducts threat modeling for cloud-hosted services. Integrates cloud incident response playbooks into the SDLC and mentors analysts on cloud forensics and threat hunting techniques.

Designs the organization's dependency vulnerability management program, defining SLA tiers based on CVSS severity, exploitability, and asset criticality. Conducts threat modeling of the software supply chain to identify risks beyond individual CVEs, such as maintainer compromise and registry poisoning. Integrates SCA tooling (Snyk, Dependabot, Trivy) with SIEM/SOAR platforms for automated alerting and response workflows. Mentors analysts on distinguishing actionable vulnerabilities from false positives using reachability and runtime context.

Leads complex forensic investigations across multiple systems and environments. Performs advanced timeline analysis, memory forensics, and malware reverse engineering. Integrates forensic findings into threat intelligence workflows and SIEM correlation rules. Mentors junior analysts on forensic methodologies.

Designs security solutions with GDPR / 152-FZ Compliance. Conducts threat modeling. Integrates security practices into SDLC. Mentors the team.

Leads incident response for complex multi-vector security incidents across cloud and on-premise environments. Conducts advanced threat hunting and root cause analysis. Develops and refines incident response playbooks based on emerging threats. Mentors team on incident handling and coordinates with external stakeholders.

Designs security monitoring for authentication infrastructure: SIEM correlation rules for JWT/OAuth2 attacks, anomaly detection for token usage patterns, and incident response playbooks for authentication compromises. Implements compliance controls for identity management (SOC2, PCI-DSS). Conducts threat modeling for OIDC provider deployments. Mentors team on authentication security analysis.

Leads Kubernetes security monitoring strategy with advanced detection rules for cluster-level threats. Conducts deep investigation of container compromise incidents including forensic analysis of pod artifacts and network traffic. Integrates Kubernetes audit telemetry into SIEM and develops automated response playbooks for cluster incidents.

Network Security Advanced

Designs network threat detection strategies: builds advanced SIEM correlation rules for multi-stage network attacks, architects honeypot deployments for early threat detection, and creates network forensics procedures. Mentors analysts on deep packet inspection, encrypted traffic analysis, and advanced persistent threat identification across network layers.

Designs application security monitoring and detection strategies aligned with OWASP attack patterns. Conducts threat modeling for detection engineering — designing correlation rules for multi-stage application attacks. Integrates security findings from SAST/DAST/pentest into SOC detection capabilities. Mentors team on application-layer threat analysis and incident forensics.

PCI DSS Advanced

Designs security solutions with PCI DSS. Conducts threat modeling. Integrates security practices into SDLC. Mentors the team.

Designs comprehensive authorization monitoring solutions for RBAC/ABAC systems. Conducts threat modeling of access control architectures across distributed services. Integrates authorization analytics into SIEM and security operations. Mentors analysts on access control risk assessment.

SAST/DAST Advanced

Designs comprehensive SAST/DAST analytics frameworks for vulnerability trend analysis. Conducts threat modeling to map scanner coverage against real attack scenarios. Integrates scanning results into SIEM for continuous security monitoring. Mentors analysts on vulnerability classification and risk scoring.

Designs security monitoring for secrets infrastructure: Vault audit log analysis pipelines, anomaly detection for credential usage, and incident response playbooks for secret compromise. Implements compliance reporting for regulatory requirements (SOC2, PCI-DSS credential handling). Conducts penetration testing focused on secrets extraction vectors. Mentors team on threat modeling for credential flows.

Designs security analysis workflows integrating secure coding intelligence — correlates code-level vulnerability data with runtime threat detection, architects detection rules informed by common coding weakness patterns, and implements automated security validation workflows. Conducts threat modeling for detection engineering and mentors team on code-aware security analysis.

SOC2 Compliance Advanced

Designs security solutions with SOC2 Compliance. Conducts threat modeling. Integrates security practices into SDLC. Mentors the team.

Designs security solutions with Supply Chain Security. Conducts threat modeling. Integrates security practices into SDLC. Mentors the team.

Threat Modeling Advanced

Designs threat modeling processes for complex distributed systems and cloud-native architectures. Creates attack tree libraries mapped to industry-specific threat landscapes. Mentors analysts on advanced threat analysis techniques including kill chain modeling. Optimizes threat detection rules based on modeled attack scenarios and emerging threat intelligence.

Designs comprehensive vulnerability management programs with risk-based prioritization frameworks. Conducts threat modeling to map vulnerability exposure across organizational assets. Integrates vulnerability data into security operations for proactive risk mitigation. Mentors analysts on advanced triage and remediation tracking.

AI-Assisted Development · 1

GitHub Copilot Advanced

Designs GitHub Copilot governance for security teams: implements policies for AI use in detection rule development, configures content controls for sensitive security repositories, evaluates AI-generated security code for accuracy and false positive risks. Mentors team on responsible AI-assisted security tooling development.

Observability & Monitoring · 5

ELK Stack Advanced

Designs comprehensive security observability strategy with ELK Stack and OpenSearch. Implements distributed tracing for security event chains across network, endpoint, and cloud layers. Defines SLI/SLO for detection coverage, alert fidelity, and mean time to detect (MTTD). Builds advanced Elasticsearch detection rules using EQL and threat intelligence enrichment. Conducts thorough post-mortems with timeline reconstruction in Kibana. Mentors analysts on query optimization and detection engineering.

Designs on-call management for security operations center: advanced threat detection automation, SOAR integration for incident response orchestration, and cross-functional security incident coordination. Implements distributed tracing for security event correlation. Defines security-specific SLIs (detection time, containment time). Conducts security post-mortems and drives detection engineering improvements.

Designs security observability strategy with Prometheus & Grafana: implements advanced security metric collection and correlation, defines SLI/SLO for security monitoring coverage and response times, conducts post-mortems for security incidents. Mentors team on metric-based threat hunting and detection engineering.

SLI / SLO / SLA Advanced

Designs observability strategy for security operations platforms — implements security event correlation and threat detection pipeline monitoring. Defines security-specific SLI/SLO frameworks covering MTTD, MTTR, and detection coverage metrics. Conducts security incident post-mortems and designs resilient security monitoring architectures.

Designs observability strategy for security operations: implements advanced SIEM correlation for multi-stage attack detection, defines SLI/SLO for security monitoring coverage and response times, conducts post-mortems for security incidents. Mentors team on forensic log analysis and threat hunting through structured logs.

Version Control & Collaboration · 2

Code Review Advanced

Designs code review processes for SecOps: SIEM rule review standards, threat detection logic review checklists, alert quality review gates. Mentors team on reviewing security monitoring code for detection accuracy and operational reliability.

Git Advanced Advanced

Designs Git security practices for organizations: implements repository auditing frameworks using Git history analysis, configures enterprise-grade commit signing and verification infrastructure, designs access control policies for sensitive codebases. Mentors team on using Git forensics for security incident investigation.

Documentation · 3

Designs comprehensive security architecture documentation frameworks combining C4 models with threat modeling outputs (STRIDE, PASTA). Creates detailed arc42 security views covering trust boundaries, encryption layers, and compliance requirements. Mentors the team on documenting security architecture decisions with proper risk assessment in ADRs. Optimizes documentation workflows to ensure security reviews are reflected in architecture artifacts.

Designs production-grade threat modeling diagrams, multi-layer attack trees, and detailed network topology maps using Mermaid, PlantUML, or D2. Optimizes diagram complexity for incident response playbooks. Mentors analysts on security diagramming practices.

Designs SOC runbook frameworks integrating SIEM, SOAR, and EDR workflows: advanced threat hunting playbooks, insider threat investigation procedures, cross-organizational incident coordination runbooks. Mentors analysts on writing runbooks that balance automation with critical human judgment points.

Additional skills

Not assessed by the team, but part of the self-assessment and the development plan.

API DocumentationAsync ProgrammingAWSChatGPT / ClaudeDesign PatternsGitHub Actions / GitLab CIIntegration TestingKubernetes CoreMultithreadingOOP & SOLID PrinciplesPostgreSQLPrompt Engineering for CodeRedisSystem Design FundamentalsUnit Testing

What changes at Lead

51 skills get a higher expectation or become core when moving from Senior to Lead. The biggest jumps first.

See the Lead page →
Run this with your whole team
Self-assessment plus manager and peer reviews against the same matrix, gap analysis and next-level readiness for every engineer. Team Pro is free for 14 days; individual tools stay free forever.
Start a team trial (14 days free) Send to my manager

} in the open competency matrix: 51 skills across 5 levels. The matrix is free for individuals and stays free.