Applies algorithmic thinking to security operations: anomaly detection algorithms for threat identification, correlation algorithms for multi-source alert analysis, pattern matching algorithms for IOC detection in log streams. Designs efficient log analysis algorithms for real-time threat hunting at scale.
Roles · Security Analyst · Senior
What a Senior } should know
36 core skills, 51 in total. Expectations per skill, and what changes at the next level.
This page lists what a Senior } is expected to know and do, skill by skill. Core skills are the ones a manager and peers assess in a review cycle; the rest count only in self-assessment. Main areas: Programming Fundamentals, API & Integration, Cloud & Infrastructure.
Core skills for a Senior
Grouped by area. The label on the right is the expected depth: Awareness, Working, Advanced or Expert.
Programming Fundamentals · 3
Designs code quality standards for security operations tooling: SIEM rule structure, incident response automation scripts, threat intelligence integration code. Refactors detection logic for accuracy and performance. Establishes review practices for alert quality, forensic script reliability, and chain-of-custody compliance.
Selects optimal data structures for security operations: log index structures for rapid threat hunting, correlation matrices for multi-source alert aggregation, timeline data models for incident reconstruction. Optimizes SIEM data structures for query performance on high-volume log streams. Designs efficient data models for threat intelligence storage and IOC matching.
API & Integration · 1
Designs API security monitoring architecture: API-specific threat detection rules, API abuse pattern analytics, API authentication anomaly detection. Defines API security monitoring standards and incident response procedures. Mentors team on API threat intelligence and analysis.
Cloud & Infrastructure · 2
Designs Docker infrastructure for security operations: containerized SIEM/SOC architecture, hardened monitoring containers, isolated forensic analysis environments. Implements best practices for container runtime security, log collection from containerized services, and threat detection in container environments.
Designs network security monitoring architectures for enterprise environments. Implements advanced threat detection through network behavior analysis, encrypted traffic inspection, and ML-based anomaly detection. Optimizes SIEM network correlation rules and implements security hardening for network infrastructure.
Testing & QA · 1
Designs security analytics for vulnerability management: automated vulnerability correlation across scanning tools, risk-based prioritization models, and executive reporting dashboards. Implements continuous security monitoring for application portfolio. Conducts organizational threat modeling and risk assessments. Mentors team on advanced security analysis techniques.
Security · 18
Designs cloud threat detection strategies using advanced SIEM correlation rules and CloudTrail analytics. Conducts threat modeling for cloud-hosted services. Integrates cloud incident response playbooks into the SDLC and mentors analysts on cloud forensics and threat hunting techniques.
Designs the organization's dependency vulnerability management program, defining SLA tiers based on CVSS severity, exploitability, and asset criticality. Conducts threat modeling of the software supply chain to identify risks beyond individual CVEs, such as maintainer compromise and registry poisoning. Integrates SCA tooling (Snyk, Dependabot, Trivy) with SIEM/SOAR platforms for automated alerting and response workflows. Mentors analysts on distinguishing actionable vulnerabilities from false positives using reachability and runtime context.
Leads complex forensic investigations across multiple systems and environments. Performs advanced timeline analysis, memory forensics, and malware reverse engineering. Integrates forensic findings into threat intelligence workflows and SIEM correlation rules. Mentors junior analysts on forensic methodologies.
Designs security solutions with GDPR / 152-FZ Compliance. Conducts threat modeling. Integrates security practices into SDLC. Mentors the team.
Leads incident response for complex multi-vector security incidents across cloud and on-premise environments. Conducts advanced threat hunting and root cause analysis. Develops and refines incident response playbooks based on emerging threats. Mentors team on incident handling and coordinates with external stakeholders.
Designs security monitoring for authentication infrastructure: SIEM correlation rules for JWT/OAuth2 attacks, anomaly detection for token usage patterns, and incident response playbooks for authentication compromises. Implements compliance controls for identity management (SOC2, PCI-DSS). Conducts threat modeling for OIDC provider deployments. Mentors team on authentication security analysis.
Leads Kubernetes security monitoring strategy with advanced detection rules for cluster-level threats. Conducts deep investigation of container compromise incidents including forensic analysis of pod artifacts and network traffic. Integrates Kubernetes audit telemetry into SIEM and develops automated response playbooks for cluster incidents.
Designs network threat detection strategies: builds advanced SIEM correlation rules for multi-stage network attacks, architects honeypot deployments for early threat detection, and creates network forensics procedures. Mentors analysts on deep packet inspection, encrypted traffic analysis, and advanced persistent threat identification across network layers.
Designs application security monitoring and detection strategies aligned with OWASP attack patterns. Conducts threat modeling for detection engineering — designing correlation rules for multi-stage application attacks. Integrates security findings from SAST/DAST/pentest into SOC detection capabilities. Mentors team on application-layer threat analysis and incident forensics.
Designs security solutions with PCI DSS. Conducts threat modeling. Integrates security practices into SDLC. Mentors the team.
Designs comprehensive authorization monitoring solutions for RBAC/ABAC systems. Conducts threat modeling of access control architectures across distributed services. Integrates authorization analytics into SIEM and security operations. Mentors analysts on access control risk assessment.
Designs comprehensive SAST/DAST analytics frameworks for vulnerability trend analysis. Conducts threat modeling to map scanner coverage against real attack scenarios. Integrates scanning results into SIEM for continuous security monitoring. Mentors analysts on vulnerability classification and risk scoring.
Designs security monitoring for secrets infrastructure: Vault audit log analysis pipelines, anomaly detection for credential usage, and incident response playbooks for secret compromise. Implements compliance reporting for regulatory requirements (SOC2, PCI-DSS credential handling). Conducts penetration testing focused on secrets extraction vectors. Mentors team on threat modeling for credential flows.
Designs security analysis workflows integrating secure coding intelligence — correlates code-level vulnerability data with runtime threat detection, architects detection rules informed by common coding weakness patterns, and implements automated security validation workflows. Conducts threat modeling for detection engineering and mentors team on code-aware security analysis.
Designs security solutions with SOC2 Compliance. Conducts threat modeling. Integrates security practices into SDLC. Mentors the team.
Designs security solutions with Supply Chain Security. Conducts threat modeling. Integrates security practices into SDLC. Mentors the team.
Designs threat modeling processes for complex distributed systems and cloud-native architectures. Creates attack tree libraries mapped to industry-specific threat landscapes. Mentors analysts on advanced threat analysis techniques including kill chain modeling. Optimizes threat detection rules based on modeled attack scenarios and emerging threat intelligence.
Designs comprehensive vulnerability management programs with risk-based prioritization frameworks. Conducts threat modeling to map vulnerability exposure across organizational assets. Integrates vulnerability data into security operations for proactive risk mitigation. Mentors analysts on advanced triage and remediation tracking.
AI-Assisted Development · 1
Designs GitHub Copilot governance for security teams: implements policies for AI use in detection rule development, configures content controls for sensitive security repositories, evaluates AI-generated security code for accuracy and false positive risks. Mentors team on responsible AI-assisted security tooling development.
Observability & Monitoring · 5
Designs comprehensive security observability strategy with ELK Stack and OpenSearch. Implements distributed tracing for security event chains across network, endpoint, and cloud layers. Defines SLI/SLO for detection coverage, alert fidelity, and mean time to detect (MTTD). Builds advanced Elasticsearch detection rules using EQL and threat intelligence enrichment. Conducts thorough post-mortems with timeline reconstruction in Kibana. Mentors analysts on query optimization and detection engineering.
Designs on-call management for security operations center: advanced threat detection automation, SOAR integration for incident response orchestration, and cross-functional security incident coordination. Implements distributed tracing for security event correlation. Defines security-specific SLIs (detection time, containment time). Conducts security post-mortems and drives detection engineering improvements.
Designs security observability strategy with Prometheus & Grafana: implements advanced security metric collection and correlation, defines SLI/SLO for security monitoring coverage and response times, conducts post-mortems for security incidents. Mentors team on metric-based threat hunting and detection engineering.
Designs observability strategy for security operations platforms — implements security event correlation and threat detection pipeline monitoring. Defines security-specific SLI/SLO frameworks covering MTTD, MTTR, and detection coverage metrics. Conducts security incident post-mortems and designs resilient security monitoring architectures.
Designs observability strategy for security operations: implements advanced SIEM correlation for multi-stage attack detection, defines SLI/SLO for security monitoring coverage and response times, conducts post-mortems for security incidents. Mentors team on forensic log analysis and threat hunting through structured logs.
Version Control & Collaboration · 2
Designs code review processes for SecOps: SIEM rule review standards, threat detection logic review checklists, alert quality review gates. Mentors team on reviewing security monitoring code for detection accuracy and operational reliability.
Designs Git security practices for organizations: implements repository auditing frameworks using Git history analysis, configures enterprise-grade commit signing and verification infrastructure, designs access control policies for sensitive codebases. Mentors team on using Git forensics for security incident investigation.
Documentation · 3
Designs comprehensive security architecture documentation frameworks combining C4 models with threat modeling outputs (STRIDE, PASTA). Creates detailed arc42 security views covering trust boundaries, encryption layers, and compliance requirements. Mentors the team on documenting security architecture decisions with proper risk assessment in ADRs. Optimizes documentation workflows to ensure security reviews are reflected in architecture artifacts.
Designs production-grade threat modeling diagrams, multi-layer attack trees, and detailed network topology maps using Mermaid, PlantUML, or D2. Optimizes diagram complexity for incident response playbooks. Mentors analysts on security diagramming practices.
Designs SOC runbook frameworks integrating SIEM, SOAR, and EDR workflows: advanced threat hunting playbooks, insider threat investigation procedures, cross-organizational incident coordination runbooks. Mentors analysts on writing runbooks that balance automation with critical human judgment points.
Additional skills
Not assessed by the team, but part of the self-assessment and the development plan.
What changes at Lead
51 skills get a higher expectation or become core when moving from Senior to Lead. The biggest jumps first.
- Algorithms & Complexity: Advanced → Expert
- Architecture Documentation: C4, arc42: Advanced → Expert
- Cloud Security: Advanced → Expert
- Code Quality & Refactoring: Advanced → Expert
- Code Review: Advanced → Expert
- Data Structures: Advanced → Expert
- Dependency Vulnerability Scanning: Advanced → Expert
- Diagramming: Mermaid, PlantUML, D2: Advanced → Expert
- Digital Forensics Basics: Advanced → Expert
- Docker: Advanced → Expert
} in the open competency matrix: 51 skills across 5 levels. The matrix is free for individuals and stays free.