Skill Profile

Network Security

Firewalls, IDS/IPS, WAF, DDoS protection, network policies, network segmentation

Security Infrastructure Security

Roles

8

where this skill appears

Levels

5

structured growth path

Mandatory requirements

34

the other 6 optional

Domain

Security

Group

Infrastructure Security

Last updated

3/17/2026

How to Use

Choose your current level and compare expectations. The items below show what to cover to advance to the next level.

What is Expected at Each Level

The table shows how skill depth grows from Junior to Principal. Click a row to see details.

Role Required Description
Application Security Engineer Required Understands basic Network Security concepts. Follows security guidelines. Recognizes typical code vulnerabilities.
DevSecOps Engineer Required Studies network security fundamentals: firewall rules, VPN, TLS/SSL. Configures Security Groups and NACLs in AWS. Understands Defense in Depth and network segmentation principles. Uses Wireshark for basic traffic analysis. Configures HTTPS with Let's Encrypt for web applications.
Infrastructure Engineer Understands the fundamentals of Network Security. Applies basic practices in daily work. Follows recommendations from the team and documentation.
Network Engineer Required Knows basic network security concepts for network engineering and can apply them in typical tasks. Uses standard tools and follows established team practices. Understands when and why this approach is used.
Penetration Testing Engineer Required Understands basic network security concepts: TCP/IP model, common ports and protocols, firewall rule logic. Can run Nmap scans, read packet captures in Wireshark, and identify open services on a target host under supervision.
QA Security Engineer Tests network security: port scanning (nmap), service enumeration, SSL/TLS configuration (testssl.sh). Understands network segmentation and firewall rules.
Security Analyst Required Understands basic Network Security concepts. Follows security guidelines. Recognizes common code vulnerabilities.
Telecom Developer Understands fundamental network security principles relevant to telecom: firewall basics, VPN tunneling concepts, and traffic encryption with TLS/IPsec. Can configure basic ACLs on network equipment and recognizes common network-level attack vectors such as ARP spoofing and DNS poisoning.
Role Required Description
Application Security Engineer Required Independently configures and audits network security controls protecting application infrastructure: WAF rules, reverse proxy hardening, TLS certificate management. Analyzes network traffic for signs of application-layer attacks (SQLi over HTTP, SSRF, DNS exfiltration). Integrates IDS/IPS alerts with application security monitoring workflows.
DevSecOps Engineer Required Designs network architecture with DMZ, private subnets and NAT gateways. Configures WAF (AWS WAF / ModSecurity) with rules against OWASP Top 10. Introduces VPN (WireGuard/IPSec) for site-to-site and remote access. Monitors network anomalies through VPC Flow Logs and AWS Traffic Mirroring.
Infrastructure Engineer Configures infrastructure network security: multi-tier segmentation (DMZ, private, database subnets), VPN for secure remote access, TLS termination on load balancer. Configures IDS/IPS rules, sets up VPC Flow Logs for traffic analysis and automates firewall rules through Terraform.
Network Engineer Required Confidently applies network security for network engineering in non-standard tasks. Independently selects the optimal approach and tools. Analyzes trade-offs and proposes improvements to existing solutions.
Penetration Testing Engineer Required Independently performs network penetration testing: conducts host discovery, service enumeration, and vulnerability scanning across subnets. Exploits misconfigured firewalls, weak VPN setups, and unpatched network services. Writes clear findings on network segmentation gaps and proposes remediation for IDS/IPS evasion techniques discovered during engagements.
QA Security Engineer Conducts network security assessment: vulnerability scanning (Nessus), network architecture review, traffic analysis (Wireshark). Tests DNS security, DDoS resilience.
Security Analyst Required Independently monitors and investigates network security events using SIEM and IDS/IPS platforms. Correlates firewall logs, NetFlow data, and DNS queries to detect lateral movement and C2 communication. Tunes IDS signatures to reduce false positives and documents network-based indicators of compromise for incident response playbooks.
Telecom Developer Independently implements network security measures in telecom systems: configures IPsec/GRE tunnels, sets up VLAN segmentation for signaling and media planes, and enforces TLS for SIP trunking. Monitors network anomalies with flow analysis tools and responds to DDoS attempts targeting telecom infrastructure.
Role Required Description
Application Security Engineer Required Designs security solutions with Network Security. Conducts threat modeling. Implements security practices in SDLC. Mentors the team.
DevSecOps Engineer Required Develops corporate network security architecture: micro-segmentation, Zero Trust Network Access (ZTNA). Introduces service mesh (Istio) with mTLS for east-west traffic. Configures DDoS protection with AWS Shield Advanced. Designs secure connectivity for hybrid cloud with Transit Gateway.
Infrastructure Engineer Required Designs enterprise-grade network security: micro-segmentation through Cilium/Calico NetworkPolicy, mTLS for service-to-service communication, DDoS protection through AWS Shield/CloudFlare. Implements network detection and response (NDR), configures deep packet inspection and designs secure connectivity for hybrid cloud.
Network Engineer Required Expertly applies network security for network engineering to design complex systems. Optimizes existing solutions and prevents architectural mistakes. Conducts code reviews and trains colleagues on best practices.
Penetration Testing Engineer Required Designs complex network penetration testing methodologies: multi-stage attack chains exploiting network trust relationships, pivoting through segmented networks, and advanced IDS/IPS evasion. Mentors junior pentesters on network protocol analysis and firewall bypass techniques. Evaluates zero-trust network architectures and identifies gaps in micro-segmentation implementations.
QA Security Engineer Required Designs network security testing: automated network scanning pipeline, infrastructure penetration testing, zero-trust architecture validation. Tests microsegmentation.
Security Analyst Required Designs network threat detection strategies: builds advanced SIEM correlation rules for multi-stage network attacks, architects honeypot deployments for early threat detection, and creates network forensics procedures. Mentors analysts on deep packet inspection, encrypted traffic analysis, and advanced persistent threat identification across network layers.
Telecom Developer Required Designs secure network architectures for telecom platforms: end-to-end encryption for signaling protocols (SIP-TLS, SRTP), multi-layer DDoS mitigation strategies, and secure interconnect designs between carrier networks. Mentors team on network security hardening for SS7/Diameter/GTP protocols and evaluates vendor solutions for telecom-grade firewalls and session border controllers.
Role Required Description
Application Security Engineer Required Defines team-level network security strategy for application environments: standardizes WAF policies, establishes network segmentation requirements for microservice deployments, and drives adoption of zero-trust network access for internal services. Coordinates with infrastructure teams on IDS/IPS tuning and ensures network security controls are integrated into CI/CD pipelines and deployment workflows.
DevSecOps Engineer Required Defines network security strategy for the entire organization. Manages SASE/SSE solution deployment (Zscaler/Cloudflare Access). Builds network security review processes for new architectures. Integrates NDR (Network Detection and Response) with SOC processes. Manages vulnerability scanning.
Infrastructure Engineer Required Defines organizational network security standards: segmentation policies for all environments, TLS configuration standards, firewall change management processes. Reviews team network architectures for zero-trust compliance, implements automated network policy auditing and defines SLO for security patching.
Network Engineer Required Establishes network security standards for the network engineering team and makes architectural decisions. Defines the technical roadmap incorporating this skill. Mentors senior engineers and influences practices of adjacent teams.
Penetration Testing Engineer Required Leads the team's network penetration testing practice: defines engagement scoping for network assessments, standardizes network attack toolchains and reporting templates, and prioritizes remediation across firewall, VPN, and segmentation findings. Builds team capabilities in advanced network exploitation and coordinates purple-team exercises focused on network defense validation.
QA Security Engineer Required Defines network security testing standards: periodic assessment schedule, scope requirements, reporting. Coordinates with infrastructure team. Implements continuous network monitoring.
Security Analyst Required Leads the team's network security monitoring and response capabilities: defines SIEM use cases for network threat detection, establishes SLAs for network incident triage, and builds runbooks for common network attack patterns. Coordinates with SOC and infrastructure teams to ensure comprehensive network visibility and drives adoption of NDR (Network Detection and Response) solutions.
Telecom Developer Required Leads network security strategy for the telecom development team: defines security standards for all network protocol implementations, establishes secure-by-default configurations for SBC and firewall deployments, and coordinates with NOC on incident response procedures. Drives team adoption of automated network security testing and ensures compliance with telecom security regulations (3GPP, GSMA).
Role Required Description
Application Security Engineer Required Shapes organization-wide network security architecture for application ecosystems: defines zero-trust network policies across all business units, establishes enterprise WAF and DDoS mitigation standards, and drives convergence of network and application security monitoring into unified platforms. Influences industry practices through publications on network-layer application protection and evaluates emerging technologies like SASE and SD-WAN security frameworks.
DevSecOps Engineer Required Architecturally defines Zero Trust Network Architecture for the enterprise. Develops strategy for transitioning from perimeter approach to identity-based security. Designs global network security for multi-regional infrastructure. Defines data encryption standards in transit and at rest.
Infrastructure Engineer Required Shapes company network security strategy: SASE/SSE architecture, zero-trust network access replacing traditional VPN, eBPF-based observability for security. Defines network automation roadmap with security-first approach, coordinates network incident response processes with SOC and designs DR scenarios.
Network Engineer Required Shapes network security strategy for network engineering at the organizational level. Defines best practices and influences technology choices beyond their own team. Is a recognized expert in this area.
Penetration Testing Engineer Required Defines the organization's network penetration testing strategy and standards: establishes red-team network attack frameworks, sets maturity benchmarks for network defense across all departments, and drives executive-level reporting on network risk posture. Builds cross-functional partnerships with network engineering and cloud teams to embed offensive security validation into infrastructure change management processes.
QA Security Engineer Required Designs network security strategy: zero-trust networking validation, micro-segmentation testing, global network security assessment. Defines organizational network security framework.
Security Analyst Required Defines the organization's network threat intelligence and detection strategy: architects enterprise-wide network security monitoring covering on-prem, cloud, and hybrid environments. Establishes network forensics standards, drives investment in NDR and SIEM capabilities, and sets organizational benchmarks for mean-time-to-detect network-based threats. Represents the company in industry threat-sharing consortiums and shapes network security policy at the board level.
Telecom Developer Required Shapes the organization's network security vision for telecom infrastructure at scale: defines enterprise standards for carrier-grade network protection, drives adoption of 5G security frameworks (NESAS, SCAS), and establishes cross-departmental governance for signaling security (SS7, Diameter, HTTP/2). Influences industry standards bodies on telecom network security and evaluates emerging threats to next-generation network architectures.

Community

👁 Watch ✏️ Suggest Change Sign in to suggest changes
📋 Proposals
No proposals yet for Network Security
Loading comments...