Skill Profile

Runbook & Playbook Writing

Runbook/Playbook: operational instructions, incident response, troubleshooting guides

Documentation Technical Documentation

Roles

9

where this skill appears

Levels

5

structured growth path

Mandatory requirements

29

the other 15 optional

Domain

Documentation

Group

Technical Documentation

Last updated

3/17/2026

How to Use

Choose your current level and compare expectations. The items below show what to cover to advance to the next level.

What is Expected at Each Level

The table shows how skill depth grows from Junior to Principal. Click a row to see details.

Role Required Description
Application Security Engineer Understands the purpose of runbooks and playbooks for security incident response. Follows existing runbooks during incidents, documenting steps taken. Assists in maintaining runbook repositories and updating known procedure changes.
Cloud Engineer Follows existing runbooks when working with cloud infrastructure: restarting services, scaling resources, basic diagnostics. Documents simple procedures — how to deploy an environment, check deployment status, connect to VPN. Updates runbooks when inaccuracies are found.
Database Engineer / DBA Follows existing DBA runbooks: backup/restore procedures, failover steps, common troubleshooting. Documents steps when performing routine operations. Updates runbooks with found discrepancies.
DevSecOps Engineer Creates runbooks for typical operational tasks: deployment, rollback, service restart. Documents security procedures: credential rotation, certificate renewal. Follows standard template: pre-conditions, steps, expected output, troubleshooting. Stores runbooks in Git with version control.
Game QA Engineer Understands the basics of runbook writing for QA incident triage and escalation. Follows existing playbooks for crash reproduction, test environment recovery, and build validation failures. Documents encountered issues according to runbook templates.
Penetration Testing Engineer Understands the structure of penetration testing runbooks and engagement playbooks. Follows established runbooks for reconnaissance, scanning, and basic exploitation phases. Documents findings according to standard reporting templates.
Security Analyst Understands the role of runbooks in SOC operations and alert triage. Follows existing playbooks for common alert types: phishing, malware detection, unauthorized access attempts. Documents incident handling steps and escalation decisions.
Technical Writer Required Understands the purpose of runbooks and their role in incident response. Knows runbook structure: prerequisites, steps, checks, rollback. Can document simple operational procedures based on engineer descriptions.
Role Required Description
Application Security Engineer Independently writes runbooks for application security incident response: vulnerability disclosure handling, SAST/DAST alert triage, dependency vulnerability remediation. Understands trade-offs between automation and manual steps in security playbooks.
Cloud Engineer Writes runbooks for common operational tasks: deployment rollback, database failover, EBS disk expansion, certificate replacement. Includes preconditions, step-by-step commands, result verification and rollback plan. Uses templates with automated steps through AWS CLI/kubectl.
Database Engineer / DBA Writes DBA runbooks: procedures for database maintenance (vacuum, reindex, partition management), incident response for common issues (replication lag, connection exhaustion). Includes diagnostic queries and remediation steps.
DevSecOps Engineer Develops security runbooks: incident response for common scenarios (compromised host, leaked credentials, DDoS). Creates automated runbooks through Rundeck or AWS Systems Manager. Introduces runbook testing: periodic dry runs for validation. Integrates runbooks with PagerDuty for automatic provision on alerts.
Engineering Manager Independently creates runbooks for engineering team operational processes: on-call rotations, incident escalation paths, production deployment rollback procedures. Balances runbook detail level with team autonomy and decision-making flexibility.
Game QA Engineer Independently writes runbooks for game QA processes: certification submission checklists, platform-specific compliance verification, live-ops incident triage procedures. Understands trade-offs between rigid step-by-step playbooks and adaptive QA workflows.
Penetration Testing Engineer Independently writes penetration testing runbooks for various engagement types: web application, network infrastructure, API testing. Creates playbooks with decision trees for exploitation paths and documents remediation guidance for common vulnerability patterns.
Security Analyst Independently writes SOC runbooks for alert investigation: SIEM correlation rule triage, endpoint detection response workflows, threat intelligence integration procedures. Understands trade-offs between automated SOAR playbooks and manual analyst decision points.
Technical Writer Required Independently creates runbooks for production systems: deployment procedures, incident response, disaster recovery. Ensures step-by-step clarity and unambiguity of instructions. Conducts dry-run testing of runbooks with the operations team.
Role Required Description
Application Security Engineer Required Designs comprehensive runbook frameworks for application security operations: secure SDLC incident response, zero-day vulnerability handling, supply chain compromise playbooks. Mentors team members on writing effective, actionable security runbooks with proper escalation matrices.
Cloud Engineer Required Designs systematic approach to runbooks: standardized format, integration with incident management (PagerDuty), automated runbooks through SSM Automation/Rundeck. Introduces executable runbooks — markdown with embedded scripts. Conducts regular gamedays for runbook validation.
Database Engineer / DBA Required Designs runbook framework for the DBA team: standardized templates, automated runbooks via scripts, monitoring alert integration. Implements executable runbooks for automating common database operations.
DevSecOps Engineer Required Designs corporate security runbook library covering MITRE ATT&CK tactics. Introduces runbook-as-code with automation through Jupyter Notebooks or Tines. Creates Decision Trees for complex incident scenarios. Develops runbooks for regulatory compliance: evidence collection, audit preparation.
Engineering Manager Required Designs runbook systems for cross-team engineering operations: multi-service incident coordination, disaster recovery orchestration, capacity planning response procedures. Optimizes runbook adoption through integration with CI/CD pipelines and automated validation of playbook steps.
Game QA Engineer Required Designs runbook architecture for game QA operations across multiple titles and platforms: live service incident response, multiplayer issue escalation, platform certification failure recovery. Mentors QA team on writing maintainable playbooks that adapt to rapid release cycles.
Penetration Testing Engineer Required Designs advanced penetration testing runbook frameworks: red team operation playbooks, social engineering campaign procedures, Active Directory attack chains documentation. Mentors junior testers on creating reusable engagement runbooks with proper evidence collection and chain-of-custody procedures.
Security Analyst Required Designs SOC runbook frameworks integrating SIEM, SOAR, and EDR workflows: advanced threat hunting playbooks, insider threat investigation procedures, cross-organizational incident coordination runbooks. Mentors analysts on writing runbooks that balance automation with critical human judgment points.
Technical Writer Required Designs a runbook system for the organization: taxonomy, lifecycle, integration with alerting and incident management. Creates automated runbooks (runbook automation through scripts/playbooks). Ensures runbooks are tested regularly.
Role Required Description
Application Security Engineer Required Defines runbook strategy for the application security program: standardizes playbook templates across security teams, establishes runbook review and update cadences, integrates runbook metrics into security KPIs. Drives adoption of executable runbooks with SOAR platform integration.
Cloud Engineer Required Defines runbook strategy for the organization: coverage requirements (each service — minimum 5 runbooks), review process, freshness policy. Introduces self-healing runbooks — automated execution on specific alerts. Links runbooks with SLOs and incident severity levels.
Database Engineer / DBA Required Defines runbook standards: mandatory sections, testing requirements, regular review cadence. Coordinates runbook creation for new database services. Implements runbook automation via ChatOps and incident management tools.
DevSecOps Engineer Required Defines documentation standards for security operations. Manages Knowledge Base with runbooks, playbooks, postmortems. Builds processes: mandatory runbook creation, periodic review, automated testing. Integrates runbooks with SOAR platform for semi-automated response. Ensures runbook coverage for all critical systems.
Engineering Manager Required Defines runbook strategy at the product level: establishes operational readiness standards requiring runbooks for all production services, creates runbook maturity models, drives cultural adoption of documented operational procedures across engineering teams.
Game QA Engineer Required Defines Runbook and Playbook Writing strategy at team/product level. Establishes standards and best practices. Conducts reviews.
Penetration Testing Engineer Required Defines runbook strategy for the penetration testing practice: standardizes engagement methodology playbooks, establishes quality gates for runbook completeness, drives integration of runbooks with vulnerability management platforms and reporting automation.
Security Analyst Required Defines runbook strategy for SOC operations at the team level: establishes playbook governance frameworks, drives SOAR-integrated automated response procedures, creates runbook effectiveness metrics tied to MTTD and MTTR improvements.
Technical Writer Required Defines runbook standards for the entire organization. Builds a culture of operational documentation. Coordinates runbook coverage: every production service has a complete set of runbooks. Conducts runbook reviews.
Role Required Description
Application Security Engineer Required Defines Runbook and Playbook Writing strategy at the organizational level. Shapes enterprise approaches. Mentors leads and architects.
Cloud Engineer Required Shapes enterprise-level operational knowledge management: AI-assisted runbook generation, automated validation through chaos engineering, runbook-as-code in Git. Designs operational knowledge management platform with versioning, testing and continuous improvement.
Database Engineer / DBA Required Shapes organizational runbook strategy: self-healing databases through automated runbooks, AI-assisted troubleshooting, runbook marketplace for cross-team sharing. Defines investments in operational automation.
DevSecOps Engineer Required Architecturally defines enterprise-scale operational documentation approach. Designs knowledge management system for security team. Defines runbook-as-code standards for IR automation. Develops operational maturity assessment framework. Influences documentation culture in the organization.
Engineering Manager Required Defines organizational runbook strategy: establishes company-wide standards for operational documentation, drives cross-departmental runbook interoperability for major incident response, creates executive-level playbooks for business continuity and disaster recovery coordination.
Game QA Engineer Required Defines Runbook and Playbook Writing strategy at organizational level. Establishes enterprise approaches. Mentors leads and architects.
Penetration Testing Engineer Required Defines organizational strategy for offensive security runbooks: establishes enterprise-wide red team and purple team engagement frameworks, drives industry-aligned methodology standards (PTES, OWASP, MITRE ATT&CK), creates runbook governance for regulatory compliance across penetration testing programs.
Security Analyst Required Defines organizational strategy for security operations runbooks: establishes enterprise-wide incident response playbook standards aligned with NIST and ISO 27001, drives cross-functional runbook integration between SOC, IT operations, and business units, creates executive communication playbooks for major security incidents.
Technical Writer Required Shapes operational documentation strategy at the corporate level. Defines how runbooks integrate with SRE practices, incident management, and organizational resilience. Ensures knowledge transfer during incidents.

Community

👁 Watch ✏️ Suggest Change Sign in to suggest changes
📋 Proposals
No proposals yet for Runbook & Playbook Writing
Loading comments...