Domain
Security
Skill Profile
Trust Service Criteria, controls, audit preparation, evidence collection, continuous compliance
Roles
2
where this skill appears
Levels
5
structured growth path
Mandatory requirements
10
the other 0 optional
Security
Compliance
3/17/2026
Choose your current level and compare expectations. The items below show what to cover to advance to the next level.
The table shows how skill depth grows from Junior to Principal. Click a row to see details.
| Role | Required | Description |
|---|---|---|
| Application Security Engineer | Required | Understands basic SOC2 Compliance concepts. Follows security guidelines. Recognizes typical code vulnerabilities. |
| Security Analyst | Required | Understands basic SOC2 Compliance concepts. Follows security guidelines. Recognizes common code vulnerabilities. |
| Role | Required | Description |
|---|---|---|
| Application Security Engineer | Required | Implements SOC 2 security controls in application architecture: access logging, encryption at rest/in transit, and vulnerability management. Conducts security code reviews aligned with Trust Services Criteria. |
| Security Analyst | Required | Applies SOC 2 compliance frameworks in daily security operations. Conducts control testing, collects audit evidence, and maintains documentation for Trust Services Criteria across availability, security, and confidentiality. |
| Role | Required | Description |
|---|---|---|
| Application Security Engineer | Required | Designs security solutions with SOC2 Compliance. Conducts threat modeling. Implements security practices in SDLC. Mentors the team. |
| Security Analyst | Required | Designs security solutions with SOC2 Compliance. Conducts threat modeling. Integrates security practices into SDLC. Mentors the team. |
| Role | Required | Description |
|---|---|---|
| Application Security Engineer | Required | Defines SOC 2 compliance strategy for application security: establishes secure SDLC policies, incident response procedures, and continuous monitoring requirements. Coordinates with auditors on technical control validation. |
| Security Analyst | Required | Defines SOC 2 compliance program spanning all Trust Services Criteria. Establishes control frameworks, manages audit relationships, coordinates remediation of control gaps, and trains cross-functional teams on compliance requirements. |
| Role | Required | Description |
|---|---|---|
| Application Security Engineer | Required | Defines enterprise application security strategy aligned with SOC 2 Type II requirements. Shapes security architecture for continuous compliance, designs automated evidence collection systems, and represents the organization in auditor engagements. |
| Security Analyst | Required | Defines enterprise-wide compliance strategy across SOC 2, ISO 27001, and related frameworks. Shapes organizational security architecture for multi-framework compliance, drives automation of compliance processes, and serves as executive liaison to audit firms. |