Dominio
Security
Perfil de habilidad
Trust Service Criteria, controls, audit preparation, evidence collection, continuous compliance
Roles
2
donde aparece esta habilidad
Niveles
5
ruta de crecimiento estructurada
Requisitos obligatorios
10
los otros 0 opcionales
Security
Compliance
17/3/2026
Selecciona tu nivel actual y compara las expectativas.
La tabla muestra cómo crece la profundidad desde Junior hasta Principal.
| Rol | Obligatorio | Descripción |
|---|---|---|
| Application Security Engineer | Obligatorio | Understands basic SOC2 Compliance concepts. Follows security guidelines. Recognizes typical code vulnerabilities. |
| Security Analyst | Obligatorio | Understands basic SOC2 Compliance concepts. Follows security guidelines. Recognizes common code vulnerabilities. |
| Rol | Obligatorio | Descripción |
|---|---|---|
| Application Security Engineer | Obligatorio | Implements SOC 2 security controls in application architecture: access logging, encryption at rest/in transit, and vulnerability management. Conducts security code reviews aligned with Trust Services Criteria. |
| Security Analyst | Obligatorio | Applies SOC 2 compliance frameworks in daily security operations. Conducts control testing, collects audit evidence, and maintains documentation for Trust Services Criteria across availability, security, and confidentiality. |
| Rol | Obligatorio | Descripción |
|---|---|---|
| Application Security Engineer | Obligatorio | Designs security solutions with SOC2 Compliance. Conducts threat modeling. Implements security practices in SDLC. Mentors the team. |
| Security Analyst | Obligatorio | Designs security solutions with SOC2 Compliance. Conducts threat modeling. Integrates security practices into SDLC. Mentors the team. |
| Rol | Obligatorio | Descripción |
|---|---|---|
| Application Security Engineer | Obligatorio | Defines SOC 2 compliance strategy for application security: establishes secure SDLC policies, incident response procedures, and continuous monitoring requirements. Coordinates with auditors on technical control validation. |
| Security Analyst | Obligatorio | Defines SOC 2 compliance program spanning all Trust Services Criteria. Establishes control frameworks, manages audit relationships, coordinates remediation of control gaps, and trains cross-functional teams on compliance requirements. |
| Rol | Obligatorio | Descripción |
|---|---|---|
| Application Security Engineer | Obligatorio | Defines enterprise application security strategy aligned with SOC 2 Type II requirements. Shapes security architecture for continuous compliance, designs automated evidence collection systems, and represents the organization in auditor engagements. |
| Security Analyst | Obligatorio | Defines enterprise-wide compliance strategy across SOC 2, ISO 27001, and related frameworks. Shapes organizational security architecture for multi-framework compliance, drives automation of compliance processes, and serves as executive liaison to audit firms. |