Skip to main content
Competrace
Cybersecurity · Level 1 of 5

Security Analyst job description

This is what Cybersecurity teams expect from a Security Analyst. 39 skills, each with the mastery level set for this rung. It is the same framework Competrace ships to new customers, so you can read it here and import it as-is.

Monitors alerts and works incident playbooks under supervision.

Security Analyst only.

Cybersecurity — Security Analyst
Monitors alerts and works incident playbooks under supervision.

REQUIRED SKILLS
Threat Operations
- Security Alert Triage — You can triage routine alerts without help, tell a true positive from noise using the context available, and record your reasoning on the ticket.
- Threat Detection Engineering — You can implement a detection rule from a provided specification and confirm it fires against a known sample.
- SIEM Monitoring and Tuning — You can build a simple search or dashboard panel, onboard a new log source with support, and flag when a source stops sending data.
- Incident Response Coordination — You can follow an incident response runbook for a routine incident under close supervision, and keep the incident log up to date as you go.
- Digital Forensics and Evidence Handling — You can capture a memory image or log export following a written procedure, without altering the evidence in the process.
- Threat Intelligence Analysis — You can read a threat intelligence report and summarise what it says about a specific indicator or actor.

Exposure Management
- Vulnerability Scanning and Triage — You can interpret scan output, separate a real finding from a false positive using the available context, and assign it a severity using the agreed scale.
- Vulnerability Remediation Coordination — You can log a vulnerability finding with the owning team and follow up until you get a status update.
- Penetration Testing and Exploitation — You can follow a test plan to run known tools against an agreed target and record what each one reports.
- Cloud Security Posture Management — You can read a posture management dashboard and describe what a specific finding means for the resource it flags.
- Attack Surface Reduction — You can list the externally reachable services for a system you support when asked, using tools someone else set up.

Identity and Access
- Identity and Access Governance — You can process a routine access request or remove access for someone who has left, against the written procedure.
- Privileged Access Management — You can raise and close a privileged access request under supervision, following the checkout process for admin accounts and returning the credential when the task is done.
- Access Control Reviews — You can run a scheduled access review end to end for a system you know, matching entitlements to roles and getting revocations actioned. You notice leavers and movers still holding rights and flag them.
- Identity Federation and Single Sign-On — You can configure a straightforward single sign-on connection from a documented pattern and test that a user can sign in, with an engineer reviewing the settings before they go live.

Secure Architecture
- Security Architecture Design — You can produce the security section of a design for a small system by following an existing pattern, and explain each control you included when an architect reviews it.
- Threat Modeling — You can take part in a threat modelling session, draw the data flow for a system you know and name the obvious attack paths, with a facilitator steering the session.
- Application Security Testing — You can run a configured scan against a test environment, triage the output against the known false positives and write findings up for a reviewer to check before they reach the team.
- Secure Code Review — You can read a small change and spot the well-known weaknesses, such as unvalidated input or a hardcoded secret, with an experienced reviewer confirming what you found.
- Security Requirements and Design Review — You can check a proposed design against a requirements checklist and write up what is missing, with a senior reviewer deciding what actually blocks approval.

Governance and Risk
- Security Risk Assessment — You can gather the information a risk assessment needs and draft the entries, with an assessor setting the ratings and deciding what goes to the risk owner.
- Security Policy and Compliance Governance — You can collect evidence for a compliance check and apply agreed edits to policy documents, with an owner reviewing what you produce before it is published.
- Third-Party and Vendor Security Risk — You can send out a supplier security questionnaire, chase the response and summarise the answers, with a reviewer deciding what the gaps actually mean.
- Security Awareness Programme Management — You can help deliver awareness activity, issuing the training, tracking completion and collating phishing simulation results for someone else to interpret.
- Security Metrics and Reporting — You can pull the data for a regular security report, produce the figures to an agreed template and flag anything in the numbers that looks wrong.

Delivery
- Project Management — You can follow a plan someone else wrote, keep your own tasks up to date, and flag a task you own as soon as you know it will slip.
- Planning & Estimation — You can estimate a task you have been given once the approach is clear, and you say promptly when the estimate turns out to be wrong.
- Ownership & Accountability — You can own a piece of work after release: you watch how it behaves, fix what you broke, and are never chased for a status update.
- Quality Focus — You can choose checks that suit the work in front of you, catch your own mistakes before review, and confirm the result behaves once it is live.

Craft
- Problem Solving — You can diagnose problems in work you did not build, and you fix the underlying cause instead of routing around the symptom.
- Domain Expertise — You can apply the basics of your field to the work you are given, and you know who to consult at the edge of what you know.
- Continuous Learning — You can pick up an unfamiliar area fast enough to be useful in it, and you turn what you learned into something others can reuse.

Communication
- Communication — You can explain your work to your team so they can act on it, and you take vague requirements and ask the questions that sharpen them.
- Collaboration — You can work well with people in other roles, share context and credit, and take criticism of your work without defending territory.
- Technical Writing — You can document your own work well enough for a colleague to follow it unaided, and you keep that document current as the work changes.
- Stakeholder Management — You can keep your manager and immediate team informed of your progress, and you raise an issue before someone else discovers it.

Leadership
- Leadership — You can act on direction well, seek feedback on how you work, and be transparent about what you need help with.
- Mentoring — You can share what you have just learned with your peers and help a newer colleague find their way around.
- Strategic Thinking — You can explain why the work you were given matters and who it is for.

Import this exact framework into your own org

Create a free account and Cybersecurity lands in your org as a department: all 39 skills, with the mastery expected at each of your 5 career levels — already filled in. Rename or delete anything you don't want.