Cybersecurity · Level 3 of 5
Security Engineer job description
This is what Cybersecurity teams expect from a Security Engineer. 39 skills, each with the mastery level set for this rung, and 3 certifications required from here on. It is the same framework Competrace ships to new customers, so you can read it here and import it as-is.
Builds and hardens security controls across a domain.
Security Engineer only.
Cybersecurity — Security Engineer Builds and hardens security controls across a domain. REQUIRED SKILLS Threat Operations - Security Alert Triage — You can tune triage criteria and playbooks from what past alerts revealed, cutting noise without hiding a real signal, and review contested calls made by other analysts. - Threat Detection Engineering — You can build detection coverage for a whole class of technique, prioritise which gaps matter most, and coach others in writing rules that hold up in production. - SIEM Monitoring and Tuning — You can plan SIEM capacity and log source coverage against real detection needs, and lead a platform migration without a monitoring gap. - Incident Response Coordination — You can act as incident commander for a major incident, make the containment-versus-evidence tradeoff under pressure, and run the post-incident review that changes something. - Digital Forensics and Evidence Handling — You can reconstruct a timeline of attacker activity across several systems from disk, memory and log evidence, and know when a finding needs a second opinion. - Threat Intelligence Analysis — You can assess the credibility and relevance of a new intelligence source, and translate known techniques used by a threat actor into specific defensive changes. Exposure Management - Vulnerability Scanning and Triage — You can validate whether a critical finding is actually exploitable in this environment before it triggers an emergency response, and improve the scanning programme from what was missed. - Vulnerability Remediation Coordination — You can negotiate a realistic remediation plan with a resistant system owner, and decide when a temporary compensating control is good enough to hold the risk. - Penetration Testing and Exploitation — You can plan and run a test against a more complex environment, develop a proof of concept for a finding that tooling alone did not confirm, and write a report a system owner can act on. - Cloud Security Posture Management — You can define the baseline a cloud environment should be checked against, and investigate why a class of finding keeps recurring rather than fixing each instance. - Attack Surface Reduction — You can find exposure the organisation did not know it had, such as forgotten infrastructure or shadow IT, and get it decommissioned or brought under control. Identity and Access - Identity and Access Governance — You can design an access review process for a new system, decide what evidence a reviewer actually needs to make a real decision, and act on stale or excessive access it turns up. - Privileged Access Management — You can design the privileged access model for a system, deciding which accounts are vaulted, how long a session lasts and what gets recorded. You handle break-glass access without leaving a standing privilege behind. - Access Control Reviews — You can review access for systems whose entitlements do not map neatly to roles, decide what evidence proves a right is still needed, and drive the removals through to completion. - Identity Federation and Single Sign-On — You can design federation for an application with awkward requirements, choosing the protocol, trust settings and token lifetimes. You know what a trust decision hands to the other party. Secure Architecture - Security Architecture Design — You can own the security design for a whole service, choosing controls that fit its risk rather than applying every control available, and defending the design to the engineers who have to build it. - Threat Modeling — You can facilitate threat modelling for a system you did not build, get engineers arguing about real attack paths rather than checklist items, and turn the output into work that gets done. - Application Security Testing — You can test systems where the interesting weakness only appears when components are chained together, and you chain them to prove the impact. You set how testing is scoped and what a report must show to be acted on. - Secure Code Review — You can review unfamiliar code and find the security flaw in its logic, not just in its patterns, including the authorisation check that is missing rather than wrong. - Security Requirements and Design Review — You can review a proposed system on your own, tell a required control apart from a preference, and give the project a decision it can build against rather than a list of concerns. Governance and Risk - Security Risk Assessment — You can assess risk for a project or system independently, argue a rating you can evidence, and get a named owner to accept or treat it rather than leaving it open. - Security Policy and Compliance Governance — You can write a policy or standard that people can actually follow, take it through consultation and approval, and check in the estate whether it is being met. - Third-Party and Vendor Security Risk — You can assess a low-risk supplier yourself, check the evidence they provide rather than taking the questionnaire at face value, and record the residual risk. - Security Awareness Programme Management — You can design awareness activity for a specific audience and threat, pick a simulation difficulty that teaches rather than shames, and show whether reporting behaviour changed. - Security Metrics and Reporting — You can choose metrics that answer a real question about exposure, build them from sources you have verified, and write a report a non-technical reader can act on. Delivery - Project Management — You can run a multi-person project end to end: you set the scope, track the dependencies between the people involved, and re-plan when reality moves. - Planning & Estimation — You can estimate a whole project including its risks and unknowns, split it into milestones, and hold the estimate up under challenge. - Ownership & Accountability — You can hold accountability for outcomes delivered mostly by other people, absorbing the blame when it fails and passing on the credit when it works. - Quality Focus — You can design the quality practice for complex work owned by several teams, and you anticipate the failure modes that only appear once systems interact. Craft - Problem Solving — You can solve problems in domains where you are not the expert, and your solutions hold up on cost, performance, and maintainability at once. - Domain Expertise — You can be the person the team consults on your area, and you follow where the field is moving and apply it where it pays off. - Continuous Learning — You can judge which new ideas are worth the team's time and which are not, and you make room for the people around you to learn too. Communication - Communication — You can bring disagreeing groups to a shared understanding, and colleagues come to you for help framing a difficult or sensitive message. - Collaboration — You can align teams with competing priorities on a common goal, surfacing the conflict early instead of letting it harden into resentment. - Technical Writing — You can own the documentation of a large project, coordinating contributions so the work can be maintained by people who never built it. - Stakeholder Management — You can win support for a proposal, reset expectations when the plan changes, and refuse a request with a reason the other side accepts. Leadership - Leadership — You can take charge of work with no clear owner, motivate people who do not report to you, and make calls others are willing to follow. - Mentoring — You can mentor someone over months, tell them the uncomfortable thing they need to hear, and adapt how you teach to how they learn. - Strategic Thinking — You can look a year ahead in your area, name what will matter by then, and turn that into work people can pick up now. REQUIRED CERTIFICATIONS - CompTIA Security+ (required from Senior Security Analyst) - GIAC Certified Incident Handler (GCIH) (required from Security Engineer) - OffSec Certified Professional (OSCP) (required from Security Engineer)
Import this exact framework into your own org
Create a free account and Cybersecurity lands in your org as a department: all 39 skills, with the mastery expected at each of your 5 career levels — already filled in. Rename or delete anything you don't want.