Skip to main content
Competrace
Cybersecurity · Level 2 of 5

Senior Security Analyst job description

This is what Cybersecurity teams expect from a Senior Security Analyst. 39 skills, each with the mastery level set for this rung, and 1 certification required from here on. It is the same framework Competrace ships to new customers, so you can read it here and import it as-is.

Investigates and closes incidents independently end to end.

Senior Security Analyst only.

Cybersecurity — Senior Security Analyst
Investigates and closes incidents independently end to end.

REQUIRED SKILLS
Threat Operations
- Security Alert Triage — You can triage alerts across multiple tools and data sources, spot when context is misleading, and pull in the extra evidence needed to decide quickly.
- Threat Detection Engineering — You can write a simple detection rule from a described behaviour, test it against sample data, and adjust it when it fires too often.
- SIEM Monitoring and Tuning — You can tune correlation rules and retention to cut noise without losing visibility, and troubleshoot why a source is not parsing correctly.
- Incident Response Coordination — You can coordinate a multi-system incident across several teams, keep stakeholders informed at the right cadence, and decide when to escalate further.
- Digital Forensics and Evidence Handling — You can collect evidence from a single system, maintain a chain of custody record, and identify obviously suspicious artefacts.
- Threat Intelligence Analysis — You can check the environment against indicators from a report, and flag matches for investigation.

Exposure Management
- Vulnerability Scanning and Triage — You can design a scanning scope and cadence for a new environment, and correlate findings across tools to avoid duplicate or contradictory severity ratings.
- Vulnerability Remediation Coordination — You can track remediation against agreed timelines for findings you own, and escalate ones that are about to breach their deadline.
- Penetration Testing and Exploitation — You can follow a test plan to run known tools against an agreed target and record what each one reports.
- Cloud Security Posture Management — You can fix a straightforward misconfiguration, such as an open storage bucket or an over-permissive rule, once it has been flagged to you.
- Attack Surface Reduction — You can run discovery scans against the known ranges of the organisation, and flag an exposed service that should not be reachable.

Identity and Access
- Identity and Access Governance — You can run a periodic access review for a system you support, and chase down owners who have not responded.
- Privileged Access Management — You can administer the privileged access tooling day to day, onboarding accounts, setting session recording and rotating credentials to the agreed schedule. You spot when a request asks for more reach than the task needs and say so.
- Access Control Reviews — You can run a scheduled access review end to end for a system you know, matching entitlements to roles and getting revocations actioned. You notice leavers and movers still holding rights and flag them.
- Identity Federation and Single Sign-On — You can configure a straightforward single sign-on connection from a documented pattern and test that a user can sign in, with an engineer reviewing the settings before they go live.

Secure Architecture
- Security Architecture Design — You can produce the security section of a design for a small system by following an existing pattern, and explain each control you included when an architect reviews it.
- Threat Modeling — You can run a threat model for a single application using an agreed method, record the threats found and link each one to a control or an accepted risk.
- Application Security Testing — You can test an application yourself with both scanner and manual technique, confirm a finding is genuinely exploitable, and describe the reproduction steps clearly enough to fix.
- Secure Code Review — You can review a feature in a language you know, trace user-controlled data to where it is used, and explain the fix to the author rather than only naming the flaw.
- Security Requirements and Design Review — You can check a proposed design against a requirements checklist and write up what is missing, with a senior reviewer deciding what actually blocks approval.

Governance and Risk
- Security Risk Assessment — You can assess a contained risk using the agreed method, describe the impact in terms the system owner recognises, and propose treatment options.
- Security Policy and Compliance Governance — You can collect evidence for a compliance check and apply agreed edits to policy documents, with an owner reviewing what you produce before it is published.
- Third-Party and Vendor Security Risk — You can send out a supplier security questionnaire, chase the response and summarise the answers, with a reviewer deciding what the gaps actually mean.
- Security Awareness Programme Management — You can run a scheduled awareness campaign or phishing simulation yourself, brief the managers affected and handle the reports that come back from staff.
- Security Metrics and Reporting — You can maintain a reporting pack, explain what each metric counts and where it comes from, and answer questions about a movement in the figures.

Delivery
- Project Management — You can break a small piece of work into tasks, sequence them, and run it to a date you agreed, escalating risks before they become slips.
- Planning & Estimation — You can estimate your own tasks with reasonable accuracy and deliver at a steady enough pace that other people can plan around you.
- Ownership & Accountability — You can pick up a problem that has no obvious owner and make yourself the accountable party for it, including the parts nobody enjoys.
- Quality Focus — You can define what good enough means for a project, put the checks in place to prove it, and hold back a release that misses the bar.

Craft
- Problem Solving — You can break a large, ambiguous problem into tractable pieces, weigh the options against evidence, and explain the tradeoff you chose.
- Domain Expertise — You can work confidently across the systems and tools your team uses daily, and you can explain how your work serves the team's goals.
- Continuous Learning — You can pick up an unfamiliar area fast enough to be useful in it, and you turn what you learned into something others can reuse.

Communication
- Communication — You can explain a complex topic to people with very different backgrounds, adjusting the detail to the audience without talking down to them.
- Collaboration — You can build working relationships beyond your own team and get things done through people who do not report to you.
- Technical Writing — You can write for a defined audience, whether a proposal, a runbook, or a decision record, and make the reasoning as clear as the conclusion.
- Stakeholder Management — You can identify who is affected by your work and keep them updated at a level of detail and a cadence that suits them.

Leadership
- Leadership — You can identify a problem and propose a way forward unprompted, and you take a small leading role such as running a working group.
- Mentoring — You can onboard someone onto your team's work, answer their questions patiently, and give feedback specific enough to act on.
- Strategic Thinking — You can connect your team's work to its goals and question a task that does not appear to serve them.

REQUIRED CERTIFICATIONS
- CompTIA Security+ (required from Senior Security Analyst)

Import this exact framework into your own org

Create a free account and Cybersecurity lands in your org as a department: all 39 skills, with the mastery expected at each of your 5 career levels — already filled in. Rename or delete anything you don't want.