Cybersecurity · Level 2 of 5
Senior Security Analyst job description
This is what Cybersecurity teams expect from a Senior Security Analyst. 39 skills, each with the mastery level set for this rung, and 1 certification required from here on. It is the same framework Competrace ships to new customers, so you can read it here and import it as-is.
Investigates and closes incidents independently end to end.
Senior Security Analyst only.
Cybersecurity — Senior Security Analyst Investigates and closes incidents independently end to end. REQUIRED SKILLS Threat Operations - Security Alert Triage — You can triage alerts across multiple tools and data sources, spot when context is misleading, and pull in the extra evidence needed to decide quickly. - Threat Detection Engineering — You can write a simple detection rule from a described behaviour, test it against sample data, and adjust it when it fires too often. - SIEM Monitoring and Tuning — You can tune correlation rules and retention to cut noise without losing visibility, and troubleshoot why a source is not parsing correctly. - Incident Response Coordination — You can coordinate a multi-system incident across several teams, keep stakeholders informed at the right cadence, and decide when to escalate further. - Digital Forensics and Evidence Handling — You can collect evidence from a single system, maintain a chain of custody record, and identify obviously suspicious artefacts. - Threat Intelligence Analysis — You can check the environment against indicators from a report, and flag matches for investigation. Exposure Management - Vulnerability Scanning and Triage — You can design a scanning scope and cadence for a new environment, and correlate findings across tools to avoid duplicate or contradictory severity ratings. - Vulnerability Remediation Coordination — You can track remediation against agreed timelines for findings you own, and escalate ones that are about to breach their deadline. - Penetration Testing and Exploitation — You can follow a test plan to run known tools against an agreed target and record what each one reports. - Cloud Security Posture Management — You can fix a straightforward misconfiguration, such as an open storage bucket or an over-permissive rule, once it has been flagged to you. - Attack Surface Reduction — You can run discovery scans against the known ranges of the organisation, and flag an exposed service that should not be reachable. Identity and Access - Identity and Access Governance — You can run a periodic access review for a system you support, and chase down owners who have not responded. - Privileged Access Management — You can administer the privileged access tooling day to day, onboarding accounts, setting session recording and rotating credentials to the agreed schedule. You spot when a request asks for more reach than the task needs and say so. - Access Control Reviews — You can run a scheduled access review end to end for a system you know, matching entitlements to roles and getting revocations actioned. You notice leavers and movers still holding rights and flag them. - Identity Federation and Single Sign-On — You can configure a straightforward single sign-on connection from a documented pattern and test that a user can sign in, with an engineer reviewing the settings before they go live. Secure Architecture - Security Architecture Design — You can produce the security section of a design for a small system by following an existing pattern, and explain each control you included when an architect reviews it. - Threat Modeling — You can run a threat model for a single application using an agreed method, record the threats found and link each one to a control or an accepted risk. - Application Security Testing — You can test an application yourself with both scanner and manual technique, confirm a finding is genuinely exploitable, and describe the reproduction steps clearly enough to fix. - Secure Code Review — You can review a feature in a language you know, trace user-controlled data to where it is used, and explain the fix to the author rather than only naming the flaw. - Security Requirements and Design Review — You can check a proposed design against a requirements checklist and write up what is missing, with a senior reviewer deciding what actually blocks approval. Governance and Risk - Security Risk Assessment — You can assess a contained risk using the agreed method, describe the impact in terms the system owner recognises, and propose treatment options. - Security Policy and Compliance Governance — You can collect evidence for a compliance check and apply agreed edits to policy documents, with an owner reviewing what you produce before it is published. - Third-Party and Vendor Security Risk — You can send out a supplier security questionnaire, chase the response and summarise the answers, with a reviewer deciding what the gaps actually mean. - Security Awareness Programme Management — You can run a scheduled awareness campaign or phishing simulation yourself, brief the managers affected and handle the reports that come back from staff. - Security Metrics and Reporting — You can maintain a reporting pack, explain what each metric counts and where it comes from, and answer questions about a movement in the figures. Delivery - Project Management — You can break a small piece of work into tasks, sequence them, and run it to a date you agreed, escalating risks before they become slips. - Planning & Estimation — You can estimate your own tasks with reasonable accuracy and deliver at a steady enough pace that other people can plan around you. - Ownership & Accountability — You can pick up a problem that has no obvious owner and make yourself the accountable party for it, including the parts nobody enjoys. - Quality Focus — You can define what good enough means for a project, put the checks in place to prove it, and hold back a release that misses the bar. Craft - Problem Solving — You can break a large, ambiguous problem into tractable pieces, weigh the options against evidence, and explain the tradeoff you chose. - Domain Expertise — You can work confidently across the systems and tools your team uses daily, and you can explain how your work serves the team's goals. - Continuous Learning — You can pick up an unfamiliar area fast enough to be useful in it, and you turn what you learned into something others can reuse. Communication - Communication — You can explain a complex topic to people with very different backgrounds, adjusting the detail to the audience without talking down to them. - Collaboration — You can build working relationships beyond your own team and get things done through people who do not report to you. - Technical Writing — You can write for a defined audience, whether a proposal, a runbook, or a decision record, and make the reasoning as clear as the conclusion. - Stakeholder Management — You can identify who is affected by your work and keep them updated at a level of detail and a cadence that suits them. Leadership - Leadership — You can identify a problem and propose a way forward unprompted, and you take a small leading role such as running a working group. - Mentoring — You can onboard someone onto your team's work, answer their questions patiently, and give feedback specific enough to act on. - Strategic Thinking — You can connect your team's work to its goals and question a task that does not appear to serve them. REQUIRED CERTIFICATIONS - CompTIA Security+ (required from Senior Security Analyst)
Import this exact framework into your own org
Create a free account and Cybersecurity lands in your org as a department: all 39 skills, with the mastery expected at each of your 5 career levels — already filled in. Rename or delete anything you don't want.