Выберите текущую позицию

Укажите роль и уровень — система покажет путь развития, навыки и gap-анализ.

Путь развития

Junior

0-2 years

Текущий

Ответственность: Completing tasks under the guidance of senior colleagues. Learning the codebase, standards, and team processes. Writing code to spec, fixing simple bugs, writing tests.

Ключевые навыки:

GDPR / 152-FZ Compliance Нужно
JWT / OAuth2 / OIDC Нужно
OWASP & Application Security Нужно
PCI DSS Нужно
RBAC / ABAC Authorization Нужно
SAST/DAST Нужно
Secrets Management Нужно
SOC2 Compliance Нужно
Supply Chain Security Нужно
Kubernetes Security Нужно
Cloud Security Нужно
Threat Modeling Нужно
Digital Forensics Basics Нужно
Secure Coding Practices Нужно
Incident Response Process Нужно
Network Security Нужно
Dependency Vulnerability Scanning Нужно
Vulnerability Management Нужно

Middle

2-5 years

Следующий

Ответственность: Independently developing features from decomposition to deployment. Participating in code review. Optimizing performance. Mentoring junior developers. Taking part in architecture discussions.

Ключевые навыки:

GDPR / 152-FZ Compliance Нужно
JWT / OAuth2 / OIDC Нужно
OWASP & Application Security Нужно
PCI DSS Нужно
RBAC / ABAC Authorization Нужно
SAST/DAST Нужно
Secrets Management Нужно
SOC2 Compliance Нужно
Supply Chain Security Нужно
Kubernetes Security Нужно
Cloud Security Нужно
Threat Modeling Нужно
Digital Forensics Basics Нужно
Secure Coding Practices Нужно
Incident Response Process Нужно
Network Security Нужно
Dependency Vulnerability Scanning Нужно
Vulnerability Management Нужно

Senior

5-8 years

Ответственность: Designing the architecture of components and services. Solving complex technical problems. Managing technical debt. Code review as a quality gatekeeper. Mentoring middle developers. Choosing technologies for new tasks.

Ключевые навыки:

Architecture Documentation: C4, arc42 Нужно
Code Review Нужно
Diagramming: Mermaid, PlantUML, D2 Нужно
Docker Нужно
ELK Stack Нужно
GDPR / 152-FZ Compliance Нужно
Git Advanced Нужно
GitHub Copilot Нужно
JWT / OAuth2 / OIDC Нужно
OWASP & Application Security Нужно
PCI DSS Нужно
Prometheus & Grafana Нужно
RBAC / ABAC Authorization Нужно
REST API Design Нужно
Runbook & Playbook Writing Нужно
SAST/DAST Нужно
Secrets Management Нужно
Security Testing Нужно
SLI / SLO / SLA Нужно
SOC2 Compliance Нужно
Supply Chain Security Нужно
Algorithms & Complexity Нужно
Kubernetes Security Нужно
Cloud Security Нужно
Code Quality & Refactoring Нужно
Threat Modeling Нужно
Network Fundamentals Нужно
Digital Forensics Basics Нужно
Secure Coding Practices Нужно
Incident Response Process Нужно
Network Security Нужно
Dependency Vulnerability Scanning Нужно
Structured Logging Нужно
Data Structures Нужно
On-Call Management Нужно
Vulnerability Management Нужно

Lead / Staff

7-12 years

Ответственность: Technical leadership of a team or area. Designing system architecture. Coordinating with other teams. Establishing standards and best practices. Participating in hiring. Planning the technical roadmap.

Ключевые навыки:

Architecture Documentation: C4, arc42 Нужно
Code Review Нужно
Diagramming: Mermaid, PlantUML, D2 Нужно
Docker Нужно
ELK Stack Нужно
GDPR / 152-FZ Compliance Нужно
Git Advanced Нужно
GitHub Copilot Нужно
JWT / OAuth2 / OIDC Нужно
OWASP & Application Security Нужно
PCI DSS Нужно
Prometheus & Grafana Нужно
RBAC / ABAC Authorization Нужно
REST API Design Нужно
Runbook & Playbook Writing Нужно
SAST/DAST Нужно
Secrets Management Нужно
Security Testing Нужно
SLI / SLO / SLA Нужно
SOC2 Compliance Нужно
Supply Chain Security Нужно
Algorithms & Complexity Нужно
Kubernetes Security Нужно
Cloud Security Нужно
Code Quality & Refactoring Нужно
Threat Modeling Нужно
Network Fundamentals Нужно
Digital Forensics Basics Нужно
Secure Coding Practices Нужно
Incident Response Process Нужно
Network Security Нужно
Dependency Vulnerability Scanning Нужно
Structured Logging Нужно
Data Structures Нужно
On-Call Management Нужно
Vulnerability Management Нужно

Principal

10+ years

Ответственность: Technical strategy at the company or domain level. Cross-organizational influence. Solving systemic business problems through technology. Mentoring lead engineers. Publicly representing the company.

Ключевые навыки:

Architecture Documentation: C4, arc42 Нужно
Code Review Нужно
Diagramming: Mermaid, PlantUML, D2 Нужно
Docker Нужно
ELK Stack Нужно
GDPR / 152-FZ Compliance Нужно
Git Advanced Нужно
GitHub Copilot Нужно
JWT / OAuth2 / OIDC Нужно
OWASP & Application Security Нужно
PCI DSS Нужно
Prometheus & Grafana Нужно
RBAC / ABAC Authorization Нужно
REST API Design Нужно
Runbook & Playbook Writing Нужно
SAST/DAST Нужно
Secrets Management Нужно
Security Testing Нужно
SLI / SLO / SLA Нужно
SOC2 Compliance Нужно
Supply Chain Security Нужно
Algorithms & Complexity Нужно
Kubernetes Security Нужно
Cloud Security Нужно
Code Quality & Refactoring Нужно
Threat Modeling Нужно
Network Fundamentals Нужно
Digital Forensics Basics Нужно
Secure Coding Practices Нужно
Incident Response Process Нужно
Network Security Нужно
Dependency Vulnerability Scanning Нужно
Structured Logging Нужно
Data Structures Нужно
On-Call Management Нужно
Vulnerability Management Нужно

Gap-анализ: навыки для развития

Для перехода на следующий уровень необходимо развить:

GDPR / 152-FZ Compliance

Applies GDPR/152-FZ compliance in security analysis: monitors data processing activities for regulatory violations, conducts DPIA assessments, and validates data retention policies. Uses DLP tools to detect unauthorized PII transfers.

JWT / OAuth2 / OIDC

Analyzes JWT/OAuth2 security posture: monitors authentication logs for anomalous token usage, reviews OIDC provider configurations for misconfigurations, and assesses token lifecycle policies. Creates security dashboards for authentication metrics. Conducts access reviews for OAuth2 client registrations and scope assignments.

OWASP & Application Security

Applies OWASP security knowledge for security event analysis and threat correlation. Conducts security reviews of application logs identifying exploitation attempts for OWASP Top 10 vulnerabilities. Uses SIEM rules and detection logic to identify application-layer attacks and suspicious authentication patterns.

PCI DSS

Applies PCI DSS controls during security assessments and risk analysis. Monitors compliance status across systems processing cardholder data. Uses scanning and log analysis tools to detect deviations from PCI requirements.

RBAC / ABAC Authorization

Analyzes RBAC and ABAC authorization policies for compliance and risk exposure. Reviews access control configurations and identifies excessive permissions. Uses audit tools to monitor authorization events and detect anomalous access patterns.

SAST/DAST

Analyzes SAST/DAST scan results to assess risk levels and prioritize remediation efforts. Correlates scanner findings with threat intelligence and known vulnerability databases. Generates actionable security reports from scanning data for development and management teams.

Secrets Management

Monitors secrets usage patterns for security anomalies: analyzes Vault audit logs, detects unauthorized access attempts, and tracks secret lifecycle compliance. Conducts periodic access reviews for secret-consuming services. Uses SIEM integration for secrets-related incident detection.

SOC2 Compliance

Applies SOC 2 compliance frameworks in daily security operations. Conducts control testing, collects audit evidence, and maintains documentation for Trust Services Criteria across availability, security, and confidentiality.

Supply Chain Security

Applies supply chain security analysis in daily work: reviews SBOM outputs for vulnerability exposure, tracks CVE impact across dependency graphs, and assesses third-party component risks. Uses SCA scanning tools to monitor software composition and produces risk reports for stakeholders.

Kubernetes Security

Monitors Kubernetes clusters for security events using Falco and audit logs. Analyzes container runtime behavior to detect anomalous activity and potential breaches. Investigates Kubernetes-specific security alerts including unauthorized API access, privilege escalation, and suspicious pod deployments.

Cloud Security

Monitors cloud environments using SIEM platforms and CloudTrail analysis. Conducts security reviews of cloud resource configurations. Uses cloud-native detection tools to identify suspicious activity, analyze security events, and escalate confirmed threats for incident response.

Threat Modeling

Independently conducts threat modeling for medium-complexity systems using STRIDE and attack trees. Correlates identified threats with MITRE ATT&CK framework tactics. Understands trade-offs between security controls and system usability. Produces actionable threat reports with risk-ranked mitigation recommendations.

Digital Forensics Basics

Performs initial forensic triage on security alerts using log analysis and artifact collection. Preserves digital evidence following established procedures and chain of custody requirements. Uses forensic imaging tools to create verified copies of affected systems for detailed investigation.

Secure Coding Practices

Applies secure coding knowledge in security event analysis — correlates SAST/DAST findings with runtime security events, identifies exploitation attempts for known code vulnerabilities, and validates security fixes in remediation workflows. Uses code analysis tools to support threat investigation and vulnerability triage.

Incident Response Process

Executes incident response procedures including detection, containment, and initial investigation. Classifies incidents by severity using established criteria and escalates appropriately. Performs log analysis and IOC correlation in SIEM to determine attack scope and impact on affected systems.

Network Security

Independently monitors and investigates network security events using SIEM and IDS/IPS platforms. Correlates firewall logs, NetFlow data, and DNS queries to detect lateral movement and C2 communication. Tunes IDS signatures to reduce false positives and documents network-based indicators of compromise for incident response playbooks.

Dependency Vulnerability Scanning

Independently runs and interprets SCA scans using Snyk, Dependabot, or Trivy across the organization's repositories. Conducts security reviews of dependency update pull requests, assessing changelog impact and potential regressions. Correlates vulnerability scanner output with threat intelligence feeds to prioritize remediation. Produces actionable reports for engineering teams with clear remediation timelines.

Vulnerability Management

Triages and prioritizes vulnerabilities based on risk scoring, asset criticality, and threat context. Monitors vulnerability feeds and correlates with organizational exposure. Uses vulnerability management platforms to generate remediation reports and track SLA compliance across teams.