Выберите текущую позицию

Укажите роль и уровень — система покажет путь развития, навыки и gap-анализ.

Путь развития

Junior

0-2 years

Текущий

Ответственность: Completing tasks under the guidance of senior colleagues. Learning the codebase, standards, and team processes. Writing code to spec, fixing simple bugs, writing tests.

Ключевые навыки:

JWT / OAuth2 / OIDC Нужно
OWASP & Application Security Нужно
RBAC / ABAC Authorization Нужно
SAST/DAST Нужно
Kubernetes Security Нужно
Cloud Security Нужно
Threat Modeling Нужно
Digital Forensics Basics Нужно
Secure Coding Practices Нужно
Incident Response Process Нужно
Network Security Нужно
Dependency Vulnerability Scanning Нужно
Vulnerability Management Нужно

Middle

2-5 years

Следующий

Ответственность: Independently developing features from decomposition to deployment. Participating in code review. Optimizing performance. Mentoring junior developers. Taking part in architecture discussions.

Ключевые навыки:

JWT / OAuth2 / OIDC Нужно
OWASP & Application Security Нужно
RBAC / ABAC Authorization Нужно
SAST/DAST Нужно
Kubernetes Security Нужно
Cloud Security Нужно
Threat Modeling Нужно
Digital Forensics Basics Нужно
Secure Coding Practices Нужно
Incident Response Process Нужно
Network Security Нужно
Dependency Vulnerability Scanning Нужно
Vulnerability Management Нужно

Senior

5-8 years

Ответственность: Designing the architecture of components and services. Solving complex technical problems. Managing technical debt. Code review as a quality gatekeeper. Mentoring middle developers. Choosing technologies for new tasks.

Ключевые навыки:

Code Review Нужно
Docker Нужно
ELK Stack Нужно
Git Advanced Нужно
GitHub Copilot Нужно
GraphQL Design Нужно
JWT / OAuth2 / OIDC Нужно
OWASP & Application Security Нужно
Rate Limiting & Throttling Нужно
RBAC / ABAC Authorization Нужно
REST API Design Нужно
Runbook & Playbook Writing Нужно
SAST/DAST Нужно
Security Testing Нужно
VPN & Network Isolation Нужно
Algorithms & Complexity Нужно
Async Programming Нужно
Kubernetes Security Нужно
Cloud Security Нужно
Code Quality & Refactoring Нужно
Multithreading Нужно
Threat Modeling Нужно
Network Fundamentals Нужно
Digital Forensics Basics Нужно
Secure Coding Practices Нужно
OOP & SOLID Principles Нужно
WebSocket API Design Нужно
Incident Response Process Нужно
Network Security Нужно
Container Security Scanning Нужно
Dependency Vulnerability Scanning Нужно
Structured Logging Нужно
Data Structures Нужно
API Testing Нужно
Vulnerability Management Нужно

Lead / Staff

7-12 years

Ответственность: Technical leadership of a team or area. Designing system architecture. Coordinating with other teams. Establishing standards and best practices. Participating in hiring. Planning the technical roadmap.

Ключевые навыки:

Code Review Нужно
Docker Нужно
ELK Stack Нужно
Git Advanced Нужно
GitHub Copilot Нужно
GraphQL Design Нужно
JWT / OAuth2 / OIDC Нужно
OWASP & Application Security Нужно
Rate Limiting & Throttling Нужно
RBAC / ABAC Authorization Нужно
REST API Design Нужно
Runbook & Playbook Writing Нужно
SAST/DAST Нужно
Security Testing Нужно
VPN & Network Isolation Нужно
Algorithms & Complexity Нужно
Async Programming Нужно
Kubernetes Security Нужно
Cloud Security Нужно
Code Quality & Refactoring Нужно
Multithreading Нужно
Threat Modeling Нужно
Network Fundamentals Нужно
Digital Forensics Basics Нужно
Secure Coding Practices Нужно
OOP & SOLID Principles Нужно
WebSocket API Design Нужно
Incident Response Process Нужно
Network Security Нужно
Container Security Scanning Нужно
Dependency Vulnerability Scanning Нужно
Structured Logging Нужно
Data Structures Нужно
API Testing Нужно
Vulnerability Management Нужно

Principal

10+ years

Ответственность: Technical strategy at the company or domain level. Cross-organizational influence. Solving systemic business problems through technology. Mentoring lead engineers. Publicly representing the company.

Ключевые навыки:

Code Review Нужно
Docker Нужно
ELK Stack Нужно
Git Advanced Нужно
GitHub Copilot Нужно
GraphQL Design Нужно
JWT / OAuth2 / OIDC Нужно
OWASP & Application Security Нужно
Rate Limiting & Throttling Нужно
RBAC / ABAC Authorization Нужно
REST API Design Нужно
Runbook & Playbook Writing Нужно
SAST/DAST Нужно
Security Testing Нужно
VPN & Network Isolation Нужно
Algorithms & Complexity Нужно
Async Programming Нужно
Kubernetes Security Нужно
Cloud Security Нужно
Code Quality & Refactoring Нужно
Multithreading Нужно
Threat Modeling Нужно
Network Fundamentals Нужно
Digital Forensics Basics Нужно
Secure Coding Practices Нужно
OOP & SOLID Principles Нужно
WebSocket API Design Нужно
Incident Response Process Нужно
Network Security Нужно
Container Security Scanning Нужно
Dependency Vulnerability Scanning Нужно
Structured Logging Нужно
Data Structures Нужно
API Testing Нужно
Vulnerability Management Нужно

Gap-анализ: навыки для развития

Для перехода на следующий уровень необходимо развить:

JWT / OAuth2 / OIDC

Conducts security testing of JWT/OAuth2 implementations: exploits JWT algorithm vulnerabilities, tests OAuth2 flows for CSRF and code interception, and identifies token leakage through side channels. Uses specialized tools (jwt_tool, OWASP ZAP) for automated authentication testing. Creates proof-of-concept exploits for identified vulnerabilities.

OWASP & Application Security

Applies OWASP Testing Guide methodology for web application penetration testing. Conducts security assessments identifying OWASP Top 10 vulnerabilities with manual exploitation techniques. Uses specialized tools (Burp Suite Professional, sqlmap, custom scripts) for deep vulnerability validation and proof-of-concept development.

RBAC / ABAC Authorization

Tests RBAC and ABAC implementations for privilege escalation and authorization bypass. Conducts penetration testing of access control mechanisms across application layers. Uses specialized tools to enumerate roles, permissions, and detect misconfigurations.

SAST/DAST

Uses DAST tools alongside manual penetration testing to discover runtime vulnerabilities. Validates SAST findings through exploitation to confirm real attack vectors. Integrates dynamic scanning into penetration testing workflows to maximize coverage of web application attack surfaces.

Kubernetes Security

Performs security assessments of Kubernetes clusters identifying misconfigurations in RBAC, network policies, and pod security. Uses tools like kube-hunter and kubeaudit to discover vulnerabilities. Tests container escape scenarios and lateral movement paths within cluster environments.

Cloud Security

Performs cloud penetration testing across AWS, Azure, and GCP environments. Conducts security reviews targeting IAM misconfigurations and exposed services. Uses cloud-specific exploitation tools and techniques to identify privilege escalation paths and data exfiltration vectors.

Threat Modeling

Independently applies threat modeling to identify attack surfaces before penetration testing engagements. Maps MITRE ATT&CK techniques to system components. Understands trade-offs between different attack paths and prioritizes testing efforts. Creates threat-informed test plans covering network, application, and social engineering vectors.

Digital Forensics Basics

Uses digital forensics fundamentals to document exploitation evidence during penetration tests. Captures system artifacts, file hashes, and timeline data to support findings. Analyzes disk images and memory snapshots to identify indicators of compromise and validate attack paths.

Secure Coding Practices

Applies secure coding knowledge in penetration testing — reviews source code to identify exploitation vectors, maps code weaknesses to MITRE ATT&CK techniques, and develops proof-of-concept exploits from code analysis. Uses SAST tools alongside manual code review to prioritize penetration testing targets.

Incident Response Process

Supports incident response by providing offensive security expertise during active incidents. Validates attack vectors and helps determine scope of compromise. Documents exploitation paths for post-incident analysis and contributes to lessons-learned reviews with remediation recommendations.

Network Security

Independently performs network penetration testing: conducts host discovery, service enumeration, and vulnerability scanning across subnets. Exploits misconfigured firewalls, weak VPN setups, and unpatched network services. Writes clear findings on network segmentation gaps and proposes remediation for IDS/IPS evasion techniques discovered during engagements.

Dependency Vulnerability Scanning

Uses dependency scanning results from Snyk, Grype, or OWASP Dependency-Check to identify attack vectors during penetration tests. Maps known CVEs in third-party libraries to practical exploit scenarios. Understands the difference between reachable and unreachable vulnerable code paths when prioritizing findings. Validates whether dependency vulnerabilities are exploitable in the application's specific deployment context.

Vulnerability Management

Discovers and validates vulnerabilities through penetration testing and exploitation. Assesses vulnerability severity using CVSS scoring and real-world exploitability analysis. Uses vulnerability management platforms to track findings and verify remediation effectiveness across tested systems.