S
Security Engineer (Professional)
Security / EngineeringCompetency profile for a professional security engineer who designs and operates security controls and responds to threats.
12SFIA skills
L3.2Avg target
L4Highest required
Strategy and architectureMain category
SFIA 9 Responsibility Levels — what each level means
L1 — FollowL2 — AssistL3 — ApplyL4 — EnableL5 — Ensure / AdviseL6 — Initiate / SetL7 — Set Strategy
Most skills in this template are L3–L4. L3 means you work independently on tasks. L4 means you own decisions and guide others.
Not sure which level to pick? During self-assessment, each level shows its definition and a suggested STAR evidence prompt.
Required Competencies
12 SFIA Skills for this Role
On smaller screens, this table scrolls horizontally so you can still read full level guidance.
| Code | Skill | Category | Target Level | What you need to demonstrate |
|---|---|---|---|---|
| SCTY | Information security Defining and operating a framework of security controls and security management strategies. | Strategy and architecture | L4 — Enable | Own decisions in your area, set patterns and guide less experienced colleagues. |
| SCAD | Security operations Manages and administers security measures, using tools and intelligence to protect assets, ensuring compliance and operational integrity. | Delivery and operation | L4 — Enable | Own decisions in your area, set patterns and guide less experienced colleagues. |
| INAS | Information assurance Protecting against and managing risks related to the use, storage and transmission of data and information systems. | Strategy and architecture | L3 — Apply | Work independently on tasks and apply standard methods effectively. |
| VURE | Vulnerability research Conducting applied research to discover, evaluate and mitigate new or unknown security vulnerabilities and weaknesses. | Strategy and architecture | L3 — Apply | Work independently on tasks and apply standard methods effectively. |
| THIN | Threat intelligence Developing and sharing actionable insights on current and potential security threats to the success or integrity of an organisation. | Strategy and architecture | L3 — Apply | Work independently on tasks and apply standard methods effectively. |
| BURM | Risk management Planning and implementing processes for managing risk across the enterprise, aligned with organisational strategy and governance frameworks. | Strategy and architecture | L3 — Apply | Work independently on tasks and apply standard methods effectively. |
| CNSL | Consultancy Providing advice and recommendations, based on expertise and experience, to address client needs. | Strategy and architecture | L3 — Apply | Work independently on tasks and apply standard methods effectively. |
| PROG | Programming/software development Developing software components to deliver value to stakeholders. | Development and implementation | L3 — Apply | Work independently on tasks and apply standard methods effectively. |
| ITOP | Infrastructure operations Provisioning, deploying, configuring, operating and optimising technology infrastructure across physical, virtual and cloud-based environments. | Delivery and operation | L3 — Apply | Work independently on tasks and apply standard methods effectively. |
| VUAS | Vulnerability assessment Identifying and classifying security vulnerabilities in networks, systems and applications and mitigating or eliminating their impact. | Delivery and operation | L3 — Apply | Work independently on tasks and apply standard methods effectively. |
| PENT | Penetration testing Testing the effectiveness of security controls by emulating the tools and techniques of likely attackers. | Delivery and operation | L3 — Apply | Work independently on tasks and apply standard methods effectively. |
| PDSV | Professional development Facilitating the professional development of individuals in line with their career goals and organisational requirements. | People and skills | L3 — Apply | Work independently on tasks and apply standard methods effectively. |
Template Preview
Ready to build your Security Engineer (Professional) profile?
Review the 12 required skills above, then start your self-assessment. You can save a draft and return anytime.
① Rate each skill L1–L7② Write evidence (~15 min)③ Save draft and continue later