JobFrame / Security
technology
Security
Security is a job family — a stable cluster of work with shared purpose, outputs, responsibilities, and labor-market identity. On the frame it spans 19 canonical roles across the P track, 7 levels in all.
Titles that map here
Employers call this work many things — these all resolve to Security.
The job family matrix
Every level of the family, side by side — what genuinely changes as the work scales, and what it pays. Open any level for its full profile.
Cybersecurity / Information Security
P1 Security Security Analyst / Junior Security Engineer 0–2 yrs · $58k open profile › | P2 Security Analyst 1–3 yrs · $67k open profile › | P3 Security Security Engineer / Penetration Tester 3–5 yrs · $77k open profile › | P4 Senior Security Engineer / Penetration Tester 5–8 yrs · $102k open profile › | P5 Security Senior Security Engineer / Security Architect 8–12 yrs · $129k open profile › | P6 Principal Security Engineer 12–18 yrs · $175k open profile › | P7 Distinguished Security Engineer 15–22 yrs · $215k open profile › | |
|---|---|---|---|---|---|---|---|
| Median pay | $58k | $67k | $77k | $102k | $129k | $175k | $215k |
| Scope | Own tasks within a defined component | Defined deliverables / small features | Features or a sub-system end-to-end | A system or set of related features | Multiple systems or a technical domain | Organization-wide architecture and the hardest problems | Cross-organization / enterprise technical strategy |
| Autonomy | Close supervision; work reviewed frequently | General supervision; reviewed at milestones | Works independently on standard work; reviewed on the non-standard | Self-directed; reviewed at critical decision points | Sets direction within the domain | Defines direction; minimal oversight | Operates autonomously at the enterprise level |
| Complexity | Routine problems with known solutions | Some non-routine problems; applies established patterns | Diverse problems; adapts existing approaches | Complex, ambiguous problems; devises new approaches | Novel, high-ambiguity problems; establishes the approach | Strategic, open-ended problems shaping the technical future | Industry-level, highly ambiguous problems |
| Impact | Own deliverables | Own and immediate-team deliverables | Project / team outcomes | Multi-team / function outcomes | Org / multi-team outcomes | Organization-wide | Enterprise-wide |
| Decision rights | Few independent decisions; escalates the rest | Routine technical choices within guidance | Owns implementation decisions for own scope | Owns technical decisions for a system; influences adjacent design | Authority over a technical domain | Sets technical strategy for a major area | Final technical authority across multiple domains |
| Leadership | None — building the craft | May guide interns | Mentors juniors informally | Technical lead for focused efforts; mentors several | Leads cross-team technical initiatives | Recognized authority; multiplies many teams | Sets technical direction org-wide; develops principals |
Incident Response
P2 Security Analyst 1–3 yrs · $67k open profile › | P3 Security Security Engineer / Penetration Tester 3–5 yrs · $77k open profile › | P4 Senior Security Engineer / Penetration Tester 5–8 yrs · $102k open profile › | P5 Security Senior Security Engineer / Security Architect 8–12 yrs · $129k open profile › | P6 Principal Security Engineer 12–18 yrs · $175k open profile › | |
|---|---|---|---|---|---|
| Median pay | $67k | $77k | $102k | $129k | $175k |
| Scope | Defined deliverables / small features | Features or a sub-system end-to-end | A system or set of related features | Multiple systems or a technical domain | Organization-wide architecture and the hardest problems |
| Autonomy | General supervision; reviewed at milestones | Works independently on standard work; reviewed on the non-standard | Self-directed; reviewed at critical decision points | Sets direction within the domain | Defines direction; minimal oversight |
| Complexity | Some non-routine problems; applies established patterns | Diverse problems; adapts existing approaches | Complex, ambiguous problems; devises new approaches | Novel, high-ambiguity problems; establishes the approach | Strategic, open-ended problems shaping the technical future |
| Impact | Own and immediate-team deliverables | Project / team outcomes | Multi-team / function outcomes | Org / multi-team outcomes | Organization-wide |
| Decision rights | Routine technical choices within guidance | Owns implementation decisions for own scope | Owns technical decisions for a system; influences adjacent design | Authority over a technical domain | Sets technical strategy for a major area |
| Leadership | May guide interns | Mentors juniors informally | Technical lead for focused efforts; mentors several | Leads cross-team technical initiatives | Recognized authority; multiplies many teams |
Security Engineering
P1 Security Security Analyst / Junior Security Engineer 0–2 yrs · $58k open profile › | P2 Security Analyst 1–3 yrs · $67k open profile › | P3 Security Security Engineer / Penetration Tester 3–5 yrs · $77k open profile › | P4 Senior Security Engineer / Penetration Tester 5–8 yrs · $102k open profile › | P5 Security Senior Security Engineer / Security Architect 8–12 yrs · $129k open profile › | P6 Principal Security Engineer 12–18 yrs · $175k open profile › | P7 Distinguished Security Engineer 15–22 yrs · $215k open profile › | |
|---|---|---|---|---|---|---|---|
| Median pay | $58k | $67k | $77k | $102k | $129k | $175k | $215k |
| Scope | Own tasks within a defined component | Defined deliverables / small features | Features or a sub-system end-to-end | A system or set of related features | Multiple systems or a technical domain | Organization-wide architecture and the hardest problems | Cross-organization / enterprise technical strategy |
| Autonomy | Close supervision; work reviewed frequently | General supervision; reviewed at milestones | Works independently on standard work; reviewed on the non-standard | Self-directed; reviewed at critical decision points | Sets direction within the domain | Defines direction; minimal oversight | Operates autonomously at the enterprise level |
| Complexity | Routine problems with known solutions | Some non-routine problems; applies established patterns | Diverse problems; adapts existing approaches | Complex, ambiguous problems; devises new approaches | Novel, high-ambiguity problems; establishes the approach | Strategic, open-ended problems shaping the technical future | Industry-level, highly ambiguous problems |
| Impact | Own deliverables | Own and immediate-team deliverables | Project / team outcomes | Multi-team / function outcomes | Org / multi-team outcomes | Organization-wide | Enterprise-wide |
| Decision rights | Few independent decisions; escalates the rest | Routine technical choices within guidance | Owns implementation decisions for own scope | Owns technical decisions for a system; influences adjacent design | Authority over a technical domain | Sets technical strategy for a major area | Final technical authority across multiple domains |
| Leadership | None — building the craft | May guide interns | Mentors juniors informally | Technical lead for focused efforts; mentors several | Leads cross-team technical initiatives | Recognized authority; multiplies many teams | Sets technical direction org-wide; develops principals |
Adjacent families
The work that sits closest to Security on the frame — by coordinate distance, not by hand.