A Security Analyst typically should have the following expertise:
Expert knowledge of and experience with security engineering tasks, techniques (e.g., passwords,
encryption/decryption, digital signatures), and tools.
Expert knowledge of security testing tasks, techniques, and tools.
Solid knowledge of requirements engineering tasks,
techniques, and tools (with emphasis on analyzing and
specifying security requirements such as identification,
authentication, authorization, content protection, privacy,
integrity, intrusion detection, nonrepudiation, and system maintenance).
Solid knowledge of security countermeasures (e.g., architectural mechanisms and components such as firewalls).
Solid knowledge of applications, contact centers, and data centers.
Basic knowledge of the customer’s business and application domain(s).
Perform security review of major software components and their code.
Perform security review of hardware architecture (production environment) for hardware placement, network
addressing and segment, and application distribution.