Security Engineer

Security Engineer handles 20 everyday tasks that together form a typical work pattern and deliverables. These examples point to common hurdles and how to use Atlassian Confluence effectively. Each one shows where we found it, and comes with an AI prompt you can copy and use straight away.

20evidenced tasks
20ready prompts
10tools of the trade
15-1299.05O*NET-SOC code
435,370hold this job (US, BLS 2025)
$116,580median pay/yr (US)
Open Security Engineer in the interactive atlas →

What it pays

Government survey numbers — not estimates, not ads.

Half of all Computer Occupations, All Other in the U.S. earn more than $116,580 a year — the middle 80% land between $55,940 and $188,470. About 435,370 people in the U.S. do this work. Figures are for the U.S. occupation group “Computer Occupations, All Other”. (U.S. Bureau of Labor Statistics survey, published 2025.) In India, Professionals earn about ₹38,298 a month on average — around ₹4.6 lakh a year (government PLFS survey via ILOSTAT, occupation-family figure).
$116,580typical pay / year
435,370people in this work
$188,470+top 10% earn
₹4.6 lakha year in India (family avg)
Think you get this job?Six quick questions on how it really works — with a hint and the reason behind every answer.
Test yourself →

The work, task by task

These are the real jobs-to-be-done, not a wish list. Each task shows where we found it, and the prompt underneath is written for that exact task.

Analysing4

Configure firewalls, SIEM, IDS/IPS

+
Deploy and validate perimeter firewall rulesets, tune the SIEM parsers for endpoint telemetry, and confirm…
Deploy and validate perimeter firewall rulesets, tune the SIEM parsers for endpoint telemetry, and confirm intrusion detection rules block the last three confirmed attack patterns, logging changes in the security ticket with evidence.
The tools that do the workAnsibleAtlassian JIRAjob descriptionsO*NET

Identify security weaknesses

+
Perform a system-wide weakness review focussing on web apps, privileged services, and third-party libraries,…
Perform a system-wide weakness review focussing on web apps, privileged services, and third-party libraries, produce a ranked list of flaws with exploitability and remediation steps, and present top five items to the dev leads on Monday.
The tools that do the workC++job descriptionsO*NET

Implement and manage security controls

+
Design and roll out role-based access controls for the finance app, review current ACLs, revoke excessive…
Design and roll out role-based access controls for the finance app, review current ACLs, revoke excessive privileges, and deliver an access-change log and approval workflow to the data owner before the month-end close.
The tools that do the workChefAtlassian Confluencejob descriptionsO*NET

Implement solutions to control access to data and programs

+
Implement multifactor enforcement and least-privilege groups for the shared development repositories, update…
Implement multifactor enforcement and least-privilege groups for the shared development repositories, update authentication policies, test service account behaviour, and hand over a runbook and audit trail to the identity team by Friday.
The tools that do the workAmazon Web Services AWSESCOO*NET
The daily work16

Review security assessments for computing environments or check for compliance with cybersecurity standards and regulations.

+
Review the latest environment security assessment for the payments platform, confirm each control mapped to…
Review the latest environment security assessment for the payments platform, confirm each control mapped to the formal ICT spec, note any gaps with severity and remediation owners, and file the signed review in the audit trail by Friday.
The tools that do the workAnsibleO*NET

Collaborate with IT and development teams

+
Work with Tom in operations and Priya in development to walk through the new CI pipeline changes, identify…
Work with Tom in operations and Priya in development to walk through the new CI pipeline changes, identify where secrets are exposed, decide mitigations, and add the agreed actions to the project record before the sprint demo on Wednesday.
The tools that do the workAtlassian JIRAAtlassian Confluencejob descriptions

Stay updated with security trends and vulnerabilities

+
Summarise this week's high-priority vulnerabilities affecting our stack, include exploitability and…
Summarise this week's high-priority vulnerabilities affecting our stack, include exploitability and recommended mitigations, and circulate a one-page briefing to the tech leads and CTO by Monday morning.
The tools that do the workBashjob descriptions

Analyze security alerts and logs

+
Triage the security alerts from last 24 hours, group by asset and confidence, assign incidents requiring…
Triage the security alerts from last 24 hours, group by asset and confidence, assign incidents requiring investigation to Jake, escalate confirmed breaches to the incident lead, and append findings to the incident log before end of shift.
The tools that do the workBorder Gateway Protocol BGPjob descriptions

Manage encryption solutions and protocols

+
Review our encryption configuration for data at rest and in transit, confirm algorithms, key lengths and…
Review our encryption configuration for data at rest and in transit, confirm algorithms, key lengths and rotation schedules meet the policy, document any nonconformance with mitigation steps and owner, and request approval from the CISO.
The tools that do the workChefjob descriptions

Ensure compliance with industry standards

+
Run a compliance check against the relevant industry standard controls for the customer data domain, capture…
Run a compliance check against the relevant industry standard controls for the customer data domain, capture evidence for each control, prepare a nonconformance list with risk ratings, and submit the package to compliance by Thursday.
The tools that do the workAmazon Web Services AWSAmazon Web Services AWS CloudFormationjob descriptions

Support secure system architecture design

+
Draft a secure architecture proposal for the payments platform that maps data flows, labels confidential data…
Draft a secure architecture proposal for the payments platform that maps data flows, labels confidential data stores, lists threat mitigations and required controls, and schedule a review with Priya in engineering next Wednesday so we can finalise the spec.
The tools that do the workAmazon Web Services AWSjob descriptions

Perform patch management and updates

+
Plan and document the patch rollout for the web fleet: inventory vulnerable hosts, schedule staged updates…
Plan and document the patch rollout for the web fleet: inventory vulnerable hosts, schedule staged updates starting Friday evening, define rollback steps and test cases, and log the runbook in the team audit trail.
The tools that do the workAnsiblejob descriptions

Explain technical issues to non-technical teams

+
Prepare a plain-language briefing for the product and legal teams that explains the recent privilege…
Prepare a plain-language briefing for the product and legal teams that explains the recent privilege escalation issue, its business impact, the technical root cause, and three concrete mitigation options with estimated time and cost.
The tools that do the workAtlassian Confluencejob descriptions

Advise ICT security solutions

+
Produce a recommendation memo for the CTO comparing three network segmentation options, include threat…
Produce a recommendation memo for the CTO comparing three network segmentation options, include threat reduction, implementation effort, and residual risk, and request decision and budget approval by Friday.
The tools that do the workBorder Gateway Protocol BGPESCO

Promote safe exchange of information

+
Create a short guidance note for client services on encrypting email and file transfers, specify approved…
Create a short guidance note for client services on encrypting email and file transfers, specify approved ciphers, key rotation cadence, and a simple checklist they can follow before sharing confidential files.
The tools that do the workApple macOSESCO

Implement solutions to control access

+
Design an access control implementation for the analytics cluster: define roles, least-privilege policies,…
Design an access control implementation for the analytics cluster: define roles, least-privilege policies, MFA requirements, and an access review cadence, then add tasks to the backlog and assign owners for rollout next quarter.
The tools that do the workChefESCO

Educate on data confidentiality

+
Write a concise one-hour training for engineering and product teams on handling confidential customer data:…
Write a concise one-hour training for engineering and product teams on handling confidential customer data: include classification rules, permitted storage locations, approved transfer methods, three real breach examples and the exact actions to take within the first 24 hours; deliver as a slide deck and an email summary to send to Maya in Product by next Tuesday.
The tools that do the workAtlassian ConfluenceESCOsee the evidence ↗

Verify formal ICT specifications

+
Review the formal ICT specification for the payments service against our security baseline: check crypto…
Review the formal ICT specification for the payments service against our security baseline: check crypto algorithms, key lifecycle, access control lists, audit logging, and change control notes; flag non-conformances with severity and remediation steps and assign each to Raj in Engineering by Friday COB.
The tools that do the workAtlassian JIRAESCOsee the evidence ↗

Execute ICT audits

+
Run a technical audit of the staging environment focused on authentication, secrets handling, and network…
Run a technical audit of the staging environment focused on authentication, secrets handling, and network segmentation: produce a findings spreadsheet with risk ratings, evidence links, and an executive one-page risk summary for the CISO; schedule remediation review with the platform team for Wednesday.
The tools that do the workBashESCOsee the evidence ↗

Keep task records

+
Consolidate this quarter's security tasks into a single chronological log: include task owner, start and…
Consolidate this quarter's security tasks into a single chronological log: include task owner, start and completion dates, evidence links, time spent, and current status; export as a printable report and notify Helen in Compliance of any open items exceeding two weeks.
The tools that do the workAtlassian ConfluenceESCOsee the evidence ↗

Says who?

These are the pages we read to build this. Open any of them and check us.

The logs, files & records this job keeps

Shared with other careers — the same record means something different in each.

Related careers

Same family of work — each with its own tasks and prompts.

The LLOS Work Atlas is the world's largest evidenced task library — a map of human work, with a ready prompt behind every task. 1,774 careers · every task named by the sources that witnessed it — O*NET, ESCO, real job descriptions, Wikipedia — and the deepest tasks by several at once. And it is honest about limits: where AI cannot help, the map says so.

The rest of the map

Same library, five ways in.

Copyright © LLOS.ai · 2026 — original pedagogy, voice, and design — all rights reserved.
Built on public evidence: O*NET®, ESCO, Wikipedia, U.S. Bureau of Labor Statistics, ILOSTAT. All sources & licenses