Resources

Competency catalog

Security operations competency

Security operations detects, investigates, and coordinates responses to security events using defined evidence and procedures. It provides a fair ladder from guided alert handling to cross-team detection and response standards.

Published by Peasy HRPublished 18 Aug 2026Updated 18 Aug 2026

Short answer

Security operations detects, investigates, and coordinates responses to security events using defined evidence and procedures. It provides a fair ladder from guided alert handling to cross-team detection and response standards.

About Security operations

Detects, investigates, and coordinates responses to security events using defined evidence and procedures. The competency measures event handling and response improvement, not every preventive security control.

Use this competency for

  • Roles that monitor alerts, investigate security events, or coordinate containment and recovery.
  • Functions accountable for detection quality, case evidence, response procedures, or security event follow-up.

Do not use this competency for

  • Roles limited to preventive control design with no security event monitoring or response responsibility.

Important distinctions

Identity management

Identity management governs identities and permissions. Security operations investigates and responds when observed activity may indicate a security event.

Risk management

Risk management evaluates possible future exposure. Security operations handles observed signals and coordinates action on active or suspected events.

Expectations by level

IC1

Handles defined alerts

Triages well-defined security alerts with guidance, follows evidence and escalation procedures, and maintains a complete case timeline.

Observable behaviors

  • Validates alert context against the current triage steps.
  • Preserves relevant evidence and records each action taken.
  • Escalates when scope or severity exceeds the defined boundary.

Examples

  • Closed a known false positive after attaching the expected verification evidence.
  • Escalated suspicious sign-in activity with affected identities, times, and source data.

IC2

Investigates events

Independently investigates ambiguous security events, coordinates scoped containment and recovery, and improves detections or procedures from case evidence.

Observable behaviors

  • Builds and tests competing explanations from available evidence.
  • Coordinates response owners without altering evidence needed for review.
  • Updates a detection or playbook after documenting a confirmed gap.

Examples

  • Linked endpoint and identity events to define the affected scope before containment.
  • Adjusted a noisy detection after reviewing closed cases and testing the revised condition.

IC3

Sets response standards

Defines detection and response standards across teams, frames unfamiliar event patterns, and directs complex investigations through clear evidence and decision points.

Observable behaviors

  • Defines case quality, severity, and escalation standards.
  • Reviews detection coverage against observed event patterns.
  • Leads cross-team response decisions with assumptions and evidence recorded.

Examples

  • Created one severity model after teams used conflicting escalation thresholds.
  • Directed an investigation across several systems and left a tested improvement plan for detection gaps.

Add security operations to your Function

Adapt the evidence sources, severity boundaries, response authority, and case artifacts to your operating environment.

Open the framework builder

Common questions

What does security operations measure?

It measures evidence-based detection, investigation, escalation, containment coordination, and improvement after security events.

How can managers assess investigations fairly?

Use case timelines, evidence quality, decision records, response outcomes, and improvements to detections or procedures.

Does this competency promise incident prevention?

No. It assesses how security events are detected and handled. It does not guarantee that events will not occur.

Related resources

Competency catalog

Cloud operations competency

Cloud operations operates cloud resources with controlled changes, clear observability, and accountable cost. The expectations focus assessment on change artifacts, operating signals, recovery work, and cost decisions.

View competency

Competency catalog

Service management competency

Service management is the capability to operate services against defined expectations and improve them using incidents, requests, and performance data. It makes service outcomes, ownership, and improvement work visible enough to assess.

View competency

Guide

How to write level expectations

A level expectation states the work someone at a specific role track and level is expected to handle. Write it in the present tense, identify scope, autonomy, and complexity, and make every adjacent level distinguishable through evidence. Add short behaviors and examples so managers can apply the standard consistently.

Read guide
Security operations competency levels | Peasy HR