+31 (0)88 88 321 88
V Skill HF-D7.6-003 sector-specific 10 kompetenser

Secure development

Builds software in which input is validated, secrets are protected and known vulnerabilities are prevented, and verifies this with targeted tests.

Hur hrmforce mäter detta

Bedömningsmetod
Work sample test · rho 0.33 (SD 0.09)
hrmforce instrument
Work sample test, Knowledge test (client-specific)
Kompetens (50-ramverk)
Commitment to Quality
Utbildningsbarhet
high
Prognos för efterfrågan 2026–2030
rising

The candidate performs a representative work sample under standardised conditions.

Beteendeankare

NivåBeteende på denna nivå
N1 Guided Follows the secure coding guideline for own changes and asks when a guideline is unclear.
works under supervision and follows instruction · routine, one variable at a time · own task
N3 Proficient Recognises vulnerabilities in design and code, resolves them and includes security tests in own way of working.
sets own approach and seeks input proactively · several variables, some ambiguity · own team or process
N5 Leading Sets secure development requirements in the organisation and judges whether solutions meet them before release.
sets the standard and the policy · strategic, under high uncertainty · organisation, value chain or profession

N2 och N4 är medvetet inte förankrade. Bedömarna placerar dem mellan förankringarna, i enlighet med konventionen O*NET.

Grundläggande kompetenser

Dessa kompetenser ärver bedömningsvägen och beteendeankarna för detta konstrukt.

TKompetensDefinitionPrognos för efterfrågan 2026–2030
V Applying secure coding
Secure coding
Writes code that distrusts input, checks permissions and does not expose technical details in errors. rising
K Applying the OWASP top ten
OWASP Top 10
Knows the ten most common web vulnerabilities and prevents them deliberately in own design and code. rising
V Building input validation
Input validation
Validates and normalises input on the server side so injection and unexpected values have no effect. rising
V Setting up secrets management
Secrets management
Removes passwords, keys and tokens from code and configuration and manages them in a vault with rotation. rising
V Checking dependencies for vulnerabilities
Dependency scanning · SBOM
Checks used libraries automatically for known vulnerabilities and updates them in time. rising
T Performing static code analysis
SAST · Static analysis
Has code analysed automatically for insecure patterns and judges which findings truly require follow up. rising
V Building secure authentication
Secure authentication
Builds sign in with secure password storage, session management, lockout after attempts and a second factor. rising
V Logging securely
Secure logging
Logs enough to reconstruct an incident and keeps passwords and personal data out of the log files. rising
V Embedding security requirements in development
Security by design · DevSecOps
Includes security requirements in stories and acceptance criteria and has them verified demonstrably at delivery. rising
V Fixing a vulnerability in own code
Vulnerability remediation
Fixes a reported vulnerability, adds a test preventing recurrence and reports the fix back. rising
Gratis demo