The scoreboard, honestly: the hard targets, how often each one is actually looked at,
and the quiet human signals that never make it onto a dashboard.
Detection Rule Efficacy
The number of new, high-fidelity detection rules you author and implement that correctly identify true positive security events, reducing false alarms.
Target · Implement at least 5 new high-fidelity detection rules per quarter.You create a new Splunk correlation rule that correctly identifies 7 instances of 'Living off the Land' attacks in Q3, with zero false positives, significantly improving our early warning system.
Mean Time to Remediate (MTTR) for Critical Incidents
Your ability to lead and drive critical incidents to full remediation, reducing the time from detection to resolution.
Target · Lead incidents to reduce MTTR for critical events by 10% quarter-over-quarter.After taking lead on a critical ransomware incident, you coordinate with IT and Network teams, bringing the MTTR down from a typical 48 hours to 36 hours, saving us significant downtime and potential data loss.
Mentorship & Team Development
The tangible impact you have on the growth and development of junior analysts on the team.
Target · At least one mentored L1/L2 analyst is promoted or takes on significant new responsibilities within a year.Through your regular code reviews and one-on-one guidance, a junior analyst you've been mentoring successfully takes ownership of our vulnerability management scanning process, a task previously handled by a more senior team member.
Threat Hunting Success Rate
The percentage of proactive threat hunts you conduct that result in the discovery of previously undetected malicious activity or significant detection gaps.
Target · Achieve a 20% success rate for proactive threat hunting engagements.You conduct a hunt for specific C2 beaconing patterns and uncover a previously unknown compromised host that had bypassed perimeter defences, leading to its isolation and eradication before data exfiltration.
Incident Leadership & Composure
How effectively you lead and manage complex security incidents, maintaining a calm and clear head under pressure, and guiding the response team.
- Feedback from incident post-mortems consistently highlights your clear communication and decisive actions. You're the person people naturally look to during a crisis. You don't panic, even when the CEO is asking for updates every 15 minutes.
Proactive Security Improvement
Your ability to not just react to alerts, but to identify systemic issues, propose solutions, and drive their implementation to prevent future incidents.
- You're regularly bringing ideas to the table for new tools, process improvements, or detection strategies. You'll often be asked to present your findings and recommendations to the wider security team or even IT leadership. Your ideas actually get implemented and make a difference.
Knowledge Sharing & Documentation
The quality and consistency of your contributions to our team's knowledge base, playbooks, and internal documentation, making it easier for everyone else.
- Your incident reports are comprehensive and easy to understand. Junior analysts frequently refer to your documentation. You're seen as a go-to person for 'how-to' questions because you've actually written it down properly.
Stakeholder Trust & Influence
The level of trust and respect you build with internal teams (IT, Network, Product) through clear, concise communication and reliable technical expertise.
- Other teams actively seek your advice on security matters before problems arise. They'll come to you with questions like 'Hey, we're planning X, what are the security implications?' instead of you having to chase them down. Your recommendations are usually taken seriously.