Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])- Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code). - Skilled in identifying different classes of attacks and attack stages- Understanding of system and application security threats and vulnerabilities- Understanding of proactive analysis of systems and networks, to include creating trust levels of critical resources.