Pipeline run
75cd1af2-4c0d-4852-8122-ca8685492154
Client output enrichment
v2 Skill cluster · Nature of work · AI index · Tech stack maturity · Evidence · KRA descriptionvocab breakdown (legacy)
Signals
Post-classification
Captured for admin review
1 POST /skills/extract-from-jd
2 POST /skills/extract-details
3 POST /skills/final-role-output
Cybersecurity Engineer
CASE Aslug: cybersecurity-engineer · id: 5 · source: db
The primary skills heavily lean towards network security, which aligns well with the Cybersecurity Engineer role.
Resolution:
in_db
— role exists in library; skill↔dim and role↔dim links saved when applicable.
Job description
Job Title: L2 Network Security Engineer We are seeking a highly skilled L2 Network Security Engineer to manage, optimize, and secure our enterprise-level network infrastructure. In this role, you will be responsible for the end-to-end administration of LAN/WAN, SD-WAN, and security frameworks. You will serve as a critical technical escalation point, ensuring high availability through proactive monitoring, root cause analysis (RCA), and precise execution of network changes. Key Responsibilities • Network Administration: Configure and manage enterprise LAN, WAN, WLAN, and SD-WAN (Fortinet) solutions. • Routing & Switching: Implement and maintain robust routing and switching environments using BGP and OSPF protocols. • Security & Access: Manage next-generation firewalls (NGFW), VPNs, and Network Access Control (NAC) systems. Lead security hardening and firewall rule optimization. • Incident Management: Act as the technical escalation point for network incidents. Lead the resolution of critical outages and perform thorough Root Cause Analysis (RCA). • Optimization: Proactively tune network bandwidth, redundancy, and failover mechanisms to ensure 99.9% uptime. • Operational Excellence: Develop Standard Operating Procedures (SOPs) for L1/L2 teams and lead the review/execution of Network Change Requests (CRs). • Documentation: Maintain high-quality network diagrams, configuration backups, and knowledge base articles. Technical Skills & Qualifications Core Networking • Multi-Vendor Expertise: Hands-on experience with Cisco and Fortinet devices is essential. • Protocols: Deep understanding of BGP4, OSPF, and enterprise switching. • Infrastructure: Solid grasp of the OSI model, TCP/IP, NAT/PAT, DNS, DHCP, and TACACS. • SD-WAN: Proven experience in deploying and managing SD-WAN (specifically Fortinet). Troubleshooting & Tools • Diagnostic Skills: Proficiency in packet analysis (Wireshark), log interpretation, and fault management. • Monitoring: Experience with Network Management Systems (NMS) to track health and performance. Operational Requirements • Shift Work: Ability to work flexibly in a 24x7 shift environment. • Process Oriented: Familiarity with ITIL practices, specifically Change Management and Risk Mitigation during maintenance windows. Soft Skills • Leadership: Ability to lead critical incident response teams under pressure. • Communication: Strong documentation skills for creating technical diagrams and incident reports. • Mentorship: Willingness to train and provide remediation steps for junior technical staff. Preferred Certifications • CCNA/CCNP (Routing & Switching/Security) • Fortinet NSE 4 or higher • ITIL Foundation Email: Raspl.hr@raspl.com
Skills from this JD
Each row merges API 1 extraction, API 2 library match / v3 orchestration (dimensions + locked dims), and API 3 persistence tags.
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Networking
- Sub-category
- general
- Skill nature
- CONCEPT
- Volatility
- STABLE
- Typical lifespan
- EVERGREEN
- Version strategy
- UNVERSIONED
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Networking
- Sub-category
- general
- Skill nature
- CONCEPT
- Volatility
- STABLE
- Typical lifespan
- EVERGREEN
- Version strategy
- UNVERSIONED
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Networking
- Sub-category
- general
- Skill nature
- CONCEPT
- Volatility
- STABLE
- Typical lifespan
- EVERGREEN
- Version strategy
- UNVERSIONED
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Networking
- Sub-category
- general
- Skill nature
- CONCEPT
- Volatility
- MEDIUM
- Typical lifespan
- MULTI_YEAR
- Version strategy
- UNVERSIONED
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Security Tools
- Sub-category
- general
- Skill nature
- TOOL
- Volatility
- MEDIUM
- Typical lifespan
- MULTI_YEAR
- Version strategy
- UNVERSIONED
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Networking
- Sub-category
- general
- Skill nature
- CONCEPT
- Volatility
- STABLE
- Typical lifespan
- EVERGREEN
- Version strategy
- UNVERSIONED
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Networking
- Sub-category
- general
- Skill nature
- CONCEPT
- Volatility
- STABLE
- Typical lifespan
- EVERGREEN
- Version strategy
- UNVERSIONED
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Security Tools
- Sub-category
- general
- Skill nature
- TOOL
- Volatility
- MEDIUM
- Typical lifespan
- MULTI_YEAR
- Version strategy
- UNVERSIONED
Aliases — catalog
- VPN (CANONICAL) primary
Context tags (catalog)
Stored enrichment (catalog DB)
- Category
- Protocol
- Sub-category
- Network Tunneling Protocol
- Confidence
- 0.90
- Version strategy
- NOT_APPLICABLE
Maturity reasoning: VPN is broadly used in enterprise networking and remote access; it appears frequently in job descriptions for network/security roles and is supported by major vendors like Cisco, Palo Alto, and AWS.
Skill profile (library / DB)
- Skill nature
- PROTOCOL
- Volatility
- STABLE
- Typical lifespan
- EVERGREEN
- Category id
- 10
- Sub-category id
- 1373
- Extractable
- True
- Also category
- False
Dimensions (API 2 worklist)
-
Cloud Network Security Controls Catalog dimension db id 242
Library dimension (catalog)
Roles linked in library: Cloud Security Engineer
-
Network Security Controls Catalog dimension db id 60
Library dimension (catalog)
Roles linked in library: Cybersecurity Engineer
API 3 link attempts (this skill)
| Dimension | Skill↔dim | Role↔dim | Outcome |
|---|---|---|---|
|
Cloud Network Security Controls
cloud-network-security-controls
|
✓ | — | Existing dimension (library) · Role↔dimension skipped (dimension not under chosen role) |
|
Network Security Controls
network-security-controls
|
✓ | ✓ | Existing dimension (library) · Role↔dimension saved |
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Networking
- Sub-category
- general
- Skill nature
- PRACTICE
- Volatility
- MEDIUM
- Typical lifespan
- MULTI_YEAR
- Version strategy
- UNVERSIONED
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Networking
- Sub-category
- general
- Skill nature
- TOOL
- Volatility
- MEDIUM
- Typical lifespan
- MULTI_YEAR
- Version strategy
- UNVERSIONED
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Networking
- Sub-category
- general
- Skill nature
- CONCEPT
- Volatility
- STABLE
- Typical lifespan
- EVERGREEN
- Version strategy
- UNVERSIONED
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Networking
- Sub-category
- general
- Skill nature
- CONCEPT
- Volatility
- STABLE
- Typical lifespan
- EVERGREEN
- Version strategy
- UNVERSIONED
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Networking
- Sub-category
- general
- Skill nature
- CONCEPT
- Volatility
- STABLE
- Typical lifespan
- EVERGREEN
- Version strategy
- UNVERSIONED
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Networking
- Sub-category
- general
- Skill nature
- CONCEPT
- Volatility
- STABLE
- Typical lifespan
- EVERGREEN
- Version strategy
- UNVERSIONED
Aliases — catalog
- DNS (CANONICAL) primary
Context tags (catalog)
Stored enrichment (catalog DB)
- Category
- Protocol
- Sub-category
- Name Resolution Protocol
- Vendor
- IETF
- License
- other_open
- Year introduced
- 1983
- Confidence
- 0.90
- Version strategy
- NOT_APPLICABLE
Maturity reasoning: DNS is a foundational internet protocol and appears routinely in SRE, network, and cloud job descriptions; major vendors still document and support it as core infrastructure.
Skill profile (library / DB)
- Skill nature
- PROTOCOL
- Volatility
- STABLE
- Typical lifespan
- EVERGREEN
- Category id
- 10
- Sub-category id
- 561
- Extractable
- True
- Also category
- False
Dimensions (API 2 worklist)
-
Cloud Networking and Connectivity Catalog dimension db id 153
Library dimension (catalog)
Roles linked in library: DevOps Engineer
-
Cloud Networking and Edge Connectivity Catalog dimension db id 136
Library dimension (catalog)
Roles linked in library: Cloud Architect
API 3 link attempts (this skill)
| Dimension | Skill↔dim | Role↔dim | Outcome |
|---|---|---|---|
|
Cloud Networking and Connectivity
cloud-networking-and-connectivity
|
✓ | — | Existing dimension (library) · Role↔dimension skipped (dimension not under chosen role) |
|
Cloud Networking and Edge Connectivity
cloud-networking-and-edge-connectivity
|
✓ | — | Existing dimension (library) · Role↔dimension skipped (dimension not under chosen role) |
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Networking
- Sub-category
- general
- Skill nature
- CONCEPT
- Volatility
- STABLE
- Typical lifespan
- EVERGREEN
- Version strategy
- UNVERSIONED
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Networking
- Sub-category
- general
- Skill nature
- CONCEPT
- Volatility
- STABLE
- Typical lifespan
- EVERGREEN
- Version strategy
- UNVERSIONED
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Networking
- Sub-category
- general
- Skill nature
- TOOL
- Volatility
- MEDIUM
- Typical lifespan
- MULTI_YEAR
- Version strategy
- UNVERSIONED
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Networking
- Sub-category
- general
- Skill nature
- TOOL
- Volatility
- MEDIUM
- Typical lifespan
- MULTI_YEAR
- Version strategy
- UNVERSIONED
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Practice
- Sub-category
- general
- Skill nature
- PRACTICE
- Volatility
- MEDIUM
- Typical lifespan
- MULTI_YEAR
- Version strategy
- UNVERSIONED
Skill enrichment (orchestrator / LLM)
No Stage 7 enrichment blob on this skill (orchestrator skipped enrichment).
- Category
- Practice
- Sub-category
- general
- Skill nature
- PRACTICE
- Volatility
- MEDIUM
- Typical lifespan
- MULTI_YEAR
- Version strategy
- UNVERSIONED
All API 3 persistence rows
Same grid as the skill-extractor “Persistence items” table: one row per (skill × dimension) work item.
| Skill | Tag | Dimension | Skill↔dim | Role↔dim | Outcome | Notes |
|---|---|---|---|---|---|---|
| VPN | in_db |
Cloud Network Security Controls
cloud-network-security-controls
|
✓ | — | Existing dimension (library) · Role↔dimension skipped (dimension not under chosen role) | |
| VPN | in_db |
Network Security Controls
network-security-controls
|
✓ | ✓ | Existing dimension (library) · Role↔dimension saved | |
| DNS | in_db |
Cloud Networking and Connectivity
cloud-networking-and-connectivity
|
✓ | — | Existing dimension (library) · Role↔dimension skipped (dimension not under chosen role) | |
| DNS | in_db |
Cloud Networking and Edge Connectivity
cloud-networking-and-edge-connectivity
|
✓ | — | Existing dimension (library) · Role↔dimension skipped (dimension not under chosen role) |
Library artifacts (this run)
| Kind | Detail | DB id |
|---|---|---|
| canonical_skill_proposed | LAN | type=Networking subtype=general nature=CONCEPT lifespan=EVERGREEN | |
| canonical_skill_proposed | WAN | type=Networking subtype=general nature=CONCEPT lifespan=EVERGREEN | |
| canonical_skill_proposed | WLAN | type=Networking subtype=general nature=CONCEPT lifespan=EVERGREEN | |
| canonical_skill_proposed | SD-WAN | type=Networking subtype=general nature=CONCEPT lifespan=MULTI_YEAR | |
| canonical_skill_proposed | Fortinet | type=Security Tools subtype=general nature=TOOL lifespan=MULTI_YEAR | |
| canonical_skill_proposed | BGP | type=Networking subtype=general nature=CONCEPT lifespan=EVERGREEN | |
| canonical_skill_proposed | OSPF | type=Networking subtype=general nature=CONCEPT lifespan=EVERGREEN | |
| canonical_skill_proposed | NGFW | type=Security Tools subtype=general nature=TOOL lifespan=MULTI_YEAR | |
| canonical_skill_proposed | Network Access Control | type=Networking subtype=general nature=PRACTICE lifespan=MULTI_YEAR | |
| canonical_skill_proposed | Cisco | type=Networking subtype=general nature=TOOL lifespan=MULTI_YEAR | |
| canonical_skill_proposed | BGP4 | type=Networking subtype=general nature=CONCEPT lifespan=EVERGREEN | |
| canonical_skill_proposed | OSI model | type=Networking subtype=general nature=CONCEPT lifespan=EVERGREEN | |
| canonical_skill_proposed | TCP/IP | type=Networking subtype=general nature=CONCEPT lifespan=EVERGREEN | |
| canonical_skill_proposed | NAT/PAT | type=Networking subtype=general nature=CONCEPT lifespan=EVERGREEN | |
| canonical_skill_proposed | DHCP | type=Networking subtype=general nature=CONCEPT lifespan=EVERGREEN | |
| canonical_skill_proposed | TACACS | type=Networking subtype=general nature=CONCEPT lifespan=EVERGREEN | |
| canonical_skill_proposed | Wireshark | type=Networking subtype=general nature=TOOL lifespan=MULTI_YEAR | |
| canonical_skill_proposed | Network Management Systems | type=Networking subtype=general nature=TOOL lifespan=MULTI_YEAR | |
| canonical_skill_proposed | ITIL | type=Practice subtype=general nature=PRACTICE lifespan=MULTI_YEAR | |
| canonical_skill_proposed | Change Management | type=Practice subtype=general nature=PRACTICE lifespan=MULTI_YEAR |
nano JD Parser — gpt-4.1-nano click to toggle
Certifications
Show raw JSON
{
"JD_type": "pass",
"about_company": null,
"certifications": [
"CCNA/CCNP (Routing \u0026 Switching/Security)",
"Fortinet NSE 4 or higher",
"ITIL Foundation"
],
"company_name": null,
"ctc": null,
"domain": {
"primary": {
"aliases": [],
"domain": "IT Services \u0026 Consulting"
},
"secondary": null
},
"education": [],
"experience": null,
"job_locations": [],
"role": "L2 Network Security Engineer",
"role_aliases": [
"Network Security Engineer",
"L2 Security Engineer",
"Network Engineer"
],
"role_archetype": "Security",
"roles_and_responsibilities": [
{
"bullet_count": 7,
"heading": "Key Responsibilities",
"heading_was_present": true,
"source_marker": {
"first_5_words": "\u2022 Network Administration: Configure and",
"last_5_words": "configuration backups, and knowledge base articles."
},
"text": "\u2022 Network Administration: Configure and manage enterprise LAN, WAN, WLAN, and SD-WAN (Fortinet) solutions.\n\u2022 Routing \u0026 Switching: Implement and maintain robust routing and switching environments using BGP and OSPF protocols.\n\u2022 Security \u0026 Access: Manage next-generation firewalls (NGFW), VPNs, and Network Access Control (NAC) systems. Lead security hardening and firewall rule optimization.\n\u2022 Incident Management: Act as the technical escalation point for network incidents. Lead the resolution of critical outages and perform thorough Root Cause Analysis (RCA).\n\u2022 Optimization: Proactively tune network bandwidth, redundancy, and failover mechanisms to ensure 99.9% uptime.\n\u2022 Operational Excellence: Develop Standard Operating Procedures (SOPs) for L1/L2 teams and lead the review/execution of Network Change Requests (CRs).\n\u2022 Documentation: Maintain high-quality network diagrams, configuration backups, and knowledge base articles.",
"word_count": 134
},
{
"bullet_count": 8,
"heading": "Technical Skills \u0026 Qualifications",
"heading_was_present": true,
"source_marker": {
"first_5_words": "Core Networking \u2022 Multi-Vendor Expertise:",
"last_5_words": "track health and performance."
},
"text": "Core Networking\n\u2022 Multi-Vendor Expertise: Hands-on experience with Cisco and Fortinet devices is essential.\n\u2022 Protocols: Deep understanding of BGP4, OSPF, and enterprise switching.\n\u2022 Infrastructure: Solid grasp of the OSI model, TCP/IP, NAT/PAT, DNS, DHCP, and TACACS.\n\u2022 SD-WAN: Proven experience in deploying and managing SD-WAN (specifically Fortinet).\n\nTroubleshooting \u0026 Tools\n\u2022 Diagnostic Skills: Proficiency in packet analysis (Wireshark), log interpretation, and fault management.\n\u2022 Monitoring: Experience with Network Management Systems (NMS) to track health and performance.",
"word_count": 134
},
{
"bullet_count": 2,
"heading": "Operational Requirements",
"heading_was_present": true,
"source_marker": {
"first_5_words": "\u2022 Shift Work: Ability to work",
"last_5_words": "during maintenance windows."
},
"text": "\u2022 Shift Work: Ability to work flexibly in a 24x7 shift environment.\n\u2022 Process Oriented: Familiarity with ITIL practices, specifically Change Management and Risk Mitigation during maintenance windows.",
"word_count": 32
},
{
"bullet_count": 3,
"heading": "Soft Skills",
"heading_was_present": true,
"source_marker": {
"first_5_words": "\u2022 Leadership: Ability to lead",
"last_5_words": "for junior technical staff."
},
"text": "\u2022 Leadership: Ability to lead critical incident response teams under pressure.\n\u2022 Communication: Strong documentation skills for creating technical diagrams and incident reports.\n\u2022 Mentorship: Willingness to train and provide remediation steps for junior technical staff.",
"word_count": 36
}
],
"urls": []
}
API 1 — extract-from-jd click to toggle
{
"final_skills": [
{
"is_primary": true,
"skill_name": "LAN"
},
{
"is_primary": true,
"skill_name": "WAN"
},
{
"is_primary": true,
"skill_name": "WLAN"
},
{
"is_primary": true,
"skill_name": "SD-WAN"
},
{
"is_primary": true,
"skill_name": "Fortinet"
},
{
"is_primary": true,
"skill_name": "BGP"
},
{
"is_primary": true,
"skill_name": "OSPF"
},
{
"is_primary": true,
"skill_name": "NGFW"
},
{
"is_primary": true,
"skill_name": "VPN"
},
{
"is_primary": true,
"skill_name": "Network Access Control"
},
{
"is_primary": true,
"skill_name": "Cisco"
},
{
"is_primary": true,
"skill_name": "BGP4"
},
{
"is_primary": true,
"skill_name": "OSI model"
},
{
"is_primary": true,
"skill_name": "TCP/IP"
},
{
"is_primary": true,
"skill_name": "NAT/PAT"
},
{
"is_primary": true,
"skill_name": "DNS"
},
{
"is_primary": true,
"skill_name": "DHCP"
},
{
"is_primary": true,
"skill_name": "TACACS"
},
{
"is_primary": true,
"skill_name": "Wireshark"
},
{
"is_primary": true,
"skill_name": "Network Management Systems"
},
{
"is_primary": true,
"skill_name": "ITIL"
},
{
"is_primary": true,
"skill_name": "Change Management"
}
],
"jd_role": {
"display_name": "L2 Network Security Engineer",
"rationale": null,
"role_aliases": [
"Network Security Engineer",
"L2 Security Engineer",
"Network Engineer"
],
"role_archetype": "Security",
"slug": ""
},
"nano_parsed": {
"JD_type": "pass",
"about_company": null,
"certifications": [
"CCNA/CCNP (Routing \u0026 Switching/Security)",
"Fortinet NSE 4 or higher",
"ITIL Foundation"
],
"company_name": null,
"ctc": null,
"domain": {
"primary": {
"aliases": [],
"domain": "IT Services \u0026 Consulting"
},
"secondary": null
},
"education": [],
"experience": null,
"job_locations": [],
"role": "L2 Network Security Engineer",
"role_aliases": [
"Network Security Engineer",
"L2 Security Engineer",
"Network Engineer"
],
"role_archetype": "Security",
"roles_and_responsibilities": [
{
"bullet_count": 7,
"heading": "Key Responsibilities",
"heading_was_present": true,
"source_marker": {
"first_5_words": "\u2022 Network Administration: Configure and",
"last_5_words": "configuration backups, and knowledge base articles."
},
"text": "\u2022 Network Administration: Configure and manage enterprise LAN, WAN, WLAN, and SD-WAN (Fortinet) solutions.\n\u2022 Routing \u0026 Switching: Implement and maintain robust routing and switching environments using BGP and OSPF protocols.\n\u2022 Security \u0026 Access: Manage next-generation firewalls (NGFW), VPNs, and Network Access Control (NAC) systems. Lead security hardening and firewall rule optimization.\n\u2022 Incident Management: Act as the technical escalation point for network incidents. Lead the resolution of critical outages and perform thorough Root Cause Analysis (RCA).\n\u2022 Optimization: Proactively tune network bandwidth, redundancy, and failover mechanisms to ensure 99.9% uptime.\n\u2022 Operational Excellence: Develop Standard Operating Procedures (SOPs) for L1/L2 teams and lead the review/execution of Network Change Requests (CRs).\n\u2022 Documentation: Maintain high-quality network diagrams, configuration backups, and knowledge base articles.",
"word_count": 134
},
{
"bullet_count": 8,
"heading": "Technical Skills \u0026 Qualifications",
"heading_was_present": true,
"source_marker": {
"first_5_words": "Core Networking \u2022 Multi-Vendor Expertise:",
"last_5_words": "track health and performance."
},
"text": "Core Networking\n\u2022 Multi-Vendor Expertise: Hands-on experience with Cisco and Fortinet devices is essential.\n\u2022 Protocols: Deep understanding of BGP4, OSPF, and enterprise switching.\n\u2022 Infrastructure: Solid grasp of the OSI model, TCP/IP, NAT/PAT, DNS, DHCP, and TACACS.\n\u2022 SD-WAN: Proven experience in deploying and managing SD-WAN (specifically Fortinet).\n\nTroubleshooting \u0026 Tools\n\u2022 Diagnostic Skills: Proficiency in packet analysis (Wireshark), log interpretation, and fault management.\n\u2022 Monitoring: Experience with Network Management Systems (NMS) to track health and performance.",
"word_count": 134
},
{
"bullet_count": 2,
"heading": "Operational Requirements",
"heading_was_present": true,
"source_marker": {
"first_5_words": "\u2022 Shift Work: Ability to work",
"last_5_words": "during maintenance windows."
},
"text": "\u2022 Shift Work: Ability to work flexibly in a 24x7 shift environment.\n\u2022 Process Oriented: Familiarity with ITIL practices, specifically Change Management and Risk Mitigation during maintenance windows.",
"word_count": 32
},
{
"bullet_count": 3,
"heading": "Soft Skills",
"heading_was_present": true,
"source_marker": {
"first_5_words": "\u2022 Leadership: Ability to lead",
"last_5_words": "for junior technical staff."
},
"text": "\u2022 Leadership: Ability to lead critical incident response teams under pressure.\n\u2022 Communication: Strong documentation skills for creating technical diagrams and incident reports.\n\u2022 Mentorship: Willingness to train and provide remediation steps for junior technical staff.",
"word_count": 36
}
],
"urls": []
},
"rejected": false,
"rejection_reason": null,
"run_id": "75cd1af2-4c0d-4852-8122-ca8685492154",
"stage3_signals": {
"alias_found": true,
"alias_match_roles": [
{
"display_name": "Cybersecurity Engineer",
"kra_matches": null,
"matched_count": null,
"matched_skills": null,
"role_id": 5,
"score": 1.0,
"slug": "cybersecurity-engineer",
"total_count": null
}
],
"kra_match_roles": [
{
"display_name": "Cybersecurity Engineer",
"kra_matches": [
{
"kra_text": "Designs and implements security controls including SIEM integration, endpoint detection and response, identity management, and firewall rule management.",
"sentence": "Security \u0026 Access: Manage next-generation firewalls (NGFW), VPNs, and Network Access Control (NAC) systems.",
"similarity": 0.6154
},
{
"kra_text": "Leads security incident response investigations including forensic analysis, malware triage, containment actions, and post-incident remediation coordination.",
"sentence": "Incident Management: Act as the technical escalation point for network incidents.",
"similarity": 0.5886
},
{
"kra_text": "Hardens system and service configurations, applies security baselines, removes unnecessary services, and reduces attack surface across infrastructure.",
"sentence": "Lead security hardening and firewall rule optimization.",
"similarity": 0.5774
}
],
"matched_count": null,
"matched_skills": null,
"role_id": 5,
"score": 0.5938,
"slug": "cybersecurity-engineer",
"total_count": null
},
{
"display_name": "Backend Developer",
"kra_matches": [
{
"kra_text": "Investigates and resolves production incidents, API bugs, and service degradation through root cause analysis, hotfixes, and post-mortems.",
"sentence": "Lead the resolution of critical outages and perform thorough Root Cause Analysis (RCA).",
"similarity": 0.6269
},
{
"kra_text": "Investigates and resolves production incidents, API bugs, and service degradation through root cause analysis, hotfixes, and post-mortems.",
"sentence": "Incident Management: Act as the technical escalation point for network incidents.",
"similarity": 0.5111
},
{
"kra_text": "Identifies and resolves backend performance bottlenecks through query optimization, indexing strategies, connection pooling, and distributed caching with Redis.",
"sentence": "Optimization: Proactively tune network bandwidth, redundancy, and failover mechanisms to ensure 99.9% uptime.",
"similarity": 0.4809
}
],
"matched_count": null,
"matched_skills": null,
"role_id": 1,
"score": 0.5396,
"slug": "backend-engineer",
"total_count": null
},
{
"display_name": "DevOps Engineer",
"kra_matches": [
{
"kra_text": "Responds to deployment failures, infrastructure incidents, and environment misconfiguration issues to restore service availability and prevent recurrence.",
"sentence": "Lead the resolution of critical outages and perform thorough Root Cause Analysis (RCA).",
"similarity": 0.552
},
{
"kra_text": "Responds to deployment failures, infrastructure incidents, and environment misconfiguration issues to restore service availability and prevent recurrence.",
"sentence": "Incident Management: Act as the technical escalation point for network incidents.",
"similarity": 0.5467
},
{
"kra_text": "Writes runbooks, deployment guides, incident playbooks, and infrastructure documentation to support operations and knowledge sharing.",
"sentence": "Documentation: Maintain high-quality network diagrams, configuration backups, and knowledge base articles.",
"similarity": 0.5143
}
],
"matched_count": null,
"matched_skills": null,
"role_id": 10,
"score": 0.5377,
"slug": "devops-engineer",
"total_count": null
},
{
"display_name": "Cloud Security Engineer",
"kra_matches": [
{
"kra_text": "Implements cloud network security controls including security groups, NACLs, VPC service controls, WAF rules, and private service endpoints.",
"sentence": "Security \u0026 Access: Manage next-generation firewalls (NGFW), VPNs, and Network Access Control (NAC) systems.",
"similarity": 0.6036
},
{
"kra_text": "Supports cloud security incident response including forensic log analysis, containment procedures, and post-incident remediation for cloud-based breaches.",
"sentence": "Incident Management: Act as the technical escalation point for network incidents.",
"similarity": 0.4905
},
{
"kra_text": "Reviews cloud infrastructure-as-code configurations for security misconfigurations and implements CIS Benchmark hardening baselines using CSPM tools.",
"sentence": "Lead security hardening and firewall rule optimization.",
"similarity": 0.4825
}
],
"matched_count": null,
"matched_skills": null,
"role_id": 23,
"score": 0.5255,
"slug": "cloud-security-engineer",
"total_count": null
},
{
"display_name": "Cloud Architect",
"kra_matches": [
{
"kra_text": "Designs multi-region and multi-availability-zone cloud infrastructure architectures for high availability, fault tolerance, and horizontal scalability.",
"sentence": "Optimization: Proactively tune network bandwidth, redundancy, and failover mechanisms to ensure 99.9% uptime.",
"similarity": 0.5194
},
{
"kra_text": "Designs IAM policies, service control policies, VPC segmentation, private endpoints, and zero-trust network access boundaries for cloud environments.",
"sentence": "Security \u0026 Access: Manage next-generation firewalls (NGFW), VPNs, and Network Access Control (NAC) systems.",
"similarity": 0.518
},
{
"kra_text": "Conducts architecture reviews, approves technical design documents, and guides engineering teams through cloud migration and modernization projects.",
"sentence": "Operational Excellence: Develop Standard Operating Procedures (SOPs) for L1/L2 teams and lead the review/execution of Network Change Requests (CRs).",
"similarity": 0.4464
}
],
"matched_count": null,
"matched_skills": null,
"role_id": 9,
"score": 0.4946,
"slug": "cloud-architect",
"total_count": null
}
],
"skill_match_roles": [
{
"display_name": "Cybersecurity Engineer",
"kra_matches": null,
"matched_count": 1,
"matched_skills": [
"VPN"
],
"role_id": 5,
"score": 0.0455,
"slug": "cybersecurity-engineer",
"total_count": 22
},
{
"display_name": "Cloud Architect",
"kra_matches": null,
"matched_count": 1,
"matched_skills": [
"DNS"
],
"role_id": 9,
"score": 0.0455,
"slug": "cloud-architect",
"total_count": 22
},
{
"display_name": "DevOps Engineer",
"kra_matches": null,
"matched_count": 1,
"matched_skills": [
"DNS"
],
"role_id": 10,
"score": 0.0455,
"slug": "devops-engineer",
"total_count": 22
},
{
"display_name": "Cloud Security Engineer",
"kra_matches": null,
"matched_count": 1,
"matched_skills": [
"VPN"
],
"role_id": 23,
"score": 0.0455,
"slug": "cloud-security-engineer",
"total_count": 22
}
]
},
"stage4_decision": {
"alias_collision_detected": false,
"case": "A",
"chosen_role": {
"display_name": "Cybersecurity Engineer",
"kra_matches": null,
"matched_count": null,
"matched_skills": null,
"role_id": 5,
"score": 0.5938,
"slug": "cybersecurity-engineer",
"total_count": null
},
"confidence": 0.5938,
"is_new_role": false,
"llm2_fired": false,
"llm2_reasoning": null,
"new_role_display_name": null,
"new_role_slug": null,
"queued": false,
"reasoning": "Skill+KRA converge on cybersecurity-engineer (0.05/0.59); alias agrees (cybersecurity-engineer)"
},
"stage5_updates": {
"centroid_n_after": 3,
"centroid_updated": true,
"collision_log_id": null,
"new_kra_attached": null,
"new_skills_attached": [
{
"is_primary": true,
"queue_id": 2421,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "LAN",
"status": "pending"
},
{
"is_primary": true,
"queue_id": 2422,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "WAN",
"status": "pending"
},
{
"is_primary": true,
"queue_id": 2423,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "WLAN",
"status": "pending"
},
{
"is_primary": true,
"queue_id": 2424,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "SD-WAN",
"status": "pending"
},
{
"is_primary": true,
"queue_id": 2425,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "Fortinet",
"status": "pending"
},
{
"is_primary": true,
"queue_id": 2426,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "BGP",
"status": "pending"
},
{
"is_primary": true,
"queue_id": 2427,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "OSPF",
"status": "pending"
},
{
"is_primary": true,
"queue_id": 2428,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "NGFW",
"status": "pending"
},
{
"is_primary": true,
"queue_id": 2429,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "Network Access Control",
"status": "pending"
},
{
"is_primary": true,
"queue_id": 2430,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "Cisco",
"status": "pending"
},
{
"is_primary": true,
"queue_id": 2431,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "BGP4",
"status": "pending"
},
{
"is_primary": true,
"queue_id": 2432,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "OSI model",
"status": "pending"
},
{
"is_primary": true,
"queue_id": 2433,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "TCP/IP",
"status": "pending"
},
{
"is_primary": true,
"queue_id": 2434,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "NAT/PAT",
"status": "pending"
},
{
"is_primary": true,
"queue_id": 2435,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "DHCP",
"status": "pending"
},
{
"is_primary": true,
"queue_id": 2436,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "TACACS",
"status": "pending"
},
{
"is_primary": true,
"queue_id": 2437,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "Wireshark",
"status": "pending"
},
{
"is_primary": true,
"queue_id": 2438,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "Network Management Systems",
"status": "pending"
},
{
"is_primary": true,
"queue_id": 2439,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "ITIL",
"status": "pending"
},
{
"is_primary": true,
"queue_id": 2440,
"role_display_name": "Cybersecurity Engineer",
"role_slug": "cybersecurity-engineer",
"skill_name": "Change Management",
"status": "pending"
}
],
"queue_entry_id": null,
"v3_pipeline_triggered": false,
"v3_role_slug": null,
"v3_run_id": null
}
}
API 2 — extract-details
{
"alias_matches": [
{
"alias_persist_skipped_reason": "alias_text already exists for this canonical skill",
"alias_persisted": false,
"existing_alias_id": 620,
"existing_alias_text": "VPN",
"input_term": "VPN",
"matched_canonical": {
"category_id": 10,
"display_name": "VPN",
"id": 304,
"is_also_category": false,
"is_extractable": true,
"skill_nature": "PROTOCOL",
"slug": "vpn",
"sub_category_id": 1373,
"typical_lifespan": "EVERGREEN",
"volatility": "STABLE"
},
"matched_via": "alias"
},
{
"alias_persist_skipped_reason": "alias_text already exists for this canonical skill",
"alias_persisted": false,
"existing_alias_id": 1285,
"existing_alias_text": "DNS",
"input_term": "DNS",
"matched_canonical": {
"category_id": 10,
"display_name": "DNS",
"id": 740,
"is_also_category": false,
"is_extractable": true,
"skill_nature": "PROTOCOL",
"slug": "dns",
"sub_category_id": 561,
"typical_lifespan": "EVERGREEN",
"volatility": "STABLE"
},
"matched_via": "alias"
}
],
"candidate_roles": [
{
"display_name": "Cloud Security Engineer",
"id": 23,
"rationale": null,
"role_archetype": null,
"slug": "cloud-security-engineer",
"source": "db"
},
{
"display_name": "Cybersecurity Engineer",
"id": 5,
"rationale": null,
"role_archetype": null,
"slug": "cybersecurity-engineer",
"source": "db"
},
{
"display_name": "DevOps Engineer",
"id": 10,
"rationale": null,
"role_archetype": null,
"slug": "devops-engineer",
"source": "db"
},
{
"display_name": "Cloud Architect",
"id": 9,
"rationale": null,
"role_archetype": null,
"slug": "cloud-architect",
"source": "db"
}
],
"chosen_role": {
"display_name": "Cybersecurity Engineer",
"id": 5,
"rationale": "The primary skills heavily lean towards network security, which aligns well with the Cybersecurity Engineer role.",
"role_archetype": null,
"slug": "cybersecurity-engineer",
"source": "db"
},
"dimensions": [
{
"dimension": {
"difficulty_hint": "well_known",
"display_name": "Cloud Network Security Controls",
"id": 242,
"rationale": "Controls and techniques for protecting cloud traffic, remote access, and boundary exposure. This includes segmentation, firewalling, private connectivity, and cloud-native network inspection patterns.",
"slug": "cloud-network-security-controls",
"source": "db"
},
"input_skill": "VPN",
"llm_role": null,
"roles_from_db": [
{
"display_name": "Cloud Security Engineer",
"id": 23,
"rationale": null,
"role_archetype": null,
"slug": "cloud-security-engineer",
"source": "db"
}
]
},
{
"dimension": {
"difficulty_hint": "well_known",
"display_name": "Network Security Controls",
"id": 60,
"rationale": "Controls and techniques for protecting network traffic, remote access, and perimeter exposure. This cluster is coherent because it covers the protocols and enforcement points used to reduce lateral movement and unauthorized access.",
"slug": "network-security-controls",
"source": "db"
},
"input_skill": "VPN",
"llm_role": null,
"roles_from_db": [
{
"display_name": "Cybersecurity Engineer",
"id": 5,
"rationale": null,
"role_archetype": null,
"slug": "cybersecurity-engineer",
"source": "db"
}
]
},
{
"dimension": {
"difficulty_hint": "well_known",
"display_name": "Cloud Networking and Connectivity",
"id": 153,
"rationale": "Network primitives and connectivity patterns used to expose services and connect environments. DevOps engineers need this to troubleshoot deployment reachability, ingress, DNS, and environment-to-environment communication.",
"slug": "cloud-networking-and-connectivity",
"source": "db"
},
"input_skill": "DNS",
"llm_role": null,
"roles_from_db": [
{
"display_name": "DevOps Engineer",
"id": 10,
"rationale": null,
"role_archetype": null,
"slug": "devops-engineer",
"source": "db"
}
]
},
{
"dimension": {
"difficulty_hint": "well_known",
"display_name": "Cloud Networking and Edge Connectivity",
"id": 136,
"rationale": "Network architecture for cloud environments, including segmentation, connectivity, and ingress/egress patterns. Cloud Architects use this to define trust boundaries and workload placement standards.",
"slug": "cloud-networking-and-edge-connectivity",
"source": "db"
},
"input_skill": "DNS",
"llm_role": null,
"roles_from_db": [
{
"display_name": "Cloud Architect",
"id": 9,
"rationale": null,
"role_archetype": null,
"slug": "cloud-architect",
"source": "db"
}
]
}
],
"input_final_skills": [
"LAN",
"WAN",
"WLAN",
"SD-WAN",
"Fortinet",
"BGP",
"OSPF",
"NGFW",
"VPN",
"Network Access Control",
"Cisco",
"BGP4",
"OSI model",
"TCP/IP",
"NAT/PAT",
"DNS",
"DHCP",
"TACACS",
"Wireshark",
"Network Management Systems",
"ITIL",
"Change Management"
],
"input_llm_skills": [
"LAN",
"WAN",
"WLAN",
"SD-WAN",
"Fortinet",
"BGP",
"OSPF",
"NGFW",
"VPN",
"Network Access Control",
"Cisco",
"BGP4",
"OSI model",
"TCP/IP",
"NAT/PAT",
"DNS",
"DHCP",
"TACACS",
"Wireshark",
"Network Management Systems",
"ITIL",
"Change Management"
],
"new_aliases_persisted": 0,
"run_id": "75cd1af2-4c0d-4852-8122-ca8685492154",
"skills_detail": [
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "LAN",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Networking",
"skill_nature": "CONCEPT",
"sub_category": "general",
"typical_lifespan": "EVERGREEN",
"version_strategy": "UNVERSIONED",
"volatility": "STABLE"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "lan",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
},
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "WAN",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Networking",
"skill_nature": "CONCEPT",
"sub_category": "general",
"typical_lifespan": "EVERGREEN",
"version_strategy": "UNVERSIONED",
"volatility": "STABLE"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "wan",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
},
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "WLAN",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Networking",
"skill_nature": "CONCEPT",
"sub_category": "general",
"typical_lifespan": "EVERGREEN",
"version_strategy": "UNVERSIONED",
"volatility": "STABLE"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "wlan",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
},
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "SD-WAN",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Networking",
"skill_nature": "CONCEPT",
"sub_category": "general",
"typical_lifespan": "MULTI_YEAR",
"version_strategy": "UNVERSIONED",
"volatility": "MEDIUM"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "sd-wan",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
},
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "Fortinet",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Security Tools",
"skill_nature": "TOOL",
"sub_category": "general",
"typical_lifespan": "MULTI_YEAR",
"version_strategy": "UNVERSIONED",
"volatility": "MEDIUM"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "fortinet",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
},
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "BGP",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Networking",
"skill_nature": "CONCEPT",
"sub_category": "general",
"typical_lifespan": "EVERGREEN",
"version_strategy": "UNVERSIONED",
"volatility": "STABLE"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "bgp",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
},
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "OSPF",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Networking",
"skill_nature": "CONCEPT",
"sub_category": "general",
"typical_lifespan": "EVERGREEN",
"version_strategy": "UNVERSIONED",
"volatility": "STABLE"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "ospf",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
},
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "NGFW",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Security Tools",
"skill_nature": "TOOL",
"sub_category": "general",
"typical_lifespan": "MULTI_YEAR",
"version_strategy": "UNVERSIONED",
"volatility": "MEDIUM"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "ngfw",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
},
{
"aliases_in_db": [
{
"alias_text": "VPN",
"alias_type": "CANONICAL",
"id": 620,
"is_primary": true,
"match_strategy": "CASE_INSENSITIVE"
}
],
"canonical": {
"category_id": 10,
"display_name": "VPN",
"id": 304,
"is_also_category": false,
"is_extractable": true,
"skill_nature": "PROTOCOL",
"slug": "vpn",
"sub_category_id": 1373,
"typical_lifespan": "EVERGREEN",
"volatility": "STABLE"
},
"dimensions": [
{
"dimension": {
"difficulty_hint": "well_known",
"display_name": "Cloud Network Security Controls",
"id": 242,
"rationale": "Controls and techniques for protecting cloud traffic, remote access, and boundary exposure. This includes segmentation, firewalling, private connectivity, and cloud-native network inspection patterns.",
"slug": "cloud-network-security-controls",
"source": "db"
},
"input_skill": "VPN",
"llm_role": null,
"roles_from_db": [
{
"display_name": "Cloud Security Engineer",
"id": 23,
"rationale": null,
"role_archetype": null,
"slug": "cloud-security-engineer",
"source": "db"
}
]
},
{
"dimension": {
"difficulty_hint": "well_known",
"display_name": "Network Security Controls",
"id": 60,
"rationale": "Controls and techniques for protecting network traffic, remote access, and perimeter exposure. This cluster is coherent because it covers the protocols and enforcement points used to reduce lateral movement and unauthorized access.",
"slug": "network-security-controls",
"source": "db"
},
"input_skill": "VPN",
"llm_role": null,
"roles_from_db": [
{
"display_name": "Cybersecurity Engineer",
"id": 5,
"rationale": null,
"role_archetype": null,
"slug": "cybersecurity-engineer",
"source": "db"
}
]
}
],
"input_skill": "VPN",
"matched_via": "alias",
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": null,
"source_tag": "db",
"was_in_llm_skills": true
},
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "Network Access Control",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Networking",
"skill_nature": "PRACTICE",
"sub_category": "general",
"typical_lifespan": "MULTI_YEAR",
"version_strategy": "UNVERSIONED",
"volatility": "MEDIUM"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "network-access-control",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
},
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "Cisco",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Networking",
"skill_nature": "TOOL",
"sub_category": "general",
"typical_lifespan": "MULTI_YEAR",
"version_strategy": "UNVERSIONED",
"volatility": "MEDIUM"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "cisco",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
},
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "BGP4",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Networking",
"skill_nature": "CONCEPT",
"sub_category": "general",
"typical_lifespan": "EVERGREEN",
"version_strategy": "UNVERSIONED",
"volatility": "STABLE"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "bgp4",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
},
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "OSI model",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Networking",
"skill_nature": "CONCEPT",
"sub_category": "general",
"typical_lifespan": "EVERGREEN",
"version_strategy": "UNVERSIONED",
"volatility": "STABLE"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "osi-model",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
},
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "TCP/IP",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Networking",
"skill_nature": "CONCEPT",
"sub_category": "general",
"typical_lifespan": "EVERGREEN",
"version_strategy": "UNVERSIONED",
"volatility": "STABLE"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "tcp-ip",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
},
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "NAT/PAT",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Networking",
"skill_nature": "CONCEPT",
"sub_category": "general",
"typical_lifespan": "EVERGREEN",
"version_strategy": "UNVERSIONED",
"volatility": "STABLE"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "nat-pat",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
},
{
"aliases_in_db": [
{
"alias_text": "DNS",
"alias_type": "CANONICAL",
"id": 1285,
"is_primary": true,
"match_strategy": "CASE_INSENSITIVE"
}
],
"canonical": {
"category_id": 10,
"display_name": "DNS",
"id": 740,
"is_also_category": false,
"is_extractable": true,
"skill_nature": "PROTOCOL",
"slug": "dns",
"sub_category_id": 561,
"typical_lifespan": "EVERGREEN",
"volatility": "STABLE"
},
"dimensions": [
{
"dimension": {
"difficulty_hint": "well_known",
"display_name": "Cloud Networking and Connectivity",
"id": 153,
"rationale": "Network primitives and connectivity patterns used to expose services and connect environments. DevOps engineers need this to troubleshoot deployment reachability, ingress, DNS, and environment-to-environment communication.",
"slug": "cloud-networking-and-connectivity",
"source": "db"
},
"input_skill": "DNS",
"llm_role": null,
"roles_from_db": [
{
"display_name": "DevOps Engineer",
"id": 10,
"rationale": null,
"role_archetype": null,
"slug": "devops-engineer",
"source": "db"
}
]
},
{
"dimension": {
"difficulty_hint": "well_known",
"display_name": "Cloud Networking and Edge Connectivity",
"id": 136,
"rationale": "Network architecture for cloud environments, including segmentation, connectivity, and ingress/egress patterns. Cloud Architects use this to define trust boundaries and workload placement standards.",
"slug": "cloud-networking-and-edge-connectivity",
"source": "db"
},
"input_skill": "DNS",
"llm_role": null,
"roles_from_db": [
{
"display_name": "Cloud Architect",
"id": 9,
"rationale": null,
"role_archetype": null,
"slug": "cloud-architect",
"source": "db"
}
]
}
],
"input_skill": "DNS",
"matched_via": "alias",
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": null,
"source_tag": "db",
"was_in_llm_skills": true
},
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "DHCP",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Networking",
"skill_nature": "CONCEPT",
"sub_category": "general",
"typical_lifespan": "EVERGREEN",
"version_strategy": "UNVERSIONED",
"volatility": "STABLE"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "dhcp",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
},
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "TACACS",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Networking",
"skill_nature": "CONCEPT",
"sub_category": "general",
"typical_lifespan": "EVERGREEN",
"version_strategy": "UNVERSIONED",
"volatility": "STABLE"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "tacacs",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
},
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "Wireshark",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Networking",
"skill_nature": "TOOL",
"sub_category": "general",
"typical_lifespan": "MULTI_YEAR",
"version_strategy": "UNVERSIONED",
"volatility": "MEDIUM"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "wireshark",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
},
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "Network Management Systems",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Networking",
"skill_nature": "TOOL",
"sub_category": "general",
"typical_lifespan": "MULTI_YEAR",
"version_strategy": "UNVERSIONED",
"volatility": "MEDIUM"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "network-management-systems",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
},
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "ITIL",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Practice",
"skill_nature": "PRACTICE",
"sub_category": "general",
"typical_lifespan": "MULTI_YEAR",
"version_strategy": "UNVERSIONED",
"volatility": "MEDIUM"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "itil",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
},
{
"aliases_in_db": [],
"canonical": null,
"dimensions": [],
"input_skill": "Change Management",
"matched_via": null,
"new_alias_persisted": false,
"new_alias_text": null,
"new_skill_meta": {
"derived": {
"category": "Practice",
"skill_nature": "PRACTICE",
"sub_category": "general",
"typical_lifespan": "MULTI_YEAR",
"version_strategy": "UNVERSIONED",
"volatility": "MEDIUM"
},
"enrichment": null,
"keep_log": [],
"locked_dimensions": [],
"merge_log": [],
"placed": null,
"relationships": null,
"skill_id": "change-management",
"split_log": [],
"typed": null,
"warnings": []
},
"source_tag": "llm",
"was_in_llm_skills": true
}
],
"unmatched_skills": [
"LAN",
"WAN",
"WLAN",
"SD-WAN",
"Fortinet",
"BGP",
"OSPF",
"NGFW",
"Network Access Control",
"Cisco",
"BGP4",
"OSI model",
"TCP/IP",
"NAT/PAT",
"DHCP",
"TACACS",
"Wireshark",
"Network Management Systems",
"ITIL",
"Change Management"
]
}
API 3 — final-role-output
{
"chosen_role": {
"display_name": "Cybersecurity Engineer",
"id": 5,
"rationale": "The primary skills heavily lean towards network security, which aligns well with the Cybersecurity Engineer role.",
"role_archetype": null,
"slug": "cybersecurity-engineer",
"source": "db"
},
"chosen_role_resolution": "in_db",
"final_input_skills": [
{
"skill": "LAN",
"tag": "new"
},
{
"skill": "WAN",
"tag": "new"
},
{
"skill": "WLAN",
"tag": "new"
},
{
"skill": "SD-WAN",
"tag": "new"
},
{
"skill": "Fortinet",
"tag": "new"
},
{
"skill": "BGP",
"tag": "new"
},
{
"skill": "OSPF",
"tag": "new"
},
{
"skill": "NGFW",
"tag": "new"
},
{
"skill": "VPN",
"tag": "in_db"
},
{
"skill": "Network Access Control",
"tag": "new"
},
{
"skill": "Cisco",
"tag": "new"
},
{
"skill": "BGP4",
"tag": "new"
},
{
"skill": "OSI model",
"tag": "new"
},
{
"skill": "TCP/IP",
"tag": "new"
},
{
"skill": "NAT/PAT",
"tag": "new"
},
{
"skill": "DNS",
"tag": "in_db"
},
{
"skill": "DHCP",
"tag": "new"
},
{
"skill": "TACACS",
"tag": "new"
},
{
"skill": "Wireshark",
"tag": "new"
},
{
"skill": "Network Management Systems",
"tag": "new"
},
{
"skill": "ITIL",
"tag": "new"
},
{
"skill": "Change Management",
"tag": "new"
}
],
"llm_cost_api1_usd": null,
"llm_cost_api2_usd": null,
"llm_cost_api3_usd": null,
"llm_cost_total_usd": null,
"persistence": {
"items": [
{
"chosen_role_id": 5,
"dimension": {
"difficulty_hint": "well_known",
"display_name": "Cloud Network Security Controls",
"id": 242,
"rationale": "Controls and techniques for protecting cloud traffic, remote access, and boundary exposure. This includes segmentation, firewalling, private connectivity, and cloud-native network inspection patterns.",
"slug": "cloud-network-security-controls",
"source": "db"
},
"dimension_id": 242,
"input_skill": "VPN",
"llm_role": null,
"matched_chosen_role": false,
"outcome_line": "Existing dimension (library) \u00b7 Role\u2194dimension skipped (dimension not under chosen role)",
"role_dimension_saved": false,
"roles_from_db": [
{
"display_name": "Cloud Security Engineer",
"id": 23,
"rationale": null,
"role_archetype": null,
"slug": "cloud-security-engineer",
"source": "db"
}
],
"skill_dimension_saved": true,
"skill_id": 304,
"skill_tag": "in_db",
"skipped_reason": null
},
{
"chosen_role_id": 5,
"dimension": {
"difficulty_hint": "well_known",
"display_name": "Network Security Controls",
"id": 60,
"rationale": "Controls and techniques for protecting network traffic, remote access, and perimeter exposure. This cluster is coherent because it covers the protocols and enforcement points used to reduce lateral movement and unauthorized access.",
"slug": "network-security-controls",
"source": "db"
},
"dimension_id": 60,
"input_skill": "VPN",
"llm_role": null,
"matched_chosen_role": true,
"outcome_line": "Existing dimension (library) \u00b7 Role\u2194dimension saved",
"role_dimension_saved": true,
"roles_from_db": [
{
"display_name": "Cybersecurity Engineer",
"id": 5,
"rationale": null,
"role_archetype": null,
"slug": "cybersecurity-engineer",
"source": "db"
}
],
"skill_dimension_saved": true,
"skill_id": 304,
"skill_tag": "in_db",
"skipped_reason": null
},
{
"chosen_role_id": 5,
"dimension": {
"difficulty_hint": "well_known",
"display_name": "Cloud Networking and Connectivity",
"id": 153,
"rationale": "Network primitives and connectivity patterns used to expose services and connect environments. DevOps engineers need this to troubleshoot deployment reachability, ingress, DNS, and environment-to-environment communication.",
"slug": "cloud-networking-and-connectivity",
"source": "db"
},
"dimension_id": 153,
"input_skill": "DNS",
"llm_role": null,
"matched_chosen_role": false,
"outcome_line": "Existing dimension (library) \u00b7 Role\u2194dimension skipped (dimension not under chosen role)",
"role_dimension_saved": false,
"roles_from_db": [
{
"display_name": "DevOps Engineer",
"id": 10,
"rationale": null,
"role_archetype": null,
"slug": "devops-engineer",
"source": "db"
}
],
"skill_dimension_saved": true,
"skill_id": 740,
"skill_tag": "in_db",
"skipped_reason": null
},
{
"chosen_role_id": 5,
"dimension": {
"difficulty_hint": "well_known",
"display_name": "Cloud Networking and Edge Connectivity",
"id": 136,
"rationale": "Network architecture for cloud environments, including segmentation, connectivity, and ingress/egress patterns. Cloud Architects use this to define trust boundaries and workload placement standards.",
"slug": "cloud-networking-and-edge-connectivity",
"source": "db"
},
"dimension_id": 136,
"input_skill": "DNS",
"llm_role": null,
"matched_chosen_role": false,
"outcome_line": "Existing dimension (library) \u00b7 Role\u2194dimension skipped (dimension not under chosen role)",
"role_dimension_saved": false,
"roles_from_db": [
{
"display_name": "Cloud Architect",
"id": 9,
"rationale": null,
"role_archetype": null,
"slug": "cloud-architect",
"source": "db"
}
],
"skill_dimension_saved": true,
"skill_id": 740,
"skill_tag": "in_db",
"skipped_reason": null
}
],
"new_skills_created": 0,
"role_dimension_saved": 0,
"skill_dimension_saved": 0,
"skipped": 0
},
"planner_output": null,
"run_id": "75cd1af2-4c0d-4852-8122-ca8685492154"
}
LLM Calls
Every model call made for this run, in pipeline order. Click a card to see the model's response.