T EC H NIC A L
R EFER ENC E
·
ENG INEER ING
C O M P ET ENC Y
M A P
Back
-
End
Development
Technical
Skills
CO NT E NT S
01
Programming
Languages
02
Frameworks
&
Runtimes
03
Databases
&
Storage
Engines
04
Data
Modeling
&
Query
Optimization
05
APIs
&
Service
Interfaces
06
Architecture
&
Design
Patterns
07
Caching
&
Performance
Engineering
08
Messaging
,
Queues
&
Streaming
09
DevOps
,
CI
/
CD
&
Infrastructure
10
Cloud
Platforms
&
Managed
Services
11
Security
,
Auth
&
Identity
12
Testing
&
Quality
Engineering
13
Observability
&
Incident
Response
14
Version
Control
&
Collaboration
15
Background
Jobs
&
Data
Pipelines
16
Computer
Science
Foundations
01
Programming
Languages
Server
-
side
languages
in
production
use
today
,
plus
the
SQL
and
shell
fluency
every
back
-
end
engineer
is
expected
to
have
.
Java
LTS
17 / 21,
virtual
threads
,
JVM
tuning
Python
3.12+,
typing
,
async
/
await
,
packaging
TypeScript
strict
mode
,
generics
,
Node
runtimes
JavaScript
(
Node
.
js
)
event
loop
,
streams
,
worker
threads
Go
goroutines
,
channels
,
context
cancellation
C
#
.
NET
8,
LINQ
,
async
patterns
Rust
ownership
,
Tokio
async
runtime
Kotlin
coroutines
,
JVM
interoperability
Ruby
idiomatic
OO
,
metaprogramming
PHP
8.
x
,
PSR
standards
,
OPcache
Scala
functional
patterns
,
Akka
,
cats
-
effect
Elixir
OTP
supervision
trees
,
BEAM
concurrency
SQL
joins
,
window
functions
,
CTEs
,
transactions
Bash
/
POSIX
Shell
scripting
,
pipes
,
process
management
1 / 9
02
Frameworks
&
Runtimes
Application
frameworks
,
dependency
injection
,
middleware
pipelines
,
and
request
lifecycle
handling
.
03
Databases
&
Storage
Engines
Relational
,
document
,
key
-
value
,
wide
-
column
,
search
,
and
analytical
stores
—
plus
when
each
is
the
right
tool
.
Spring
Boot
Spring
MVC
,
Data
JPA
,
Security
,
Actuator
Django
ORM
,
migrations
,
admin
,
DRF
FastAPI
Pydantic
validation
,
dependency
injection
Flask
blueprints
,
extensions
,
WSGI
/
ASGI
NestJS
modules
,
guards
,
interceptors
,
DI
container
Express
/
Fastify
middleware
chains
,
schema
validation
ASP
.
NET
Core
minimal
APIs
,
middleware
,
EF
Core
Ruby
on
Rails
ActiveRecord
,
Action
Cable
,
conventions
Laravel
Eloquent
,
queues
,
service
container
Gin
/
Echo
Go
HTTP
routing
and
middleware
Quarkus
/
Micronaut
native
-
image
builds
,
fast
startup
Phoenix
Channels
,
LiveView
,
Ecto
Dependency
Injection
container
config
,
scopes
,
lifecycle
Middleware
&
Filters
request
/
response
interception
,
ordering
PostgreSQL
MVCC
,
extensions
,
JSONB
,
logical
replication
MySQL
/
MariaDB
InnoDB
,
replication
topologies
,
query
cache
Microsoft
SQL
Server
T
-
SQL
,
execution
plans
,
Always
On
MongoDB
aggregation
pipeline
,
sharding
,
replica
sets
Redis
data
structures
,
Lua
scripts
,
persistence
modes
Cassandra
/
ScyllaDB
tunable
consistency
,
partition
keys
DynamoDB
single
-
table
design
,
GSIs
,
capacity
modes
Elasticsearch
/
OpenSearch
inverted
indexes
,
analyzers
,
relevance
tuning
ClickHouse
columnar
storage
,
MergeTree
,
real
-
time
OLAP
Neo
4
j
Cypher
,
graph
traversals
,
relationship
modeling
Snowflake
/
BigQuery
warehouse
compute
,
cost
control
,
ELT
patterns
Object
Storage
S
3,
GCS
,
lifecycle
policies
,
presigned
URLs
Transactions
&
Isolation
ACID
,
isolation
levels
,
deadlock
handling
Replication
&
Failover
primary
/
replica
,
quorum
,
read
-
your
-
writes
2 / 9
04
Data
Modeling
&
Query
Optimization
Schema
design
decisions
that
determine
whether
a
system
scales
or
collapses
at
ten
million
rows
.
05
APIs
&
Service
Interfaces
How
services
talk
to
browsers
,
mobile
clients
,
and
each
other
—
synchronously
and
in
real
time
.
Normalization
&
Denormalization
3
NF
baselines
,
deliberate
denormalization
for
reads
Indexing
Strategy
B
-
tree
,
GIN
,
GiST
,
covering
and
partial
indexes
Query
Plan
Analysis
EXPLAIN
ANALYZE
,
sequential
scan
detection
N
+1
Query
Elimination
eager
loading
,
batching
,
DataLoader
Partitioning
&
Sharding
range
,
hash
,
list
;
shard
key
selection
Migrations
zero
-
downtime
DDL
,
backfills
,
rollback
plans
Connection
Pooling
PgBouncer
,
HikariCP
,
pool
sizing
math
Schema
Versioning
Flyway
,
Liquibase
,
Alembic
,
Prisma
Migrate
Data
Integrity
constraints
,
foreign
keys
,
check
rules
Time
-
Series
Modeling
retention
windows
,
downsampling
,
rollups
REST
resource
modeling
,
status
codes
,
pagination
GraphQL
schema
design
,
resolvers
,
N
+1
batching
gRPC
&
Protocol
Buffers
streaming
RPCs
,
code
generation
,
deadlines
WebSockets
connection
lifecycle
,
heartbeats
,
fan
-
out
Server
-
Sent
Events
one
-
way
streaming
for
live
updates
OpenAPI
/
Swagger
spec
-
first
design
,
generated
clients
API
Versioning
URI
vs
header
strategies
,
deprecation
policy
Idempotency
idempotency
keys
,
retry
safety
Rate
Limiting
&
Throttling
token
bucket
,
sliding
window
,
quotas
Pagination
cursor
-
based
,
keyset
,
stable
ordering
Webhooks
signing
,
retries
,
delivery
guarantees
Backend
for
Frontend
client
-
specific
aggregation
layers
API
Gateways
routing
,
transformation
,
auth
offload
Contract
-
First
Design
schema
review
before
implementation
3 / 9
06
Architecture
&
Design
Patterns
Structural
patterns
for
decomposing
systems
and
managing
the
complexity
that
decomposition
creates
.
07
Caching
&
Performance
Engineering
Reducing
latency
and
load
through
caching
layers
,
profiling
,
and
empirical
measurement
under
pressure
.
Modular
Monolith
enforced
module
boundaries
within
one
deployable
Microservices
service
boundaries
,
ownership
,
blast
radius
Event
-
Driven
Architecture
publish
/
subscribe
,
event
sourcing
,
choreography
CQRS
separate
read
and
write
models
,
projections
Domain
-
Driven
Design
aggregates
,
bounded
contexts
,
ubiquitous
language
Hexagonal
Architecture
ports
and
adapters
,
dependency
inversion
Clean
/
Onion
Architecture
use
-
case
layer
isolation
from
frameworks
Saga
Pattern
distributed
transactions
,
compensating
actions
Transactional
Outbox
atomic
DB
write
plus
event
publish
Circuit
Breaker
failure
isolation
,
half
-
open
recovery
Bulkhead
&
Timeout
resource
isolation
,
deadline
propagation
Serverless
&
FaaS
cold
starts
,
statelessness
,
event
triggers
Strangler
Fig
Migration
incremental
replacement
of
legacy
systems
SOLID
Principles
applied
at
module
and
service
boundaries
Application
Caching
in
-
process
caches
,
TTL
policies
,
invalidation
Distributed
Caching
Redis
,
Memcached
,
consistent
hashing
Cache
Invalidation
write
-
through
,
write
-
behind
,
stampede
control
HTTP
Caching
ETags
,
Cache
-
Control
,
conditional
requests
CDN
&
Edge
Caching
CloudFront
,
Cloudflare
,
cache
keys
,
purge
Database
Query
Tuning
index
usage
,
join
strategy
,
result
set
size
Profiling
JProfiler
,
py
-
spy
,
pprof
,
flame
graphs
Load
Testing
k
6,
Gatling
,
JMeter
,
Locust
Latency
Budgets
p
50/
p
95/
p
99
targets
,
tail
-
latency
control
Concurrency
Control
locks
,
optimistic
concurrency
,
semaphores
Batch
vs
Stream
Processing
choosing
the
cheaper
path
per
workload
Compression
&
Serialization
gzip
,
zstd
,
protobuf
,
MessagePack
4 / 9
08
Messaging
,
Queues
&
Streaming
Asynchronous
communication
between
services
:
delivery
semantics
,
ordering
,
and
backpressure
.
09
DevOps
,
CI
/
CD
&
Infrastructure
Building
,
shipping
,
and
running
services
repeatably
—
containers
,
pipelines
,
and
infrastructure
as
code
.
Apache
Kafka
partitions
,
consumer
groups
,
offset
management
RabbitMQ
exchanges
,
routing
keys
,
dead
-
letter
queues
AWS
SQS
/
SNS
FIFO
queues
,
fan
-
out
,
visibility
timeout
Google
Pub
/
Sub
push
vs
pull
,
ordering
keys
NATS
/
JetStream
lightweight
pub
/
sub
,
at
-
least
-
once
delivery
Apache
Pulsar
multi
-
tenancy
,
tiered
storage
Delivery
Semantics
at
-
most
-
once
,
at
-
least
-
once
,
exactly
-
once
Backpressure
Handling
flow
control
,
bounded
queues
,
shedding
Dead
-
Letter
Handling
poison
messages
,
retry
policies
,
alerting
Event
Schema
Evolution
Avro
,
JSON
Schema
,
Schema
Registry
Stream
Processing
Kafka
Streams
,
Flink
,
windowing
and
state
Docker
multi
-
stage
builds
,
layer
caching
,
slim
images
Kubernetes
deployments
,
services
,
ingress
,
HPA
,
probes
Helm
charts
,
values
templating
,
release
management
Terraform
modules
,
state
management
,
drift
detection
Ansible
playbooks
,
idempotent
configuration
GitHub
Actions
workflows
,
matrix
builds
,
reusable
actions
GitLab
CI
stages
,
runners
,
artifacts
and
caches
Jenkins
pipelines
as
code
,
agents
,
plugins
Argo
CD
/
Flux
GitOps
,
declarative
sync
,
progressive
delivery
Build
&
Artifact
Repos
Maven
,
Gradle
,
npm
,
Artifactory
,
ECR
Deployment
Strategies
blue
/
green
,
canary
,
rolling
,
feature
flags
Linux
Administration
systemd
,
permissions
,
networking
,
disk
I
/
O
Configuration
Management
env
vars
,
ConfigMaps
,
secrets
injection
Service
Mesh
Istio
,
Linkerd
,
mTLS
,
traffic
shifting
5 / 9
10
Cloud
Platforms
&
Managed
Services
Cloud
primitives
and
the
managed
equivalents
that
replace
self
-
hosted
infrastructure
.
11
Security
,
Auth
&
Identity
Protecting
data
,
authenticating
users
,
authorizing
actions
,
and
managing
secrets
and
vulnerabilities
.
AWS
EC
2,
ECS
/
EKS
,
Lambda
,
RDS
,
S
3,
IAM
,
VPC
Google
Cloud
GKE
,
Cloud
Run
,
Cloud
SQL
,
BigQuery
Microsoft
Azure
AKS
,
App
Service
,
Azure
SQL
,
Entra
ID
Serverless
Compute
Lambda
,
Cloud
Functions
,
Azure
Functions
Container
Orchestration
Services
ECS
Fargate
,
Cloud
Run
,
App
Runner
Managed
Databases
RDS
,
Aurora
,
Cloud
SQL
,
Atlas
,
ElastiCache
Networking
&
DNS
VPC
design
,
subnets
,
load
balancers
,
Route
53
Identity
&
Access
Management
roles
,
policies
,
least
privilege
,
OIDC
federation
Cost
Optimization
right
-
sizing
,
reserved
capacity
,
tagging
Multi
-
Region
Design
failover
,
data
residency
,
latency
routing
Infrastructure
Cost
Modeling
unit
economics
per
request
and
per
tenant
OAuth
2.0
authorization
code
+
PKCE
,
scopes
,
token
exchange
OpenID
Connect
ID
tokens
,
discovery
,
claims
validation
JWT
signing
algorithms
,
expiry
,
rotation
,
revocation
SAML
2.0 /
SSO
enterprise
federation
,
metadata
exchange
Session
Management
cookies
,
SameSite
,
refresh
token
rotation
RBAC
&
ABAC
roles
,
policies
,
attribute
-
based
rules
OWASP
Top
10
injection
,
broken
access
control
,
SSRF
Input
Validation
schema
validation
,
sanitization
,
allowlists
Encryption
TLS
1.3,
at
-
rest
encryption
,
key
rotation
Secrets
Management
HashiCorp
Vault
,
AWS
Secrets
Manager
,
SOPS
SAST
/
DAST
/
SCA
static
analysis
,
dependency
scanning
,
SBOMs
Threat
Modeling
STRIDE
,
trust
boundaries
,
attack
surface
Audit
Logging
tamper
-
evident
trails
,
compliance
retention
Compliance
Frameworks
SOC
2,
GDPR
,
HIPAA
,
PCI
DSS
controls
6 / 9
12
Testing
&
Quality
Engineering
Verification
at
every
level
of
the
stack
,
from
a
single
function
to
a
full
production
-
like
environment
.
13
Observability
&
Incident
Response
Knowing
what
your
system
is
doing
in
production
,
and
being
able
to
fix
it
quickly
when
it
misbehaves
.
Unit
Testing
JUnit
,
pytest
,
Jest
,
xUnit
,
Go
testing
Integration
Testing
Testcontainers
,
embedded
databases
,
fixtures
Contract
Testing
Pact
,
consumer
-
driven
contracts
,
provider
verification
End
-
to
-
End
Testing
Playwright
,
Cypress
,
Postman
collections
Test
Data
Management
factories
,
seeders
,
anonymized
production
data
Mocking
&
Stubbing
Mockito
,
WireMock
,
nock
,
MSW
Mutation
Testing
PIT
,
Stryker
,
test
-
suite
strength
measurement
Code
Coverage
Analysis
line
,
branch
,
and
meaningful
-
threshold
policy
Performance
Regression
Testing
baseline
benchmarks
in
CI
Chaos
Engineering
fault
injection
,
GameDays
,
failure
drills
Test
Pyramid
Discipline
proportioning
fast
vs
slow
tests
Static
Analysis
&
Linting
ESLint
,
SonarQube
,
Checkstyle
,
golangci
-
lint
Structured
Logging
JSON
logs
,
correlation
IDs
,
log
levels
Distributed
Tracing
OpenTelemetry
,
Jaeger
,
span
propagation
Metrics
&
Time
Series
Prometheus
,
Micrometer
,
StatsD
,
Grafana
Log
Aggregation
ELK
Stack
,
Loki
,
Splunk
,
Datadog
Logs
Alerting
&
On
-
Call
PagerDuty
,
alert
fatigue
,
escalation
policies
SLOs
,
SLIs
&
Error
Budgets
defining
reliability
targets
that
matter
Dashboards
RED
and
USE
methods
,
golden
signals
APM
Tooling
Datadog
APM
,
New
Relic
,
Elastic
APM
Incident
Management
severity
levels
,
roles
,
comms
cadence
Postmortems
blameless
analysis
,
action
item
tracking
Health
Checks
&
Readiness
liveness
probes
,
dependency
checks
7 / 9
14
Version
Control
&
Collaboration
Working
effectively
on
a
shared
codebase
—
branching
,
review
,
release
,
and
documentation
practices
.
15
Background
Jobs
&
Data
Pipelines
Work
that
must
not
block
a
request
:
scheduled
tasks
,
async
workers
,
ETL
,
and
orchestration
.
16
Computer
Science
Foundations
The
underlying
theory
that
explains
why
systems
fail
the
way
they
do
at
scale
.
Git
rebasing
,
cherry
-
picking
,
bisect
,
reflog
Branching
Strategies
trunk
-
based
development
,
release
branches
Pull
Request
Review
reviewing
for
correctness
,
not
style
preference
Commit
Hygiene
atomic
commits
,
conventional
commits
Merge
Conflict
Resolution
rebase
vs
merge
,
conflict
root
-
causing
Monorepo
Tooling
Nx
,
Bazel
,
Turborepo
,
affected
builds
Technical
Documentation
ADRs
,
runbooks
,
README
standards
Agile
Delivery
sprint
planning
,
estimation
,
scope
negotiation
Code
Review
Tooling
GitHub
,
GitLab
,
Bitbucket
,
Gerrit
Release
Management
semantic
versioning
,
changelogs
,
tagging
Task
Queues
Celery
,
Sidekiq
,
BullMQ
,
RQ
,
Hangfire
Workflow
Orchestration
Temporal
,
Airflow
,
Dagster
,
Step
Functions
Scheduling
cron
,
Quartz
,
Kubernetes
CronJobs
Batch
Processing
chunked
jobs
,
checkpointing
,
restartability
ETL
/
ELT
dbt
,
Apache
Spark
,
Airbyte
,
Fivetran
Idempotent
Job
Design
safe
replays
,
deduplication
keys
Retry
&
Backoff
Strategies
exponential
backoff
,
jitter
,
max
attempts
Job
Observability
queue
depth
metrics
,
stuck
-
job
alerting
Change
Data
Capture
Debezium
,
logical
decoding
,
WAL
streaming
Data
Quality
Checks
Great
Expectations
,
contract
assertions
Data
Structures
maps
,
heaps
,
tries
,
bloom
filters
,
LRU
caches
Algorithms
&
Complexity
Big
-
O
analysis
,
sorting
,
graph
traversal
Concurrency
&
Parallelism
threads
,
locks
,
atomics
,
race
conditions
Distributed
Systems
Theory
CAP
,
PACELC
,
consistency
models
Consensus
Algorithms
Raft
,
Paxos
,
leader
election
Networking
TCP
/
IP
,
HTTP
/2,
HTTP
/3,
DNS
,
TLS
handshakes
Operating
Systems
processes
,
memory
,
file
systems
,
syscalls
Memory
Management
garbage
collection
,
heap
sizing
,
leak
detection
System
Design
capacity
estimation
,
tradeoff
articulation
Fault
Tolerance
redundancy
,
graceful
degradation
,
idempotency
Capacity
Planning
traffic
modeling
,
headroom
,
scaling
curves
8 / 9
P R O F IC IEN C Y
S C AL E
Foundational
—
can
read
and
modify
existing
code
with
guidance
.
Working
—
ships
features
independently
in
production
.
Advanced
—
designs
solutions
and
mentors
others
on
tradeoffs
.
Expert
—
owns
architecture
,
sets
standards
,
handles
edge
cases
.
9 / 9