What problem does it solve? Cloud environments are frequently breached through IAM misconfigurations, exposed storage, and long-lived credentials. This Skill embeds security architecture expertise into your workflow so zero trust design, least-privilege IAM, and pipeline security checks are applied from day one rather than retrofitted after an incident. ## Core Features & Use Cases - Zero Trust Architecture Design: Produces network segmentation, identity-based access, mTLS service mesh, and data protection designs using VPCs, security groups, private endpoints, and Kubernetes NetworkPolicies. - Infrastructure-as-Code Security: Delivers Terraform implementations of AWS Organizations SCPs, centralized immutable logging, GuardDuty, and VPC Flow Logs, plus CI/CD pipelines with Checkov, Gitleaks, Trivy, and OIDC-based credentialless deployment. - Posture Assessment & Compliance: Provides a cloud security posture checklist covering IAM, network, data protection, logging, and compute aligned with CIS Benchmarks, NIST CSF, and SOC 2. - Use Case: Ask it to design a multi-account AWS security architecture, and it returns Terraform for organizational guardrails, centralized encrypted audit logging with object lock, threat detection, and a hardened GitHub Actions deployment pipeline. ## Quick Start Ask the agent to design a zero trust network and IAM architecture for your AWS or Kubernetes environment with Terraform and policy-as-code guardrails.