security-architect

Design secure system architectures with Zero Trust and compliance frameworks.

Updated Dec 10, 2025
One-click install
npx skills add https://github.com/marcosfpina/phantom --skill security-architect-marcosfpina
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-architect
Source: https://github.com/marcosfpina/phantom/tree/main/skills/security-architect
Command: npx skills add https://github.com/marcosfpina/phantom --skill security-architect-marcosfpina

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill provides expert guidance on designing sophisticated, pragmatic security architectures to protect systems and data against evolving threats.

Core Features & Use Cases

  • Secure System Design: Architectures for cloud-native, hybrid, and legacy systems.
  • Threat Modeling: Identify and mitigate risks using STRIDE and other methodologies.
  • Compliance Frameworks: Align designs with NIST, ISO 27001, SOC 2, GDPR, HIPAA, etc.
  • Zero Trust & Defense-in-Depth: Implement robust security strategies.
  • Use Case: You are designing a new microservices-based application and need to ensure it adheres to Zero Trust principles, incorporates defense-in-depth, and meets SOC 2 compliance requirements.

Quick Start

Design a Zero Trust architecture for a cloud-native application that handles sensitive customer data.

Frequently Asked Questions about security-architect

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I design a Zero Trust architecture for a cloud-native application?

Threat modeling identifies and mitigates risks using methodologies like STRIDE. This process systematically uncovers security vulnerabilities in system design before implementation, ensuring robust protection against evolving threats.

How do I align my system architecture with SOC 2 and ISO 27001 compliance frameworks?

Defense in depth secures systems by layering multiple independent controls, so if one fails, others remain. This strategy protects cloud-native and hybrid architectures by mitigating risks across network, application, and data layers.

When do I need threat modeling for secure system design?

Implementing Zero Trust requires strict identity verification, device health checks, and micro-segmentation. This approach secures sensitive data by assuming breach and verifying every request explicitly across cloud-native environments.

What is the best way to implement defense in depth for hybrid systems?

Threat modeling identifies and mitigates risks using methodologies like STRIDE. This process systematically uncovers security vulnerabilities in system design before implementation, ensuring robust protection against evolving threats.