security-engineer

Produce threat models, risk registers, and security checklists across SDLC phases.

9|1|Updated Mar 21, 2026
One-click install
npx skills add https://github.com/e-t-y-b/etyb-skills --skill security-engineer-e-t-y-b
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-engineer
Source: https://github.com/e-t-y-b/etyb-skills/tree/main/skills/security-engineer
Command: npx skills add https://github.com/e-t-y-b/etyb-skills --skill security-engineer-e-t-y-b

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Security engineering leadership and threat-modeling guidance to integrate security across the software development lifecycle, enabling teams to design, build, and ship with verifiable security controls.

Core Features & Use Cases

  • Provides threat-modeling guidance (STRIDE/PASTA/LINDDUN) and security design reviews spanning AppSec, Infrastructure, IAM, and compliance to identify and mitigate risks early.
  • Acts as an on-demand security consultant that triggers at Design, Plan, Verify, and Ship gates, producing security requirements, risk registers, and guardrails aligned to organizational policies.
  • Leverages dedicated references (appsec-specialist, infra-security-specialist, iam-specialist, compliance-specialist, secret-management, security-reviewer) to tailor recommendations and ensure cross-cutting security coverage.

Quick Start

Ask the Security Engineer to produce a threat model and security requirements for the upcoming release.

Frequently Asked Questions about security-engineer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I integrate threat modeling into the software development lifecycle?

Threat modeling integrates into the SDLC by applying frameworks like STRIDE, PASTA, or LINDDUN during planning, design, and deployment phases to reduce design and implementation flaws. It produces security requirements, risk registers, and automated gating guardrails aligned with organizational policies.

What is the best way to conduct a security architecture review for cloud infrastructure?

A security architecture review for cloud infrastructure evaluates AppSec, IAM, and data protection controls against regulatory compliance standards. It generates security design decisions and checklists to reduce implementation flaws across the deployment phase.

Can I use automated security gating for risk management during software releases?

Automated security gating applies risk-based guidance at the verify and ship phases to ensure safer software releases. It triggers security design reviews and compliance checks, producing security checklists and guardrails that enforce policy alignment across the SDLC.

When do I need risk-based security guidance for regulatory compliance?

Risk-based security guidance for regulatory compliance is needed when designing software products, cloud infrastructure, or data protection workflows. It ensures policy alignment by producing risk registers, security requirements, and design decisions tailored to compliance standards during the planning phase.

Does threat modeling work with existing AppSec and IAM specialist workflows?

Threat modeling works with AppSec and IAM specialist workflows by leveraging dedicated references to tailor security recommendations. This ensures cross-cutting security coverage across infrastructure, application security, identity access management, and secret management during architecture reviews.