security-engineer

Audit infrastructure security controls and configurations across cloud, on-premise, and CI/CD environments.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/KojiroSasa/www.havoc-it.ro --skill security-engineer-kojirosasa
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-engineer
Source: https://github.com/KojiroSasa/www.havoc-it.ro/tree/main/.agent/skills/secagent--security-engineer
Command: npx skills add https://github.com/KojiroSasa/www.havoc-it.ro --skill security-engineer-kojirosasa

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes assets (resource) components.

What problem does it solve?

This Skill helps organizations implement DevSecOps practices by embedding security into every stage of the SDLC, automating vulnerability management, compliance checks, and incident response to reduce risk and accelerate delivery.

Core Features & Use Cases

  • Security assessment & posture reviews across cloud, on-prem, and hybrid environments to identify gaps.
  • Automation of security controls in CI/CD pipelines, IaC, and runtime protection with policy-driven guardrails.
  • Compliance & incident readiness including evidence collection, reporting, and runbooks for rapid response.

Quick Start

Run a comprehensive infrastructure security assessment and generate a prioritized remediation roadmap for the current environment.

Frequently Asked Questions about security-engineer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate infrastructure security auditing across cloud and on-premise environments?

Automate infrastructure security auditing by scanning configurations and threat surfaces across cloud, on-prem, and hybrid environments to identify control gaps. The process enforces CIS benchmarks and generates a prioritized remediation roadmap for identified vulnerabilities.

What is the best way to embed DevSecOps controls into CI/CD pipelines?

Embed DevSecOps controls into CI/CD pipelines by applying policy-driven guardrails to infrastructure as code and runtime environments. This automates security testing and secret management throughout the software development lifecycle to reduce delivery risk.

Does this approach support compliance automation and evidence collection for audits?

Compliance automation is supported through continuous control checks and auditable evidence collection. It satisfies security engineering requirements by mapping configurations against CIS benchmarks and generating reports for rapid compliance verification.

Can I use this for incident response readiness in hybrid infrastructure?

Use this for incident response readiness in hybrid infrastructure by automating threat surface analysis and deploying response runbooks. It enables rapid remediation of configuration gaps and vulnerabilities across cloud and on-premise deployments.

How do I run a comprehensive security posture review for my current environment?

Run a comprehensive security posture review by auditing existing infrastructure controls, configurations, and threat surfaces. The assessment identifies security gaps and outputs a prioritized remediation roadmap tailored to your specific environment.

What are the limitations of automating vulnerability management with policy-driven guardrails?

Automating vulnerability management with policy-driven guardrails is limited by the accuracy of configuration inputs and the scope of defined policies. It requires correctly mapping CIS benchmarks to your specific infrastructure to avoid false positives or missed threat surfaces.