security-engineer

Automate security controls and compliance across cloud-native environments.

68|6|Updated Apr 16, 2020
One-click install
npx skills add https://github.com/zenobi-us/dotfiles --skill security-engineer-zenobi-us
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-engineer
Source: https://github.com/zenobi-us/dotfiles/tree/main/devtools/files/opencode/skills/security-engineer
Command: npx skills add https://github.com/zenobi-us/dotfiles --skill security-engineer-zenobi-us

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The complex and ever-evolving security landscape, coupled with manual processes, often leads to critical vulnerabilities, compliance gaps, and reactive incident response. This Skill automates proactive security.

Core Features & Use Cases

  • DevSecOps Integration: Embed security into every phase of the development lifecycle with automation.
  • Cloud Security Mastery: Configure and manage security across AWS, Azure, and GCP environments.
  • Compliance Automation: Automate evidence collection and continuous monitoring for frameworks like SOC2 and ISO27001.
  • Use Case: Automatically audit your AWS environment against CIS benchmarks, identify critical vulnerabilities, and generate compliance reports for SOC2, all while integrating security into your CI/CD pipeline.

Quick Start

Use the security-engineer skill to perform a comprehensive security audit of your cloud infrastructure and generate a compliance report.

Frequently Asked Questions about security-engineer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate security audits and compliance checks in my cloud infrastructure?

Automate security audits by running continuous vulnerability scans and compliance checks against cloud environments. This Skill integrates with CI/CD pipelines to audit infrastructure against standards like CIS benchmarks, identify misconfigurations, and generate compliance reports for frameworks such as SOC2 and ISO27001 automatically.

Can I embed security controls into my DevSecOps workflow?

Yes. DevSecOps integration embeds automated security controls throughout the development lifecycle. This includes RBAC enforcement, secret management, encryption configuration, and network segmentation, ensuring security gates run alongside code deployment and infrastructure provisioning.

What security frameworks can I enforce across AWS, Azure, and GCP?

You can automate compliance for SOC2, ISO27001, and CIS benchmarks across multi-cloud environments. The Skill configures and validates security controls across AWS, Azure, and GCP, collecting evidence and monitoring continuously to maintain compliance posture.

How do I implement zero-trust architecture in Kubernetes clusters?

Implement zero-trust by automating network segmentation, RBAC policies, and encryption within Kubernetes deployments. This Skill configures least-privilege access controls and monitors cluster security to enforce zero-trust principles across containerized workloads.

Can I automate incident response and vulnerability remediation?

Yes. Automate vulnerability detection, risk assessment, and remediation workflows for infrastructure security incidents. The Skill identifies critical vulnerabilities in cloud-native environments and triggers automated responses within incident response processes.

Does this support secret management in containerized deployments?

Yes. Secret management automation secures sensitive data across containerized deployments and Kubernetes clusters. The Skill handles encryption, rotation, and access controls for secrets throughout your DevSecOps pipeline.