senior-security-engineer

Eliminate vulnerabilities and enforce security controls across web apps, APIs, and cloud infrastructure.

Updated Mar 3, 2026
One-click install
npx skills add https://github.com/AbrahamOO/security-mcp --skill senior-security-engineer
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: senior-security-engineer
Source: https://github.com/AbrahamOO/security-mcp/tree/main/skills/senior-security-engineer
Command: npx skills add https://github.com/AbrahamOO/security-mcp --skill senior-security-engineer

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The Senior Security Engineer persona actively fortifies code, APIs, cloud infrastructure, and AI/LLM integrations by writing secure code, implementing robust security controls, and enforcing policies to prevent vulnerabilities.

Core Features & Use Cases

  • Actively rewrites insecure code and config to adhere to security best practices across web apps, APIs, mobile apps, cloud environments, and AI components.
  • Implements defense-in-depth measures including input validation, authentication, authorization, secret management, encryption, and secure deployment pipelines.
  • Applies security frameworks (OWASP, MITRE ATT&CK, NIST) to guide design, validation, and compliance while balancing development velocity.

Quick Start

Activate the Senior Security Engineer persona to start fortifying your stack immediately.

Frequently Asked Questions about senior-security-engineer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I fix insecure code and enforce security controls in my web APIs?

To fix insecure code and enforce security controls in web APIs, you need to implement input validation, authentication, and least-privilege access. Rewriting configurations to align with OWASP and MITRE ATT&CK frameworks actively eliminates vulnerabilities during development and deployment.

What is the best way to secure cloud infrastructure and AI integrations?

Securing cloud infrastructure and AI integrations requires defense-in-depth measures like secret management, encryption, and policy enforcement. Applying NIST controls ensures robust protection across runtime environments while balancing development velocity.

How does threat modeling map to MITRE ATT&CK and NIST controls for software surfaces?

Threat modeling maps to MITRE ATT&CK and NIST controls by providing traceable validations for security design. This mapping guides the enforcement of least-privilege access and policy compliance across REST/GraphQL APIs, mobile apps, and cloud environments.

Can I use automated code fixes to implement defense-in-depth for mobile apps?

Yes, you can use automated code fixes to implement defense-in-depth for mobile apps. Actively rewriting insecure code establishes robust authentication, authorization, and encryption controls to prevent vulnerabilities across deployment pipelines.

Does this approach apply to both development and runtime environments?

Yes, this approach applies to both development and runtime environments. Fortifying software surfaces requires eliminating vulnerabilities and enforcing security controls continuously across web apps, cloud infrastructure, and AI components throughout their lifecycle.

Why should I map secure code practices to OWASP and MITRE ATT&CK frameworks?

Mapping secure code practices to OWASP and MITRE ATT&CK frameworks provides traceable validation for eliminating vulnerabilities. It guides the implementation of input validation and secret management to ensure compliance while maintaining development velocity.