Security Engineering
Comprehensive security engineering skill covering application security, infrastructure security, compliance, and incident response.
When to Use This Skill
- Designing security architecture
- Implementing authentication and authorization
- Conducting threat modeling
- Security code review
- Implementing compliance controls (SOC2, HIPAA, PCI-DSS)
- Incident response planning
- Security monitoring and alerting
Security Architecture
Defense in Depth
Layer security controls at multiple levels:
| Layer |
Controls |
| Perimeter |
Firewall, WAF, DDoS protection |
| Network |
Segmentation, IDS/IPS, VPN |
| Host |
Hardening, EDR, patch management |
| Application |
Input validation, secure coding, SAST/DAST |
| Data |
Encryption, access control, DLP |
| Identity |
MFA, SSO, privileged access management |
Zero Trust Architecture
Core Principles:
- Never trust, always verify
- Assume breach mentality
- Least privilege access
- Micro-segmentation
- Continuous verification
Implementation:
- Identity-based access (not network-based)
- Device health verification
- Continuous authentication
- Encrypted communications everywhere
- Detailed logging and monitoring
Authentication Patterns
OAuth 2.0 / OIDC
Grant Types:
| Grant |
Use Case |
| Authorization Code + PKCE |
Web/mobile apps |
| Client Credentials |
Service-to-service |
| Device Code |
CLI tools, IoT |
Token Best Practices:
- Short-lived access tokens (15 min - 1 hour)
- Secure refresh token storage
- Token rotation on use
- Revocation capabilities
Session Management
- Secure, HttpOnly, SameSite cookies
- Session timeout (idle and absolute)
- Session invalidation on logout
- Concurrent session limits
- Session binding to device/IP
Multi-Factor Authentication
- TOTP (authenticator apps)
- WebAuthn/FIDO2 (hardware keys)
- Push notifications
- SMS (last resort, vulnerable to SIM swap)
Authorization Patterns
RBAC (Role-Based Access Control)
Users → Roles → Permissions
Best for: Well-defined organizational hierarchies
ABAC (Attribute-Based Access Control)
If user.department == "engineering" AND
resource.classification == "internal" AND
time.hour BETWEEN 9 AND 17
THEN allow
Best for: Complex, dynamic access requirements
Policy as Code
Use OPA/Rego or Cedar for externalized policy:
- Version controlled policies
- Testable access rules
- Audit trail
- Separation of concerns
Secure Development
OWASP Top 10 Mitigations
| Risk |
Mitigation |
| Injection |
Parameterized queries, input validation |
| Broken Auth |
Strong password policy, MFA, rate limiting |
| Sensitive Data |
Encryption, minimal data collection |
| XXE |
Disable external entities |
| Broken Access |
Authorization checks, default deny |
| Misconfig |
Secure defaults, hardening guides |
| XSS |
Output encoding, CSP |
| Deserialization |
Integrity checks, avoid untrusted data |
| Components |
Dependency scanning, updates |
| Logging |
Centralized logging, alerting |
Security Testing
SAST (Static Analysis):
- Run on every commit
- Block high-severity findings
- Tools: Semgrep, CodeQL, SonarQube
DAST (Dynamic Analysis):
- Run against staging/dev
- Tools: OWASP ZAP, Burp Suite
Dependency Scanning:
- Check for known vulnerabilities
- Tools: Snyk, Dependabot, npm audit
Secrets Management
Never:
- Commit secrets to git
- Log secrets
- Pass secrets in URLs
- Hardcode secrets
Do:
- Use secret managers (Vault, AWS Secrets Manager)
- Rotate secrets regularly
- Audit secret access
- Use short-lived credentials
Compliance Frameworks
Common Requirements
| Framework |
Focus Area |
| SOC 2 |
Trust services (security, availability, etc.) |
| HIPAA |
Healthcare data protection |
| PCI-DSS |
Payment card data |
| GDPR |
EU personal data protection |
| ISO 27001 |
Information security management |
Key Controls
- Access control and authentication
- Encryption (at rest and in transit)
- Logging and monitoring
- Incident response procedures
- Business continuity planning
- Vendor management
- Employee security training
Incident Response
Response Phases
- Preparation: Runbooks, tools, training
- Detection: Monitoring, alerting, triage
- Containment: Isolate, preserve evidence
- Eradication: Remove threat, patch vulnerabilities
- Recovery: Restore services, verify clean
- Lessons Learned: Post-mortem, improvements
Severity Levels
| Level |
Description |
Response Time |
| P1 |
Active breach, data exfiltration |
Immediate |
| P2 |
Vulnerability being exploited |
< 4 hours |
| P3 |
High-risk vulnerability discovered |
< 24 hours |
| P4 |
Security improvement needed |
Next sprint |
Reference Files
references/threat_modeling.md - STRIDE methodology and examples
references/compliance_controls.md - Framework-specific control mappings
Integration with Other Skills
- cloud-infrastructure - For cloud security
- debugging - For security incident investigation
- testing - For security testing patterns
1---2name: security-engineering3description: Security architecture and implementation patterns. Use when designing security controls, implementing authentication/authorization, conducting threat modeling, or ensuring compliance with security frameworks.4---5
6# Security Engineering
7
8Comprehensive security engineering skill covering application security, infrastructure security, compliance, and incident response.
9
10## When to Use This Skill
11
12- Designing security architecture
13- Implementing authentication and authorization
14- Conducting threat modeling
15- Security code review
16- Implementing compliance controls (SOC2, HIPAA, PCI-DSS)
17- Incident response planning
18- Security monitoring and alerting
19
20## Security Architecture
21
22### Defense in Depth
23
24Layer security controls at multiple levels:
25
26| Layer | Controls |
27|-------|----------|
28| Perimeter | Firewall, WAF, DDoS protection |
29| Network | Segmentation, IDS/IPS, VPN |
30| Host | Hardening, EDR, patch management |
31| Application | Input validation, secure coding, SAST/DAST |
32| Data | Encryption, access control, DLP |
33| Identity | MFA, SSO, privileged access management |
34
35### Zero Trust Architecture
36
37**Core Principles:**
38
391. Never trust, always verify
402. Assume breach mentality
413. Least privilege access
424. Micro-segmentation
435. Continuous verification
44
45**Implementation:**
46
47- Identity-based access (not network-based)
48- Device health verification
49- Continuous authentication
50- Encrypted communications everywhere
51- Detailed logging and monitoring
52
53## Authentication Patterns
54
55### OAuth 2.0 / OIDC
56
57**Grant Types:**
58
59| Grant | Use Case |
60|-------|----------|
61| Authorization Code + PKCE | Web/mobile apps |
62| Client Credentials | Service-to-service |
63| Device Code | CLI tools, IoT |
64
65**Token Best Practices:**
66
67- Short-lived access tokens (15 min - 1 hour)
68- Secure refresh token storage
69- Token rotation on use
70- Revocation capabilities
71
72### Session Management
73
74- Secure, HttpOnly, SameSite cookies
75- Session timeout (idle and absolute)
76- Session invalidation on logout
77- Concurrent session limits
78- Session binding to device/IP
79
80### Multi-Factor Authentication
81
82- TOTP (authenticator apps)
83- WebAuthn/FIDO2 (hardware keys)
84- Push notifications
85- SMS (last resort, vulnerable to SIM swap)
86
87## Authorization Patterns
88
89### RBAC (Role-Based Access Control)
90
91```
92Users → Roles → Permissions
93```
94
95Best for: Well-defined organizational hierarchies
96
97### ABAC (Attribute-Based Access Control)
98
99```
100If user.department == "engineering" AND
101 resource.classification == "internal" AND
102 time.hour BETWEEN 9 AND 17
103THEN allow
104```
105
106Best for: Complex, dynamic access requirements
107
108### Policy as Code
109
110Use OPA/Rego or Cedar for externalized policy:
111
112- Version controlled policies
113- Testable access rules
114- Audit trail
115- Separation of concerns
116
117## Secure Development
118
119### OWASP Top 10 Mitigations
120
121| Risk | Mitigation |
122|------|------------|
123| Injection | Parameterized queries, input validation |
124| Broken Auth | Strong password policy, MFA, rate limiting |
125| Sensitive Data | Encryption, minimal data collection |
126| XXE | Disable external entities |
127| Broken Access | Authorization checks, default deny |
128| Misconfig | Secure defaults, hardening guides |
129| XSS | Output encoding, CSP |
130| Deserialization | Integrity checks, avoid untrusted data |
131| Components | Dependency scanning, updates |
132| Logging | Centralized logging, alerting |
133
134### Security Testing
135
136**SAST (Static Analysis):**
137
138- Run on every commit
139- Block high-severity findings
140- Tools: Semgrep, CodeQL, SonarQube
141
142**DAST (Dynamic Analysis):**
143
144- Run against staging/dev
145- Tools: OWASP ZAP, Burp Suite
146
147**Dependency Scanning:**
148
149- Check for known vulnerabilities
150- Tools: Snyk, Dependabot, npm audit
151
152### Secrets Management
153
154**Never:**
155
156- Commit secrets to git
157- Log secrets
158- Pass secrets in URLs
159- Hardcode secrets
160
161**Do:**
162
163- Use secret managers (Vault, AWS Secrets Manager)
164- Rotate secrets regularly
165- Audit secret access
166- Use short-lived credentials
167
168## Compliance Frameworks
169
170### Common Requirements
171
172| Framework | Focus Area |
173|-----------|------------|
174| SOC 2 | Trust services (security, availability, etc.) |
175| HIPAA | Healthcare data protection |
176| PCI-DSS | Payment card data |
177| GDPR | EU personal data protection |
178| ISO 27001 | Information security management |
179
180### Key Controls
181
182- Access control and authentication
183- Encryption (at rest and in transit)
184- Logging and monitoring
185- Incident response procedures
186- Business continuity planning
187- Vendor management
188- Employee security training
189
190## Incident Response
191
192### Response Phases
193
1941. **Preparation**: Runbooks, tools, training
1952. **Detection**: Monitoring, alerting, triage
1963. **Containment**: Isolate, preserve evidence
1974. **Eradication**: Remove threat, patch vulnerabilities
1985. **Recovery**: Restore services, verify clean
1996. **Lessons Learned**: Post-mortem, improvements
200
201### Severity Levels
202
203| Level | Description | Response Time |
204|-------|-------------|---------------|
205| P1 | Active breach, data exfiltration | Immediate |
206| P2 | Vulnerability being exploited | < 4 hours |
207| P3 | High-risk vulnerability discovered | < 24 hours |
208| P4 | Security improvement needed | Next sprint |
209
210## Reference Files
211
212- **`references/threat_modeling.md`** - STRIDE methodology and examples
213- **`references/compliance_controls.md`** - Framework-specific control mappings
214
215## Integration with Other Skills
216
217- **cloud-infrastructure** - For cloud security
218- **debugging** - For security incident investigation
219- **testing** - For security testing patterns