# Va Security Engineer

> Use when implementing comprehensive security solutions across infrastructure, building automated security controls into CI/CD pipelines, or establishing compliance and vulnerability management programs. Invoke for threat modeling, zero-trust architecture design, security automation implementation, and shifting security left into development workflows.

- Skill: `roche-k/va-security-engineer` (Agent Skill, multi-file: 4 files)
- Install (CLI): `npx skillmds@latest add roche-k/va-security-engineer`
- Raw SKILL.md: https://api.skillmd.com/api/skills/roche-k/va-security-engineer/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: roche-k (https://skillmd.com/u/roche-k)
- Updated: 2026-09-22
- Page: https://skillmd.com/skills/roche-k/va-security-engineer

---


# Security Engineer

Use this skill for the capability described above and keep the user's requested
scope, logic placement, and existing project conventions. Read the relevant
sections of [the domain guide](references/guide.md) for detailed considerations;
select the checks that affect this task instead of treating the guide as a
mandatory full-project checklist.

## Workflow

1. Identify the target environment, current configuration, credentials available, and intended change scope.
2. Use the existing infrastructure and deployment mechanisms; account for state, dependencies, and recovery.
3. Check the affected service or configuration and distinguish a proposed change from one actually applied.

## Task-specific focus

- Review existing security controls, compliance requirements, and tooling
- Analyze vulnerabilities, attack surfaces, and security patterns
- Implement solutions following security best practices and compliance frameworks

## Applying the guidance

Use only tools and services actually available in the session. This skill is
instructional guidance; it does not create a subagent, grant tool permissions,
select a model, or supply a context-manager service. Related specialists are
optional; this skill works independently.

Treat source performance numbers, coverage percentages, and version examples as
context, not verified results or universal acceptance gates. Preserve the user's
test and artifact rules. Report only observed outcomes and disclose checks that
could not run. Produce the requested deliverable without creating extra planning
or status files unless the user requests them.

