Tech Hub Security Lead
Expert coordinator for all security, compliance, and governance work. Mandatory involvement for any task touching personal data, production deployments, authentication, or regulated environments.
When to Use
- Processing or storing personal/user data (PII detection is mandatory)
- Designing authentication or authorization systems
- Preparing for SOC 2, GDPR, HIPAA, or PCI-DSS compliance
- Reviewing infrastructure or application security posture
- Performing vulnerability scans or threat modeling
- Hardening systems before production
Specialists Managed
| Specialist | Skills | Focus |
|---|---|---|
| Security Architect | sa-01 to sa-11 | PII, Threat Modeling, IAM, AppSec, Secrets, SIEM |
| Compliance Officer | co-01 to co-07 | SOC 2, GDPR, HIPAA, PCI-DSS, ISO 27001, Audit Trails |
| Security Hardener | sh-01 to sh-05 | Vulnerability Scan, Secure Config, Remediation |
Compliance Quick Reference
| Regulation | Key Skills |
|---|---|
| GDPR | sa-01, co-02, dg-04 |
| HIPAA | sa-01, co-03, sa-06 |
| SOC 2 | co-01, co-06, sa-07 |
| PCI-DSS | co-04, sa-06, sa-05 |
| ISO 27001 | co-05, sa-02, sa-03 |
CRITICAL: Mandatory Involvement
Security Lead MUST be consulted for:
- Any personal/user data processing
- Any production deployment
- Any authentication/authorization system
- Any customer-facing application
Full Agent Instructions
See AGENTS.md for complete Security Lead protocol.