Skill 詳細

cybersecurity

Broad enterprise cybersecurity strategy, control design, risk, incident, and GRC guidance.

一致度直接一致サイバーセキュリティ 向けにレビュー済み
出典daemon-blockint-tech/agentic-enteprises-skill外部ソース
報告インストール数33人気度の参考値

使用前に確認

自動レビューは関連性のみを確認し、安全性や推奨を保証しません。使用前に出典の説明を読んでください。

保存された出典プレビュー

SKILL.md

これはレビュー時に保存された抜粋です。完全で最新の内容は外部ソースを確認してください。

---
name: cybersecurity
description: |
  Guides enterprise cybersecurity across security architecture, control design, vulnerability and
  threat management, incident response, identity security, and GRC alignment (SOC 2, ISO 27001, NIST CSF).
  Use when defining security strategy, assessing risk, designing defense-in-depth, running security
  incidents, scoping penetration tests, writing security policies, or high-level GRC strategy—not for
  hands-on audit evidence automation (compliance-engineer), GRC program/audit prep
  (compliance-specialist),
  embedding scans in CI/CD (devsecops), provisioning cloud networks (infrastructure-engineer), or
  LLM or enterprise red team (ai-redteam, red-team-specialist), binary RE (reverse-engineer),
  web/API pentest (web-pentester), or on-call/SEV program
  (incident-management-engineer).
---

# Cybersecurity

## When to Use

- Define enterprise security strategy, policy, and control architecture
- Assess risk across identity, infrastructure, applications, vendors, and incident readiness
- Design defense-in-depth programs aligned to NIST CSF, ISO 27001, SOC 2, or similar frameworks
- Scope penetration tests, vulnerability management programs, or security incident response
- Prepare high-level GRC, board, or leadership security narratives

## When NOT to Use

- GRC program, framework scope, gap plans, audit prep → `compliance-specialist`
- Implement audit evidence automation or control-by-control mapping → `compliance-engineer`
- Add SAST, SBOM, OIDC, or pipeline security gates → `devsecops`
- Triage SOC alerts, SIEM queues, or SOAR cases → `soc-analyst`
- Proactive threat hunts and hunt program design → `threat-hunter`
- Alert-driven investigation and detection tuning → `defensive-security-analyst`
- Execute authorized penetration tests or PoCs → `penetration-tester`
- Lead red team / adversary simulation campaigns → `red-team-specialist`
- Execute web/API OWASP assessments → `web-pentester`
- Hands-on binary, firmware, or protocol reverse engineering → `reverse-engineer`
- Provision cloud networks, clusters, or infrastructure modules → `infrastructure-engineer`
- Design application integration ADRs → `senior-system-architecture`

## Related skills

| Need | Skill |
|---|---|
| Pipeline scanning, SBOM, CI OIDC | `devsecops` |
| Cloud/K8s hardening implementation | `infrastructure-engineer` |
| AI model risk, policies, EU AI Act | `ai-risk-governance` |
| LLM jailbreaks and prompt injection tests | `ai-redteam` |
| SOC alert triage, playbooks, shift handoffs | `soc-analyst` |
| Proactive threat hunts, ATT&CK campaigns, hunt metrics | `threat-hunter` |
| Alert investigation, detection tuning, DFIR depth | `defensive-security-analyst` |
| Authorized pentest, exploitation, retest | `penetration-tester` |
| CTI function, intel briefs, IOC/TTP production, ISAC sharing | `cti-analyst` |
| Red team, purple team, adversary simulation | `red-team-specialist` |
| Binary RE, patch diff, defensive malware analysis | `reverse-engineer` |
| Network/AD/infra pentest methodology | `network-pentester` |
| Web/API pentest methodology | `web-pentester` |
| Web/API OWASP and proxy-based pentest | `web-pentester` |
| Implement IAM, encryption, SIEM, guardrails | `information-security-engineer` |
| Product multi-tenancy, customer data plane security | `product-infrastructure-security-engineer` |
| GRC program, audit prep, vendor questionnaires | `compliance-specialist` |
| Control implementation, audit evidence automation | `compliance-engineer` |
| On-call, SEV, postmortem, paging integrations | `incident-management-engineer` |
| Active security incident response (CSIRT) | `incident-responder` |
| SOC alert triage | `soc-analyst` |
| Vendor/customer contract security exhibits and DPAs | `commercial-counsel` |
| Solution architecture review (app layer) | `senior-system-architecture` |
| Applied AI / LLM commercial & enterprise architecture | `applied-ai-architect-commercial-enterprise` |
| Crisis and security 
GitHub で全文を読む (外部ページ)
関連情報

関連する仕事