Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Cloud Security Engineer

  • 28 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Implement and audit cloud security: org guardrails, IAM hardening, network segmentation, KMS encryption, CSPM detective controls, and misconfig fixes.

About

Guides cloud security engineering on AWS/GCP/Azure covering org guardrails, IAM hardening, network segmentation, encryption/KMS, audit logging, CSPM, and misconfiguration remediation. A developer uses it when implementing or auditing cloud security controls.

  • Org guardrails (SCPs/org policies), cloud IAM hardening, KMS encryption
  • CSPM and detective controls: Config, Security Hub, GuardDuty, SCC, Defender

Cloud Security Engineer by the numbers

  • 28 all-time installs (skills.sh)
  • Ranked #1,512 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill cloud-security-engineer

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs28
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Implement and audit cloud security: org guardrails, IAM hardening, network segmentation, KMS encryption, CSPM detective controls, and misconfig fixes.

Files

SKILL.mdMarkdownGitHub ↗

Cloud Security Engineer

When to Use

  • Design and implement org/account guardrails — SCPs, policy constraints, landing zone security
  • Harden cloud IAM — roles, trust policies, permission boundaries, federation, break-glass
  • Secure cloud networking — segmentation, SG/NSG rules, private endpoints, egress control
  • Configure encryption — KMS/CMK policies, default encryption, TLS, secrets managers
  • Enable audit and detective controls — CloudTrail/Audit Logs, Config, GuardDuty, CSPM
  • Remediate misconfigurations from scans, audits, or Well-Architected security pillar
  • Review workload designs for cloud threat patterns (IMDS, public buckets, open SGs)
  • Integrate cloud findings into vulnerability and exception workflows
  • Support incident forensics with cloud log analysis (with SOC/IR partners)

When NOT to Use

  • Company security strategy, policies, board metrics → cybersecurity
  • SSO/PAM/SIEM/EDR for corp-wide stack (non-cloud-specific) → information-security-engineer
  • SAST/SCA/SBOM and GitHub Actions hardening → devsecops
  • Live SOC alert triage and playbooks → soc-analyst
  • Cloud telemetry threat hunts and ATT&CK campaigns → threat-hunter
  • Authorized exploitation and pentest validation → penetration-tester
  • Network/AD/infra pentest from corp paths → network-pentester
  • Web/API OWASP testing → web-pentester
  • GRC program, audit prep, vendor questionnaires → compliance-specialist
  • SOC 2 control narratives and audit binders → compliance-engineer, cloud-compliance-specialist
  • Build VPC/RDS without security as primary goal → cloud-engineer
  • Landing zone business architecture and migration → cloud-architect
  • Cloud program strategy and CCoE investment themes → vp-of-cloud
  • Product multi-tenant isolation in app layer → product-infrastructure-security-engineer
  • Cloud access tickets and patching → cloud-system-administrator
  • Entitlement design, access reviews, federation, PAM → iam-specialist
  • Customer security questionnaires, deal compliance fit (architecture) → solutions-architect

Related skills

NeedSkill
VP cloud program and risk investment themesvp-of-cloud
Corporate security tooling and IdPinformation-security-engineer
Pipeline and supply-chain securitydevsecops
Cloud architecture and WAF reviewscloud-architect
Enterprise CCoE and regulated programenterprise-cloud-architect
Cloud resource implementationcloud-engineer
Terraform platform modulesinfrastructure-engineer
GRC program, gap plans, audit coordinationcompliance-specialist
Compliance evidence (org-wide)compliance-engineer
Cloud audit evidence and framework mappingcloud-compliance-specialist
SOC triage and playbookssoc-analyst
Active security IR, cloud log coordinationincident-responder
Cloud telemetry threat hunts and hunt campaignsthreat-hunter
Cloud alert investigation and detection tuningdefensive-security-analyst
Pentest validationpenetration-tester
Network/AD/infra pentestnetwork-pentester
Web/API OWASP pentestweb-pentester
Product tenancyproduct-infrastructure-security-engineer
Customer deal security/compliance fit memosolutions-architect
CVD and disclosuretechnical-program-manager-security-cvd
Cloud audit log forensics and super-timelines after preservationdigital-forensics-analyst
Security risk registers and treatment prioritizationsecurity-risk-analyst
IAM lifecycle, access reviews, federation, PAMiam-specialist

Core Workflows

1. Scope and shared responsibility

Cloud security boundaries, provider vs customer duties.

See `references/cloud_security_scope.md`.

2. Cloud IAM and identity

Roles, federation, privilege escalation prevention.

See `references/identity_iam_cloud.md`.

3. Network security in cloud

Segmentation, private access, logging.

See `references/network_cloud_security.md`.

4. Data protection and KMS

Encryption, keys, secrets.

See `references/data_encryption_kms.md`.

5. Logging, CSPM, and detection

Audit logs, posture management, native detectors.

See `references/detection_cspm_logging.md`.

6. Architecture review and remediation

Threat patterns, review checklist, fix prioritization.

See `references/secure_cloud_architecture_review.md`.

Outputs

  • Guardrail definition — SCP/policy JSON, exceptions, rollout plan
  • IAM policy set — least-privilege roles with trust boundaries documented
  • Network security diagram — zones, flows allowed/denied, private endpoints
  • Remediation backlog — finding, severity, owner, compensating control
  • Control evidence — Config rules, scan exports, sample audit log queries
  • Architecture review notes — risks, required controls before launch

Principles

  • Deny by default — explicit allow for network and IAM
  • Security as code — guardrails versioned and reviewed like application code
  • Detect and prove — every preventive control has a detective check
  • Break-glass is rare and monitored — not a bypass for convenience
  • Minimize blast radius — account segmentation and permission boundaries

Related skills

Securityappsecaudit

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.