Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Compliance Engineer

  • 28 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Maps regulatory frameworks to technical controls and automates audit evidence for SOC 2, ISO 27001, GDPR, HIPAA, PCI, and NIST CSF.

About

An agent skill for compliance engineering that maps framework requirements to technical controls, automates audit evidence, and builds continuous compliance monitoring and auditor packages. A developer uses it when implementing audit controls, building evidence pipelines, or doing pre-attestation remediation.

  • Evidence pipelines, testable policy checks, and audit-ready documentation
  • Covers SOC 2, ISO 27001, GDPR, HIPAA, PCI, and NIST CSF

Compliance Engineer by the numbers

  • 28 all-time installs (skills.sh)
  • Ranked #1,512 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill compliance-engineer

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs28
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Maps regulatory frameworks to technical controls and automates audit evidence for SOC 2, ISO 27001, GDPR, HIPAA, PCI, and NIST CSF.

Files

SKILL.mdMarkdownGitHub ↗

Compliance Engineer

When to Use

  • Map security, privacy, or operational frameworks to technical controls
  • Build audit evidence pipelines from infrastructure, CI/CD, IdP, or ticketing systems
  • Design continuous control monitoring and exception workflows
  • Prepare evidence packages and remediation tracking for SOC 2, ISO 27001, GDPR, HIPAA, PCI, or NIST CSF
  • Translate policy requirements into testable engineering checks

When NOT to Use

  • Contract negotiation, DPAs, or commercial redlines → commercial-counsel
  • Corporate governance, board approvals, or entity matters → corporate-counsel
  • Financial close controls, journal entries, or SOX accounting evidence → senior-revenue-accountant
  • Broad security strategy without audit/control mapping → cybersecurity
  • CI/CD scan configuration without compliance evidence requirements → devsecops
  • Cloud-only framework evidence, residency, FedRAMP/PCI in AWS/GCP/Azure → cloud-compliance-specialist
  • GRC program charter, gap plans, audit prep, vendor questionnaires (non-technical) → compliance-specialist
  • Execute authorized penetration tests or write offensive findings → penetration-tester

Related skills

NeedSkill
GRC program, scope, gap plans, audit coordinationcompliance-specialist
Cloud SOC/HIPAA/PCI evidence and CSPM mappingcloud-compliance-specialist
Infrastructure capex SOX and asset controlsdirector-infrastructure-capex-accounting
Security program and IR strategycybersecurity
CI gates, SBOM, SSDF evidence from pipelinesdevsecops
IAM, encryption, guardrail implementationinformation-security-engineer
Access reviews, entitlement catalog, SoD evidence designiam-specialist
Data governance and privacy architecturedata-architect
AI system risk tiers and model governanceai-risk-governance
Enterprise cloud controls and residency designenterprise-cloud-architect
Privacy research for safeguard pipelinesprivacy-research-engineer-safeguards
Financial SOX control testingsenior-revenue-accountant
Commercial contract review and negotiationcommercial-counsel
Pentest reports (factual input to audits, not attestation)penetration-tester
Corporate governance, entity, board packagescorporate-counsel
HRIS access reviews, training completion opspeople-operations-specialist
Physical DC design and commissioning evidencedata-center-design-execution-lead
Incident artifact analysis and forensic investigation reports (factual)digital-forensics-analyst
Security risk registers, inherent/residual scoring, acceptancessecurity-risk-analyst

Core Workflows

1. Framework scoping

1. Identify in-scope systems, data classes, and subprocessors 2. Select frameworks (e.g., SOC 2 Type II, ISO 27001, GDPR, HIPAA, PCI) 3. Define trust service criteria / Annex A controls in scope 4. Document exclusions with risk acceptance 5. Align calendar: observation period, audit windows, evidence cutoffs

See `references/framework_scoping.md` for common scope boundaries.

2. Control design and mapping

Translate each control to testable technical implementation:

LayerExamples
PolicyApproved access policy
ProcessQuarterly access review ticket
TechnicalSSO enforced; IAM policy as code
EvidenceIdP export + review sign-off

Avoid controls that cannot be evidenced automatically or manually on schedule.

See `references/control_mapping.md` for SOC 2 / ISO mapping patterns.

3. Evidence automation

control ID → evidence source (API, Git, SIEM) → collector → storage → reviewer attestation

Evidence quality rules:

  • Timestamped, tamper-evident storage
  • Named owner per control
  • Sample size documented for population controls
  • Redact customer PII in shared audit folders

See `references/evidence_automation.md` for source catalog and collection cadence.

4. Continuous control monitoring

  • Detect drift from baseline (public buckets, open SGs, missing MFA)
  • Alert owners before audit finding
  • Integrate CSPM, Git policy checks, and HRIS for joiner/leaver
  • Weekly dashboard: pass/fail per control, trend

See `references/continuous_monitoring.md` for CCM metrics and alert routing.

5. Gap assessment and remediation

1. Run gap analysis against chosen framework 2. Classify: missing control, partial, implemented 3. Assign remediation with owner, due date, evidence plan 4. Verify fix with re-test and attach proof 5. Track exceptions with expiry and approver

See `references/audit_readiness.md` for pre-audit checklist.

6. Auditor engagement (engineering)

Prepare evidence packages per control family:

  • Access (IdP, reviews, privileged accounts)
  • Change management (PR approvals, deploy logs)
  • Vulnerability management (scan reports, SLAs)
  • Logging and monitoring (retention config, alert samples)
  • Vendor risk (subprocessor list, reviews)

Provide narrative only where logs are insufficient; prefer primary artifacts.

See `references/audit_readiness.md` for walkthrough agenda and FAQ for auditors.

7. Privacy engineering hooks (GDPR-style)

Coordinate with data-architect for:

  • Data inventory and lawful basis documentation
  • DSR workflows (access/delete) with engineering tickets
  • DPIA triggers for new processing
  • Cross-border transfer mechanisms (SCCs, etc.) as documented requirements—not legal advice

When to load references

  • Scope and frameworksreferences/framework_scoping.md
  • Control mappingreferences/control_mapping.md
  • Evidence collectorsreferences/evidence_automation.md
  • Drift and CCMreferences/continuous_monitoring.md
  • Audit prepreferences/audit_readiness.md

Related skills

Securitycomplianceaudit

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.