Security engineers & AppSec teams
The Security Engineering Stack
Threat modeling, security code review, zero-trust architecture, secrets management, ISO 27001, GDPR compliance, and ISMS auditing.
New to Agent Skills?
Click any skill below to read what it does, then install it into Claude Code, ChatGPT, Claude.ai, or another agent in minutes.
Skills in this stack
Senior Security Engineer
DevelopmentThreat modeling, penetration testing guidance, zero-trust architecture design, and security code review from a senior security engineering perspective.
Environment & Secrets Manager
DevelopmentDesign secure secrets management workflows — vaults, rotation policies, environment variable hygiene, and developer-friendly secret distribution.
GDPR/DSGVO Expert
ComplianceNavigate EU GDPR and German DSGVO compliance — data processing agreements, DPIAs, privacy policies, consent management, and data subject rights workflows.
Information Security Manager (ISO 27001)
ComplianceImplement and manage an ISMS per ISO 27001/27002 — risk assessments, security controls, incident management, and certification readiness.
ISMS Audit Expert
ComplianceConduct ISO 27001 internal audits — audit planning, evidence collection, nonconformance identification, and management review preparation.
Stack details
- Skills
- 5
- Audience
- Security engineers & AppSec teams
- License
- Free & open source
Works with
Claude skills for security engineers and AppSec teams cover both the technical and compliance dimensions of security work — threat modeling and code review on one side, ISO 27001 and GDPR documentation on the other. Most security teams handle these separately. This stack covers both so engineers have structured support for security decisions and the compliance documentation that comes alongside them.
What these skills do
Senior Security Engineer
Get senior security engineering perspective on architecture decisions — threat modeling, security design review, zero-trust implementation, authentication and authorization patterns, and the security tradeoffs that affect system design. Useful for reviewing new systems, assessing existing ones, or making decisions on security controls.
Environment & Secrets Manager
Design and implement secrets management practices — secret rotation, environment variable handling, vault configuration, and the operational security patterns that prevent credential exposure in development and production systems. Covers common platforms and the CI/CD integration patterns that matter in practice.
GDPR Expert
Assess data processing activities against GDPR requirements, draft privacy notices and data processing agreements, run Data Protection Impact Assessments, and document the lawful basis for processing activities. Covers the specific requirements for special category data and the cross-border transfer mechanisms that apply post-Schrems II.
Information Security Manager — ISO 27001
Design and document an information security management system to ISO 27001 standard — risk assessment methodology, Annex A control selection, Statement of Applicability, and the documentation structure that supports certification. Covers both initial ISMS design and the ongoing maintenance requirements.
ISMS Audit Expert
Prepare for and conduct ISMS audits — internal audit planning, evidence gathering, control effectiveness assessment, nonconformity identification, and the audit reporting format that gives leadership a clear picture of ISMS health.
Who this is for
- Security engineers and AppSec teams doing threat modeling and security code review
- Engineering teams implementing zero-trust architecture or managing secrets at scale
- Security leads responsible for ISO 27001 certification or ISMS audit preparation
- Engineering teams in regulated industries where GDPR compliance is a recurring requirement
For broader infrastructure security including CI/CD pipeline security, see the DevOps & Platform Stack. For the compliance and quality management angle in regulated industries, see the Compliance & Quality Stack.
More stacks
AI engineers & ML practitioners
The AI Engineer Stack
Build production AI systems — RAG pipelines, agent architectures, MCP servers, prompt engineering, and the MLOps to keep them running reliably.
11 skills
Life sciences researchers & bioinformaticians
The Bio Research Stack
Single-cell RNA QC, scVI tools, Nextflow pipeline development, scientific problem selection, instrument data conversion, and research workflow design.
6 skills
MedTech, healthtech & regulated industries
The Compliance & Quality Stack
Navigate regulatory requirements for medical devices and digital health — ISO 13485, FDA, EU MDR, ISO 27001, and GDPR in one coordinated stack.
12 skills