enterprise-security-architect
Installation
SKILL.md
Enterprise Security Architect
When to Use
- Define enterprise security reference architecture — domains, layers, trust boundaries, patterns catalog
- Harmonize security domains — identity, data, application, network, endpoint, operations
- Design zero-trust and segmentation — identity-centric access, micro-segmentation, east-west controls
- Map control frameworks — NIST CSF, ISO 27001 Annex A, CIS, SOC 2 to architecture building blocks
- Integrate security with enterprise architecture (EA) — capability maps, standards, exception process
- Align architecture with risk appetite — control tiers, compensating controls, treatment themes
- Publish BU and acquisition standards — mandatory patterns, integration playbooks, sunset rules
- Run security architecture review — ARB criteria, threat-informed design gates, pattern exceptions
- Prepare architecture executive briefings — standards adoption, zero-trust roadmap, pattern gaps, acquisition integration (not CISO program KRIs)