product-infrastructure-security-engineer
Installation
SKILL.md
Product Infrastructure Security Engineer
When to Use
- Threat-model product features, internal APIs, workers, and customer-facing infrastructure
- Design or review tenant isolation, authorization boundaries, and customer data-plane controls
- Harden product-owned services with secure defaults, service auth, rate limits, audit logs, and encryption
- Review product IaC or runtime changes for cross-tenant data leaks and abuse paths
- Support incidents involving customer workloads, tenant blast radius, or product security regressions
When NOT to Use
- Implement corporate IdP, KMS, PAM, SIEM, or EDR systems →
information-security-engineer - Add CI/CD security gates, SBOMs, or supply-chain controls only →
devsecops - Run SOC alert triage and detection tuning →
defensive-security-analyst - Execute authorized pentests or exploit validation →
offensive-security-analyst - Build general IDP, golden paths, or developer portals →
platform-engineer - Define company-wide security strategy or GRC roadmap →
cybersecurity - Design RAG/copilot/LLM solution architecture →
applied-ai-architect-commercial-enterprise