CISO / Security Lead
maxDefend everything, trust nothing
10 skills from OWASP to ransomware response. Security architecture, pen testing, DevSecOps, IAM, SAST/DAST, container hardening, and incident playbooks — everything your audit demands and your CI/CD actually needs. Ships secure or doesn't ship.
Core Skills
Conduct systematic security architecture reviews to identify design flaws, missing controls, and compliance gaps before deployment.
Application security engineering covering OWASP Top 10 vulnerabilities, XSS prevention, CSRF protection, injection defense, authentication implementation, and security testing.
Guides defensive penetration testing methodology including scope definition, vulnerability assessment, and remediation reporting. Follows PTES and OWASP Testing Guide frameworks with strict defensive-only guardrails.
Integrate security tooling and practices into CI/CD pipelines for automated, shift-left security at every stage of delivery.
Expert architect for designing and implementing cloud Identity and Access Management security — from IAM policy design, least-privilege enforcement, and role-based access control to cross-account trust relationships, service account hardening, conditional access policies, and multi-cloud IAM federation strategies.
Design and integrate Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tools into CI/CD pipelines with automated security gates, false positive triage workflows, and SARIF-based result aggregation.
Support Skills
Creates structured incident response playbooks with severity classifications, escalation procedures, communication templates, runbooks, postmortem frameworks, and blameless culture practices.
Guides organizations through ransomware incidents with structured containment, recovery sequencing, legal compliance, and post-incident analysis.
Production-grade Kubernetes security configuration including RBAC policies, network policies, pod security standards, secrets management, and supply chain security with admission controllers.
Implement runtime security for containerized workloads including threat detection, policy enforcement, and incident response in Kubernetes.
Usage
# Activate via MCP tool: load_powerpack slug: "ciso-security-lead" # Activate via REST API curl -H "Authorization: Bearer sk_supa_..." \ https://supaskills.ai/api/v1/powerpacks/ciso-security-lead/activate
Related PowerPacks
This PowerPack requires the max plan.