Browse Skills

1307+ expert skills across 6 domains. Scored on 6 quality dimensions.

API Security Hardener

Platinum
90.2Security

Hardens API endpoints with rate limiting, input validation, CORS, CSP, authentication, bot protection, and gateway security following OWASP API Security Top 10.

api-securityrate-limitinginput-validation

Authentication & Authorization Architect

Platinum
89.6Security

Designs secure authentication and authorization systems using OAuth2, OIDC, JWT, RBAC/ABAC, MFA, and Passkeys with defense-in-depth strategies.

authenticationauthorizationoauth2

WebAuthn Passkey Engineer

Platinum
89.5Security

Expert guidance for implementing passwordless authentication with WebAuthn passkeys — covering registration/authentication ceremonies, platform vs roaming authenticators, cross-device flows, conditional UI, and migration from passwords to phishing-resistant credentials.

webauthnpasskeysfido2

Security Engineering

Platinum
89.5Security

Comprehensive application security guidance covering OWASP Top 10, authentication, authorization, encryption, secure coding practices, dependency auditing, and security architecture for building resilient software.

securityOWASPauthentication

Privileged Access Controls Specialist

Platinum
89.4Security

Design and implement privileged access management (PAM) systems including credential vaulting, just-in-time access, session management, and compliance-ready access governance for enterprise and cloud environments.

pamprivileged-accessiam

Supabase RLS Security Expert

Platinum
89.3Security

Design and implement production-grade Row-Level Security policies for Supabase applications, ensuring data isolation, multi-tenant security, and optimal query performance.

supabaserow-level-securityrls

Secrets Management Advisor

Platinum
89.3Security

Guides secure secrets lifecycle management including storage, rotation, access control, and CI/CD integration using Vault, cloud KMS, and zero-trust patterns.

secrets-managementvaultaws-secrets-manager

Security Architecture Reviewer

Platinum
89.1Security

Conduct systematic security architecture reviews to identify design flaws, missing controls, and compliance gaps before deployment.

security-architecturethreat-modelingarchitecture-review

Webhook Security Architect

Platinum
89.1Security

Design and implement secure webhook receiving endpoints with HMAC signature verification, replay attack prevention, idempotent processing, and secret rotation strategies.

webhook-securityhmac-verificationreplay-prevention

Container Runtime Security Expert

Platinum
89.1Security

Implement runtime security for containerized workloads including threat detection, policy enforcement, and incident response in Kubernetes.

container-securityruntime-securityfalco

API Security Hardening Specialist

Platinum
89.0Security

Comprehensive API security assessment and hardening specialist that analyzes REST, GraphQL, and gRPC APIs against the OWASP API Security Top 10, identifies vulnerabilities, and produces prioritized hardening plans with implementation roadmaps.

api-securityowasp-top-10security-hardening

OAuth Hardening Specialist

Platinum
89.0Security

Systematically audit and fortify OAuth 2.0 and OpenID Connect implementations against authorization code interception, redirect URI manipulation, token leakage, and scope escalation attacks using RFC-backed security best practices.

oauthoidcauthentication

IoT Security Specialist

Platinum
88.9Security

Secure IoT ecosystems from device to cloud, addressing firmware, communication, authentication, and lifecycle security challenges.

iot-securityembedded-securityfirmware

Red Team Operations Advisor

Platinum
88.8Security

Plan and execute adversary simulation exercises using real-world TTPs to validate defensive controls and detection capabilities.

red-teamadversary-simulationmitre-attack

DevSecOps Pipeline Architect

Platinum
88.8Security

Integrate security tooling and practices into CI/CD pipelines for automated, shift-left security at every stage of delivery.

devsecopscicd-securitysast

Penetration Testing Guide

Platinum
88.8Security

Guides defensive penetration testing methodology including scope definition, vulnerability assessment, and remediation reporting. Follows PTES and OWASP Testing Guide frameworks with strict defensive-only guardrails.

penetration-testingpentestowasp

Zero Trust Network Designer

Platinum
88.8Security

Designs zero trust architectures based on NIST SP 800-207 and BeyondCorp principles. Covers identity-based access, micro-segmentation, software-defined perimeters, and migration strategies from perimeter-based security.

zero-trustbeyondcorpmicro-segmentation

Mobile App Security Auditor

Platinum
88.8Security

Conducts comprehensive security audits of iOS and Android applications, covering OWASP Mobile Top 10, data storage, network communication, authentication, and binary protections with actionable remediation guidance.

mobile-securityowaspios-security

Security Code Reviewer

Platinum
88.7Security

Performs security-focused code reviews identifying vulnerabilities, misconfigurations, and insecure patterns across OWASP Top 10 categories with actionable fix recommendations.

securitycode-reviewowasp

Cryptography Implementation Advisor

Platinum
88.7Security

Advises on cryptographic implementation including encryption at rest/in transit, key management (KMS/HSM), TLS configuration, hashing algorithms, digital signatures, and post-quantum readiness. Focuses on correct usage of proven primitives rather than custom cryptography.

cryptographyencryptionkey-management

Secure SDLC Advisor

Platinum
88.5Security

Guides organizations in embedding security throughout every phase of the Software Development Lifecycle, from requirements gathering through deployment, using industry frameworks like BSIMM, OWASP SAMM, and threat modeling methodologies.

secure-sdlcssdlcthreat-modeling

Consent Logging Architect

Platinum
88.4Security

Designs tamper-evident consent logging architectures that provide audit-complete proof of user consent across GDPR, CCPA/CPRA, and ePrivacy regulations, with immutable event sourcing and real-time consent signal propagation.

consent-managementgdprccpa

Zero Trust Access Patterns

Platinum
88.4Security

Design and implement zero trust architecture patterns including identity-centric access, microsegmentation, continuous verification, and least-privilege enforcement across cloud and hybrid environments.

zero-trustidentitymicrosegmentation

Content Security Policy Architect

Platinum
88.3Security

Expert guidance for designing, deploying, and maintaining Content Security Policy (CSP) headers that effectively prevent XSS, data injection, and content integrity attacks across modern web applications.

cspcontent-security-policyxss-prevention
Page 1 of 2Next