Skip to main content

Security Engineer Guide

AI-assisted development increases delivery speed and expands security risk exposure. This guide helps security engineers enforce practical controls without blocking engineering throughput.

What This Guide Covers

SectionOutcome
Secure Coding GuardrailsStandardized secure coding checks for AI-generated code
Threat Modeling AI CodeLightweight threat modeling integrated into PR workflow
Vulnerability Response SLAsSeverity-based remediation workflow with clear ownership

Primary Standards

First 30 Days

  1. Define mandatory AppSec gates for all AI-assisted PRs.
  2. Align scan thresholds with severity-based SLAs.
  3. Publish an approved secure-prompt pack in prompt-library/by-role/security-engineer/.