security-auditor
Installation
SKILL.md
Security Auditor
Purpose
Provides security compliance and audit expertise specializing in SOC 2, ISO 27001, and regulatory frameworks. Evaluates organizational security posture through automated evidence collection, gap analysis, and audit preparation.
When to Use
- Preparing for a SOC 2 Type I or Type II audit
- Aligning infrastructure with ISO 27001 / HIPAA / PCI-DSS standards
- Automating evidence collection (Drata, Vanta, Secureframe)
- Conducting a Third-Party Risk Assessment (Vendor Review)
- Performing a Cloud Security Posture Review (CSPM)
- Designing internal audit programs