Back to skills
Engineering — Core

Senior Secops

Senior Secops: Improve day-to-day security operations. Review alerts, asset inventory, detection gaps, response paths, and staffing and produce a SecOps plan with detection and response checks.

---
name: engineering-team-senior-secops
description: Use for senior secops when asked to improve day-to-day security operations; produce a SecOps plan with detection and response checks.
license: MIT
metadata:
  author: Thrive
  category: engineering-team
---

# Senior Secops

## When to use

Use this skill for senior secops when you need to improve day-to-day security operations. The expected result is a SecOps plan with detection and response checks.

## Boundaries

Work within the requested task and its stated acceptance criteria. Drafting an artifact does not authorize publishing it, spending funds, changing a live system, or contacting another person. Identify any such action separately before taking it.

## Inputs

Inspect alerts, asset inventory, detection gaps, response paths, and staffing. Resolve missing information that would change the method; state lesser assumptions in the result.

## Method

1. **Diagnose.** Find the exact call path, interface owner, tests, and failure reproduction before changing shared code.
2. **Decide.** Prioritize high-signal detections and clear triage ownership.
3. **Produce.** Build a SecOps plan with detection and response checks from the inspected material; keep assumptions distinguishable from observed facts.

## Decision rules

- Keep the change at the narrowest boundary that fixes the cause. Document any contract change and migrate callers deliberately.
- When sources or constraints conflict, record the conflict and choose the path supported by the user's goal and the strongest available evidence. If neither path can be supported, identify the missing decision before changing the artifact.

## Domain rules

- Inspect the code path and tests before changing a shared interface.
- Prefer a reproduction and focused regression test over a broad speculative refactor.

## Verification

Test an alert from detection through closure. Compare the result with the user's acceptance criteria and record any unverified boundary.

Show the failing case, changed files, targeted test result, and any broader integration check affected by the change.

## Stop conditions

If a material input, required authorization, or a safe way to verify the result is absent, stop the affected action. Return the specific blocker and the smallest fact or decision needed to continue. Do not report an unrun check as passed.

## Output

Provide a SecOps plan with detection and response checks. Include the decisive evidence and actual verification result. Name any artifact location and unresolved issue that affects its use.

<!--
MIT License

Copyright (c) 2026 Thrive

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
-->