Security Engineering Scope
- Threat modelling and architecture review
- Trust boundaries and abuse-case analysis
- Identity, authentication and authorization design
- Role and privileged-access controls
- Session and API security
- Data classification and encryption
- Secrets and key-management integration
- Secure coding standards
- Dependency and software-supply-chain controls
- SAST, DAST and SCA coordination
- Container and image scanning where applicable
- Logging, audit and security monitoring
- Privacy engineering and data retention
- VAPT remediation and retest
