Skip to main content 홈 크리에이터 daemon-blockint-tech agentic-enteprises-skill cyber-resilience-engineer
cyber-resilience-engineer Designs and operates cyber resilience capabilities—RTO/RPO architecture, backup/restore and
immutable backup patterns, dependency mapping for critical services, crisis playbooks for
ransomware, destructive malware, and cloud control-plane loss, chaos and failure injection for
security-relevant failures, resilience testing with evidence, and alignment with NIST CSF
Recover and business continuity. Use when engineering recovery objectives and tiers, designing
backup immutability and restore validation, running resilience or chaos tests, mapping
attack-scenario playbooks, reporting resilience metrics, or sustaining continuity during active
attacks—not enterprise BCM program ownership alone (bcm-disaster-recovery-specialist), live
incident command (incident-responder), SRE performance and toil only (site-reliability-engineer),
backup operator runbooks without architecture (cloud-system-administrator), GRC audit prep only
(compliance-specialist), or CISO board strategy (chief-information-security-officer).
설치로 이동 Skills Marketplace 커뮤니티가 만든 AI 스킬을 발견하고 탐색하세요.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill cyber-resilience-engineer명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
Zip 다운로드 다운로드 중... Guides experimentation engineering for A/B and multivariate tests—hypothesis framing,
primary/secondary/guardrail metrics, design (A/B, A/B/n, MVT), sample size and power,
duration and seasonality, allocation and randomization units, SRM checks, instrumentation,
analysis plans (frequentist and Bayesian workflow level), stopping rules, readouts,
rollout/kill decisions, and experiment registry hygiene (sound statistical practice only).
Use for "A/B test", "A/B testing engineer", "experiment design", "sample size calculator",
"statistical significance", "power analysis", "split test", "experiment readout",
"guardrail metrics", "SRM", "randomization unit", "experiment duration", "multivariate test",
"holdout", or "experiment analysis". Not for analytics stack build (analytics-data-engineer),
marketing copy (cmo-advisor), roadmap-only (cpo-advisor), ML model experiments
(ml-research-engineer-safeguards), or privacy/legal review (compliance-engineer).
Guides hands-on actuarial analyst work for insurance, reinsurance, and pension—reserving and loss
development (IBNR, triangles, chain-ladder diagnostics), pricing and rate indication support
(experience, trend, credibility, basic GLM at spec level), data validation and model I/O review,
reporting packs and workpapers, assumption application under actuary direction, and statutory
tie-outs at analyst depth. Use when the user mentions actuarial analyst, loss development, IBNR,
reserve analysis, rate indication, pricing support, actuarial workpaper, triangle analysis,
credibility, experience study, actuarial reporting, or reserve roll-forward—not actuary sign-off
(actuary), consulting engagements (actuarial-consulting), assumption governance (assumption-setting),
ALM strategy (asset-liability-management), P&C legal depth (property-casualty-insurance), charts only
(data-visualization), or ETL-only pipelines (data-scrubbing).
Guides actuarial consulting engagements—client scoping and SOW design, stakeholder communication
(CFO, risk, boards, regulators at overview level), due diligence and M&A actuarial support,
reserving/pricing/capital review programs, model validation and opinion support, regulatory
interaction prep, and deliverable governance (memos, exhibits, management presentations).
Use when the user mentions actuarial consulting, actuarial engagement, reserve opinion,
due diligence actuarial, model validation engagement, actuarial memo, SOW actuarial,
regulatory actuarial, M&A reserves, or actuarial review—not deep technical modeling execution
(actuary), P&C line education only (property-casualty-insurance), legal advice
(commercial-counsel), or generic management consulting without actuarial lens
(business-consultant).
daemon-blockint-tech
daemon-blockint-tech/Agentic-Enteprises-Skill
GitHub 저장소 열기 name cyber-resilience-engineer description Designs and operates cyber resilience capabilities—RTO/RPO architecture, backup/restore and
immutable backup patterns, dependency mapping for critical services, crisis playbooks for
ransomware, destructive malware, and cloud control-plane loss, chaos and failure injection for
security-relevant failures, resilience testing with evidence, and alignment with NIST CSF
Recover and business continuity. Use when engineering recovery objectives and tiers, designing
backup immutability and restore validation, running resilience or chaos tests, mapping
attack-scenario playbooks, reporting resilience metrics, or sustaining continuity during active
attacks—not enterprise BCM program ownership alone (bcm-disaster-recovery-specialist), live
incident command (incident-responder), SRE performance and toil only (site-reliability-engineer),
backup operator runbooks without architecture (cloud-system-administrator), GRC audit prep only
(compliance-specialist), or CISO board strategy (chief-information-security-officer).
Cyber Resilience Engineer
When to Use
Define RTO/RPO and recovery tiers for production, security, and identity services
Design backup, restore, and immutability architecture (object lock, air-gap, WORM, vault isolation)
Map critical service dependencies and failure domains for continuity during attacks
Author attack-scenario playbooks (ransomware, wiper, IdP loss, logging blind spot, cloud control-plane)
Plan and run resilience tests —restore drills, game days, chaos/failure injection with pass/fail evidence
Align engineering deliverables with NIST CSF Recover and BCM/IR interfaces
Produce resilience metrics and engineering briefs for leadership and audit consumers
When NOT to Use
Own enterprise BCM program, BIA facilitation, and regulatory BCM policy → bcm-disaster-recovery-specialist
Lead active incident war room, containment, and forensic preservation → incident-responder
Define SEV matrices, paging policy, and status-page program → incident-management-engineer
Operate SLIs, SLOs, error budgets, and capacity toil without recovery design → site-reliability-engineer
Execute ticket-level snapshots and restores without resilience architecture → cloud-system-administrator
Control-by-control audit evidence and framework mapping only → compliance-specialist
Board-level security strategy and risk appetite without engineering recovery → chief-information-security-officer
Broad security program ownership without resilience engineering → cybersecurity
Greenfield cloud landing zone without recovery lens → cloud-engineer (pair for placement; you own RTO/RPO fit)
Related skills Need Skill BCM/DR program, BIA, tabletops, crisis comms cadence bcm-disaster-recovery-specialistActive CSIRT response, containment, timelines incident-responderIncident program, SEV, on-call, postmortem process incident-management-engineerSLO impact, reliability mitigation, error budgets site-reliability-engineerBackup/restore execution, snapshots, operational hygiene cloud-system-administratorSIEM/EDR/IdP/KMS implementation and hardening information-security-engineerSecurity program, IR policy, executive narratives cybersecurityCISO strategy, board reporting, risk appetite chief-information-security-officerCloud architecture, DR regions, service selection cloud-engineer
Core Workflows
1. Scope and engineering charter Clarify resilience boundaries, ownership, and interfaces with BCM, IR, SRE, and platform teams.
See references/cyber_resilience_scope.md.
2. Recovery objectives and tiers Set RTO/RPO, tiering, and recovery strategies with explicit trade-offs and test hooks.
See references/recovery_objectives_and_tiers.md.
3. Backup, restore, and immutability Design backup topology, isolation, encryption, and restore validation for cyber events.
See references/backup_restore_and_immutability.md.
4. Resilience testing and chaos Plan game days, restore drills, and controlled failure injection with evidence and remediation.
See references/resilience_testing_and_chaos.md.
5. Attack scenarios and playbooks Engineer playbooks for ransomware, destructive malware, identity and logging loss, and cloud control-plane failure.
See references/attack_scenarios_and_playbooks.md.
6. Metrics, reporting, and governance Track RTA vs RTO, restore success, test coverage, and NIST CSF Recover alignment for stakeholders.
See references/metrics_reporting_and_governance.md.
Outputs
Resilience architecture — tiers, dependencies, backup/immutability design, failure domains
RTO/RPO register — per service with strategy, owner, last test, and known gaps
Playbook pack — attack-scenario sequences with decision gates and IR handoffs
Test report — scope, RTA/RPO achieved, integrity checks, findings, remediation backlog
Chaos/game-day summary — hypothesis, blast radius, controls validated, follow-ups
Resilience dashboard brief — KPIs, trend, top risks (engineering lens; not legal advice)
Principles
Engineer for compromise — assume attacker presence; prefer rebuild and immutable recovery paths
Test restores, not jobs — backup success ≠ recoverable; measure RTA and data integrity
Recover security first — identity, logging, and detection before convenience workloads
Separate roles — resilience engineering complements BCM policy and IR command
Evidence by design — every tier and playbook links to a test or exercise with dated results