The Roles · Who defends it

Security engineer

Written from published sources

The person who builds and runs the controls. Where the architect decides that traffic between two zones must be authenticated and inspected, the engineer is the one who makes that true in a specific product, on a specific night, without breaking the applications that were already working. This is the role that turns a security decision into a running system, and then owns it.

What the day looks like

  • Implementing a control in the platform that actually exists, rather than the one the design assumed.
  • Tuning it afterwards, because the first configuration is always either too permissive or in the way.
  • Automating the deployment so the twentieth instance matches the first.
  • Being the person the application team argues with when the control blocks something legitimate.
  • Patching, upgrading and certificate renewal - the unglamorous work that decides whether the control is still real.

What it answers for

  • Controls that are deployed, functioning and monitored rather than merely purchased.
  • Changes that do not take production down in the name of securing it.
  • Knowing which controls are currently degraded, before someone else finds out.

What it is measured on

  • Coverage: how much of the estate the control actually reaches.
  • False positives, which is the number that decides whether the control survives its first month.
  • Time to deploy a change, since a control nobody can modify safely becomes a control nobody modifies.

Who it receives from

Security architecture
The design and the requirement it satisfies.
The security operations centre
What is not being detected, and what is drowning them.
Vendors
Products, and roadmaps that arrive later than promised.

Who it serves

The security operations centre
Telemetry that is complete enough to detect with.
Application and infrastructure teams
Controls that let them ship, rather than a queue.
Incident responders
The ability to contain, which depends on what was built beforehand.

Who else has a stake

  • Every team whose traffic passes through something this role configured.
  • The service desk, whose ticket volume moves with each tuning decision.
  • Finance, since licence consumption is a consequence of engineering choices.

What it takes

  • Real depth in at least one platform, and enough in the neighbouring ones to integrate them.
  • Change discipline, because this role breaks production in a uniquely embarrassing way.
  • The patience to tune rather than to disable.
  • Scripting, since consistency at scale is not achieved by hand.

What the job turns on

A control that is deployed but untuned is worse than no control: it produces noise that trains everyone to ignore it, and it is counted as coverage by whoever reports upward.

The published sources

Where it leads

The work itself

The Practice covers how this work is done — triage, escalation, evidence, handover — across the whole corpus.

Read The Practice