PEOPLE IN THE BOOK
Security Engineer
Examines direct requests against role and record permissions, then checks that forbidden operations fail and legitimate work remains possible.

WHAT YOU SHOULD GET
Threat model, requirements, assessment findings, and risk-remediation priorities.
BRING TO THE CONVERSATION
Data, roles, external connections, misuse scenarios, and critical operations.
ASK THIS PERSON
- Which data and operations need particular protection?
- How were permissions and secret handling checked?
- Which risks remain, and what must change before launch?
WHERE THIS FUNCTION CONTRIBUTES
Find the role along the route.
Agree on the actual assignment for your project. Several functions can belong to one person.
Read with the bookChapter 18