> security daemons
AKA compliance checkbox crap?
If infrastructure is immutable (which makes it work even better for autoscaling), nothing new will get installed unless you build a new image. Export whatever data you require to ensure things you want to be running are running. Monitor entry and exit points.
What is left for the "security deamons" to do?