I gave my security team group unit the role roles/securitycenter.adminViewer as described in gcp documentation found here
roles/securitycenter.adminViewer
The objective is to let the sec