Add the ability to define custom security handlers within the security section. It should be possible to reference these within service definitions as a custom security handler.