Definition:
Social engineering (SE) is any act that influences a person to take an action that may or may not be in their best interests; it takes advantage of the fact that gender bias, racial, age, and status bias (as well as combinations of those biases) exist.
Why learn about SE
Most people take social engineering as someone wanting to gain small favours or obviously manipulation.
However, there is more to that from a security standpoint:
1. Identifying loopeholes - this is the process of identifying vulnerabilities within the chain; lets say in an organization by conducting simulated phishing and even physical intrusion campaings.
It helps the organization update their risk register and matrix as far as physical and information security is concerned.
2. Training to defend - after the loophole has been identified, it needs to be patched. This has to involve training of the relevant stakeholders because as Kevin Mitnick put it "There is no patch to human stupidity"