Partner with Engineering to establish best-in-class application security through threat modeling for critical systems, secure design reviews, vulnerability intake and prioritization, dependency and software supply chain risk, penetration testing, security testing in CI/CD, remediation SLAs and risk acceptance, product security incident response, customer facing security-assurance. This will include: model approval and vendor management, data classification and model-use restrictions, agent identities and IAM, framework for human approvals, prompt-injection and data-exfiltration protections, logging and monitoring of agent actions, AI incident response, cost, quality, and business impact measurement.