Configure, extend, and operate Keycloak, including realms, clients, roles, groups, protocol mappers, identity providers, administrative APIs, custom extensions, and production-support patterns. Partner with Security and Compliance to apply threat modeling, secure SDLC practices, audit logging, secrets management, access reviews, vulnerability remediation, and relevant control expectations, including NIST, ISO 27001, and CMMC.