Image provenance and supply-chain integrity, registry and admission controls, runtime sandboxing and isolation, and Kubernetes hardening (RBAC, network policies, pod security), with particular attention to the isolated workers that execute customer workflows. Design, implement, and operate Servals infrastructure security program across cloud (AWS), Kubernetes, container runtimes, networking, and CI/CD, including hardening, configuration baselines, workload isolation, and continuous posture management.