Own AI and agentic risk, mitigating threats like prompt injection, excessive agency, and context/memory poisoning; design human-in-the-loop gates for high-risk actions; and define least-privilege scoping, audit logging, and short-lived credentials for agent and connector integrations, including for the Model Context Protocol (MCP). Lead security assurance for the experience and UI layer, driving threat modeling, security design reviews, and targeted code review (JavaScript/TypeScript, Java) across web and UI frameworks, runtimes, rendering pipelines, and the guest-user-exposed data-access APIs beneath them.