Partner with legal, commercial, engineering, and operations to translate customer contracts and data-license requirements into enforceable controls for data access, provenance, permitted use, retention, deletion, isolation, and auditability. CVEs, or have created security tooling on GitHub, have conference talks, bug bounty history, or blog posts about incidents/something security related they've done that would also be good.