Design, implement, and operate Serval's infrastructure security program across cloud (AWS), Kubernetes, container runtimes, networking, and CI/CD, including hardening, configuration baselines, workload isolation, and continuous posture management. Image provenance and supply-chain integrity, registry and admission controls, runtime sandboxing and isolation, and Kubernetes hardening (RBAC, network policies, pod security), with particular attention to the isolated workers that execute customer workflows.