Most of my work is for organisations where the data is sensitive and the output gets scrutinised: health plans, legal practices, a government agency. In that setting, a clever prompt isn't enough. What matters is where the data goes, whether an answer can be reproduced, and whether someone can check how it was reached.
So I spend a lot of time below the prompt layer — isolating sensitive data, making pipelines deterministic, and fine-tuning, compressing and self-hosting models when an API can't meet the cost, latency or data-residency requirement. I also build AI tooling for security testing, which has taught me a lot about where systems break.
Alongside the engineering, I teach. Explaining this material to a room of engineers is the quickest way I know to find the gaps in my own understanding.