Hands-on familiarity with security control planes and their APIs and policy models: EDR (CrowdStrike, SentinelOne, Defender), firewalls and segmentation (Palo Alto, Fortinet), identity and conditional access (Entra ID, Okta), SIEM and detection content (Splunk, Sentinel), cloud IAM, WAF, MDM, and GPO. Youll build agents that reason from a proven attack path to the specific control changes that break it - EDR policy, firewall and segmentation rules, conditional access, detection content, cloud IAM, GPO - apply or stage those changes in the customers environment, and then prove the fix by re-running the attack.