Knowledge of cloud security concepts, identity-based attacks, credential compromise, privilege escalation, lateral movement, data exfiltration, ransomware, phishing, malware, and emerging AI-enabled threats will be important to effectively investigate and respond to modern cyberattacks. The Incident Response Administrator will correlate and analyze telemetry from multiple security technologies—including SIEM, XDR, EDR, identity, network, cloud, email, and data protection platforms—to reconstruct attack activity, determine scope and impact, identify root cause, and recommend appropriate remediation actions.