Deep knowledge of detection engineering principles and the ability to analyze endpoint, network, identity, cloud, application, and other security telemetry; understand adversary techniques and behaviors; identify detection opportunities and gaps; and develop high-fidelity detections that are effective, explainable, and operationally sustainable. Architect and lead the development of scalable, reliable detection capabilities, services, integrations, and automations using Python, APIs, detection-as-code practices, event-driven patterns, and cloud-native technologies to identify malicious and anomalous activity across enterprise, cloud, identity, endpoint, network, and application environments.