Knowledge of cloud security concepts, identity-based attacks, credential compromise, privilege escalation, lateral movement, data exfiltration, ransomware, phishing, malware, and emerging AI-enabled threats will be important to effectively investigate and respond to modern cyberattacks. The Incident Response Administrator will correlate and analyze telemetry from multiple security technologies-including SIEM, XDR, EDR, identity, network, cloud, email, and data protection platforms-to reconstruct attack activity, determine scope and impact, identify root cause, and recommend appropriate remediation actions.