Documented coursework, training, certification, or experience with Security Information and Event Management (SIEM) technology and security technologies, including intrusion detection and prevention systems (IDS/IPS), Data Loss Prevention (DLP), proxy technology, web application firewalls (WAF), endpoint detection and response (EDR), antivirus tools, sandboxing, network- and host-based firewalls, threat intelligence, and penetration testing. Documented coursework, training, certification, or experience identifying attack activity, including network probing and scanning, distributed denial-of-service (DDoS), and malicious code activity; networking protocols, including Transmission Control Protocol/Internet Protocol (TCP/IP), Domain Name System (DNS), and Hypertext Transfer Protocol (HTTP); and system security architecture and security solutions.