Design, write, deploy, and tune high-fidelity detection logic using Structured Query Language (SQL), Sigma, YARA-L, or Python for network-based attack techniques, including command-and-control beaconing, data exfiltration, and lateral movement; reduce false positives while maintaining detection signal; and support custom detection development through data discovery, enrichment, normalization, validation, and behavioral and tradecraft-based detection. Architect, build, and maintain security telemetry pipelines that identify, onboard, and ingest network, endpoint, identity, cloud, application, operational technology (OT), and security-infrastructure data-including NetFlow, packet capture (PCAP), virtual private cloud (VPC) flow logs, firewall and proxy logs, and Domain Name System (DNS) records-into centralized and deployed detection solutions.