Depending on the risks you identify, this may include areas such as cloud IAM and service accounts, network security, secrets and key management, vulnerability management, secure configuration, CI/CD and code security, logging and monitoring, or security architecture reviews. You should be comfortable reasoning about areas such as cloud IAM, networking, application and infrastructure security, data protection, secrets management, logging and detection, vulnerability management, and endpoint or identity security.