Hands-on experience with several of the following: alert triage, detection tuning and writing, detection-as-code, security log ingestion, investigations and security incident response, identity and access management (IAM), phishing response, user access reviews, managing endpoint detection and response tooling. Familiarity with operating distributed cloud technology (AWS, CICD, GCP, Azure, Kubernetes, Docker, Terraform, etc.) and experience with corporate (SSO, SAML, IAM) and defensive security tooling (EDR, SIEM, CNAPP, ZTNA, etc.).