Practical experience with several of the following categories: SIEM/log management, EDR/XDR, email security, IDS/IPS, next-gen firewalls/VPN, web filtering/proxy, vulnerability scanning, DLP, MDM/endpoint management, identity security (SSO/MFA), and secure backup/DR. Monitor and manage alerts across a multi-tool ecosystem (e.g., MDR/XDR, email security, IDS/IPS, firewall, MDM, vulnerability scanner, DLP, password/privileged access tools, cloud security, backup/DR, and threat-intel feeds).