You will not be solely responding to alerts or consuming a detection platform that someone else runs, you will build and run it: the ingestion pipelines, the Terraform that defines them across sandbox, staging and production AWS accounts, the retention and cost posture, and the automation layered on top. Hands-on experience with SIEM or log analytics platforms and data lake technologies (OpenSearch, Elasticsearch, Clickhouse, Sentinel, Splunk, Datadog, AWS Athena, Azure synapse, Databricks or equivalent) and alerting/monitoring tooling.