Solid understanding of security telemetry sources; identity and access (SSO, IGA, PAM), endpoint/EDR, network/proxy, cloud (AWS/GCP/Azure), and SaaS audit logs, and how to shape them into model features. Design, build, and maintain machine learning models for anomaly detection (unsupervised clustering, time-series and seasonality baselines, isolation forests, autoencoders, risk scoring) with measurable precision/recall targets.