You can perform host and network forensics across Windows, macOS, and Linux - analyzing file system, memory, process, and network artifacts for indicators of compromise - and have responded to incidents in cloud environments (AWS, Azure, and/or GCP), including familiarity with cloud architectures, CI/CD (continuous integration/continuous delivery) pipelines, and cloud logging/telemetry. You've handled high-priority incidents, including insider investigations, adversary activity, and web application attacks, and have a solid, current understanding of the threat landscape - attacker tactics, techniques, and procedures (TTPs), tooling, and hardening best practices - including working knowledge of a framework such as MITRE ATT&CK.