Essential Functions: · Design, build, and maintain automation for alert enrichment, correlation, triage, incident response, and case handoffs across SIEM/SOAR platforms such as Microsoft Sentinel, Defender/XDR, Azure Logic Apps, Tines, ServiceNow, Log Analytics, and Confluence. · Collaborate with detection engineers, incident responders, and SOC analysts to identify automation opportunities, improve detection workflows, reduce false positives, and streamline analyst operations.