Build scripts, automations, and tools (Python, Go, Bash, or directly on Replit) that speed up response, such as automated enrichment, evidence collection, credential and session revocation, workload isolation, and alert triage. Investigate suspicious activity across cloud infrastructure, containers, identity systems, and application layers using SIEM, Cloud Logging, telemetry, and host and container artifacts.