Deep hands-on identity and access management expertise, including least-privilege access, cross-account access patterns, short-lived workload credentials (e.g., IRSA, OIDC federation), and service-to-service identity and authorization (e.g., mTLS, SPIFFE/SPIRE, or service mesh identity models), with experience reducing standing access and long-lived credentials. Experience with cloud security visibility and response, including cloud-native security tooling (e.g., GuardDuty, Security Command Center, CloudTrail, or Cloud Audit Logs), detection capabilities, SIEM integration, and applying incident learnings to improve preventive and detective controls.