Hands-on experience with several of the following: alert triage, detection tuning and writing, detection-as-code, security log ingestion, investigations and security incident response, identity and access management (IAM), phishing response, user access reviews, managing endpoint detection and response tooling. • Familiarity with operating distributed cloud technology (AWS, CICD, GCP, Azure, Kubernetes, Docker, Terraform, etc.) and experience with corporate (SSO, SAML, IAM) and defensive security tooling (EDR, SIEM, CNAPP, ZTNA, etc.).