- 6+ years of experience in security operations, detection engineering, incident response, or a similar hands-on technical security role.
- Strong experience writing, tuning, validating, and maintaining detections in SIEM, EDR, cloud, identity, or SaaS environments.
- Hands-on experience with SIEM platforms and EDR tools such as CrowdStrike Falcon or comparable technology.
- Practical AWS security knowledge including IAM, CloudTrail, GuardDuty, VPC flow logs, S3, and cloud-native detection opportunities.
- Ability to script or automate security workflows using Python, Bash, PowerShell, SQL, or similar tools.
- Working knowledge of audit evidence, control documentation, third-party reviews, policies, standards, and security frameworks.
- Ability to work a weekend-inclusive schedule to support continuous security operations coverage.