Demonstrate strong technical foundation, preferably with hands-on experience in security technologies (e.g. SIEM, EDR, SOAR), scripting languages (e.g. Python, PowerShell) and automation tools to facilitate the development and tuning of detection rules. Working knowledge of one or more detection rule languages such as Sigma, YARA-L, Splunk SPL, Microsoft KQL, or Elastic EQL, with the ability to translate threat intelligence and attacker TTPs into structured, testable detection logic.