Required Education and Experience
• Bachelor’s degree in a technical field, or equivalent professional experience
• 3–5 years of hands-on information security experience, with demonstrated depth in at least two of: detection
engineering, incident response, security automation, or SOC operations
• Hands-on experience writing, tuning, or maintaining detection content in a SIEM or NG-SIEM platform (e.g., CrowdStrike NG-SIEM, Splunk, Microsoft Sentinel)
• Experience with EDR/XDR platforms and log analysis across diverse sources: endpoint, network, cloud, and identity
• Working knowledge of the MITRE ATT&CK framework and its practical application to detection engineering and gap analysis
• Scripting or automation experience (Python, PowerShell, or similar) applied to security use cases AND/OR experience using LLM coding tools such as Claude Code, Gemini CLI, or Codex.
• Solid understanding of networking, cloud infrastructure (AWS especially, but also Azure and GCP), Windows/Linux systems, and identity platforms
• Working knowledge of PCI-DSS or a comparable compliance framework
• Excellent written and verbal communication skills, including the ability to translate technical findings for non- technical stakeholders