• Own end-to-end security incident response, including triage, containment, eradication, recovery, and post-incident learnings.
• Build and continuously improve detection coverage across cloud, endpoint, identity, and SaaS systems.
• Develop security automation and workflows to reduce manual toil and improve response speed.
• Lead investigations into suspicious activity, account compromise, and potential data exposure events.
• Partner with Engineering and IT to harden systems, improve logging/telemetry, and close recurring control gaps.
• Drive readiness through tabletop exercises, runbooks, metrics, and operational reviews.
• Manage security tooling configuration and tuning (SIEM, EDR, IAM, alerting) to reduce noise and increase fidelity.
• Communicate clearly during high-severity situations, aligning stakeholders on impact, status, and next steps.