•Hands on experience in security operations, incident response, or a security operations center environment
•Practical knowledge of monitoring and alerting tools such as SIEM, EDR, or network security platforms
•Experience analyzing security events, logs, and alerts to identify threats and false positives
•Understanding of common attack techniques, vulnerabilities, and threat categories
•Ability to follow documented procedures, escalation paths, and evidence handling requirements
•Experience documenting incidents, actions taken, and outcomes in a structured manner
•Familiarity with basic networking, operating systems, and identity concepts