Threat detection, monitoring, and mitigation. You are expected to know how attacks actually run — credential and token abuse, cross-account privilege escalation, exposed control and management interfaces, lateral movement from a compromised site network into cloud, supply-chain and dependency compromise, ransomware staging — and to build the monitoring that catches them. GuardDuty, Security Hub, Detective, Inspector, Config, and CloudTrail tuned for real signal-to-noise, detections mapped to MITRE ATT&CK and ATT&CK for ICS, runbooks the wider team can execute, and the mitigations driven to done.