5+ years of cybersecurity, security platform, SOC, security data, or security infrastructure engineering experience
3+ years of hands-on SIEM and/or SOAR platform experience in an enterprise, MSSP, MDR, SOC, or security consulting environment
Experience with agent deployment and patching, collector and forwarder management, connector updates, platform upgrades, change control, rollback planning, and production validation
Preferred Qualifications
Microsoft SC-200, SC-100, AZ-500, or equivalent Microsoft security certifications
Splunk Admin or Architect, Palo Alto Cortex XSOAR or XSIAM, Fortinet NSE, Google SecOps, or other platform certifications
GIAC certifications such as GCIA, GCIH, GCFA, GDAT, GCTI, or equivalent practitioner certifications
CISSP, CCSP, AWS Security Specialty, or cloud/security architecture certifications
Training or practical experience in MITRE ATT&CK, detection engineering, threat hunting, purple teaming, cloud security, platform engineering, or DevSecOps