- Design, develop, and maintain automated detection logic across SIEM, EDR, and cloud platforms.
- Build and manage SOAR playbooks to enhance Tier 1/2 incident response workflows.
- Conduct detection gap analyses and continuously update rules based on threat intelligence and adversary tactics.