- Hands-on experience with Google Chronicle SIEM (log ingestion, rule tuning, dashboards, detections),Crowdstrike EDR. - Solid understanding of SOC operations, incident response, and cyber kill chain methodologies. - Familiarity with other SIEM solutions (Splunk, QRadar, Azure Sentinel, etc.) as an add-on capability. - Knowledge of MITRE ATT&CK;, threat intelligence, and detection engineering principles. - Proficiency in scripting (Python, PowerShell, or similar) for automation and data enrichment. - Experience with EDR, NDR, and IAM integrations within the SIEM ecosystem. - Excellent analytical, communication, and documentation skills.