Deep expertise in SIEM platforms (e.g., Splunk, Microsoft Sentinel, Google SecOps, Elastic, QRadar) or leveraging a Datalake (Snowflake, Databricks) for security logging, with experience designing and optimizing large-scale security monitoring and analytics environments.
Strong background in security telemetry engineering, including log collection, normalization, enrichment, parsing, and data quality management across cloud, on-premises, application, identity, and endpoint data sources.
Experience building and maintaining scalable data pipelines using technologies such as Kafka, Cribl, Kinesis, Event Hubs, Data Lake architectures, cloud-native services, or similar high-volume data processing platforms.
Advanced knowledge of security operations, threat detection engineering, threat hunting, incident response, and MITRE ATT&CK;, with the ability to translate security use cases into actionable telemetry and detection requirements.
Proficiency in scripting, automation, and data analysis using languages such as Python, PowerShell, SQL, or similar technologies to improve telemetry onboarding, validation, and operational efficiency.