5+ years of hands-on experience in Security Operations, Incident Response, or Detection Engineering. Proven experience leading end-to-end incident response for high-severity security incidents in cloud or enterprise environments. Strong understanding of detection engineering, threat hunting, and modern security operations, with hands-on experience using SIEM, EDR, and cloud security platforms. Experience building and improving incident response processes, including runbooks, severity frameworks, escalation paths, and post-incident reviews. Hands-on experience automating security operations using SOAR platforms and AI-powered workflows (Torq, Tines, or similar). Solid understanding of AWS security fundamentals, including IAM, CloudTrail, and containerized environments (EKS is an