issues, coordinating response across IDR, engineering, product and business teams. Perform DFIR and endpoint forensics, including log, network and packet analysis, malware analysis and firewall investigation where applicable. Write and improve detections, playbooks, orchestrations and preventions using evidence from incidents and threat hunting. Build production-quality automation that removes repetitive … What You Will Bring Strong enterprise incident response experience across endpoint, identity, cloud, network and product-focused investigations. Practical capability in DFIR, endpoint and firewall forensics, threat hunting, detection engineering and analysis of unstructured telemetry. Ability to write reliable automation in Python or a comparable language, work with APIs ...