teams. Create investigation workflows, triage processes and escalation procedures for security incidents across Microsoft Defender, CrowdStrike, Cortex XDR, SentinelOne, Carbon Black, Azure, AWS, and GCP environments . Define required enrichment data, threat intelligence inputs and decision‐making criteria. Ensure procedures are practical, repeatable and aligned with global security operations. Develop … detection content. Experience within financial services or highly regulated environments. Experience delivering analyst training and knowledge transfer sessions. Experience working within Azure, AWS, or GCP cloud environments . Experience with threat intelligence integration, detection use case development, and security monitoring strategy. Qualifications Degree in Cyber Security, Information Security, Computer Science ...