Requirements Must have: - Expert in KQL - Technical SME for Microsoft Sentinel setup - Strong understanding of cloud and on-premises logging (Windows, Linux, application, DB, identity) - Experience onboarding data using AMA, DCRs, syslog/CEF, and Event Hub integrations - Comfortable using AI-assiste