Experience with SIEM/logging tools (Splunk, or similar); log analysis and KQL/SPL query writing
Proficiency with vulnerability management (InsightVM and AppSec or other), endpoint detection & response (SentinelOne EDR or similar), and patch management tools (Automox or similar)