Experience analyzing cyber insurance claims or translating security findings into underwriting, rating, or risk-scoring inputs
Hands-on experience with cloud security, security architecture, data protection, or security control assessments
Background in threat intelligence and developing detection tradecraft from observed attacker behavior
Experience advising CISOs or customers on prioritizing security improvements based on risk, feasibility, and business context
Demonstrated ability to create or improve internal security processes, products, or analytical methodologies
Background & Domain
2–4 years of experience in security analysis, defensive or blue-team operations, penetration testing, red-team work, incident response, or cyber risk consulting
Experience assessing security programs, investigating incidents, or analyzing control effectiveness in complex business environments
Exposure to cloud security, security architecture, data protection, threat intelligence, or cyber insurance is particularly relevant
Technical & Regulatory
Strong understanding of network threats, attack vectors, exploitation methods, and intrusion-set tactics, techniques, and procedures
Practical knowledge of TCP/IP, network analysis, security technologies, logs, and network traffic captures
Familiarity with NIST, ISO, HIPAA, and PCI frameworks, and the ability to connect requirements to real-world controls
Collaboration & Influence
Able to turn ambiguous technical evidence into clear conclusions and prioritized business recommendations
Comfortable communicating with security practitioners, business stakeholders, customers, and executive audiences, including CISOs
Collaborative and self-directed, with the judgment and initiative expected at the P4 level
Effective in a fast-paced, evolving environment where they can help improve processes and products
2–4 years of experience in security analysis, blue-team or defensive security, penetration testing, red-team operations, incident response, or a related discipline
Expert understanding of network threat lifecycles, attack vectors, exploitation methods, and attacker TTPs
Knowledge of TCP/IP protocols, network analysis, and network and security applications, including log analysis and network traffic capture analysis
Ability to investigate incidents and claims, determine root cause, and recommend effective preventive or detective controls
Familiarity with NIST, ISO, HIPAA, and PCI frameworks and their practical application
Strong written and verbal communication skills, with the ability to provide clear recommendations to technical and executive audiences