3 + years in a Security Operations Center, CERT, or similar on-call/triage environment for a cloud-native product company. Comfortable with bug-bounty platforms (HackerOne, Bugcrowd), compliance tooling (Vanta, Drata), ticketing/CRM systems (HubSpot, Jira), and at least one log/SIEM stack. Process-oriented & relentless at follow-up. Clear and empathetic communicator. Working knowledge of SOC 2, HIPAA, ISO 27001, or related standards. Comfortable in an async-first, globally distributed team.