This role fills the operational gap by owning the hands-on security engineering and production security work: detection tuning, incident coordination, tool administration, Jira/Slack workflow hygiene, runbooks, dashboards, Identity management, evidence collection, and day-to-day security operations. This person will help operate and improve our security monitoring stack, support incident response, tune detections, maintain runbooks, validate security controls, coordinate with managed SOC/MDR partners, and help ensure systems are secure, observable, supportable, and ready for Day 2 operations.