· Hands-on offence: adversary emulation, C2, exploitation, attack-path analysis across cloud / infra / endpoint
· Detection and logging fluency (the purple half)
· BAS and ATT&CK;
· Python and automation; tight rules-of-engagement discipline
Valuable-to-Have skills:
· AI coding / agentic tools (GPT-5.5 Trusted Access for Cyber, Codex, Claude Code, Copilot or similar) to find and prove exploitable vulns at repo scale
· GitLab Ultimate; standing up AI-assisted code-analysis infrastructure