Human judgement on top of the model.
The platform notices. People decide. The team is deliberately weighted towards analysts who have worked incidents rather than sold them, which is why escalations arrive with an argument attached rather than a severity colour.
Analysts, engineers and researchers.
Placeholder profiles for design review, real names and biographies to follow.
Runs the shift rota and owns escalation policy. Worked incidents for eleven years before building a floor of her own.
Owns the scoring model. Spends most of his week arguing with false positives and winning.
Came from operations rather than security, which is why nothing she deploys goes inline.
Publishes the papers, including the ones that describe where the method falls short.
Built the read-only collection path so nothing needs write access to your accounts.
Ran the first cohort. Still takes shifts, on purpose.
Four things we look for.
Weighted towards people who have carried a pager, because judgement is the product.
Operational history
Time spent responding to real incidents outranks certifications, every time.
Ability to write
An escalation nobody can read is worthless. Writing is a hiring criterion here.
Willingness to be wrong
Analysts who argue with the model make it better. Analysts who defer to it do not.
Teaching instinct
Everyone on the floor takes apprentices. It is not optional.
Three tiers, continuous cover.
How the floor is organised, so you know who reads your traffic and when.
Tier one · triage
Reviews every flagged deviation, closes the benign ones with a note on the record.
Tier two · investigation
Takes anything with a plausible attack shape, reconstructs the trace, acts under standing authority.
Tier three · escalation
Named senior analysts who make the call to contact you, and who write the evidence pack first.
Skip the account manager.
Ask operational questions and get answers from someone who works the shift you would be buying.