← All posts post

What This Work Actually Takes

CareerOctober 2026 · 1 min read

What threat investigation actually takes, from three years in email security:

  • End-to-end investigation: phishing, BEC, malware delivery, malicious URLs and attachments, spoofing, impersonation
  • Evidence correlation: authentication headers, message trace, hop-by-hop path analysis, timeline reconstruction
  • True vs. false positive calls, with proof
  • Root cause analysis and harm assessment
  • Data work: SQL, Python, regex, backend logs, APIs, stack traces
  • Email and identity: SMTP, SPF, DKIM, DMARC, TLS, DNS, Microsoft 365, Google Workspace, OAuth2, SAML/SSO
  • Data protection: DLP policy design and tuning, data classification
  • AI: building agents, workflow automation, guardrail testing
  • And the one nobody lists: explaining all of it so people act on it

Notice how little of that is "knowing which button to click."