I think it depends on the role but it can also change over time. I've got Sr colleagues who are and have always been very hands on day to day within the IR, SOC, VM, and IAM spaces. My Sr AppSec role started out hands on with pen tests, implementing and maintaining tools, etc.