About the Role
Sun Life is driven by its Purpose: helping Clients achieve lifetime financial security and live healthier lives. This role is crucial in enhancing security monitoring to detect suspicious activity, policy violations, and potential cyber threats across complex enterprise environments.
Responsibilities
- Lead the development, enhancement, and lifecycle management of cyber security detection use cases across SIEM, EDR, XDR, cloud, identity, network, endpoint, and application telemetry sources.
- Translate adversary tactics, techniques, procedures, threat intelligence, incident learnings, and business risk scenarios into scalable, high-fidelity detection logic aligned to frameworks such as MITRE ATT&CK.
- Design, write, test, tune, and peer review advanced correlation rules, search queries, analytics, dashboards, and alert logic using platforms.
- Establish and maintain use case development standards, including intake, prioritization, design documentation, validation, deployment readiness, tuning, change control, performance measurement, and retirement criteria.
- Assess enterprise telemetry coverage, data quality, parsing, normalization, and logging gaps, and partner with engineering teams to improve data source reliability and detection readiness.
- Lead detection gap assessments and coverage mapping for priority threat scenarios, critical assets, attack paths, control failures, and emerging threat behaviors.
- Partner with Threat Hunting and Threat Intelligence teams to operationalize intelligence, hypotheses, and hunting outcomes into durable monitoring content and proactive detection capabilities.
- Drive false-positive reduction and alert quality improvements through structured tuning, enrichment, suppression logic, threshold refinement, and feedback from operational teams.
- Support purple team, attack simulation, breach and attack emulation, tabletop, and control validation exercises to test and improve detection coverage.
- Measure and report use case performance through metrics such as alert volume, precision, true-positive rate, false-positive rate, coverage, mean time to detect, and operational usefulness.
- Be a mentor for the team and contribute to knowledge sharing, peer reviews, technical training, and continuous improvement of detection development practices.
- Stay current on emerging threats, vulnerabilities, adversary tradecraft, cloud and identity attack techniques, and security monitoring best practices, and apply those insights to detection strategy.
Requirements
- Post-secondary education in Cyber Security, Information Technology, Computer Science, Information Systems, Engineering, or a related field, or equivalent practical experience.
- 5 or more years of experience in security operations, detection engineering, threat hunting, incident response, cyber threat intelligence, security engineering, or a related cyber security function.
- Demonstrated experience leading or materially contributing to detection use case development, SIEM content engineering, alert tuning, and use case lifecycle management in an enterprise environment.
- Advanced hands-on experience working with SIEM, EDR, XDR, cloud security, identity, network, endpoint, and application telemetry.
- Strong proficiency writing detection logic or search queries using languages such as SPL, KQL, SQL, Sigma, YARA, Python, PowerShell, regular expressions, or similar.
- Deep understanding of attacker behaviours, malware techniques, persistence, privilege escalation, lateral movement, credential abuse, phishing, data exfiltration, cloud compromise, and identity-based attacks.
- Strong working knowledge of security frameworks and methodologies such as MITRE ATT&CK, Cyber Kill Chain, NIST, CIS Controls, detection engineering frameworks, and threat-informed defence practices.
- Experience analyzing complex security telemetry and incident data to identify detection gaps, define requirements, and produce actionable findings.
- Ability to lead technical discussions, influence stakeholders, mentor peers, and communicate detection strategy clearly to technical and non-technical audiences.
- Strong documentation, quality assurance, prioritization, and stakeholder management skills.
- Requires Reliability Status Clearance, including a law enforcement inquiry and credit check.
- Must account for all activities during the last 5 years if lived or travelled outside of Canada for 6 consecutive months.
Skills
- Cyber Security
- Information Technology
- Computer Science
- Information Systems
- Engineering
- Security Operations
- Detection Engineering
- Threat Hunting
- Incident Response
- Cyber Threat Intelligence
- Security Engineering
- SIEM
- EDR
- XDR
- Cloud Security
- Identity Management
- Network Security
- Endpoint Security
- Application Security
- SPL
- KQL
- SQL
- Sigma
- YARA
- Python
- PowerShell
- Regular Expressions
- MITRE ATT&CK
- Cyber Kill Chain
- NIST
- CIS Controls
- Detection Engineering Frameworks
- Threat-Informed Defense
- Documentation
- Quality Assurance
- Prioritization
- Stakeholder Management
Location
- Hybrid
Work Type
- Hybrid
- Full-time
Experience Level
- Senior
- 5+ years
Education Level
- Post-secondary education in Cyber Security, Information Technology, Computer Science, Information Systems, Engineering, or a related field, or equivalent practical experience.
Salary/Compensations
- 90,000 - 140,000
Benefits
- Participation in various incentive plans
- Discretionary bonus potential
- Sales incentive plans (for certain sales-focused roles)
About the Company
- Sun Life is driven by its Purpose: helping Clients achieve lifetime financial security and live healthier lives.
- Values: caring, authentic, bold, inspiring, and impactful.
- A hybrid organization offering flexibility to work from both the office and virtually.
- May use artificial intelligence to support candidate sourcing, screening, and interview scheduling.
Equal Opportunity
- Diversity and inclusion have always been at the core of our values at Sun Life. A diverse workforce with wide perspectives and creative ideas benefits our Clients, the communities where we operate and all of us as colleagues. We welcome applications from qualified individuals from all backgrounds.
- Persons with disabilities who need accommodation in the application process, or those needing job postings in an alternative format, may e-mail a request to thebrightside@sunlife.com.
