Cyber Use Case Developer at Sun Life | Ontario | Rezi

Cyber Use Case Developer at Sun Life

Cyber Use Case Developer

Sun Life · Ontario

Yesterday

Cyber Use Case Developer

Sun Life · Ontario

2 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

The Cyber Use Case Developer is responsible for designing, developing, testing, and continuously improving security monitoring use cases that detect suspicious activity, policy violations, and potential cyber threats across enterprise environments. This role works closely with Security Operations, Threat Hunting, Cyber Threat Intelligence, Incident Response, and various teams to translate threat behaviours, business risks, and operational requirements into actionable detection logic and high-quality alerts. The analyst plays a key role in strengthening the organization’s ability to identify threats early, reduce false positives, improve alert fidelity, and support timely investigation and response.

Responsibilities

  • Develop, enhance, and maintain cyber security detection use cases across SIEM, EDR, XDR, cloud, identity, network, and endpoint data sources.
  • Translate adversary tactics, techniques, and procedures into practical detection logic aligned to frameworks such as MITRE ATT&CK.
  • Map detection use cases to MITRE ATT&CK framework to ensure comprehensive adversary coverage.
  • Write, test, and tune detection rules, search queries, analytics, and alert logic.
  • Perform use case lifecycle management, including requirements gathering, design, development, validation, deployment, tuning, documentation, periodic review and retirement.
  • Analyze security telemetry, logs, alerts, and incident data to identify detection gaps and opportunities for improvement.
  • Partner with Threat Hunting team to convert hunt findings into permanent detection use cases.
  • Partner with Threat Intelligence team to operationalize intelligence into monitoring content and proactive detection capabilities.
  • Collaborate with Defensive Security and Incident Response teams to ensure use cases generate actionable, high-fidelity alerts with clear triage guidance.
  • Conduct false-positive analysis and continuously tune detection content to improve precision, reduce noise, and increase operational efficiency.
  • Document use case logic, data source dependencies, alert handling instructions, validation results, and performance metrics.
  • Support purple team, attack simulation, tabletop, and control validation activities to test and improve detection coverage.
  • Track use case performance through metrics such as alert volume, true-positive rate, false-positive rate, coverage, and mean time to detect.
  • Stay current on emerging threats, attack techniques, vulnerabilities, and security monitoring best practices.

Requirements

  • Post-secondary education in Cyber Security, Information Technology, Computer Science, Information Systems, or a related field, or equivalent practical experience.
  • Experience in security operations, detection engineering, threat hunting, incident response, cyber threat intelligence, or a related cyber security function.
  • Hands-on experience working with SIEM, EDR, XDR, cloud security, identity, network, or endpoint telemetry.
  • Experience writing detection logic or search queries using languages such as SPL, KQL, SQL, Sigma, YARA, Python, PowerShell, or similar.
  • Strong understanding of common attacker behaviours, malware techniques, persistence methods, lateral movement, credential abuse, phishing, data exfiltration, and cloud or identity-based attacks.
  • Familiarity with security frameworks and methodologies such as MITRE ATT&CK, Cyber Kill Chain, NIST, CIS Controls, or similar.
  • Ability to analyze large volumes of security data and identify patterns, anomalies, and actionable findings.
  • Strong documentation, communication, and stakeholder management skills.
  • Reliability Status Clearance.
  • Must account for all activities during 6-consecutive months lived or travelled outside of Canada during the last 5 years.
  • Must undergo a law enforcement inquiry and a credit check.

Skills

  • SIEM
  • EDR
  • XDR
  • Cloud Security
  • Identity Management
  • Network Security
  • Endpoint Security
  • SPL
  • KQL
  • SQL
  • Sigma
  • YARA
  • Python
  • PowerShell
  • MITRE ATT&CK
  • Cyber Kill Chain
  • NIST
  • CIS Controls

Location

  • Remote
  • Hybrid

Work Type

  • Hybrid

Experience Level

  • Equivalent practical experience

Education Level

  • Post-secondary education in Cyber Security, Information Technology, Computer Science, Information Systems, or a related field

Salary/Compensations

  • 65,000 - 105,000

Benefits

  • Various incentive plans
  • Discretionary payment based on individual and company performance
  • Sales incentive plans for certain sales-focused roles

About the Company

  • At Sun Life, we're driven by our Purpose: helping our Clients achieve lifetime financial security and live healthier lives.
  • Our values shape how we work: caring, authentic, bold, inspiring, and impactful.
  • When you join Sun Life, you'll work with passionate colleagues and empowering leaders who support your growth and celebrate your contributions, so you can make a meaningful difference in our Clients' lives.
  • Discover how you can make a difference in the lives of individuals, families and communities around the world.

Equal Opportunity

  • Diversity and inclusion have always been at the core of our values at Sun Life. A diverse workforce with wide perspectives and creative ideas benefits our Clients, the communities where we operate and all of us as colleagues. We welcome applications from qualified individuals from all backgrounds.
  • Persons with disabilities who need accommodation in the application process, or those needing job postings in an alternative format, may e-mail a request to thebrightside@sunlife.com.