Cyber Use Case Developer
Job Summary
You are as unique as your background experience and point of view. Here youll be encouraged empowered and challenged to be your best self. Youll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day youll have new and exciting opportunities to make life brighter for our Clients - who are at the heart of everything we do.
At Sun Life were driven by our Purpose: helping our Clients achieve lifetime financial security and live healthier lives. Our values shape how we work: caring authentic bold inspiring and impactful.
When you join Sun Life youll work with passionate colleagues and empowering leaders who support your growth and celebrate your contributions so you can make a meaningful difference in our Clients lives.
Discover how you can make a difference in the lives of individuals families and communities around the world.
Job Description:
The Cyber Use Case Developer is responsible for designing developing testing and continuously improving security monitoring use cases that detect suspicious activity policy violations and potential cyber threats across enterprise environments. This role works closely with Security Operations Threat Hunting Cyber Threat Intelligence Incident Response and various teams to translate threat behaviours business risks and operational requirements into actionable detection logic and high-quality alerts. The analyst plays a key role in strengthening the organizations ability to identify threats early reduce false positives improve alert fidelity and support timely investigation and response.
Qualifications
- Post-secondary education in Cyber Security Information Technology Computer Science Information Systems or a related field or equivalent practical experience.
- Experience in security operations detection engineering threat hunting incident response cyber threat intelligence or a related cyber security function.
- Hands-on experience working with SIEM EDR XDR cloud security identity network or endpoint telemetry.
- Experience writing detection logic or search queries using languages such as SPL KQL SQL Sigma YARA Python PowerShell or similar.
- Strong understanding of common attacker behaviours malware techniques persistence methods lateral movement credential abuse phishing data exfiltration and cloud or identity-based attacks.
- Familiarity with security frameworks and methodologies such as MITRE ATT&CK Cyber Kill Chain NIST CIS Controls or similar.
- Ability to analyze large volumes of security data and identify patterns anomalies and actionable findings.
- Strong documentation communication and stakeholder management skills.
Responsibilities
- Develop enhance and maintain cyber security detection use cases across SIEM EDR XDR cloud identity network and endpoint data sources.
- Translate adversary tactics techniques and procedures into practical detection logic aligned to frameworks such as MITRE ATT&CK.
- Map detection use cases to MITRE ATT&CK framework to ensure comprehensive adversary coverage.
- Write test and tune detection rules search queries analytics and alert logic.
- Perform use case lifecycle management including requirements gathering design development validation deployment tuning documentation periodic review and retirement.
- Analyze security telemetry logs alerts and incident data to identify detection gaps and opportunities for improvement.
- Partner with Threat Hunting team to convert hunt findings into permanent detection use cases.
- Partner with Threat Intelligence team to operationalize intelligence into monitoring content and proactive detection capabilities.
- Collaborate with Defensive Security and Incident Response teams to ensure use cases generate actionable high-fidelity alerts with clear triage guidance.
- Conduct false-positive analysis and continuously tune detection content to improve precision reduce noise and increase operational efficiency.
- Document use case logic data source dependencies alert handling instructions validation results and performance metrics.
- Support purple team attack simulation tabletop and control validation activities to test and improve detection coverage.
- Track use case performance through metrics such as alert volume true-positive rate false-positive rate coverage and mean time to detect.
- Stay current on emerging threats attack techniques vulnerabilities and security monitoring best practices.
The Base Pay range is for the primary location for which the job is posted. It may vary depending on the work location of the successful candidate or other addition to Base Pay eligible Sun Life employees participate in various incentive plans payment under which is discretionary and subject to individual and company performance. Certain sales focused roles have sales incentive plans based on individual or group sales results.
Diversity and inclusion have always been at the core of our values at Sun Life. A diverse workforce with wide perspectives and creative ideas benefits our Clients the communities where we operate and all of us as colleagues. We welcome applications from qualified individuals from all backgrounds.
Persons with disabilities who need accommodation in the application process or those needing job postings in an alternative format may e-mail a request to .
We are proud to be a hybrid organization that offers our employees the choice and flexibility to work from both the office and virtually based on the needs of the business our Clients and you.
We may use artificial intelligence to support candidate sourcing screening interview scheduling.
We thank all applicants for showing an interest in this position. Only those selected for an interview will be contacted.
Salary Range:
65000/65 000 - 105000/105 000Job Category:
IT - Technology ServicesPosting End Date:
07/08/2026Required Experience:
IC