Senior Cyber Use Case Developer

Sun Life


Job Location:

Toronto - Canada

Monthly Salary: Not Disclosed
Posted on: 9 hours ago
Vacancies: 1 Vacancy

Job Summary

You are as unique as your background experience and point of view. Here youll be encouraged empowered and challenged to be your best self. Youll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day youll have new and exciting opportunities to make life brighter for our Clients - who are at the heart of everything we do.


At Sun Life were driven by our Purpose: helping our Clients achieve lifetime financial security and live healthier lives. Our values shape how we work: caring authentic bold inspiring and impactful.


When you join Sun Life youll work with passionate colleagues and empowering leaders who support your growth and celebrate your contributions so you can make a meaningful difference in our Clients lives.


Discover how you can make a difference in the lives of individuals families and communities around the world.


Job Description:

Job description

  • The Senior Cyber Use Case Developer is responsible for leading the design development testing and continuously improvement of advanced security monitoring use cases that detect suspicious activity policy violations and potential cyber threats across complex enterprise environments. This role provides subject matter expertise in detection engineering threat-informed defense telemetry analysis and alert optimization translating adversary behaviors business risks and operational requirements into actionable high-fidelity detection logic.

  • The senior developer acts as a technical lead and trusted advisor for various teams including Security Operations Cyber Threat Hunting Cyber Threat Intelligence Incident Response. The role helps mature the organizations detection capability by improving coverage of priority threats reducing false positives standardizing use case lifecycle practices and ensuring detections remain effective as threats technologies and business priorities evolve.

Qualifications

  • Post-secondary education in Cyber Security Information Technology Computer Science Information Systems Engineering or a related field or equivalent practical experience.
  • 5 or more years of experience in security operations detection engineering threat hunting incident response cyber threat intelligence security engineering or a related cyber security function.
  • Relevant certifications such as CompTIA CySA GIAC GCIH GCIA GCTI GCDA GCFA CISSP Microsoft Security certifications Splunk certifications cloud security certifications or MITRE ATT&CK Defender.
  • Demonstrated experience leading or materially contributing to detection use case development SIEM content engineering alert tuning and use case lifecycle management in an enterprise environment.
  • Advanced hands-on experience working with SIEM EDR XDR cloud security identity network endpoint and application telemetry.
  • Strong proficiency writing detection logic or search queries using languages such as SPL KQL SQL Sigma YARA Python PowerShell regular expressions or similar.
  • Deep understanding of attacker behaviours malware techniques persistence privilege escalation lateral movement credential abuse phishing data exfiltration cloud compromise and identity-based attacks.
  • Strong working knowledge of security frameworks and methodologies such as MITRE ATT&CK Cyber Kill Chain NIST CIS Controls detection engineering frameworks and threat-informed defence practices.
  • Experience analyzing complex security telemetry and incident data to identify detection gaps define requirements and produce actionable findings.
  • Ability to lead technical discussions influence stakeholders mentor peers and communicate detection strategy clearly to technical and non-technical audiences.
  • Strong documentation quality assurance prioritization and stakeholder management skills.

Responsibilities

  • Lead the development enhancement and lifecycle management of cyber security detection use cases across SIEM EDR XDR cloud identity network endpoint and application telemetry sources.
  • Translate adversary tactics techniques procedures threat intelligence incident learnings and business risk scenarios into scalable high-fidelity detection logic aligned to frameworks such as MITRE ATT&CK.
  • Design write test tune and peer review advanced correlation rules search queries analytics dashboards and alert logic using platforms.
  • Establish and maintain use case development standards including intake prioritization design documentation validation deployment readiness tuning change control performance measurement and retirement criteria.
  • Assess enterprise telemetry coverage data quality parsing normalization and logging gaps and partner with engineering teams to improve data source reliability and detection readiness.
  • Lead detection gap assessments and coverage mapping for priority threat scenarios critical assets attack paths control failures and emerging threat behaviors.
  • Partner with Threat Hunting and Threat Intelligence teams to operationalize intelligence hypotheses and hunting outcomes into durable monitoring content and proactive detection capabilities.
  • Drive false-positive reduction and alert quality improvements through structured tuning enrichment suppression logic threshold refinement and feedback from operational teams.
  • Support purple team attack simulation breach and attack emulation tabletop and control validation exercises to test and improve detection coverage.
  • Measure and report use case performance through metrics such as alert volume precision true-positive rate false-positive rate coverage mean time to detect and operational usefulness.
  • Be a mentor for the team and contribute to knowledge sharing peer reviews technical training and continuous improvement of detection development practices.
  • Stay current on emerging threats vulnerabilities adversary tradecraft cloud and identity attack techniques and security monitoring best practices and apply those insights to detection strategy.

This role requires Reliability Status addition to a law enforcement inquiry and a credit check as part of your application the Government of Canada will ask if you lived or travelled outside of Canada for 6-consecutive months during the last 5 years and you must account for all activities during this time.


The Base Pay range is for the primary location for which the job is posted. It may vary depending on the work location of the successful candidate or other addition to Base Pay eligible Sun Life employees participate in various incentive plans payment under which is discretionary and subject to individual and company performance. Certain sales focused roles have sales incentive plans based on individual or group sales results.


Diversity and inclusion have always been at the core of our values at Sun Life. A diverse workforce with wide perspectives and creative ideas benefits our Clients the communities where we operate and all of us as colleagues. We welcome applications from qualified individuals from all backgrounds.


Persons with disabilities who need accommodation in the application process or those needing job postings in an alternative format may e-mail a request to .


We are proud to be a hybrid organization that offers our employees the choice and flexibility to work from both the office and virtually based on the needs of the business our Clients and you.


We may use artificial intelligence to support candidate sourcing screening interview scheduling.


We thank all applicants for showing an interest in this position. Only those selected for an interview will be contacted.


Salary Range:

90000/90 000 - 140000/140 000

Job Category:

IT - Technology Services

Posting End Date:

07/08/2026

Required Experience:

Senior IC

You are as unique as your background experience and point of view. Here youll be encouraged empowered and challenged to be your best self. Youll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your...