Senior Cyber Use Case Developer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Cyber Use Case Developer (Cybersecurity/SIEM): Leading the design, development, and continuous improvement of advanced security monitoring use cases to detect suspicious activity across complex enterprise environments with an accent on detection engineering and threat-informed defense. Focus on translating adversary behaviors and business risks into high-fidelity detection logic and optimizing SIEM/EDR telemetry.
Location: Toronto, Ontario (Hybrid)
Salary: $90,000 – $140,000 CAD
Company
is a leading financial services organization dedicated to helping clients achieve lifetime financial security and live healthier lives.
What you will do
- Lead the development and lifecycle management of cyber security detection use cases across SIEM, EDR, XDR, cloud, identity, network, and endpoint telemetry.
- Translate adversary tactics, techniques, and procedures (TTPs) and threat intelligence into scalable detection logic aligned with the MITRE ATT&CK framework.
- Design, test, and tune advanced correlation rules, search queries, and dashboards to reduce false positives and improve alert quality.
- Perform detection gap assessments and coverage mapping for priority threat scenarios and critical assets.
- Partner with Threat Hunting and Threat Intelligence teams to operationalize hypotheses into durable monitoring content.
- Mentor peers and establish standardized use case development practices, including documentation and validation.
Requirements
- Must be able to obtain Reliability Status Clearance from the Government of Canada (includes law enforcement inquiry and credit check).
- 5+ years of experience in security operations, detection engineering, threat hunting, or incident response.
- Strong proficiency in writing detection logic using SPL, KQL, SQL, Sigma, YARA, Python, or PowerShell.
- Deep understanding of attacker behaviors (persistence, lateral movement, credential abuse) and frameworks like MITRE ATT&CK, NIST, and CIS Controls.
- Hands-on experience with SIEM, EDR, XDR, and cloud security telemetry in an enterprise environment.
- Post-secondary degree in Cyber Security, Computer Science, Engineering, or equivalent practical experience.
Nice to have
- Relevant certifications such as CISSP, GIAC (GCIH, GCIA, GCTI, GCDA, GCFA), CompTIA CySA+, or Microsoft Security certifications.
- Splunk or cloud security specific certifications.
- Experience with MITRE ATT&CK Defender certification.
Culture & Benefits
- Hybrid work model offering flexibility to work both from the office and virtually.
- Inclusive environment that values diverse perspectives and encourages professional growth.
- Access to various incentive plans based on individual and company performance.
- Collaborative atmosphere working alongside subject matter experts in a purpose-driven organization.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →