Cyber Use Case Developer

Jobtailor

Toronto

On-site

CAD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor in Toronto, Ontario, is seeking a Security Detection Engineer to design, test, and continuously improve security monitoring use cases that detect suspicious activity and potential cyber threats.

You will work with Security Operations, Threat Hunting, Cyber Threat Intelligence, Incident Response, and other teams to translate threat behaviours into actionable detection logic and high-quality alerts, strengthening early threat identification and reducing false positives.

Qualifications

  • Post-secondary education in cyber security, IT, CS, or related field, or equivalent experience.
  • Experience in security operations, detection engineering, threat hunting, incident response, or cyber threat intelligence.
  • Hands-on with SIEM, EDR, XDR, cloud security telemetry.
  • Experience writing detection logic or queries using SPL, KQL, SQL, Sigma, YARA, Python, or PowerShell.
  • Strong understanding of attacker techniques, MITRE ATT&CK, NIST, CIS Controls.
  • Ability to analyze large volumes of security data and identify patterns and actionable findings.
  • Strong documentation, communication, and stakeholder management skills.

Responsibilities

  • Design and improve security monitoring use cases that detect threats, policy violations, and potential cyber threats.
  • Collaborate with Security Operations, Threat Hunting, CTI, Incident Response to translate threat behaviours into actionable detection logic and high‑quality alerts.
  • Strengthen the organization's ability to identify threats early, reduce false positives, and support timely investigation and response.

Skills

Security operations
Detection engineering
SIEM experience
Threat hunting
Incident response
Documentation
Stakeholder management

Education

Bachelor's in Cyber Security / related field

Tools

SIEM
EDR
XDR
Cloud security
Network telemetry
Endpoint telemetry

Job description

  • Design, develop, test, and continuously improve security monitoring use cases that detect suspicious activity, policy violations, and potential cyber threats
  • Work closely with Security Operations, Threat Hunting, Cyber Threat Intelligence, Incident Response, and various teams to translate threat behaviours, business risks, and operational requirements into actionable detection logic and high-quality alerts
  • Strengthen the organization's ability to identify threats early, reduce false positives, improve alert fidelity, and support timely investigation and response
Requirements
  • Post-secondary education in Cyber Security, Information Technology, Computer Science, Information Systems, or related field, or equivalent practical experience
  • Experience in security operations, detection engineering, threat hunting, incident response, cyber threat intelligence, or related cyber security function
  • Hands-on experience working with SIEM, EDR, XDR, cloud security, identity, network, or endpoint telemetry
  • Experience writing detection logic or search queries using languages such as SPL, KQL, SQL, Sigma, YARA, Python, PowerShell, or similar
  • Strong understanding of common attacker behaviours, malware techniques, persistence methods, lateral movement, credential abuse, phishing, data exfiltration, and cloud or identity-based attacks
  • Familiarity with security frameworks and methodologies such as MITRE ATT&CK, Cyber Kill Chain, NIST, CIS Controls, or similar
  • Ability to analyze large volumes of security data and identify patterns, anomalies, and actionable findings
  • Strong documentation, communication, and stakeholder management skills.
Core Competencies

Demonstrates expertise in security operations and detection engineering, with a strong ability to develop detection logic and analyze security data to identify threats. Proficient in using SIEM, EDR, and various programming languages to enhance security monitoring and incident response.

Highest-signal resume keywords
  • Security Operations
  • Detection Engineering
  • SIEM Experience
  • Detection Logic Development
  • Cyber Threat Intelligence
ATS Optimization Keywords
Hard Skills
  • Detection Logic
  • SPL
  • KQL
  • SQL
  • Sigma
  • YARA
  • Python
  • PowerShell
  • Threat Hunting
  • Incident Response
Soft Skills
  • Documentation
  • Communication
  • Stakeholder Management
Industry Keywords
  • Cyber Security
  • MITRE ATT&CK
  • Cyber Kill Chain
  • NIST
  • CIS Controls
Tools & Technologies
  • SIEM
  • EDR
  • XDR
  • Cloud Security
  • Network Telemetry
  • Endpoint Telemetry
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Jobtailor • Boisbriand

On-site
CAD 90,000 - 130,000
Information Security Specialist – Attack Surface Reduction
Information Security Specialist – Attack Surface Reduction

Jobtailor • Toronto

On-site
CAD 120,000 - 160,000
Senior Software Developer
Senior Software Developer

Jobtailor • Ottawa

On-site
CAD 120,000 - 180,000
Information Security Operations Lead
Information Security Operations Lead

Jobtailor • Toronto

On-site
CAD 110,000 - 150,000
Cybersecurity Analyst
Cybersecurity Analyst

Spait Infotech • Toronto

On-site
CAD 60,000 - 90,000
Security Operations Specialist
Security Operations Specialist

Jobtailor • Montreal (administrative region)

On-site
CAD 90,000 - 130,000
Cyber Use Case Developer
Cyber Use Case Developer

United States Digital Space LLC • Toronto

Hybrid
CAD 65,000 - 105,000
Cyber Security Analyst
Cyber Security Analyst

koundinyasa Technology Services • Montreal (administrative region)

On-site
CAD 70,000 - 100,000
Security Compliance Specialist
Security Compliance Specialist

Jobtailor • Calgary

On-site
CAD 110,000 - 150,000
Senior DevSecOps Analyst
Senior DevSecOps Analyst

Jobtailor • Mississauga

On-site
CAD 110,000 - 170,000