Cyber Use Case Developer

United States Digital Space LLC

Toronto

On-site

CAD 65,000 - 105,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

United States Digital Space LLC is seeking a Cyber Use Case Developer to design, develop, test, and continuously improve security monitoring detection across SIEM, EDR, XDR, cloud, identity, and network sources.

You will translate threat behaviors into actionable detection logic and high-quality alerts, partnering with Security Operations, Threat Hunting, and Incident Response to strengthen threat detection capabilities.

Qualifications

  • Post-secondary education in Cyber Security, IT, CS, IS, or related field or equivalent practical experience.
  • Experience in security operations, detection engineering, threat hunting, incident response, cyber threat intelligence or related function.
  • Hands-on with SIEM, EDR, XDR, cloud security, identity, network, or endpoint telemetry.
  • Experience writing detection logic/search queries with SPL, KQL, SQL, Sigma, YARA, Python, PowerShell or similar.
  • Strong understanding of attacker behaviors, malware techniques, persistence, lateral movement, credential abuse, phishing, data exfiltration, cloud/identity attacks.
  • Familiarity with MITRE ATT&CK, Cyber Kill Chain, NIST, CIS Controls or similar.
  • Ability to analyze large security data volumes to find patterns and anomalies.
  • Strong documentation, communication and stakeholder management skills.

Responsibilities

  • Develop and maintain cyber security detection use cases across SIEM/EDR/XDR, cloud, identity, network, and endpoint data sources.
  • Translate attacker techniques into practical detection logic aligned to MITRE ATT&CK.
  • Map detection use cases to MITRE ATT&CK framework for coverage.
  • Write, test, and tune detection rules, queries, analytics, and alert logic.
  • Manage full use case lifecycle from requirements to retirement.
  • Analyze telemetry and logs to identify gaps and improve detections.
  • Collaborate with Threat Hunting to convert findings into detections.
  • Work with Threat Intelligence to operationalize intelligence into monitoring content.
  • Coordinate with Defensive Security and Incident Response to ensure high-fidelity alerts and triage guidance.
  • Conduct false-positive analysis to reduce noise and improve efficiency.
  • Document use case logic, data sources, alert handling, validation results, and performance metrics.
  • Support purple team exercises, simulations, and control validation.

Skills

Security operations
Detection engineering
Threat hunting
Incident response
Cyber threat intelligence
Telemetry analysis
MITRE ATT&CK
Scripting (Python/PowerShell)
SIEM/EDR/XDR
Stakeholder comms

Education

Cyber Security / IT / CS degree

Tools

SPL/KQL/SQL
YARA
Python/PowerShell
Threat intel tooling
Cloud security telemetry

Job description

You are as unique as your background, experience and point of view. Here, you’ll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day, you'll have new and exciting opportunities to make life brighter for our Clients - who are at the heart of everything we do.

At the company, we're driven by our Purpose: helping our Clients achieve lifetime financial security and live healthier lives. Our values shape how we work: caring, authentic, bold, inspiring, and impactful.

When you join the company, you'll work with passionate colleagues and empowering leaders who support your growth and celebrate your contributions, so you can make a meaningful difference in our Clients' lives.

Discover how you can make a difference in the lives of individuals, families and communities around the world.

Job Description:

The Cyber Use Case Developer is responsible for designing, developing, testing, and continuously improving security monitoring use cases that detect suspicious activity, policy violations, and potential cyber threats across enterprise environments. This role works closely with Security Operations, Threat Hunting, Cyber Threat Intelligence, Incident Response, and various teams to translate threat behaviours, business risks, and operational requirements into actionable detection logic and high-quality alerts. The analyst plays a key role in strengthening the organization’s ability to identify threats early, reduce false positives, improve alert fidelity, and support timely investigation and response.

Qualifications
  • Post-secondary education in Cyber Security, Information Technology, Computer Science, Information Systems, or a related field, or equivalent practical experience.
  • Experience in security operations, detection engineering, threat hunting, incident response, cyber threat intelligence, or a related cyber security function.
  • Hands-on experience working with SIEM, EDR, XDR, cloud security, identity, network, or endpoint telemetry.
  • Experience writing detection logic or search queries using languages such as SPL, KQL, SQL, Sigma, YARA, Python, PowerShell, or similar.
  • Strong understanding of common attacker behaviours, malware techniques, persistence methods, lateral movement, credential abuse, phishing, data exfiltration, and cloud or identity-based attacks.
  • Familiarity with security frameworks and methodologies such as MITRE ATT&CK, Cyber Kill Chain, NIST, CIS Controls, or similar.
  • Ability to analyze large volumes of security data and identify patterns, anomalies, and actionable findings.
  • Strong documentation, communication, and stakeholder management skills.
Responsibilities
  • Develop, enhance, and maintain cyber security detection use cases across SIEM, EDR, XDR, cloud, identity, network, and endpoint data sources.
  • Translate adversary tactics, techniques, and procedures into practical detection logic aligned to frameworks such as MITRE ATT&CK.
  • Map detection use cases to MITRE ATT&CK framework to ensure comprehensive adversary coverage.
  • Write, test, and tune detection rules, search queries, analytics, and alert logic.
  • Perform use case lifecycle management, including requirements gathering, design, development, validation, deployment, tuning, documentation, periodic review and retirement.
  • Analyze security telemetry, logs, alerts, and incident data to identify detection gaps and opportunities for improvement.
  • Partner with Threat Hunting team to convert hunt findings into permanent detection use cases.
  • Partner with Threat Intelligence team to operationalize intelligence into monitoring content and proactive detection capabilities.
  • Collaborate with Defensive Security and Incident Response teams to ensure use cases generate actionable, high-fidelity alerts with clear triage guidance.
  • Conduct false-positive analysis and continuously tune detection content to improve precision, reduce noise, and increase operational efficiency.
  • Document use case logic, data source dependencies, alert handling instructions, validation results, and performance metrics.
  • Support purple team, attack simulation, tabletop, and control validation activities to test and improve detection coverage.
  • Track use case performance through metrics such as alert volume, true-positive rate, false-positive rate, coverage, and mean time to detect.
  • Stay current on emerging threats, attack techniques, vulnerabilities, and security monitoring best practices.

This role requires Reliability Status Clearance . In addition to a law enforcement inquiry and a credit check, as part of your application, the Government of Canada will ask if you lived or travelled outside of Canada for 6-consecutive months during the last 5 years, and you must account for all activities during this time.

The Base Pay range is for the primary location for which the job is posted. It may vary depending on the work location of the successful candidate or other factors. In addition to Base Pay, eligible the company employees participate in various incentive plans, payment under which is discretionary and subject to individual and company performance. Certain sales focused roles have sales incentive plans based on individual or group sales results.

Diversity and inclusion have always been at the core of our values at the company. A diverse workforce with wide perspectives and creative ideas benefits our Clients, the communities where we operate and all of us as colleagues. We welcome applications from qualified individuals from all backgrounds.

Persons with disabilities who need accommodation in the application process, or those needing job postings in an alternative format, may e-mail a request to hr@unitedstatesdigital.space .

We are proud to be a hybrid organization that offers our employees the choice and flexibility to work from both the office and virtually based on the needs of the business, our Clients and you.

We may use artificial intelligence to support candidate sourcing, screening, interview scheduling.

We thank all applicants for showing an interest in this position. Only those selected for an interview will be contacted.

Salary Range:

65,000/65 000 - 105,000/105 000

Job Category:

IT - Technology Services

Posting End Date:

07/08/2026

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Use Case Developer
Senior Cyber Use Case Developer

United States Digital Space LLC • Toronto

Hybrid
CAD 90,000 - 140,000
Organisation hybride (bureau et télétr
Senior Java Developer (Kafka/API)
Senior Java Developer (Kafka/API)

United States Digital Space LLC • Toronto

Hybrid
CAD 90,000 - 140,000
Cyber Use Case Developer
Cyber Use Case Developer

Jobtailor • Toronto

On-site
CAD 90,000 - 130,000
Analyst, Data Loss Prevention
Analyst, Data Loss Prevention

Sun Life • Toronto

Hybrid
CAD 65,000 - 105,000
Flexible benefits
Hybrid work model
Diversity & inclusion
Information Security Analyst 3 (Cybersecurity Incident Response)
Information Security Analyst 3 (Cybersecurity Incident Response)

TechAlliance of Southwestern Ontario, London Economic Development Corporation • Toronto

On-site
CAD 85,000 - 135,000
Health & dental benefits
Mental health benefit
Volunteer day
Lead Software Engineer (JAVA, API)
Lead Software Engineer (JAVA, API)

United States Digital Space LLC • Toronto

Hybrid
CAD 126,000 - 197,000
Information Security Analyst 3 (Cybersecurity Incident Response)
Information Security Analyst 3 (Cybersecurity Incident Response)

Canada Life • Toronto

On-site
CAD 85,000 - 135,000
Career Development
Health & Wellness
Time Off
+3
Cybersecurity Detection Engineer / Purple Team
Cybersecurity Detection Engineer / Purple Team

act digital • Montreal (administrative region)

On-site
CAD 90,000 - 135,000
L3 SOC Analyst / Incident Responder
L3 SOC Analyst / Incident Responder

act digital • Montreal (administrative region)

Hybrid
CAD 90,000 - 120,000
Remote working available
Flex Office work environment
Annual training and certification
Incident Response Lead (Cyber)
Incident Response Lead (Cyber)

CyberClan • Canada

On-site
CAD 100,000 - 130,000