Cyber Detection Use Case Engineer

Sun Life Financial

Ireland

On-site

EUR 75,000 - 115,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Sun Life Financial is hiring a Cyber Use Case Developer to design, develop, test, and improve security monitoring use cases with emphasis on network security, telemetry, and threat detection across enterprise environments.

You will collaborate with Security Operations, Threat Hunting, and Incident Response teams to translate network behaviors and operational requirements into high-quality alerts, reducing false positives and enabling timely investigations.

Qualifications

  • Post-secondary education in Cyber Security, Information Technology, Computer Science, Information Systems, or a related field, or equivalent practical experience.
  • Experience in security operations, detection engineering, threat hunting, incident response, cyber threat intelligence, network operations or a related cyber security function.
  • Hands-on experience working with network security tools and telemetry, including firewalls, proxies, DNS logs, DHCP logs, VPN platforms, IDS/IPS, NAC, packet capture, or similar technologies.
  • Experience writing detection logic or search queries using languages such as SPL, KQL, SQL, Sigma, YARA, Python, PowerShell, or similar.
  • Strong understanding of network security concepts, common attacker behaviours, malware techniques, persistence methods, lateral movement, credential abuse, phishing, data exfiltration, cloud or identity-based attacks, and how these behaviours appear in network telemetry.

Responsibilities

  • Develop, enhance, and maintain cyber security detection use cases across SIEM, EDR, XDR, cloud, identity, endpoint, and network security data sources.
  • Translate adversary tactics, techniques, and procedures into practical detection logic aligned to MITRE ATT&CK.
  • Map detection use cases to MITRE ATT&CK framework to ensure comprehensive adversary coverage.
  • Write, test, and tune detection rules, search queries, analytics, and alert logic.
  • Perform use case lifecycle management, including requirements gathering, design, development, validation, deployment, tuning, documentation, periodic review and retirement.
  • Analyze network security telemetry, logs, alerts, packet metadata, flow data, and incident data to identify suspicious patterns.
  • Create detections for network-based threats such as C2, lateral movement, beaconing, port scanning, suspicious remote access, anomalous DNS, data exfiltration, and policy violations.
  • Collaborate with network security and engineering teams to understand network architecture, segmentation, traffic patterns, security controls, and logging requirements.
  • Partner with Threat Hunting team to convert hunt findings into permanent detection use cases.
  • Partner with Threat Intelligence team to operationalize intelligence into monitoring content and proactive detection capabilities.
  • Collaborate with Defensive Security and Incident Response teams to ensure use cases generate actionable, high-fidelity alerts with clear triage guidance.
  • Conduct false-positive analysis and continuously tune detection content to improve precision, reduce noise, and increase operational efficiency.
  • Document use case logic, data source dependencies, alert handling instructions, validation results, and performance metrics.
  • Support purple team, attack simulation, tabletop, and control validation activities to test and improve detection coverage.
  • Track use case performance through metrics such as alert volume, true-positive rate, false-positive rate, coverage, and mean time to detect.
  • Stay current on emerging threats, attack techniques, vulnerabilities, and security monitoring best practices.

Skills

SPL
KQL
SQL
Sigma
YARA
Python
PowerShell

Education

Post-secondary education in Cyber Security

Tools

Firewalls
Proxies
DNS Logs
DHCP Logs
VPN Platforms
IDS/IPS
NAC
Packet Capture

Job description

Sun Life Financial is hiring a Cyber Use Case Developer to design, develop, test, and improve security monitoring use cases with emphasis on network security, telemetry, and threat detection across enterprise environments.

You will collaborate with Security Operations, Threat Hunting, and Incident Response teams to translate network behaviors and operational requirements into high-quality alerts, reducing false positives and enabling timely investigations.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Detection Engineer - Use Case Specialist
Cyber Detection Engineer - Use Case Specialist

sunlife • Ireland

On-site
EUR 70,000 - 120,000
Cyber Use Case Developer
Cyber Use Case Developer

sunlife • Ireland

On-site
EUR 70,000 - 120,000
Cyber Use Case Developer
Cyber Use Case Developer

Sun Life Financial • Ireland

On-site
EUR 75,000 - 115,000
Threat Detection Engineer - Hybrid (Cloud & On-Prem)
Threat Detection Engineer - Hybrid (Cloud & On-Prem)

SMBC Group • Ireland

Hybrid
EUR 75,000 - 110,000
Hybrid work model
Disability accommodations
Cybersecurity Deployment Technician
Cybersecurity Deployment Technician

Jobless • Dublin

Hybrid
EUR 43,000 - 65,000
Competitive compensation and benefits
Threat Detection Engineer - Hybrid (Cloud & On-Prem)
Threat Detection Engineer - Hybrid (Cloud & On-Prem)

SMBC Group • Tralee

Hybrid
EUR 90,000 - 120,000
Vulnerability Management Security Analyst
Vulnerability Management Security Analyst

sunlife • Waterford

Hybrid
EUR 55,000 - 90,000
Senior Red Team Operator
Senior Red Team Operator

sunlife • Waterford

On-site
EUR 90,000 - 130,000
Senior Red Team Operator - Offensive Security Lead
Senior Red Team Operator - Offensive Security Lead

sunlife • Waterford

On-site
EUR 90,000 - 130,000
Cyber Incident Response Analyst
Cyber Incident Response Analyst

Realtime Recruitment • Ireland

On-site
EUR 111,000 - 166,000