Cyber Use Case Developer

sunlife

Ireland

On-site

EUR 70,000 - 120,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Sun Life is seeking a Cyber Use Case Developer to design, implement, and improve security monitoring use cases across SIEM, EDR, XDR, cloud, and network data sources. You will translate attacker techniques into practical detection logic and high‑fidelity alerts, coordinating with Security Operations, Threat Hunting, and Incident Response teams.

Responsibilities include developing detections for network threats, maintaining lifecycle documentation, and ensuring alerts support timely investigation

Qualifications

  • Post‑secondary education in Cyber Security, Information Technology, Computer Science, Information Systems, or equivalent practical experience.
  • Experience in security operations, detection engineering, threat hunting, incident response, cyber threat intelligence, network operations or a related cyber security function.
  • Hands‑on experience working with network security tools and telemetry, including firewalls, proxies, DNS logs, DHCP logs, VPN platforms, IDS/IPS, NAC, packet capture, or similar technologies.
  • Experience writing detection logic or search queries using SPL, KQL, SQL, Sigma, YARA, Python, PowerShell, or similar.
  • Strong understanding of network security concepts, common attacker techniques and defensive controls.

Responsibilities

  • Develop, enhance, and maintain cyber security detection use cases across SIEM, EDR, XDR, cloud, identity, endpoint, and network security data sources.
  • Translate adversary tactics, techniques, and procedures into practical detection logic aligned to MITRE ATT&CK.
  • Map detection use cases to MITRE ATT&CK framework for comprehensive adversary coverage.
  • Write, test, and tune detection rules, search queries, analytics, and alert logic.
  • Perform use case lifecycle management: requirements, design, development, validation, deployment, tuning, and review.
  • Collaborate with network security and engineering teams to understand architecture and logging requirements.

Skills

Threat detection
Analytical thinking
Team collaboration

Education

Post-secondary education in Cyber Security or related field

Tools

SPL
KQL
SQL
Sigma
YARA
Python
PowerShell
Firewall
Proxy

Job description

You are as unique as your background, experience and point of view. Here, you'll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day, you'll have new and exciting opportunities to make life brighter for our Clients - who are at the heart of everything we do.

At Sun Life, we're driven by our Purpose: helping our Clients achieve lifetime financial security and live healthier lives. Our values shape how we work: caring, authentic, bold, inspiring, and impactful.

When you join Sun Life, you'll work with passionate colleagues and empowering leaders who support your growth and celebrate your contributions, so you can make a meaningful difference in our Clients' lives.

Discover how you can make a difference in the lives of individuals, families and communities around the world.

Job Description:

The Cyber Use Case Developer is responsible for designing, developing, testing, and continuously improving security monitoring use cases with a strong focus on network security, network telemetry, and threat detection across enterprise environments. This role works closely with Security Operations, Threat Hunting, Cyber Threat Intelligence, Incident Response, Network Security, and infrastructure teams to translate network behaviours, adversary tradecraft, business risks, and operational requirements into actionable detection logic and high-quality alerts. The analyst plays a key role in strengthening the organization's ability to identify threats early across perimeter, internal, cloud, and hybrid networks; reduce false positives; improve alert fidelity; and support timely investigation and response.

Key Responsibilities
  • Develop, enhance, and maintain cyber security detection use cases across SIEM, EDR, XDR, cloud, identity, endpoint, and network security data sources, including firewall, proxy, DNS, DHCP, VPN, IDS/IPS, NAC, and network traffic telemetry.
  • Translate adversary tactics, techniques, and procedures into practical detection logic aligned to frameworks such as MITRE ATT&CK.
  • Map detection use cases to MITRE ATT&CK framework to ensure comprehensive adversary coverage.
  • Write, test, and tune detection rules, search queries, analytics, and alert logic.
  • Perform use case lifecycle management, including requirements gathering, design, development, validation, deployment, tuning, documentation, periodic review and retirement.
  • Analyze network security telemetry, logs, alerts, packet metadata, flow data, and incident data to identify suspicious patterns, detection gaps, and opportunities for improvement.
  • Create detections for network-based threats such as command-and-control activity, lateral movement, beaconing, port scanning, suspicious remote access, anomalous DNS activity, data exfiltration, and policy violations.
  • Collaborate with network security and engineering teams to understand network architecture, segmentation, traffic patterns, security controls, and logging requirements needed for effective detection coverage.
  • Partner with Threat Hunting team to convert hunt findings into permanent detection use cases.
  • Partner with Threat Intelligence team to operationalize intelligence into monitoring content and proactive detection capabilities.
  • Collaborate with Defensive Security and Incident Response teams to ensure use cases generate actionable, high‑fidelity alerts with clear triage guidance.
  • Conduct false-positive analysis and continuously tune detection content to improve precision, reduce noise, and increase operational efficiency.
  • Document use case logic, data source dependencies, alert handling instructions, validation results, and performance metrics.
  • Support purple team, attack simulation, tabletop, and control validation activities to test and improve detection coverage.
  • Track use case performance through metrics such as alert volume, true‑positive rate, false‑positive rate, coverage, and mean time to detect.
  • Stay current on emerging threats, attack techniques, vulnerabilities, and security monitoring best practices.
Qualifications
  • Post‑secondary education in Cyber Security, Information Technology, Computer Science, Information Systems, or a related field, or equivalent practical experience.
  • Experience in security operations, detection engineering, threat hunting, incident response, cyber threat intelligence, network operations or a related cyber security function.
  • Hands‑on experience working with network security tools and telemetry, including firewalls, proxies, DNS logs, DHCP logs, VPN platforms, IDS/IPS, NAC, packet capture, or similar technologies.
  • Experience writing detection logic or search queries using languages such as SPL, KQL, SQL, Sigma, YARA, Python, PowerShell, or similar.
  • Strong understanding of network security concepts, common attacker
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Use Case Developer
Cyber Use Case Developer

Sun Life Financial • Ireland

On-site
EUR 75,000 - 115,000
Cyber Detection Engineer - Use Case Specialist
Cyber Detection Engineer - Use Case Specialist

sunlife • Ireland

On-site
EUR 70,000 - 120,000
Cyber Detection Use Case Engineer
Cyber Detection Use Case Engineer

Sun Life Financial • Ireland

On-site
EUR 75,000 - 115,000
Senior Red Team Operator
Senior Red Team Operator

sunlife • Waterford

On-site
EUR 90,000 - 130,000
Senior Information Security Analyst
Senior Information Security Analyst

Jobtailor • Dublin

Hybrid
EUR 85,000 - 105,000
Cyber Incident Response Analyst
Cyber Incident Response Analyst

Realtime Recruitment • Ireland

On-site
EUR 111,000 - 166,000
Senior Red Team Operator
Senior Red Team Operator

Sun Life • Waterford

On-site
EUR 62,000 - 93,000
Information Security Analyst
Information Security Analyst

sunlife • Waterford

Hybrid
EUR 55,000 - 90,000
Senior Cyber Incident Response Analyst
Senior Cyber Incident Response Analyst

integrity360 • Ireland

On-site
EUR 70,000 - 100,000
Senior Cyber Incident Response Analyst
Senior Cyber Incident Response Analyst

Integrity360 • Dublin

Hybrid
EUR 90,000 - 130,000