21 Aug
|
Jobtailor
|
Winnipeg
21 Aug
Jobtailor
Winnipeg
Design, develop, test, and continuously improve security monitoring use cases that detect suspicious activity, policy violations, and potential cyber threatsWork closely with Security Operations, Threat Hunting, Cyber Threat Intelligence, Incident Response, and various teams to translate threat behaviours, business risks, and operational requirements into actionable detection logic and high-quality alertsStrengthen the organization's ability to identify threats early, reduce false positives, improve alert fidelity, and support timely investigation and responseRequirementsPost-secondary education in Cyber Security, Information Technology, Computer Science, Information Systems, or related field, or equivalent practical experienceExperience in security operations, detection engineering, threat hunting, incident response, cyber threat intelligence, or related cyber security functionHands-on experience working with SIEM, EDR, XDR, cloud security, identity, network, or endpoint telemetryExperience writing detection logic or search queries using languages such as SPL, KQL, SQL, Sigma, YARA, Python, PowerShell, or similarStrong understanding of common attacker behaviours, malware techniques, persistence methods, lateral movement, credential abuse, phishing,
data exfiltration, and cloud or identity-based attacksFamiliarity with security frameworks and methodologies such as MITRE ATT&CK;, Cyber Kill Chain, NIST, CIS Controls, or similarAbility to analyze large volumes of security data and identify patterns, anomalies, and actionable findingsStrong documentation, communication, and stakeholder management skills.Core CompetenciesDemonstrates expertise in security operations and detection engineering, with a robust ability to develop detection logic and analyze security data to identify threats. Proficient in using SIEM, EDR, and various programming languages to enhance security monitoring and incident response.Highest-signal resume keywordsSecurity OperationsDetection EngineeringSIEM ExperienceDetection Logic DevelopmentCyber Threat IntelligenceATS Optimization KeywordsHard SkillsDetection LogicSPLKQLSQLSigmaYARAPythonPowerShellThreat HuntingIncident ResponseSoft SkillsDocumentationCommunicationStakeholder ManagementIndustry KeywordsCyber SecurityMITRE ATT&CKCyber; Kill ChainNISTCIS ControlsTools & TechnologiesSIEMEDRXDRCloud SecurityNetwork TelemetryEndpoint Telemetry#J-18808-Ljbffr
📌 Cyber Use Case Developer (Winnipeg)
🏢 Jobtailor
📍 Winnipeg