23 Aug
|
Jobtailor
|
Toronto
Design, develop, test, and continuously improve security monitoring use cases that detect suspicious activity, policy violations, and potential cyber threats
Work closely with Security Operations, Threat Hunting, Cyber Threat Intelligence, Incident Response, and various teams to translate threat behaviours, business risks, and operational requirements into actionable detection logic and high-quality alerts
Strengthen the organization's ability to identify threats early, reduce false positives, improve alert fidelity, and support timely investigation and response
Requirements
Post-secondary education in Cyber Security, Information Technology, Computer Science, Information Systems, or related field, or equivalent practical experience
Experience in security operations, detection engineering, threat hunting, incident response, cyber threat intelligence, or related cyber security function
Hands-on experience working with SIEM, EDR, XDR, cloud security, identity, network, or endpoint telemetry
Experience writing detection logic or search queries using languages such as SPL, KQL, SQL, Sigma, YARA, Python, PowerShell, or similar
Solid understanding of common attacker behaviours, malware techniques, persistence methods, lateral movement, credential abuse, phishing, data exfiltration,
and cloud or identity-based attacks
Familiarity with security frameworks and methodologies such as MITRE ATT&CK;, Cyber Kill Chain, NIST, CIS Controls, or similar
Ability to analyze large volumes of security data and identify patterns, anomalies, and actionable findings
Robust documentation, communication, and stakeholder management skills.
Core Competencies
Demonstrates expertise in security operations and detection engineering, with a robust ability to develop detection logic and analyze security data to identify threats. Proficient in using SIEM, EDR, and various programming languages to enhance security monitoring and incident response.
Highest-signal resume keywords
Security Operations
Detection Engineering
SIEM Experience
Detection Logic Development
Cyber Threat Intelligence
ATS Optimization Keywords
Hard Skills
Detection Logic
SPL
KQL
SQL
Sigma
YARA
Python
PowerShell
Threat Hunting
Incident Response
Soft Skills
Documentation
Communication
Stakeholder Management
Industry Keywords
Cyber Security
MITRE ATT&CK;
Cyber Kill Chain
NIST
CIS Controls
Tools & Technologies
SIEM
EDR
XDR
Cloud Security
Network Telemetry
Endpoint Telemetry
📌 Cyber Use Case Developer Toronto
🏢 Jobtailor
📍 Toronto