Role: Cybersecurity Technical Lead - CrowdStrike, Proofpoint, MDE, MDI, and MDCA Calgary - Onsite Primary Skillset • Microsoft Defender for Endpoint (MDE) • Microsoft Defender for Identity (MDI) • Microsoft Defender for Cloud Apps (MDCA) Secondary Skillset • CrowdStrike EDR • Proofpoint Email Security Job Summary • We are seeking an experienced and highly motivated Security Tools Team Lead to lead the administration, optimization, and continuous improvement of enterprise cybersecurity platforms. • The role requires deep expertise in CrowdStrike EDR, Microsoft Defender for Endpoint (MDE), Microsoft Defender for Identity (MDI), Microsoft Defender for Cloud Apps (MDCA), and Proofpoint Email Security. • The successful candidate will lead a team of security specialists, manage daily operations, drive cybersecurity initiatives, support incident response activities, and collaborate closely with SOC, Infrastructure, Cloud, and Business teams. • The ideal candidate will possess strong technical expertise, leadership capabilities, stakeholder management skills, and a proactive mindset focused on enhancing the organization's security posture. Key Responsibilities Security Tools Leadership & Operations • Lead the Security Tools team responsible for endpoint, email, identity, and cloud security technologies. • Provide technical leadership, mentoring, and guidance to team members. • Ensure operational excellence and availability of all security platforms. • Manage day-to-day administration, configuration, maintenance, and optimization of security tools. • Develop and maintain operational procedures, SOPs, and knowledge articles. • Drive service improvements and automation initiatives. Endpoint Security Management • Manage and administer CrowdStrike EDR. • Manage and administer Microsoft Defender for Endpoint (MDE). • Oversee agent deployment, sensor health, policy management, exclusions, detections, and preventive controls. • Drive endpoint hardening initiatives and security posture improvements. • Monitor security recommendations and remediation activities. Email Security Administration • Administer and support Proofpoint Email Protection. • Administer and support Proofpoint TAP. • Administer and support Proofpoint TRAP. • Manage phishing protection, email authentication, mail flow security, URL defense, attachment defense, and threat remediation. • Review and implement policy updates, safe sender lists, and threat intelligence recommendations. Identity & Cloud Security • Manage Microsoft Defender for Identity (MDI). • Manage Microsoft Defender for Cloud Apps (MDCA). • Monitor identity-based threats, cloud application risks, suspicious activities, and compliance alerts. • Collaborate with IAM, Azure, and Cloud teams for remediation activities. Incident Response & Threat Management • Act as an escalation point for critical security incidents. • Support SOC investigations involving endpoint, email, cloud, and identity threats. • Conduct threat hunting and root cause analysis. • Ensure timely containment, eradication, and recovery activities. Governance & Reporting • Own weekly, monthly, and quarterly security reporting. • Develop KPI and SLA dashboards for security tool operations. • Present operational updates, risks, and improvement plans to customers and senior management. • Maintain risk registers and track remediation activities. Stakeholder & Vendor Management • Partner with internal security teams, infrastructure teams, and business stakeholders. • Engage with Microsoft, CrowdStrike, and Proofpoint support teams for issue resolution. • Participate in architecture reviews and security enhancement initiatives. Team Management • Manage resource planning, workload distribution, and shift coverage. • Conduct performance coaching, mentoring, and technical reviews. • Drive skill development and certification initiatives. • Ensure adequate backup coverage and succession planning. Required Technical Skills Endpoint Security • CrowdStrike EDR • Microsoft Defender for Endpoint (MDE) • Endpoint Threat Detection & Response • Vulnerability Management Email Security • Proofpoint Email Protection • Proofpoint TAP • Proofpoint TRAP • Anti-Phishing Technologies • SPF, DKIM, DMARC Identity & Cloud Security • Microsoft Defender for Identity (MDI) • Microsoft Defender for Cloud Apps (MDCA) • Microsoft Entra ID / Azure AD • Identity Threat Detection Security Operations • Incident Response • Threat Hunting • Security Monitoring • Cyber Threat Intelligence • Security Governance Additional Skills • PowerShell Automation • Microsoft Security Portal • SIEM Integration • ServiceNow • Azure Security Services Experience & Qualifications Required • Degree in Computer Science, Cyber Security, Information Technology, or a related discipline. • 8+ years of cybersecurity experience. • Minimum 5+ years leading security tools teams. • Strong hands-on experience with CrowdStrike, Proofpoint, MDE, MDI, and MDCA. • Experience supporting enterprise-scale environments. • Excellent communication and stakeholder management skills. Preferred Certifications • CrowdStrike Administrator • Microsoft Certified: Security Operations Analyst (SC-200) • Microsoft Certified: Identity & Access Administrator (SC-300) • Microsoft Certified: Security Administrator (SC-100 / AZ-500) Preferred Candidate Profile • Strong customer-facing experience. • Ability to work in a fast-paced operational environment. • Demonstrated ability to drive proactive security improvements. • Strong analytical, troubleshooting, and leadership capabilities. • Willingness to work from Calgary, Alberta, Canada and participate in on-call support when required. |