Astra North Infoteck Inc.
Cybersecurity Tools Lead – Microsoft Defender (MDE, MDI, MDCA)
Veröffentlicht am 22. Sept. 2026
Diese Stelle wird in EN ausgeschrieben
Cybersecurity Tools Lead – Microsoft Defender (MDE, MDI, MDCA)
Required Skillset
-
Microsoft Defender for Endpoint (MDE)
-
Microsoft Defender for Identity (MDI)
-
Microsoft Defender for Cloud Apps (MDCA)
-
CrowdStrike Falcon
-
Proofpoint Email Security
-
Security Incident Investigation and Response
-
Threat Hunting and Threat Intelligence
-
Endpoint Detection & Response (EDR)
-
SIEM/SOAR Integration Knowledge (Microsoft Sentinel preferred)
-
Windows Server and Active Directory Security
-
Email Security and Anti-Phishing Controls
-
Security Monitoring and Alert Triage
Job Summary
We are seeking an experienced and highly motivated Security Tools Team Lead to lead the administration, optimization, and continuous improvement of enterprise cybersecurity platforms.
The role requires deep expertise in CrowdStrike EDR, Microsoft Defender for Endpoint (MDE), Microsoft Defender for Identity (MDI), Microsoft Defender for Cloud Apps (MDCA), and Proofpoint Email Security.
The successful candidate will lead a team of security specialists, manage daily operations, drive cybersecurity initiatives, support incident response activities, and collaborate closely with SOC, Infrastructure, Cloud, and Business teams.
The ideal candidate will possess strong technical expertise, leadership capabilities, stakeholder management skills, and a proactive mindset focused on enhancing the organization's security posture.
Key Responsibilities
-
Administer and support Microsoft Defender Suite (MDE, MDI, MDCA).
-
Manage CrowdStrike Falcon platform, including policy tuning, threat detection, and endpoint protection.
-
Monitor and administer Proofpoint email security solutions to protect against phishing, malware, and business email compromise attacks.
-
Investigate security alerts and incidents, perform root cause analysis, and provide remediation recommendations.
-
Conduct proactive threat hunting across endpoints, identities, cloud applications, and email environments.
-
Fine-tune detection rules and security policies to reduce false positives and improve security visibility.
-
Integrate security tools with SIEM platforms such as Microsoft Sentinel.
-
Develop and maintain security monitoring dashboards, reports, and operational documentation.
-
Collaborate with infrastructure, application, and SOC teams during incident response and remediation activities.
-
Support vulnerability management and security compliance initiatives.
Rollenübersicht
Jobart
Vollzeit
Erforderliche Kompetenzen
Ähnliche Stellen
Senior Infrastructure Operations Analyst – SCCM, SCOM & Intune
Astra North Infoteck Inc.
*Software Engineer — 100% Remote (Alberta)
Recrute Action
Cybersecurity Technical Lead - CrowdStrike, Proofpoint, MDE, MDI, and MDCA
Astra North Infoteck Inc.
Windows Server Administrator - SCCM
Astra North Infoteck Inc.
Linux Systems Administrator – Patch Management
Astra North Infoteck Inc.
Technical Program Lead – Data Governance, Business Case & Asset Management
Astra North Infoteck Inc.