IT & Software

Cybersecurity Tools Lead – Microsoft Defender (MDE, MDI, MDCA)

Astra-North Infoteck Inc. ~ Conquering today’s challenges, achieving tomorrow’s vision!

Calgary · Ab · Canada

Cybersecurity Tools Lead – Microsoft Defender (MDE, MDI, MDCA)Required Skillset Microsoft Defender for Endpoint (MDE)

Microsoft Defender for Identity (MDI)

Microsoft Defender for Cloud Apps (MDCA)

CrowdStrike Falcon

Proofpoint Email Security

Security Incident Investigation and Response

Threat Hunting and Threat Intelligence

Endpoint Detection & Response (EDR)

SIEM/SOAR Integration Knowledge (Microsoft Sentinel preferred)

Windows Server and Active Directory Security

Email Security and Anti-Phishing Controls

Security Monitoring and Alert Triage

Job Summary

We are seeking an experienced and highly motivated

Security Tools Team Lead

to lead the administration, optimization, and continuous improvement of enterprise cybersecurity platforms. The role requires deep expertise in

CrowdStrike EDR, Microsoft Defender for Endpoint (MDE), Microsoft Defender for Identity (MDI), Microsoft Defender for Cloud Apps (MDCA), and Proofpoint Email Security .

The successful candidate will lead a team of security specialists, manage daily operations, drive cybersecurity initiatives, support incident response activities, and collaborate closely with SOC, Infrastructure, Cloud, and Business teams. The ideal candidate will possess strong technical expertise, leadership capabilities, stakeholder management skills, and a proactive mindset focused on enhancing the organization's security posture. Key Responsibilities

Administer and support Microsoft Defender Suite (MDE, MDI, MDCA).

Manage CrowdStrike Falcon platform, including policy tuning, threat detection, and endpoint protection.

Monitor and administer Proofpoint email security solutions to protect against phishing, malware, and business email compromise attacks.

Investigate security alerts and incidents, perform root cause analysis, and provide remediation recommendations.

Conduct proactive threat hunting across endpoints, identities, cloud applications, and email environments.

Fine-tune detection rules and security policies to reduce false positives and improve security visibility.

Integrate security tools with SIEM platforms such as Microsoft Sentinel.

Develop and maintain security monitoring dashboards, reports, and operational documentation.

Collaborate with infrastructure, application, and SOC teams during incident response and remediation activities.

Support vulnerability management and security compliance initiatives.

#J-18808-Ljbffr

Reference: WJ-3875_13084230

Apply now

Continue on the employer's official application - the same link they use for every candidate.

More jobs

Find more on GigBlows

This role is listed on GigBlows for discovery and search. Hiring decisions and applications are handled by the employer or their chosen application system.