Location: Remote
Responsibilities
- Review the CrowdStrike Falcon configuration and confirm it is set up correctly and tuned to the environment.
- Assess whether monitoring, alerting, log ingestion, and retention are configured optimally.
- Identify where the CrowdStrike Falcon platform is under-utilized and recommend improvements.
- Validate and optimize detection, alerting, and dashboards within CrowdStrike Falcon.
- Review log ingestion and data retention settings to ensure they align with operational needs.
- Evaluate how CrowdStrike Falcon and other monitoring controls work together across the setting.
- Identify opportunities to bring additional log sources into the SIEM.
- Provide independent assurance that the platform is configured correctly and fully leveraged.
- Assess the overall cybersecurity monitoring and detection environment.
- Prepare and deliver a comprehensive written report documenting the assessment of the cybersecurity environment.
- Identify key findings and provide clear, actionable recommendations and remediation guidance.
- Communicate clearly and produce professional documentation for both technical and management audiences.
Qualifications
- Demonstrated, hands-on expertise configuring, tuning, and optimizing the CrowdStrike Falcon platform, including endpoint and server protection, Next-Gen SIEM, threat intelligence, and continuous monitoring.
- Experience validating and optimizing detection, alerting, dashboards, log ingestion, and data retention within CrowdStrike Falcon.
- Working experience with security monitoring and threat-detection tooling beyond a single vendor, including network monitoring and log/SIEM integration.
- Proven ability to assess an existing security environment and deliver practical, prioritized recommendations and remediation guidance.
- Strong analytical and problem-solving skills, with the ability to communicate clearly and produce professional documentation for both technical and management audiences.
- Relevant industry or vendor certifications, such as CrowdStrike Falcon certifications or an equivalent recognized security certification.
- Experience integrating additional log sources, such as file-share and audit logs, into a SIEM.
- Familiarity with recognized frameworks such as the NIST Cybersecurity Framework.
AI Disclosure: We do not use artificial intelligence (AI) tools to screen, assess, or select applicants at any stage of our recruitment process. All applications are reviewed by our recruitment team. OXARO is committed to fostering an inclusive, equitable and respectful workplace where every individual feels valued and empowered to contribute their best. We believe that diversity drives innovation and strengthens our ability to serve our clients and communities. We are dedicated to ensuring a fair and unbiased recruitment process and welcome applications from members of the four designated groups under the Employment Equity Act: women, Indigenous peoples, persons with disabilities and members of visible minorities.
Accommodations are available upon request for candidates taking part in all aspects of the recruitment process.
We sincerely thank all applicants for their interest in this opportunity. While we appreciate every application, only those selected for an interview will be contacted.
📌 Cybersecurity Expert (Ottawa)
🏢 OXARO
📍 Ottawa