04 Sep
|
22nd Century Technologies
|
Regina
04 Sep
22nd Century Technologies
Regina
Client: Elections Saskatchewan (ESK) Job Title: Cybersecurity Expert Crowd
Strike Falcon / Security Monitoring Location: Fully Remote Saskatchewan, Canada Work Arrangement: Remote; fully remote resources will be considered Engagement Type: Statement of Work (SOW) Estimated Effort: Approximately 80120 hours Start Date: As soon as possible End Date: December 31, 2026, or earlier based on completion of deliverables and milestones Resources Requested: 1 fully qualified resource Minimum Experience: No prescribed minimum level of experience RFR Reference: ESK-RFR-IT-2026-004 Issued Under: ESK-2025-003-RFPQ Date Issued: August 27, 2026 Closing Date: September 11, 2026 at 2:00 PM CST Position Overview Elections Saskatchewan (ESK) is seeking an experienced Cybersecurity Expert to review, validate, and optimize its security monitoring environment. ESK uses the Crowd
Strike Falcon platform for endpoint and server protection, threat intelligence, and continuous monitoring, and it is now the core of ESK''s detection and response capability. ESK is seeking independent assurance that the platform is configured correctly, monitoring is set up optimally, and ESK is fully leveraging the capabilities available within Crowd
Strike Falcon.
The emphasis of this engagement is Crowd
Strike Falcon expertise , complemented by broader working knowledge of security monitoring and detection tooling.
Important This is not a scanning, vulnerability-assessment, or penetration-testing engagement.
The selected resource will focus on Crowd
Strike Falcon configuration, tuning, optimization, security monitoring, detection, alerting, SIEM integration, and cybersecurity posture assessment.
Work Arrangement & Engagement Details Fully remote resources will be considered.
Occasional meetings with ESK stakeholders may be required. ESK will provide the necessary hardware and system access.
The engagement is estimated to require approximately 80120 hours of effort .
The SOW would commence as soon as possible and shall expire on December 31, 2026 , or earlier based on completion of the deliverables and milestones agreed to at the outset of the engagement.
The term may be extended if mutually agreed to in writing by both parties in accordance with the Master Services Agreement.
Experience Requirement There is no prescribed minimum level of experience for this engagement.
Proponents should use the evaluation criteria and response table included in the RFR to demonstrate the candidate''s relevant experience, qualifications, and expertise. ESK will evaluate submissions based on the information provided in the response table and the overall fit of the proposed resource to the requirements of the engagement.
Key Responsibilities The selected resource will be required to: 1.
Crowd
Strike Falcon Configuration & Optimization Review ESK''s Crowd
Strike Falcon configuration and confirm it is set up correctly and tuned to ESK''s workplace.
Configure, tune, and optimize the Crowd
Strike Falcon platform.
Review endpoint and server protection capabilities.
Assess Crowd
Strike Falcon Next-Gen SIEM capabilities.
Review threat intelligence and continuous monitoring capabilities.
Identify areas where the Crowd
Strike Falcon platform is under-utilized.
Recommend opportunities to fully leverage available Crowd
Strike capabilities. 2.
Security Monitoring, Detection & Alerting Assess whether ESK''s monitoring, alerting, log ingestion, and retention are configured optimally.
Validate and optimize Crowd
Strike detection capabilities.
Validate and optimize alerting.
Review and optimize dashboards.
Assess log ingestion.
Assess data retention.
Identify gaps and opportunities to improve security monitoring and detection capabilities. 3. SIEM & Log Integration Evaluate how Crowd
Strike and ESK''s other monitoring controls work together.
Identify opportunities to bring additional log sources into the SIEM.
Assess opportunities to integrate additional security and operational data sources.
Provide recommendations for improving SIEM visibility and monitoring.
Potential additional log sources may include: File-share logs Audit logs Network monitoring data Other relevant security and operational logs 4.
Cybersecurity Environment Assessment Assess ESK''s overall cybersecurity environment.
Conduct a cybersecurity posture assessment.
Identify key findings, security gaps, configuration issues, and areas of under-utilization.
Evaluate existing security monitoring and threat-detection capabilities.
Provide practical and prioritized recommendations.
Provide clear remediation guidance. 5.
Reporting & Documentation Prepare and deliver a comprehensive written report documenting the assessment of ESK''s overall cybersecurity environment.
Clearly document key findings.
Provide actionable recommendations.
Provide prioritized remediation guidance.
Communicate findings clearly to both technical and management audiences.
Produce professional cybersecurity documentation.
Required Qualifications The preferred resource must have: Crowd
Strike Falcon Expertise Demonstrated, hands-on expertise configuring, tuning, and optimizing the Crowd
Strike Falcon platform .
Experience with endpoint protection.
Experience with server protection.
Experience with Next-Gen SIEM .
Experience with threat intelligence.
Experience with continuous monitoring.
Experience validating and optimizing Crowd
Strike detection.
Experience validating and optimizing alerting.
Experience with Crowd
Strike dashboards.
Experience with log ingestion.
Experience with data retention.
Security Monitoring & Threat Detection Working experience with security monitoring and threat-detection tooling beyond a single vendor.
Experience with network monitoring.
Experience with log/SIEM integration.
Ability to evaluate how multiple security monitoring controls work together.
Experience identifying opportunities to improve security visibility and detection.
Cybersecurity Assessment Proven ability to assess an existing security workplace.
Experience conducting cybersecurity posture assessments.
Ability to identify security gaps and areas of improvement.
Ability to provide practical, prioritized recommendations.
Ability to provide remediation guidance.
Communication & Documentation Strong analytical and problem-solving skills.
Ability to communicate clearly.
Ability to produce professional documentation.
Ability to communicate technical findings effectively to both technical and management audiences.
Preferred Qualifications It is preferred that the resource also have: Relevant industry or vendor certifications.
Crowd
Strike Falcon certifications or an equivalent recognized security certification.
Experience integrating additional log sources, such as file-share and audit logs, into a SIEM.
Familiarity with recognized frameworks such as the NIST Cybersecurity Framework .
Crowd
Strike Falcon Modules & Components Candidates should list the specific Crowd
Strike Falcon modules and components with which they have hands-on experience and describe their experience with each.
Examples include: Crowd
Strike Falcon Next-Gen SIEM Crowd
Strike Insight / EDR Crowd
Strike Prevent Endpoint Protection Server Protection Threat Intelligence Continuous Monitoring Detection & Alerting Dashboards Log Ingestion Data Retention Key Deliverables The selected resource will be expected to provide: Crowd
Strike Falcon configuration review.
Crowd
Strike Falcon tuning and optimization assessment.
Monitoring assessment.
Detection and alerting assessment.
Dashboard assessment.
Log ingestion assessment.
Data retention assessment. SIEM integration assessment.
Additional log-source integration recommendations.
Cybersecurity posture assessment.
Identification of key findings and gaps.
Prioritized recommendations.
Remediation guidance.
Comprehensive written cybersecurity assessment report.
Communication of findings to technical and management stakeholders.
📌 Cybersecurity Expert CrowdStrike Falcon / Security Monitoring (Regina)
🏢 22nd Century Technologies
📍 Regina