Task 1: CrowdStrike Falcon Platform Support
- Provide dedicated assistance for the deployment, configuration, and integration of the Airport’s CrowdStrike Falcon Platform.
- Maximize the efficiency of the CrowdStrike platform for large enterprise environments.
- Maintain all relevant CrowdStrike certifications to ensure up-to-date platform expertise.
- Serve as the subject matter expert (SME) for CrowdStrike, providing ongoing support and recommendations for platform optimization.
Task 2: Palo Alto Networks (PAN-OS) Security Controls
- Assist with the design, implementation, and support of enhanced cybersecurity controls using Palo Alto Networks firewalls.
- Provide support for the integration of Prisma Cloud for comprehensive cloud security.
- Ensure the proper configuration and maintenance of firewall security settings to meet enterprise security requirements.
- Deliver guidance on the best practices for firewall management and risk mitigation.
Task 3: Microsoft Security and Identity Management
- Implement and manage Microsoft Azure cloud services, Intune, and Entra ID identity management.
- Design and configure SAML integration for secure authentication across applications and systems.
- Develop and implement conditional access policies to minimize MFA interactions during work hours, improving user experience without compromising security.
- Collaborate with internal teams to ensure seamless integration and continuous improvement of identity and security controls.
Minimum Requirements:
MQ1 - Proposer must provide at least three (3) similar projects in the past five (5) years.
- Client name and type of organization (government, private corporation, etc.).
- Project start and end dates.
MQ2 – Candidates(s) must have at least five (5) years of experience in the technologies with CrowdStrike, and Palo Alto Networks PAN-OS firewalls.
MQ3 - Candidates(s) must have current Certifications in the technologies (i.e., CrowdStrike, Palo Alto Networks firewalls, et al.) and their products the Airport has implemented and be able to provide a copy of certifications.
Additional Desirable Qualifications:
- Experience designing and deploying simple Splunk environments.
- Experience with Microsoft Azure Entra ID features and capabilities.
- Experience with the design and deployment of Microsoft sensitivity labels.
- Working Knowledge of Wireshark and Tshark.
- Working Knowledge of Powershell, Python, and Bash scripts.
- Familiarity with PCI DSS version 3 or version 4.