أبلاي إيدج ابدأ البحث عن عمل

Security Engineer EDR

Core42 · Abu Dhabi, Abu Dhabi Emirate, United Arab Emirates

قدّم وتابع مع أبلاي إيدج
About Us Core42, a leader in AI-powered cloud and digital infrastructure, is driving transformative technology solutions globally. Leveraging advanced resources and partnerships, Core42 empowers clients to harness sovereign AI infrastructure, especially in sectors with stringent regulatory needs. With a mission to redefine digital transformation, we combine sovereign capabilities with scalable, high-performance compute infrastructure, positioning itself at the forefront of AI innovation in the Middle East and beyond.The opportunity Security Engineer - Endpoint Detection & Response (Elastic EDR), Core42 - Abu Dhabi, UAE. We are seeking a highly skilled Security Engineer with hands-on expertise in the Elastic Security Platform, including Elastic Agent, Elastic Defend, Elasticsearch, Kibana, detection rules, threat hunting and incident response. The successful candidate will be responsible for designing, implementing, managing and optimising the organisation's EDR platform to ensure continuous monitoring, threat detection, incident investigation and response across enterprise environments. The role requires close collaboration with Security Operations, Incident Response, Platform Engineering, Infrastructure and Compliance teams to strengthen cyber defence capabilities and maintain security compliance requirements. The focus of this position is Elastic EDR engineering.Your key responsibilities Elastic EDR administration & engineeringDesign, deploy, configure and maintain Elastic EDR infrastructure and endpoint security agentsManage Elastic Agent lifecycle activities, including deployment, upgrades, troubleshooting and policy managementDevelop and maintain EDR baselines, security policies and endpoint hardening standardsEnsure high availability, scalability, performance and health of the Elastic Security platformIntegrate Elastic EDR with SIEM, SOAR, IAM, vulnerability management and threat intelligence platformsUpgrade, patch and maintain existing clustersDetection engineeringDevelop, tune and maintain detection rules and security use cases within Elastic SecurityEnhance threat detection capabilities to reduce false positives and improve security visibilityDesign and implement behavioural analytics, anomaly detection and advanced threat detection logicCreate custom dashboards, alerts, reports and visualisations within KibanaThreat hunting & incident responseConduct proactive threat hunting activities using Elastic Security datasetsInvestigate endpoint security incidents, malware infections, insider threats and advanced attacksAnalyse telemetry, process activities, file events, registry modifications, network connections and user behaviourSupport digital forensics and incident response investigationsIdentify root causes and recommend mitigation strategiesSecurity monitoring & optimisationMonitor EDR platform performance, coverage and security effectivenessPerform continuous tuning of endpoint security controlsEstablish KPIs and operational metrics for EDR effectivenessValidate security controls through attack simulation and red team exercisesIntegration & automationIntegrate Elastic EDR with IDP, LDAP, AI and ML integrations, vulnerability management solutions, SIEM platforms, threat intelligence feeds and SOAR workflowsIntegrate with OpenStack, OpenShift, NVIDIA and AMD systemsAutomate security operations using APIs, scripts and orchestration toolsGovernance & complianceEnsure EDR deployment aligns with NIST SP 800-53, ISO 27001, SOC 2, CIS Controls and internal security standards and policiesSupport audit activities and provide security evidence when requiredMaintain security documentation, procedures and operational runbooksWhat we’re looking for (a) Required skills / qualificationsBachelor's degree in Cyber Security, Computer Science, Information Security or a related discipline5 to 7 years of experience in security engineering, incident response, threat hunting or detection engineeringExperience supporting enterprise-scale EDR deployments (10,000+ endpoints preferred)Hands-on expertise across Elastic Security, Elastic Defend, Elastic Agent, Elasticsearch and KibanaDetection rule engineering, threat hunting and log analysisEndpoint security, Windows security and Linux securityMITRE ATT&CK framework, incident response and malware analysis fundamentals(b) Preferred skills / qualificationsPython and Bash scriptingExperience with threat intelligence platformsCertifications: Elastic Certified Engineer, Elastic Security AnalystWhat working at Core42 offers With a diverse team of 1,100+ employees from 68 nationalities, we foster an inclusive, innovative and collaborative environment. At Core42, we foster a culture grounded in trust, accountability and high performance. We are united by our values: Grit, where we overcome challenges with resilience and determination, Passion, which drives us to pursue excellence in everything we do, and Impact, as we aim to inspire progress and create meaningful change. Our team members thrive in an environment where each person’s contributions propel us forward, and together, we commit to achieving extraordinary results. Competitive Salary: We offer an attractive salary package based on your skills and experience Yearly Bonus: In recognition of your contributions, you will receive a performance-based annual bonusExclusive Discount Cards: Access special benefits with Esaad and Fazaa cards, offering discounts across a wide range of servicesPremium Family Insurance: We provide comprehensive health coverage, including dental, vision and life insurance, ensuring the well-being of you and your familyLearning & Development: We offer access to top-tier learning platforms to help you grow in your career. Learn at your own pace with unlimited access to premium courses.