Core42

Security Engineer - Elastic Endpoint Detection & Response (EDR)

Core42

Abu Dhabi, United Arab Emirates · Full Time

Be the first to apply

Experience
5–7 yrs
Salary
Openings
1
Posted
1 hour ago
Work mode
In office
Education
Bachelor's degree in Cyber Security or related field
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About Core42

Core42 is a pioneering force in AI-driven cloud and digital infrastructure, delivering transformative technology solutions on a global scale. Focused on enabling sovereign AI infrastructure, particularly in sectors with strict regulatory demands, Core42 merges sovereign capabilities with high-performance, scalable compute resources. This positions the company at the cutting edge of AI innovation throughout the Middle East and beyond.

Role Overview

The Security Engineer for Endpoint Detection & Response (EDR) at Core42, based in Abu Dhabi, UAE, is a highly skilled professional specializing in the Elastic Security Platform. This role involves hands-on management of Elastic Agent, Elastic Defend, Elasticsearch, Kibana, and related components including detection rules, threat hunting, and incident response.

The position entails the design, deployment, management, and optimization of the organization's Elastic EDR platform to facilitate continuous threat monitoring, detection, incident investigation, and response within enterprise environments. Collaboration with teams such as Security Operations, Incident Response, Platform Engineering, Infrastructure, and Compliance is essential to bolster cyber defense and ensure security conformity.

Responsibilities

  • Design, deploy, and maintain the Elastic EDR infrastructure and endpoint security agents ensuring lifecycle management, including deployment, upgrades, and policy control.
  • Create and enforce EDR baselines, security policies, and endpoint hardening protocols.
  • Maintain platform availability, scalability, health, and optimal performance.
  • Integrate Elastic EDR with SIEM, SOAR, IAM, vulnerability management, and threat intelligence systems.
  • Patch, upgrade, and sustain existing Elastic clusters.
  • Develop and refine detection rules, security use cases, behavioral analytics, anomaly detection, and advanced threat detection algorithms.
  • Construct tailored dashboards, alerts, reports, and visualizations within Kibana.
  • Conduct proactive threat hunting exercising Elastic Security data sets and investigate security incidents such as malware infections, insider threats, and sophisticated attacks.
  • Analyze telemetry, system activities, file events, registry changes, network traffic, and user behavior patterns.
  • Support digital forensics and incident investigations identifying root causes and suggesting remediation approaches.
  • Continuously monitor and optimize EDR platform performance, endpoint security controls, and establish metrics and KPIs to measure effectiveness.
  • Validate controls through red team exercises and attack simulations.
  • Integrate the EDR platform with OpenStack, OpenShift, NVIDIA, AMD systems, and automate operations via APIs, scripting, and orchestration tools.
  • Ensure compliance with security frameworks including NIST SP 800-53, ISO 27001, SOC 2, CIS Controls, and internal policies.
  • Support audits and maintain comprehensive security documentation, operational runbooks, and procedures.

Required Qualifications

  • Bachelor's degree in Cyber Security, Computer Science, Information Security, or related fields.
  • 5 to 7 years of professional experience in security engineering, incident response, threat hunting, or detection engineering.
  • Proven experience managing enterprise-scale EDR deployments covering 10,000+ endpoints is preferred.
  • In-depth hands-on expertise with Elastic Security Suite including Elastic Defend, Elastic Agent, Elasticsearch, and Kibana.
  • Skillful in detection rule engineering, threat hunting techniques, and log analysis.
  • Strong knowledge of endpoint security across Windows and Linux environments.
  • Familiarity with MITRE ATT&CK framework, incident response procedures, and malware analysis fundamentals.

Preferred Skills

  • Proficiency in Python and Bash scripting.
  • Experience working with threat intelligence platforms.
  • Professional certifications such as Elastic Certified Engineer and Elastic Security Analyst are advantageous.

Work Culture & Benefits

Core42 values an inclusive culture that embraces over 1,100 employees representing 68 nationalities. The organization thrives on trust, accountability, and high-performance culture guided by values of grit, passion, and impactful innovation. Team members enjoy an environment where their contributions drive organizational success.

  • Competitive salary packages aligned with candidate qualifications and experience.
  • Annual performance bonuses recognizing individual contributions.
  • Access to exclusive discount cards (Esaad and Fazaa) providing benefits across diverse services.
  • Comprehensive family health insurance covering dental, vision, and life insurance.
  • Opportunities for learning and professional development with unlimited access to premium educational content.

Minimum education

Bachelor's Degree

Tools & software

Python required

How they work

Teamwork & Collaboration Problem Solving Attention to Detail Resilience

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer