EDR Expert

VaporVM

Dubai

On-site

AED 240,000 - 400,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

VaporVM seeks an experienced EDR Expert to monitor, investigate, and analyze SentinelOne alerts, distinguishing false positives from genuine incidents. You will support timely incident response and collaborate across teams to improve containment and remediation.

The role focuses on reviewing endpoint telemetry, processing trees, and IOCs, with emphasis on MITRE ATT&CK tactics and techniques. Strong analytical skills are essential.

Qualifications

  • 3–5+ years in EDR, SOC, cybersecurity operations or incident response.
  • Hands-on SentinelOne experience is mandatory.
  • Strong understanding of endpoint security, malware analysis and investigations.
  • Experience analyzing process trees, endpoint telemetry and IOCs.
  • Familiarity with Windows and Linux endpoint security and MITRE ATT&CK.

Responsibilities

  • Review SentinelOne EDR alerts to classify false positives vs incidents.
  • Investigate endpoint alerts, suspicious activity, malware behavior and IOCs.
  • Analyze telemetry, process trees and detection data for root causes.
  • Validate incidents, determine severity and impact; escalate when needed.
  • Correlate alerts with SIEM data to identify attack patterns.
  • Document findings and remediation recommendations; maintain records.
  • Tune alerts and policies to reduce recurring false positives.
  • Support containment, remediation and eradication activities.
  • Prepare regular reports on EDR alerts and incidents.
  • Stay updated on new endpoint threats and MITRE techniques.

Skills

EDR
SOC
Incident Response
SentinelOne
MITRE ATT&CK
Windows security
Linux security
Endpoint telemetry
IOC analysis
Threat hunting

Tools

Splunk
Microsoft Sentinel
QRadar

Job description

We are seeking an experienced EDR Expert with strong hands‑on expertise in SentinelOne to monitor, investigate, and analyze endpoint security alerts. The ideal candidate will be responsible for reviewing alerts, distinguishing between false positives and genuine security incidents, and supporting timely incident response.

Key Responsibilities
  • Review and analyze SentinelOne EDR alerts to determine whether they represent false positives or genuine security incidents.
  • Investigate endpoint alerts, suspicious activities, malicious processes, files, scripts, and user behavior.
  • Perform detailed analysis of endpoint telemetry, detection data, process trees, and indicators of compromise (IOCs).
  • Validate security incidents and determine the severity and potential impact on the environment.
  • Correlate EDR alerts with other available security data to identify potential attack patterns.
  • Escalate confirmed security incidents according to established incident response procedures.
  • Document investigation findings, root causes, and recommended remediation actions.
  • Identify recurring false positives and recommend appropriate alert tuning and policy adjustments.
  • Support containment, remediation, and threat eradication activities where required.
  • Maintain incident records and prepare regular reports on EDR alerts and security incidents.
  • Stay updated on emerging endpoint threats, malware techniques, and MITRE ATT&CK tactics and techniques.
Required Skills & Experience
  • 3–5+ years of experience in EDR, SOC, Cybersecurity Operations, or Incident Response.
  • Strong hands‑on experience with SentinelOne is mandatory.
  • Good understanding of endpoint security, malware analysis, and incident investigation.
  • Experience analyzing process trees, endpoint telemetry, IOCs, and suspicious activities.
  • Strong knowledge of Windows and Linux endpoint security.
  • Understanding of common attack techniques, malware behavior, and MITRE ATT&CK framework.
  • Experience with SIEM platforms such as Splunk, Microsoft Sentinel, or QRadar is an advantage.
  • Strong analytical and incident investigation skills.
  • Relevant cybersecurity certifications such as CompTIA Security+, CySA+, CEH, GCIH, or equivalent are preferred.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SentinelOne EDR Investigator — Incident Response Pro
SentinelOne EDR Investigator — Incident Response Pro

VaporVM • Dubai

On-site
AED 240,000 - 400,000
Specialist – Endpoint Security
Specialist – Endpoint Security

CPX • Abu Dhabi

On-site
AED 240,000 - 360,000
Senior IT Security Operations Engineer
Senior IT Security Operations Engineer

VaporVM • Dubai

On-site
AED 250,000 - 390,000
Senior Security Engineer - EDR & NDR
Senior Security Engineer - EDR & NDR

Help AG • Dubai

Hybrid
AED 260,000 - 460,000
Health insurance
Flexible/Hybrid working environment
Specialist Cybersecurity Analyst (Emirati Talent)
Specialist Cybersecurity Analyst (Emirati Talent)

EDGE • Abu Dhabi

On-site
AED 180,000 - 260,000
Security Specialist
Security Specialist

iConnect IT Business Solutions DMCC • Abu Dhabi

On-site
AED 180,000 - 280,000
Senior Security Engineer - Splunk Sentinel and Cribl
Senior Security Engineer - Splunk Sentinel and Cribl

HELP INFORMATION TECHNOLOGY CONSULTANCY - SOLE PROPRIETORSHIP L.L.C • Dubai

On-site
AED 300,000 - 550,000
Senior Endpoint Security Engineer: EDR/XDR & SOC
Senior Endpoint Security Engineer: EDR/XDR & SOC

CPX • Abu Dhabi

On-site
AED 240,000 - 360,000
Lead Consultant – Incident Response
Lead Consultant – Incident Response

Forensic Focus Limited • Abu Dhabi

On-site
AED 300,000 - 520,000
Threat Hunting Specialist (UAEN)
Threat Hunting Specialist (UAEN)

Confidential • Abu Dhabi Emirate

On-site
AED 260,000 - 420,000