Elastic EDR Security Engineer: Threat Detection & Response

Core42

Dubai

On-site

AED 446,000 - 714,000

Full time

11 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Yearly bonus
Discount cards (Esaad/Fazaa)
Health insurance
Learning & development opportunities

Job summary

Core42 in Dubai is seeking a Security Engineer specialized in Elastic EDR to design, deploy and optimise the endpoint security platform across enterprise environments. You will work with Security Operations, Incident Response and Platform Engineering teams to strengthen cyber defence and ensure compliance.

The role emphasizes detection engineering, threat hunting, and incident response, with hands-on Elastic Agent, Elasticsearch and Kibana; experience across SIEM and SOAR is valued, and a path

Qualifications

  • Bachelor's degree in Cyber Security, Computer Science, Information Security or related discipline.
  • 5 to 7 years of experience in security engineering, incident response, threat hunting or detection engineering.
  • Hands-on expertise across Elastic Security, Elastic Defend, Elastic Agent, Elasticsearch and Kibana.

Responsibilities

  • Design, deploy, configure and maintain Elastic EDR infrastructure and endpoint security agents.
  • Manage Elastic Agent lifecycle activities, including deployment, upgrades, troubleshooting and policy management.
  • Develop and maintain EDR baselines, security policies and endpoint hardening standards.
  • Ensure high availability, scalability, performance and health of the Elastic Security platform.
  • Integrate Elastic EDR with SIEM, SOAR, IAM, vulnerability management and threat intelligence platforms.
  • Upgrade, patch and maintain existing clusters.
  • Develop, tune and maintain detection rules and security use cases within Elastic Security.
  • Enhance threat detection capabilities to reduce false positives and improve security visibility.
  • Design and implement behavioural analytics, anomaly detection and advanced threat detection logic.
  • Create custom dashboards, alerts, reports and visualisations within Kibana.
  • Conduct proactive threat hunting activities using Elastic Security datasets.
  • Investigate endpoint security incidents, malware infections, insider threats and advanced attacks.
  • Analyse telemetry, process activities, file events, registry modifications, network connections and user behaviour.
  • Support digital forensics and incident response investigations.
  • Identify root causes and recommend mitigation strategies.
  • Monitor EDR platform performance, coverage and security effectiveness.
  • Perform continuous tuning of endpoint security controls.
  • Establish KPIs and operational metrics for EDR effectiveness.
  • Validate security controls through attack simulation and red team exercises.
  • Integrate Elastic EDR with IDP, LDAP, AI and ML integrations, vulnerability management solutions, SIEM platforms, threat intelligence feeds and SOAR workflows.
  • Integrate with OpenStack, OpenShift, NVIDIA and AMD systems.
  • Automate security operations using APIs, scripts and orchestration tools.
  • Ensure EDR deployment aligns with NIST SP 800-53, ISO 27001, SOC 2, CIS Controls and internal security standards and policies.
  • Support audit activities and provide security evidence when required.
  • Maintain security documentation, procedures and operational runbooks.

Education

Bachelor's degree in Cyber Security, Computer Science, Information Security or related discipline

Tools

Elastic Agent
Elasticsearch
Kibana
Elastic Defend
SIEM
SOAR
Threat Hunting

Job description

Core42 in Dubai is seeking a Security Engineer specialized in Elastic EDR to design, deploy and optimise the endpoint security platform across enterprise environments. You will work with Security Operations, Incident Response and Platform Engineering teams to strengthen cyber defence and ensure compliance.

The role emphasizes detection engineering, threat hunting, and incident response, with hands-on Elastic Agent, Elasticsearch and Kibana; experience across SIEM and SOAR is valued, and a path

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Elastic EDR Security Engineer – Threat Detection & Response
Elastic EDR Security Engineer – Threat Detection & Response

Core42 • United Arab Emirates

On-site
AED 350,000 - 550,000
Competitive salary
Yearly bonus
Discount cards (Esaad & Fazaa)
+2
Security Engineer
Security Engineer

Core42 • Dubai

On-site
AED 446,000 - 714,000
Yearly bonus
Discount cards (Esaad/Fazaa)
Health insurance
+1
Security Engineer
Security Engineer

Core42 • United Arab Emirates

On-site
AED 350,000 - 550,000
Competitive salary
Yearly bonus
Discount cards (Esaad & Fazaa)
+2
Dubai Senior Cybersecurity Engineer: Incident Response & MDR
Dubai Senior Cybersecurity Engineer: Incident Response & MDR

Emerald Zebra - Recruitment & Executive Search • Dubai

On-site
AED 420,000 - 600,000
Competitive salary package
Medical Insurance starting day 1
Training and development opportunities
+3
Security Platform Engineer: SIEM & EDR Expert
Security Platform Engineer: SIEM & EDR Expert

EDGE • Abu Dhabi

On-site
AED 240,000 - 360,000
Security Engineer: Threat Mitigation, Cloud & Incident Response
Security Engineer: Threat Mitigation, Cloud & Incident Response

prelev-consulting • Dubai

On-site
AED 200,000 - 300,000
NDR & Cloudflare Security Engineer — Abu Dhabi
NDR & Cloudflare Security Engineer — Abu Dhabi

Core42 • Abu Dhabi

On-site
AED 300,000 - 520,000
Competitive salary
Yearly bonus
Discount cards (Esaad/Fazaa)
+2
Solution Engineer (MDR)
Solution Engineer (MDR)

Eventussecurity • Dubai

On-site
AED 293,000 - 441,000
Security Engineer NDR
Security Engineer NDR

Core42 • Abu Dhabi

On-site
AED 300,000 - 520,000
Competitive salary
Yearly bonus
Discount cards (Esaad/Fazaa)
+2
Solution Engineer (MDR)
Solution Engineer (MDR)

Eventus Security • Dubai

On-site
AED 257,000 - 331,000