Senior Security Engineer - EDR & NDR

Help AG

Dubai

On-site

AED 260,000 - 380,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Career progression
Learning and development opportunities
Flexible/Hybrid working environment

Job summary

Help AG is seeking a Senior Security Engineer – EDR & NDR in Dubai to design, implement, and optimize enterprise EDR and NDR platforms, ensuring visibility and coverage across customer environments.

You will work with SOC Analysts, Incident Response, Threat Intelligence, SIEM Engineering, and Solution Architects to deliver Managed Security Services and strategic cybersecurity initiatives.

Qualifications

  • Minimum 5–7 years of cybersecurity engineering or security operations.
  • Minimum 4 years of hands-on experience administering enterprise EDR platforms.
  • Minimum 3 years of experience administering NDR platforms.
  • Strong certifications in leading security platforms are preferred.

Responsibilities

  • Design, implement, administer, optimize, and support EDR & NDR platforms.
  • Collaborate with SOC Analysts, Incident Response, Threat Intelligence, and SIEM teams.
  • Perform platform health checks, upgrades, and policy tuning.
  • Develop automation workflows using APIs and scripting.
  • Support onboarding, integration, and runbooks.

Skills

Security engineering
Threat hunting
Incident response
SOC collaboration
Mentoring juniors

Tools

Microsoft Defender for Endpoint
CrowdStrike Falcon
Carbon Black
Trend Micro Vision One
Vectra AI
ExtraHop Reveal(x)
Splunk Enterprise Security
Microsoft Sentinel
PowerShell
Python scripting
Active Directory & Entra ID

Job description

Help AG is looking for a Senior Security Engineer – EDR & NDR who will be responsible for the design, implementation, administration, optimization, and support of Endpoint Detection & Response (EDR) and Network Detection & Response (NDR) platforms across customer environments. The role requires strong technical expertise in deploying, integrating, tuning, and maintaining enterprise security platforms while ensuring optimal performance, visibility, and security coverage.

The engineer will work closely with SOC Analysts, Incident Response, Threat Intelligence, SIEM Engineering, Solution Architects, and customers to deliver high-quality Managed Security Services and support strategic cybersecurity initiatives.

Responsibilities
  • EDR Platform Administration
    • Deploy, configure, administer, and maintain enterprise EDR platforms including:
      • Microsoft Defender for Endpoint
      • CrowdStrike Falcon
      • Carbon Black
      • Trend Micro Vision One / Apex One
    • Perform health checks, upgrades, troubleshooting, and lifecycle management.
    • Configure prevention policies, detection rules, IOC/IOA indicators, device control, and endpoint security baselines.
    • Fine-tune EDR policies to minimize false positives while maintaining effective detection coverage.
    • Perform endpoint containment, host isolation, malware remediation, and forensic support during security incidents.
    • Support endpoint onboarding, offboarding, RBAC configuration, and policy management.
    • Integrate EDR platforms with SIEM, SOAR, Identity, and Threat Intelligence solutions.
  • NDR Platform Administration
    • Deploy, configure, administer, and maintain Network Detection & Response platforms including:
      • Vectra AI
      • ExtraHop Reveal(x)
    • Configure sensors, packet capture, metadata collection, and monitoring infrastructure.
    • Tune AI-based detections and behavioural analytics.
    • Investigate suspicious network activities including lateral movement, command-and-control communications, ransomware, insider threats, and credential abuse.
    • Integrate NDR platforms with SIEM, SOAR, EDR, and Threat Intelligence platforms.
    • Perform platform health monitoring, upgrades, and capacity management.
  • Engineering & Integration
    • Design and implement integrations between EDR, NDR, SIEM, SOAR, Threat Intelligence Platforms, Active Directory, Microsoft Entra ID, and ITSM platforms.
    • Develop automation workflows using APIs and scripting to improve operational efficiency.
    • Create and maintain architecture diagrams, technical documentation, SOPs, and operational runbooks.
    • Support customer onboarding, migration, and platform integration projects.
    • Validate telemetry collection, data quality, and event visibility across integrated security platforms.
  • Threat Detection & Security Operations
    • Work closely with SOC and Incident Response teams to investigate and respond to security incidents.
    • Conduct threat hunting using endpoint, network, and SIEM telemetry.
    • Develop and improve detection use cases aligned with the MITRE ATT&CK framework.
    • Participate in purple team exercises, adversary emulation, and continuous improvement initiatives.
    • Recommend security improvements based on emerging threats and incident findings.
  • Operational Responsibilities
    • Perform platform upgrades, patching, backup validation, and preventive maintenance.
    • Monitor platform health, licensing, storage, and overall performance.
    • Maintain technical documentation, SOPs, and knowledge base articles.
    • Provide technical mentoring and guidance to junior engineers and SOC analysts.
    • Participate in after-hours maintenance and critical incident support when required.
Qualifications & Skills
  • Minimum 5–7 years of experience in cybersecurity engineering or security operations.
  • Minimum 4 years of hands-on experience administering enterprise EDR platforms.
  • Minimum 3 years of experience administering NDR platforms.
  • Preferred Certifications
    • CrowdStrike Falcon Administrator / Responder
    • Microsoft Defender for Endpoint Administrator
    • VMware Carbon Black Administrator
    • Trend Micro Vision One Professional
    • Vectra AI Certified Administrator
    • ExtraHop Reveal(x) Certified Engineer
    • Microsoft Certified: Security Operations Analyst (SC-200)
    • Microsoft Certified: Azure Security Engineer (AZ-500)
    • Splunk Core Certified Power User, Enterprise Security Admin, or Microsoft Sentinel certification (preferred)
    • CISSP, GCIH, GCED, CySA+, Security+, or equivalent
  • Working knowledge of SIEM platforms, preferably Splunk Enterprise Security and/or Microsoft Sentinel, including data onboarding, alert tuning, dashboards, and investigations.
  • Experience supporting enterprise security platforms within a SOC or Managed Security Services (MSS) environment.
  • EDR
    • Microsoft Defender for Endpoint
    • CrowdStrike Falcon
    • VMware Carbon Black Cloud
    • Trend Micro Vision One / Apex One
  • NDR
    • Vectra AI
    • ExtraHop Reveal(x)
  • SIEM
    • Splunk Enterprise / Splunk Enterprise Security
    • Microsoft Sentinel
    • Basic knowledge of KQL and SPL
    • Log onboarding and normalization
    • Correlation rule development
    • Dashboard creation
    • Alert tuning
    • Data connector troubleshooting
  • Strong understanding of:
    • Endpoint Security
    • Network Security
    • Incident Response
    • Threat Hunting
    • Detection Engineering
    • MITRE ATT&CK Framework
    • IOC/IOA Management
    • Malware Analysis
    • Windows and Linux Security
    • Active Directory & Microsoft Entra ID
    • Networking (TCP/IP, DNS, VPN, Firewalls)
    • REST APIs
    • PowerShell and/or Python scripting
Benefits
  • Health insurance with one of the leading global providers for medical insurance.
  • Career progression and growth through challenging projects and work.
  • Employee engagement and wellness campaigns activities throughout the year.
  • Excellent learning and development opportunities.
  • Inclusive and diverse working environment.
  • Flexible/Hybrid working environment.
  • Open door policy.
About Us

Help AG present in the Middle East since 2004, was strategically acquired by e& (formerly Etisalat Group) in 2020, hence creating a cybersecurity and digital transformation powerhouse in the region.

Help AG has firmly established itself as the region's trusted IT security advisor by remaining vendor‑agnostic, trustworthy, independent, and maintaining its focus on all aspects of cybersecurity.

With best of breed technologies from industry‑leading vendor partners, expertly qualified service delivery teams and a state‑of‑the‑art consulting practice, Help AG delivers unmatched value to its customers by strengthening their cyber defenses and safeguarding their business.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer - Microsoft Defender Suite & Sentinel
Senior Security Engineer - Microsoft Defender Suite & Sentinel

Help AG • Dubai

On-site
AED 350,000 - 550,000
Health insurance
Career progression
Annual flight tickets
+5
Associate Security Analyst
Associate Security Analyst

Help AG, an e& enterprise company • Dubai

Hybrid
AED 200,880 - 334,800
Health insurance
Career progression
Wellness campaigns
+3
Senior Security Engineer – NGFW & DDOS
Senior Security Engineer – NGFW & DDOS

Help AG, an e& enterprise company • Dubai

Hybrid
Health insurance
Career progression through challenging projects
Annual flight tickets to home country
+2
Senior Incident Response Specialist
Senior Incident Response Specialist

Help AG, an e& enterprise company • Abu Dhabi

On-site
AED 279,000 - 446,400
Career progression
Learning and development
Flexible working
+1
Senior Infrastructure Engineer
Senior Infrastructure Engineer

Help AG, an e& enterprise company • Dubai

Hybrid
AED 390,600 - 725,400
Health insurance
Career progression
Wellness campaigns
+4
IT Support Technician
IT Support Technician

Help AG, an e& enterprise company • Dubai

Hybrid
AED 90,000 - 130,000
Health insurance
Career progression
Wellness campaigns and activities
+3
OT Senior Security Engineer
OT Senior Security Engineer

Help AG, an e& enterprise company • Abu Dhabi

On-site
AED 25,000 - 45,000
Solution Architect - Pre Sales (UAE National)
Solution Architect - Pre Sales (UAE National)

Help AG • Dubai

Hybrid
AED 446,000 - 781,000
Health insurance
Career growth
Learning & development
+3
FortiSOAR Specialist
FortiSOAR Specialist

Help AG • Dubai

Hybrid
AED 250,000 - 450,000
Health insurance with leading global?
Career progression and growth through…
Learning and development opportunities
+3
Web Developer & Digital Specialist (UAE National)
Web Developer & Digital Specialist (UAE National)

Help AG, an e& enterprise company • Dubai

Hybrid
AED 80,000 - 100,000
Health insurance
Career progression and growth
Flexible/Hybrid working environment