SentinelOne EDR Investigator — Incident Response Pro

VaporVM

Dubai

On-site

AED 240,000 - 400,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

VaporVM seeks an experienced EDR Expert to monitor, investigate, and analyze SentinelOne alerts, distinguishing false positives from genuine incidents. You will support timely incident response and collaborate across teams to improve containment and remediation.

The role focuses on reviewing endpoint telemetry, processing trees, and IOCs, with emphasis on MITRE ATT&CK tactics and techniques. Strong analytical skills are essential.

Qualifications

  • 3–5+ years in EDR, SOC, cybersecurity operations or incident response.
  • Hands-on SentinelOne experience is mandatory.
  • Strong understanding of endpoint security, malware analysis and investigations.
  • Experience analyzing process trees, endpoint telemetry and IOCs.
  • Familiarity with Windows and Linux endpoint security and MITRE ATT&CK.

Responsibilities

  • Review SentinelOne EDR alerts to classify false positives vs incidents.
  • Investigate endpoint alerts, suspicious activity, malware behavior and IOCs.
  • Analyze telemetry, process trees and detection data for root causes.
  • Validate incidents, determine severity and impact; escalate when needed.
  • Correlate alerts with SIEM data to identify attack patterns.
  • Document findings and remediation recommendations; maintain records.
  • Tune alerts and policies to reduce recurring false positives.
  • Support containment, remediation and eradication activities.
  • Prepare regular reports on EDR alerts and incidents.
  • Stay updated on new endpoint threats and MITRE techniques.

Skills

EDR
SOC
Incident Response
SentinelOne
MITRE ATT&CK
Windows security
Linux security
Endpoint telemetry
IOC analysis
Threat hunting

Tools

Splunk
Microsoft Sentinel
QRadar

Job description

VaporVM seeks an experienced EDR Expert to monitor, investigate, and analyze SentinelOne alerts, distinguishing false positives from genuine incidents. You will support timely incident response and collaborate across teams to improve containment and remediation.

The role focuses on reviewing endpoint telemetry, processing trees, and IOCs, with emphasis on MITRE ATT&CK tactics and techniques. Strong analytical skills are essential.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

EDR Expert
EDR Expert

VaporVM • Dubai

On-site
AED 240,000 - 400,000
Senior Security Operations Engineer: Threat Detection
Senior Security Operations Engineer: Threat Detection

VaporVM • Dubai

On-site
AED 250,000 - 390,000
Lead Consultant – Incident Response
Lead Consultant – Incident Response

Forensic Focus Limited • Abu Dhabi

On-site
AED 300,000 - 520,000
Cybersecurity Analyst – 24/7 Monitoring & Incident Response
Cybersecurity Analyst – 24/7 Monitoring & Incident Response

Remotedxb • Dubai

On-site
AED 180,000 - 280,000
Specialist – Endpoint Security
Specialist – Endpoint Security

CPX • Abu Dhabi

On-site
AED 240,000 - 360,000
Cyber Defense Specialist - Threat Detection & Incident Response
Cyber Defense Specialist - Threat Detection & Incident Response

EDGE • Abu Dhabi

On-site
AED 180,000 - 260,000
Senior Endpoint Security Engineer: EDR/XDR & SOC
Senior Endpoint Security Engineer: EDR/XDR & SOC

CPX • Abu Dhabi

On-site
AED 240,000 - 360,000
Cyber Defense Specialist: Incident Response & Threat Analysis
Cyber Defense Specialist: Incident Response & Threat Analysis

EDGE • Abu Dhabi

On-site
AED 180,000 - 260,000
Senior Incident Response Lead — Threat Hunting & Forensics
Senior Incident Response Lead — Threat Hunting & Forensics

Forensic Focus Limited • Abu Dhabi

On-site
AED 300,000 - 520,000
CyberSecurity Specialist
CyberSecurity Specialist

Remotedxb • Dubai

On-site
AED 180,000 - 280,000