Specialist - Information Security

Core42

Dubai

On-site

AED 380,000 - 600,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive Salary
Yearly Bonus
Discount Cards (Esaad/Fazaa)
Premium Health Insurance
Learning & Development

Job summary

Core42 is seeking a Specialist - Information Security in Abu Dhabi, UAE, to lead hands-on security operations across Microsoft Defender XDR, CrowdStrike, Elastic, Corelight, and cloud security. You will architect Sentinel deployments, build detection use cases, and drive incident response in a large enterprise environment.

The role emphasizes advanced hunting, MITRE ATT&CK mappings, and integration across the Microsoft security stack with BAU operations and ongoing improvements.

Qualifications

  • 7-8 years of cybersecurity experience with hands-on SOC/ security operations
  • Strong expertise in Microsoft Sentinel architecture and deployment in large environments
  • Advanced KQL skills for analytics, hunting, dashboards and detection engineering
  • Experience with Defender XDR/EDR, CrowdStrike, Elastic, Corelight, and cloud security
  • Proficiency in SOAR, Logic Apps, and incident response processes

Responsibilities

  • Design and implement Microsoft Sentinel architectures for enterprise, hybrid and multi-cloud environments
  • Onboard telemetry using connectors, Syslog, CEF, APIs and custom ingestion
  • Integrate Sentinel with Defender, CrowdStrike, Elastic and Corelight
  • Develop KQL-based rules, dashboards and MITRE-aligned detection use cases
  • Implement SOAR automation rules and playbooks for response workflows
  • Own day-to-day Sentinel administration, monitoring, and platform health
  • Troubleshoot ingestion issues, log gaps and integration problems
  • Mentor junior SOC/security engineers and improve detection quality

Skills

Microsoft Sentinel
KQL
Threat hunting
MITRE ATT&CK
SOAR
Defender XDR
CrowdStrike Falcon EDR
Elastic EDR
Corelight NDR
Red Hat OpenShift
OpenStack security
Microsoft Defender for Cloud
Cloud security

Tools

OpenShift
OpenStack
Kubernetes
REST APIs

Job description

Job Description:

Specialist - Information Security 8/10/26

About Us

Core42, a leader in AI-powered cloud and digital infrastructure, is driving transformative technology solutions globally. Leveraging advanced resources and partnerships, Core42 empowers clients to harness sovereign AI infrastructure, especially in sectors with stringent regulatory needs. With a mission to redefine digital transformation, we combine sovereign capabilities with scalable, high-performance compute infrastructure, positioning itself at the forefront of AI innovation in the Middle East and beyond.

The opportunity

Specialist - Information Security, Core42 - Abu Dhabi, UAE. A hands‑on security specialist role with 7-8 years of cybersecurity experience and deep expertise across the Microsoft Security Stack, CrowdStrike, Elastic EDR, Corelight NDR, Red Hat OpenShift and OpenStack security implementation and daily BAU operations. The role requires strong capability across Microsoft Defender, EDR/XDR/NDR, cloud security, threat hunting, detection engineering and complex incident response in large enterprise environments.

Your Key Responsibilities
SIEM & detection engineering (Microsoft Sentinel)
  • Design and implement Microsoft Sentinel architectures for enterprise, hybrid and multi-cloud environments, including Log Analytics workspace strategy, retention, scalability and cost optimisation
  • Onboard Microsoft and third-party telemetry using native connectors, Syslog, CEF, APIs, Data Collection Rules and custom ingestion methods
  • Integrate Sentinel with Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Defender for Cloud, Entra ID, CrowdStrike, Elastic and Corelight
  • Develop KQL-based analytics rules, correlation logic, hunting queries, workbooks, dashboards, watchlists and MITRE ATT&CK-aligned detection use cases
  • Implement SOAR using Sentinel automation rules and Logic Apps/playbooks for enrichment, containment, notification, ticketing and response workflows
Platform operations & BAU ownership
  • Own day-to-day administration, monitoring and health management of Sentinel, including data connectors, ingestion, analytics rules, incidents, automation and platform availability
  • Troubleshoot missing logs, ingestion delays, parser issues, connector failures, query errors and integration problems
  • Tune rules and incident grouping to improve detection quality, reduce false positives and close detection gaps
  • Maintain operational dashboards, KPIs, SOPs, runbooks and documentation; support platform change, upgrade and continuous improvement activities
Threat detection, response & investigation
  • Perform incident triage, correlation, investigation, escalation and closure; conduct proactive threat hunting using KQL
  • Operate and optimise Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Defender for Cloud and Defender Threat Intelligence
  • Deploy, administer and troubleshoot CrowdStrike Falcon EDR, Elastic EDR and Corelight NDR; correlate endpoint, network, identity, email and cloud telemetry
  • Investigate malware, phishing, ransomware, credential compromise, persistence, lateral movement, command-and-control and data-exfiltration scenarios
  • Perform IOC/IOA analysis, threat hunting, root‑cause analysis, containment and remediation, and mentor junior SOC/security engineers
What We're Looking For
  • Required skills / qualifications
  • 7-8 years of overall cybersecurity experience with significant hands‑on exposure to SOC, SIEM, EDR/XDR/NDR, cloud security, incident response or threat hunting
  • Strong hands‑on architecture, design, end-to-end implementation and BAU operations of Microsoft Sentinel, with proven delivery in large‑scale enterprise environments
  • Advanced Kusto Query Language (KQL) for analytics rules, hunting, dashboards and detection engineering
  • SOAR experience using Sentinel automation rules and Logic Apps/playbooks for response automation
  • Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Defender for Cloud and Defender Threat Intelligence
  • CrowdStrike Falcon EDR, Elastic EDR and Corelight NDR
  • Advanced incident investigation, threat hunting and MITRE ATT&CK mapping across endpoint, network, identity, email and cloud telemetry
  • Preferred skills / qualifications
  • Working knowledge of Linux administration and security monitoring
  • Experience with Red Hat OpenShift, OpenStack, Kubernetes/container security and private/hybrid cloud environments
  • PowerShell, Python, shell scripting, REST APIs and security platform integration/automation
  • Experience in large enterprise, government, telecom, cloud or managed security environments
  • Preferred certifications (minimum 3): Microsoft SC-200, SC-100, CISSP, CISA, SC-401, AZ-500
What Working At Core42 Offers

With a diverse team of 1,100+ employees from 68 nationalities, we foster an inclusive, innovative and collaborative environment. At Core42, we foster a culture grounded in trust, accountability and high performance. We are united by our values: Grit, where we overcome challenges with resilience and determination, Passion, which drives us to pursue excellence in everything we do, and Impact, as we aim to inspire progress and create meaningful change. Our team members thrive in an environment where each person’s contributions propel us forward, and together, we commit to achieving extraordinary results.

  • Competitive Salary: We offer an attractive salary package based on your skills and experience
  • Yearly Bonus: In recognition of your contributions, you will receive a performance-based annual bonus
  • Exclusive Discount Cards: Access special benefits with Esaad and Fazaa cards, offering discounts across a wide range of services
  • Premium Family Insurance: We provide comprehensive health coverage, including dental, vision and life insurance, ensuring the well‑being of you and your family
  • Learning & Development: We offer access to top-tier learning platforms to help you grow in your career. Learn at your own pace with unlimited access to premium courses.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Specialist - Information Security
Specialist - Information Security

Core42 • Abu Dhabi

On-site
AED 520,000 - 760,000
Competitive salary
Yearly bonus
Discount cards
Security Engineer
Security Engineer

Core42 • United Arab Emirates

On-site
AED 350,000 - 550,000
Yearly bonus
Competitive salary
Exclusive discount cards (Esaad Faza)
+2
Senior DevOps Engineer
Senior DevOps Engineer

Core42 • United Arab Emirates

On-site
AED 350,000 - 600,000
Competitive Salary
Yearly Bonus
Discount Cards
+2
Senior Information Security & SIEM Architect
Senior Information Security & SIEM Architect

Core42 • Dubai

On-site
AED 380,000 - 600,000
Competitive Salary
Yearly Bonus
Discount Cards (Esaad/Fazaa)
+2
Senior Microsoft Sentinel & Cloud Security Architect
Senior Microsoft Sentinel & Cloud Security Architect

Core42 • Abu Dhabi

On-site
AED 520,000 - 760,000
Competitive salary
Yearly bonus
Discount cards
Senior Devops Engineer
Senior Devops Engineer

Core42 • Dubai

On-site
AED 320,000 - 520,000
Yearly Bonus
Exclusive Discount Cards: Esaad and Fa
Premium Family Insurance
+1
Senior Security Engineer - Microsoft Defender Suite & Sentinel
Senior Security Engineer - Microsoft Defender Suite & Sentinel

Help AG, an e& enterprise company • Dubai

On-site
AED 300,000 - 520,000
Health insurance
Career progression
Wellness campaigns
+5
Senior Software Engineer (Go)
Senior Software Engineer (Go)

Core42 • Abu Dhabi

On-site
AED 320,000 - 520,000
Competitive Salary
Yearly Bonus
Discount Cards (Esaad & Fazaa)
+2
IT Asset Specialist (UAE National)
IT Asset Specialist (UAE National)

Core42 • Abu Dhabi

On-site
Competitive salary
Yearly performance bonus
Discount cards (Esaad & Fazaa)
+2
Senior Specialist - Human Capital
Senior Specialist - Human Capital

Core42 • Dubai

On-site
AED 180,000 - 260,000
Yearly bonus
Esaad/Fazaa discount cards
Premium family health insurance
+2