Security Engineer 8/17/26
About Us
Core42, a leader in AI-powered cloud and digital infrastructure, is driving transformative technology solutions globally. Leveraging advanced resources and partnerships, Core42 empowers clients to harness sovereign AI infrastructure, especially in sectors with stringent regulatory needs. With a mission to redefine digital transformation, we combine sovereign capabilities with scalable, high-performance compute infrastructure, positioning itself at the forefront of AI innovation in the Middle East and beyond.
The opportunity
Security Engineer - Endpoint Detection & Response (Elastic EDR), Core42 - Abu Dhabi, UAE. We are seeking a highly skilled Security Engineer with hands-on expertise in the Elastic Security Platform, including Elastic Agent, Elastic Defend, Elasticsearch, Kibana, detection rules, threat hunting and incident response. The successful candidate will be responsible for designing, implementing, managing and optimising the organisation's EDR platform to ensure continuous monitoring, threat detection, incident investigation and response across enterprise environments.
The role requires close collaboration with Security Operations, Incident Response, Platform Engineering, Infrastructure and Compliance teams to strengthen cyber defence capabilities and maintain security compliance requirements. The focus of this position is Elastic EDR engineering.
Your Key Responsibilities
Elastic EDR administration & engineering
- Design, deploy, configure and maintain Elastic EDR infrastructure and endpoint security agents
- Manage Elastic Agent lifecycle activities, including deployment, upgrades, troubleshooting and policy management
- Develop and maintain EDR baselines, security policies and endpoint hardening standards
- Ensure high availability, scalability, performance and health of the Elastic Security platform
- Integrate Elastic EDR with SIEM, SOAR, IAM, vulnerability management and threat intelligence platforms
- Upgrade, patch and maintain existing clusters
Detection engineering
- Develop, tune and maintain detection rules and security use cases within Elastic Security
- Enhance threat detection capabilities to reduce false positives and improve security visibility
- Design and implement behavioural analytics, anomaly detection and advanced threat detection logic
- Create custom dashboards, alerts, reports and visualisations within Kibana
Threat hunting & incident response
- Conduct proactive threat hunting activities using Elastic Security datasets
- Investigate endpoint security incidents, malware infections, insider threats and advanced attacks
- Analyse telemetry, process activities, file events, registry modifications, network connections and user behaviour
- Support digital forensics and incident response investigations
- Identify root causes and recommend mitigation strategies
Security monitoring & optimisation
- Monitor EDR platform performance, coverage and security effectiveness
- Perform continuous tuning of endpoint security controls
- Establish KPIs and operational metrics for EDR effectiveness
- Validate security controls through attack simulation and red team exercises
Integration & automation
- Integrate Elastic EDR with IDP, LDAP, AI and ML integrations, vulnerability management solutions, SIEM platforms, threat intelligence feeds and SOAR workflows
- Integrate with OpenStack, OpenShift, NVIDIA and AMD systems
- Automate security operations using APIs, scripts and orchestration tools
Governance & compliance
- Ensure EDR deployment aligns with NIST SP 800-53, ISO 27001, SOC 2, CIS Controls and internal security standards and policies
- Support audit activities and provide security evidence when required
- Maintain security documentation, procedures and operational runbooks
What We’re Looking For
- Required skills / qualifications
- Bachelor's degree in Cyber Security, Computer Science, Information Security or a related discipline
- 5 to 7 years of experience in security engineering, incident response, threat hunting or detection engineering
- Experience supporting enterprise-scale EDR deployments (10,000 endpoints preferred)
- Hands-on expertise across Elastic Security, Elastic Defend, Elastic Agent, Elasticsearch and Kibana
- Detection rule engineering, threat hunting and log analysis
- Endpoint security, Windows security and Linux security
- MITRE ATT&CK framework, incident response and malware analysis fundamentals
- Preferred skills / qualifications
- Python and Bash scripting
- Experience with threat intelligence platforms
- Certifications: Elastic Certified Engineer, Elastic Security Analyst
What Working At Core42 Offers
With a diverse team of 1,100 employees from 68 nationalities, we foster an inclusive, innovative and collaborative environment. At Core42, we foster a culture grounded in trust, accountability and high performance.
We are united by our values: Grit, where we overcome challenges with resilience and determination, Passion, which drives us to pursue excellence in everything we do, and Impact, as we aim to inspire progress and create meaningful change. Our team members thrive in an environment where each person’s contributions propel us forward, and together, we commit to achieving extraordinary results.
- Competitive Salary: We offer an attractive salary package based on your skills and experience
- Yearly Bonus: In recognition of your contributions, you will receive a performance-based annual bonus
- Exclusive Discount Cards: Access special benefits with Esaad and Fazaa cards, offering discounts across a wide range of services
- Premium Family Insurance: We provide comprehensive health coverage, including dental, vision and life insurance, ensuring the well-being of you and your family
- Learning & Development: We offer access to top-tier learning platforms to help you grow in your career. Learn at your own pace with unlimited access to premium courses.