Core
42, a leader in AI-powered cloud and digital infrastructure, is driving transformative technology solutions globally. Leveraging advanced resources and partnerships, Core
42 empowers clients to harness sovereign AI infrastructure, especially in sectors with stringent regulatory needs. With a mission to redefine digital transformation, we combine sovereign capabilities with scalable, high-performance compute infrastructure, positioning itself at the forefront of AI innovation in the Middle East and beyond.
Specialist - Information Security, Core
42 - Abu Dhabi, UAE. A hands-on security specialist role with 7-8 years of cybersecurity experience and deep expertise across the Microsoft Security Stack, Crowd Strike, Elastic EDR, Corelight NDR, Red Hat Open Shift and Open Stack security implementation and daily BAU operations. The role requires strong capability across Microsoft Defender, EDR/XDR/NDR, cloud security, threat hunting, detection engineering and complex incident response in large enterprise environments.
key responsibilities
- Design and implement Microsoft Sentinel architectures for enterprise, hybrid and multi-cloud environments, including Log Analytics workspace strategy, retention, scalability and cost optimisation
- Onboard Microsoft and third-party telemetry using native connectors, Syslog, CEF, APIs, Data Collection Rules and custom ingestion methods
- Integrate Sentinel with Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Defender for Cloud, Entra , Crowd Strike, Elastic and Corelight
- Develop KQL-based analytics rules, correlation logic, hunting queries, workbooks, dashboards, watchlists and MITRE ATT&CK-aligned detection use cases
- Implement SOAR using Sentinel automation rules and Logic Apps/playbooks for enrichment, containment, notification, ticketing and response workflows
- Own day-to-day administration, monitoring and health management of Sentinel, including data connectors, ingestion, analytics rules, incidents, automation and platform availability
- Troubleshoot missing logs, ingestion delays, parser issues, connector failures, query errors and integration problems
- Tune rules and incident grouping to improve detection quality, reduce false positives and close detection gaps
- Maintain operational dashboards, KPIs, SOPs, runbooks and documentation; support platform change, upgrade and continuous improvement activities
- Perform incident triage, correlation, investigation, escalation and closure; conduct proactive threat hunting using KQL
- Deploy, administer and troubleshoot Crowd Strike Falcon EDR, Elastic EDR and Corelight NDR; correlate endpoint, network, identity, email and cloud telemetry
- Investigate malware, phishing, ransomware, credential compromise, persistence, lateral movement, command-and-control and data-exfiltration scenarios
- Perform IOC/IOA analysis, threat hunting, root-cause analysis, containment and remediation, and mentor junior SOC/security engineers
- 7-8 years of overall cybersecurity experience with significant hands-on exposure to SOC, SIEM, EDR/XDR/NDR, cloud security, incident response or threat hunting
- Strong hands-on architecture, design, end-to-end implementation and BAU operations of Microsoft Sentinel, with proven delivery in large-scale enterprise environments
- Advanced Kusto Query Language (KQL) for analytics rules, hunting, dashboards and detection engineering
- SOAR experience using Sentinel automation rules and Logic Apps/playbooks for response automation
- Crowd Strike Falcon EDR, Elastic EDR and Corelight NDR
- Advanced incident investigation, threat hunting and MITRE ATT&CK mapping across endpoint, network, identity, email and cloud telemetry
- Working knowledge of Linux administration and security monitoring
- Experience with Red Hat Open Shift, Open Stack, Kubernetes/container security and private/hybrid cloud environments
- Power Shell, Python, shell scripting, REST APIs and security platform integration/automation
- Experience in large enterprise, government, telecom, cloud or managed…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).