Job Description
Job Title:  Specialist - Information Security
Posting Start Date:  8/10/26
Job Description: 

 

 

About Us

Core42, a leader in AI-powered cloud and digital infrastructure, is driving transformative technology solutions globally. Leveraging advanced resources and partnerships, Core42 empowers clients to harness sovereign AI infrastructure, especially in sectors with stringent regulatory needs. With a mission to redefine digital transformation, we combine sovereign capabilities with scalable, high-performance compute infrastructure, positioning itself at the forefront of AI innovation in the Middle East and beyond.


The opportunity

Specialist - Information Security, Core42 - Abu Dhabi, UAE. A hands-on security specialist role with 7-8 years of cybersecurity experience and deep expertise across the Microsoft Security Stack, CrowdStrike, Elastic EDR, Corelight NDR, Red Hat OpenShift and OpenStack security implementation and daily BAU operations. The role requires strong capability across Microsoft Defender, EDR/XDR/NDR, cloud security, threat hunting, detection engineering and complex incident response in large enterprise environments.

 

Your key responsibilities

SIEM & detection engineering (Microsoft Sentinel)

  • Design and implement Microsoft Sentinel architectures for enterprise, hybrid and multi-cloud environments, including Log Analytics workspace strategy, retention, scalability and cost optimisation
  • Onboard Microsoft and third-party telemetry using native connectors, Syslog, CEF, APIs, Data Collection Rules and custom ingestion methods
  • Integrate Sentinel with Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Defender for Cloud, Entra ID, CrowdStrike, Elastic and Corelight
  • Develop KQL-based analytics rules, correlation logic, hunting queries, workbooks, dashboards, watchlists and MITRE ATT&CK-aligned detection use cases
  • Implement SOAR using Sentinel automation rules and Logic Apps/playbooks for enrichment, containment, notification, ticketing and response workflows

Platform operations & BAU ownership

  • Own day-to-day administration, monitoring and health management of Sentinel, including data connectors, ingestion, analytics rules, incidents, automation and platform availability
  • Troubleshoot missing logs, ingestion delays, parser issues, connector failures, query errors and integration problems
  • Tune rules and incident grouping to improve detection quality, reduce false positives and close detection gaps
  • Maintain operational dashboards, KPIs, SOPs, runbooks and documentation; support platform change, upgrade and continuous improvement activities

Threat detection, response & investigation

  • Perform incident triage, correlation, investigation, escalation and closure; conduct proactive threat hunting using KQL
  • Operate and optimise Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Defender for Cloud and Defender Threat Intelligence
  • Deploy, administer and troubleshoot CrowdStrike Falcon EDR, Elastic EDR and Corelight NDR; correlate endpoint, network, identity, email and cloud telemetry
  • Investigate malware, phishing, ransomware, credential compromise, persistence, lateral movement, command-and-control and data-exfiltration scenarios
  • Perform IOC/IOA analysis, threat hunting, root-cause analysis, containment and remediation, and mentor junior SOC/security engineers

 

What we’re looking for



(a) Required skills / qualifications

  • 7-8 years of overall cybersecurity experience with significant hands-on exposure to SOC, SIEM, EDR/XDR/NDR, cloud security, incident response or threat hunting
  • Strong hands-on architecture, design, end-to-end implementation and BAU operations of Microsoft Sentinel, with proven delivery in large-scale enterprise environments
  • Advanced Kusto Query Language (KQL) for analytics rules, hunting, dashboards and detection engineering
  • SOAR experience using Sentinel automation rules and Logic Apps/playbooks for response automation
  • Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Defender for Cloud and Defender Threat Intelligence
  • CrowdStrike Falcon EDR, Elastic EDR and Corelight NDR
  • Advanced incident investigation, threat hunting and MITRE ATT&CK mapping across endpoint, network, identity, email and cloud telemetry

(b) Preferred skills / qualifications

  • Working knowledge of Linux administration and security monitoring
  • Experience with Red Hat OpenShift, OpenStack, Kubernetes/container security and private/hybrid cloud environments
  • PowerShell, Python, shell scripting, REST APIs and security platform integration/automation
  • Experience in large enterprise, government, telecom, cloud or managed security environments
  • Preferred certifications (minimum 3): Microsoft SC-200, SC-100, CISSP, CISA, SC-401, AZ-500

 

What working at Core42 offers 

 

With a diverse team of 1,100+ employees from 68 nationalities, we foster an inclusive, innovative and collaborative environment. At Core42, we foster a culture grounded in trust, accountability and high performance. We are united by our values: Grit, where we overcome challenges with resilience and determination, Passion, which drives us to pursue excellence in everything we do, and Impact, as we aim to inspire progress and create meaningful change. Our team members thrive in an environment where each person’s contributions propel us forward, and together, we commit to achieving extraordinary results.

  • Competitive Salary: We offer an attractive salary package based on your skills and experience
  • Yearly Bonus: In recognition of your contributions, you will receive a performance-based annual bonus
  • Exclusive Discount Cards: Access special benefits with Esaad and Fazaa cards, offering discounts across a wide range of services
  • Premium Family Insurance: We provide comprehensive health coverage, including dental, vision and life insurance, ensuring the well-being of you and your family
  • Learning & Development: We offer access to top-tier learning platforms to help you grow in your career. Learn at your own pace with unlimited access to premium courses.