Security Engineer - Network Detection and Response (NDR)
Abu Dhabi, United Arab Emirates · Full Time
Be the first to apply
- Experience
- 5–7 yrs
- Salary
- —
- Openings
- 1
- Posted
- 46 minutes ago
- Work mode
- In office
- Education
- Bachelor's degree in Cyber Security, Computer Science, Information Security or IT Engineering
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About Core42
Core42 is a leading company specializing in AI-driven cloud and digital infrastructure solutions, committed to revolutionizing technology on a global scale. The company enables clients, especially those in highly regulated sectors, to leverage sovereign AI infrastructure combined with scalable, high-performance computing power. Positioned as a pioneer in advancing AI innovation across the Middle East and beyond, Core42 continues to deliver transformative digital experiences.
Role Overview
We are looking for a seasoned Security Engineer focused on Network Detection and Response (NDR) and Cloudflare security platforms. This position involves designing, deploying, managing, and continuously enhancing the organization's Corelight NDR and Cloudflare environments. The role is pivotal in strengthening network visibility, elevating threat detection, enforcing Zero Trust principles, safeguarding against DDoS attacks, and managing web and DNS security for enterprise and cloud systems.
Key Responsibilities
- Administer and engineer Corelight NDR sensors across data centers, enterprise, and cloud infrastructures.
- Develop and refine detection use cases utilizing Zeek, Suricata, Corelight Smart PCAP, YARA rules, and threat intelligence feeds.
- Ensure comprehensive network traffic visibility including both east-west and north-south flows.
- Set baseline network behavior and implement anomaly detection mechanisms.
- Integrate Corelight solutions seamlessly with SIEM and SOC platforms, monitoring their health, capacity, and performance.
- Create and tune advanced network detection patterns and engage in proactive threat hunting using network telemetry, DNS, HTTP/S, SMB, and authentication logs.
- Implement detection strategies aligned with MITRE ATT&CK framework to reduce false positives and enhance detection accuracy.
- Design and manage Cloudflare security services encompassing WAF, bot mitigation, rate limiting, API security, and custom rulesets.
- Oversee DNS security via Cloudflare DNS, DNSSEC, and security policies.
- Deploy Zero Trust security measures including Cloudflare Access, Secure Web Gateway, browser isolation, and device identity controls.
- Manage Cloudflare network protection features such as DDoS mitigation, Magic Transit, Magic Firewall, and Magic WAN.
- Lead investigations of network-centric incidents, performing malware analysis, forensic packet inspection, and incident triage with containment protocols.
- Develop, maintain, and enhance incident response playbooks to improve readiness and response effectiveness.
- Continuously improve security monitoring across cloud, network, data centers, and internet edge environments, establishing KPIs and security metrics.
- Identify security vulnerabilities and recommend remediations to strengthen defenses.
- Integrate Corelight and Cloudflare with various platforms and technologies including IDP, SIEM, Cribl, EDR, ITSM, threat intelligence, SOAR, LDAP, AI/ML, and CMDB systems.
- Create automation tools and scripts employing Python, PowerShell, and REST APIs to enhance operational efficiency.
- Ensure compliance with security frameworks and standards such as NIST SP 800-53, NIST CSF, ISO 27001, CIS Controls, SOC 2, UAE Information Assurance Standards, and internal policies.
- Support security audits and compliance evaluations as necessary.
Qualifications & Experience
- Bachelor's degree in Cyber Security, Computer Science, Information Security, or IT Engineering.
- 5 to 7 years of professional experience in cybersecurity focusing on network security technologies.
- Proven expertise with Corelight NDR or Zeek-based technologies.
- Hands-on experience managing Cloudflare security services.
- Experience supporting enterprise network and cloud environments.
- Background in SOC operations, incident response, threat hunting, or security engineering roles.
- Strong foundational knowledge of network protocols TCP/IP, DNS, HTTP/HTTPS, TLS alongside packet analysis skills.
- Familiarity with Corelight NDR, Zeek, Suricata, Cloudflare WAF, Cloudflare Access, Zero Trust frameworks, DDoS defense mechanisms, Magic Transit, Magic Firewall, and Cloudflare Analytics.
- Preferred: Proficiency with Python and PowerShell scripting languages.
- Preferred: Certifications such as Cloudflare Certified Administrator, Security+, or equivalent network security credentials.
Work Environment and Culture
Core42 boasts a diverse workforce of over 1,100 employees representing 68 nationalities. The company emphasizes a nurturing workplace culture based on trust, accountability, and exceptional performance. Core values include resilience (Grit), passion for excellence, and striving for meaningful impact. Employees are encouraged to contribute actively toward shared goals, fostering collaboration and innovation.
Employee Benefits
- Competitive salary packages tailored to experience and skills.
- Annual performance-based bonus schemes.
- Exclusive discount access through Esaad and Fazaa cards across various services.
- Comprehensive family health insurance covering dental, vision, and life policies.
- Access to premier learning platforms facilitating continuous professional growth with unlimited course materials.
Minimum education
Bachelor's Degree