1,435,554open jobs
84,007companies
217,972added this week
Browse all
Salary
≈ $60k – $139k per year (Estimated)
Location
In office (United Arab Emirates)
Seniority
Senior · 5+ years exp

Confirmed on the employer's own hiring board on Oct 10, 2026. First seen by Alion on Oct 7, 2026.

Overview
Company
Impact
Profile match
Core42 is the sovereign cloud and artificial intelligence infrastructure company of the G42 group, formed in 2023 from Inject, Injazat and G42 Cloud. It runs regulated cloud regions in the United Arab Emirates, operates large graphics processor clusters and offers model training and inference as a service. Its Compass and Insight platforms give government and enterprise clients artificial intelligence capability inside national data boundaries.

About Us

Core42, a leader in AI-powered cloud and digital infrastructure, is driving transformative technology solutions globally. Leveraging advanced resources and partnerships, Core42 empowers clients to harness sovereign AI infrastructure, especially in sectors with stringent regulatory needs. With a mission to redefine digital transformation, we combine sovereign capabilities with scalable, high-performance compute infrastructure, positioning itself at the forefront of AI innovation in the Middle East and beyond.

The opportunity

Security Analyst, Core42 - Abu Dhabi, UAE. We are looking for a senior Security Analyst to anchor the technical depth of our 24x7 Security Operations Centre. This role detects, triages, investigates and responds to security incidents across our private-cloud platform and the enterprise services it supports. The successful candidate is a hands-on practitioner who can own an incident end to end - from the first alert in Splunk through containment, eradication and recovery - while also raising the quality of our detections and acting as a senior escalation point and mentor for less-experienced analysts. The environment is a private cloud built on OpenStack and Red Hat OpenShift, instrumented with Splunk (SIEM), Cribl (data pipeline), Elastic Security (EDR) and Corelight (NDR). Comfort working across virtualised and containerised infrastructure log sources is expected. The role reports to the SOC Manager and operates on a full-time, 24x7 rotational shift basis.

Your key responsibilities

Security monitoring, triage & detection

  • Monitor security alerts and events in Splunk to identify threats, anomalies and malicious activity across the private-cloud platform and enterprise services
  • Perform triage and investigation of security events, acting as the senior technical decision point on whether an alert represents a genuine incident
  • Serve as the senior escalation point for front-line analysts, providing investigative guidance and validating findings before escalation
  • Investigate EDR and NDR alerts involving malware, suspicious scripts, credential theft, lateral movement, persistence, ransomware and endpoint or network compromise

Incident response (full lifecycle)

  • Own security incidents end to end across the full response lifecycle: identification, containment, eradication, recovery and post-incident review
  • Execute containment and remediation actions in coordination with platform, infrastructure, network and application teams
  • Lead the response on assigned incidents and coordinate cross-team activity to ensure timely investigation, escalation and resolution
  • Develop and maintain incident response playbooks and standard operating procedures (SOPs), and drive their improvement after each major incident

SIEM, detection engineering & log pipeline

  • Create, tune and optimise Splunk correlation searches, alerts, dashboards and reports to improve detection quality and coverage
  • Write and maintain efficient SPL queries supporting investigation, hunting, reporting and detection engineering
  • Reduce alert fatigue by tuning noisy detections, lowering false positives and strengthening correlation logic, weighing false-positive cost against miss cost when making tuning decisions
  • Support onboarding of new log sources and validate log quality, parsing, field extraction and normalisation
  • Manage and maintain Cribl Stream/Edge pipelines for log routing, filtering, enrichment and normalisation, optimising data flow and Splunk licence consumption

Threat hunting & intelligence

  • Conduct hypothesis-driven threat hunts to uncover advanced persistent threats (APTs) and techniques that evade existing detections
  • Map detection coverage to MITRE ATT&CK, identify and report gaps, and convert successful hunts into durable detections
  • Apply threat intelligence and frameworks (MITRE ATT&CK, Cyber Kill Chain, Diamond Model) to enrich investigations and improve detection and response
  • Identify patterns, trends and indicators of compromise (IOCs) to proactively detect and prevent recurrence

Documentation, reporting & governance

  • Conduct root cause analysis (RCA) and produce clear incident reports for management and stakeholders
  • Maintain accurate, detailed records of incidents, actions taken, evidence collected and lessons learned in the case-management platform
  • Contribute to the continuous improvement of security monitoring use cases and detection rules
  • Support audit and compliance requirements by providing evidence of incident-management activities

Working arrangement

  • Operate within a 24x7 SOC, participating in rotational day, evening and night shifts, including weekends and public holidays on a rotational basis
  • Meet defined acknowledgement, triage and escalation SLAs on each shift and complete structured shift handovers to maintain continuity of in-flight incidents

What we’re looking for

(a) Required skills / qualifications

  • Bachelor's degree in Computer Science, Information Security, Cybersecurity or a related field; equivalent professional experience and certifications will be considered in lieu of a degree
  • 5-8 years in security operations, incident response or SOC monitoring, with at least 2 years at a senior level
  • Proven hands-on experience with Splunk Enterprise / Splunk Cloud - advanced SPL, dashboard development, correlation searches, alert creation and tuning, and administration
  • Demonstrated experience with Cribl Stream / Cribl Edge - log routing, parsing, filtering, enrichment and pipeline management
  • Strong background in incident analysis, investigation, evidence handling, escalation management and full-lifecycle response aligned with industry standards, including playbook and SOP development and RCA
  • Elastic Security (EDR) and Corelight (NDR) for endpoint and network threat detection, investigation and response
  • Threat frameworks: MITRE ATT&CK (including coverage mapping), Cyber Kill Chain and Diamond Model
  • Strong understanding of networking: TCP/IP, DNS, HTTP/S, firewalls, proxies and IDS/IPS
  • Proficiency in Windows and Linux environments
  • Proficiency in Python, Bash or PowerShell for automation and analysis
  • Familiarity with private-cloud and platform log sources: Red Hat OpenShift, OpenStack, Commvault, Scality and related infrastructure
  • ServiceNow, Jira or equivalent ticketing/case management for incident tracking, evidence attachment, escalation notes and closure documentation

(b) Preferred skills / qualifications

  • Splunk Core Certified Power User or Splunk Certified Admin
  • Cribl Certified Admin
  • GIAC certifications relevant to detection and response - GCIA, GCIH, GCDA or GCFA
  • Blue Team Level 2 (BTL2) or equivalent hands-on defensive certification
  • Experience monitoring OpenStack and Kubernetes/OpenShift environments
  • Familiarity with detection-as-code practices (version control and peer review of detection content)

What working at Core42 offers

With a diverse team of 1,100+ employees from 68 nationalities, we foster an inclusive, innovative and collaborative environment. At Core42, we foster a culture grounded in trust, accountability and high performance. We are united by our values: Grit, where we overcome challenges with resilience and determination, Passion, which drives us to pursue excellence in everything we do, and Impact, as we aim to inspire progress and create meaningful change. Our team members thrive in an environment where each person’s contributions propel us forward, and together, we commit to achieving extraordinary results.

  • Competitive Salary: We offer an attractive salary package based on your skills and experience
  • Yearly Bonus: In recognition of your contributions, you will receive a performance-based annual bonus
  • Exclusive Discount Cards: Access special benefits with Esaad and Fazaa cards, offering discounts across a wide range of services
  • Premium Family Insurance: We provide comprehensive health coverage, including dental, vision and life insurance, ensuring the well-being of you and your family
  • Learning & Development: We offer access to top-tier learning platforms to help you grow in your career. Learn at your own pace with unlimited access to premium courses.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,435,554 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
United Arab Emirates
$190k – $225k per year • In office • Full-Time • 7+ years exp • Bachelor's Degree • San Jose
Python
Go
AI/ML
Claude Code
Model Context Protocol
Vertex AI
LiteLLM
AWS Bedrock
LLM
OpenAI
LLM Guardrails
DevOps
Terraform
Istio
OpenTofu
Azure
CI/CD
GitOps
ArgoCD
AWS
Kubernetes
SRE
Service Mesh
Amazon EKS
IAM
DNS
VPN
BGP
Cybersecurity
FedRAMP
PKI
Apply
$69k – $93k per year (gross) • In office • Contractor • Amsterdam
Cybersecurity
ISO 27001
Apply
$67k per year • Remote (Austria) • Full-Time • Vienna
AI/ML
Red Teaming
DevOps
Linux
Windows
Cybersecurity
Active Directory
SIEM
Apply
$61k per year • In office • Full-Time • Innsbruck
Apply
In office
Cybersecurity
Crowdstrike
Apply
DevOps 1 day ago
≈ $40k – $93k per year (Estimated) • In office • Madrid
PowerShell
Bash
Databases
PostgreSQL
DevOps
Terraform
Ansible
OpenShift
Helm
Azure DevOps
GitHub Actions
Kustomize
Prometheus
Azure
CI/CD
GitOps
ArgoCD
Jenkins
Git
Docker
Kubernetes
Grafana
GitLab
Windows
Cybersecurity
SonarQube
OWASP Top 10
Apply
$101k – $141k per year • Remote (United States) • Full-Time • 2+ years exp • Bachelor's Degree • United States
Python
AI/ML
Machine Learning
Robotics
Digital Twin
Design
SolidWorks
AutoCAD
Apply
$161k – $243k per year • Remote (United States) • Full-Time • 5+ years exp • Bachelor's Degree • Cambridge
Python
SQL
Databases
Databricks
Analytics
Tableau
Apply
≈ $23k – $57k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Bengaluru
Python
Java
C#
DevOps
CI/CD
Windows
Cybersecurity
CAPA
Apply
In office • 2+ years exp • Bengaluru
Python
JavaScript
TypeScript
Node JS
Frontend
React.js
Mobile
React Native
State Management
DevOps
Rest API
CI/CD
AWS
Docker
Apply
≈ $63k – $161k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • United Arab Emirates
Python
DevOps
Splunk
Azure
AWS
Cybersecurity
MITRE ATT&CK
Cortex XSOAR
SIEM
Management
ServiceNow
Apply
≈ $24k – $45k per year (Estimated) • In office • Nationals only • 1+ year exp • High School Diploma • United Arab Emirates
AI/ML
PyTorch
Ignite
Management
Service Desk
Apply
≈ $24k – $45k per year (Estimated) • In office • Nationals only • 1+ year exp • High School Diploma • United Arab Emirates
AI/ML
PyTorch
Ignite
Management
Service Desk
Apply
≈ $48k – $127k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • United Arab Emirates
Apply
In office • United Arab Emirates
Apply
See all jobs
This is one of many
1,435,554 more open roles from verified company boards, updated every day.