شرح موقعیت
Important Note: -Given the urgency of this position, the recruitment process has been accelerated. Interviews are progressing actively, with all candidate assessments expected to be completed over the next two weeks. Title - Senior Elastic Security & Detection Engineer (SIEM) Important Information: Only candidates who meet the below criteria and are genuinely interested in the opportunity are encouraged to apply. Applications that do not align with the specified requirements may not be considered. Salary - AED 20,000 - AED 21,0000 per month Duration - 1 year (can be extendable) Required Notice Period -Immediate or max 1 month Education - Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field. Location -Abu Dhabi, UAE Experience - 5-8 Years Role Overview We are seeking a highly skilled Senior Elastic Security & Detection Engineer to support and enhance enterprise security monitoring and detection capabilities. The ideal candidate will possess strong expertise in the Elastic Stack (Elasticsearch, Kibana, Logstash, Beats, Elastic Security) and have hands-on experience in Detection Engineering, Threat Hunting, SIEM Operations, and Security Content Development. This role will be responsible for building, optimizing, and maintaining Elastic Security use cases, detections, dashboards, and data pipelines to strengthen the organization's cyber defense capabilities. Key Administer, maintain, and optimize Elastic Stack infrastructure and Elasticsearch clusters. Design and implement scalable data ingestion pipelines using Logstash, Beats, and Elastic Agent. Perform Elasticsearch performance tuning, index lifecycle management, cluster health monitoring, and troubleshooting. Develop and maintain Kibana dashboards, visualizations, and operational reporting. Detection Engineering Design, develop, test, and maintain high-fidelity detection use cases within Elastic Security. Create and enhance detection content aligned with the MITRE ATT&CK framework. Develop correlation rules, behavioral analytics, anomaly detection, and advanced threat detection logic. Continuously improve detection coverage while reducing false positives. Conduct detection gap assessments and implement new security monitoring capabilities. Partner with SOC analysts and threat hunters to operationalize threat intelligence and emerging attack techniques. Threat Hunting & Incident Support Perform proactive threat hunting using Elastic Security and threat intelligence. Support incident investigations through log analysis, event correlation, and forensic review. Assist in root cause analysis and development of preventive detection mechanisms. Provide recommendations to enhance visibility across endpoints, network, cloud, and application environments. Security Content Development Develop and maintain security dashboards, reports, alerts, and monitoring content. Onboard new log sources and ensure proper normalization and enrichment. Create operational documentation, runbooks, and detection engineering standards. Required Skills & Experience Primary Skills Strong hands-on experience with: Elasticsearch Kibana Logstash Beats Elastic Agent Elastic Security (SIEM) Experience managing large-scale Elasticsearch clusters. Strong understanding of KQL, Lucene, and Elasticsearch Query DSL. Experience developing detection rules, behavioral analytics, and threat detection use cases. Knowledge of MITRE ATT&CK, Cyber Kill Chain, and detection engineering best practices. Experience in threat hunting, incident investigation, and security monitoring. Understanding of Windows, Linux, Active Directory, cloud, and network security logs. Secondary Skills (Preferred) Other SIEM experiences are good to have ex Splunk, Enterprise SIEM good to have Certifications Elastic Certified Engineer Elastic Certified Observability Engineer Elastic Certified Analyst Elastic Security Certifications CompTIA Security+ GIAC Certifications (GCIA, GCIH, GMON) - (Preferred) CISSP (Preferred) Ideal Candidate Profile 5-8 years of experience in Cyber Security, SIEM Engineering, Detection Engineering, or Security Operations. Strong analytical and problem-solving skills. Ability to work independently while collaborating with SOC, Incident Response, Detection Engineering, and Threat Hunting teams. Experience supporting enterprise-scale security monitoring environments.
مسئولیتها
- Elastic Platform Engineering