Company logo hidden

EDR Expert

Unlock employer Dubai, United Arab Emirates 1 hour ago · 18 Sep 2026

Financial

  • Estimate: $50k - $80k*
  • Zero income tax location

Accessibility

  • Office Only
  • Visa Provided

Requirements

  • Experience: Intermediate
  • English: Professional

Position

About the job
We are seeking an experienced EDR Expert with strong hands-on expertise in SentinelOne to monitor, investigate, and analyze endpoint security alerts. The ideal candidate will be responsible for reviewing alerts, distinguishing between false positives and genuine security incidents, and supporting timely incident response.

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

Key Responsibilities

  • Review and analyze SentinelOne EDR alerts to determine whether they represent false positives or genuine security incidents.
  • Investigate endpoint alerts, suspicious activities, malicious processes, files, scripts, and user behavior.
  • Perform detailed analysis of endpoint telemetry, detection data, process trees, and indicators of compromise (IOCs).
  • Validate security incidents and determine the severity and potential impact on the environment.
  • Investigate suspicious or malicious activities using SentinelOne capabilities.
  • Correlate EDR alerts with other available security data to identify potential attack patterns.
  • Escalate confirmed security incidents according to established incident response procedures.
  • Document investigation findings, root causes, and recommended remediation actions.
  • Identify recurring false positives and recommend appropriate alert tuning and policy adjustments.
  • Support containment, remediation, and threat eradication activities where required.
  • Maintain incident records and prepare regular reports on EDR alerts and security incidents.
  • Stay updated on emerging endpoint threats, malware techniques, and MITRE ATT&CK tactics and techniques.

Required Skills & Experience

  • 3–5+ years of experience in EDR, SOC, Cybersecurity Operations, or Incident Response.
  • Strong hands-on experience with SentinelOne is mandatory.
  • Good understanding of endpoint security, malware analysis, and incident investigation.
  • Experience analyzing process trees, endpoint telemetry, IOCs, and suspicious activities.
  • Strong knowledge of Windows and Linux endpoint security.
  • Understanding of common attack techniques, malware behavior, and MITRE ATT&CK framework.
  • Experience with SIEM platforms such as Splunk, Microsoft Sentinel, or QRadar is an advantage.
  • Strong analytical and incident investigation skills.
  • Relevant cybersecurity certifications such as CompTIA Security+, CySA+, CEH, GCIH, or equivalent are preferred.
Apply Direct

Jobs you might like   View all jobs

About Information Technology & Services Company

Company details are hidden. Subscribe to view full company profile.

Ready to apply for this role?

Apply Direct