🇦🇪 HireDeveloper.ae

MDASH Reached UAE Government on 30 September — I Was Hiring the Wrong Security Engineer, and 4 Questions Fixed It

Security engineers in a Dubai operations room reviewing AI-generated code vulnerability findings
William

William

Talent Sourcing Expert · October 1, 2026 · 9 min read

TL;DR

  • •The event: on 30 September 2026, Microsoft, the UAE Cyber Security Council and Core42 announced they will scale MDASH, Microsoft’s AI-powered code security capability, across UAE government entities.
  • •What it actually changes: when AI finds vulnerabilities continuously, detection stops being the bottleneck. Remediation capacity becomes it — and almost every Dubai security job specification I read is still written for the old bottleneck.
  • •What I changed: I stopped sourcing scanner operators, started sourcing engineers who can close findings, and added 4 questions to the first call that sort the two in under ten minutes.

The headline on 30 September was “Microsoft, UAE Cyber Security Council and Core42 unite to scale AI-powered cyber defense across UAE government”. I almost filed it with the other partnership announcements. Then I read Dr Mohamed Al Kuwaiti’s quote properly — he does not say threat detection, he says code safety — and I realised the job specification I had been sourcing against for two years was written for a bottleneck that is about to disappear.

What Was Actually Announced on 30 September

Microsoft, the UAE Cyber Security Council (CSC) and Core42, a G42 company, announced a collaboration to deploy MDASH across UAE government entities. MDASH is described as using advanced AI models and automated analysis to identify vulnerabilities, prioritise risks and improve security posture at speed and scale.

The division of labour is the interesting part. Microsoft provides technical expertise, onboarding and implementation guidance. The Cyber Security Council supports government adoption and responsible use of AI for cybersecurity through the UAE’s National AI Test and Validation Lab. Core42 provides local expertise, integration with its sovereign controls platform and implementation services, delivered through its sovereign public cloud. The rollout is phased: awareness sessions, pilots, technical workshops. No single switch-on date.

Three statements came with it. H.E. Dr Mohamed Al Kuwaiti, Head of Cyber Security for the UAE Government, said “Code safety is a national priority and a cornerstone of cyber resilience… Bringing MDASH capabilities to the UAE is a major catalyst for wider adoption of AI-powered code security across government and our national digital ecosystem.” Hayete Gallot, Executive Vice President for Security and Emerging Technologies at Microsoft, framed AI as “a force multiplier to protect the nation, its critical assets, and people.” Talal M. Al Kaissi, Chief Executive Officer of Core42, said the collaboration gives government entities advanced capabilities “while keeping security, privacy and operational control at the center.”

The primary announcement sits on Microsoft’s EMEA newsroom, with regional coverage the same day from Security MEA, TechAfrica News and Economy Middle East. It did not arrive alone: the day before, Core42 and the Cyber Security Council signed an MoU on sovereign AI cloud. Read together, the two days describe an infrastructure decision, not a tool purchase.

Our expert take #1

Every employer I speak to reads an announcement like this as “we will need more cybersecurity people”. That is the wrong inference. The phrase in the release is identify vulnerabilities and prioritise risks — which is precisely the work that human security analysts have been doing by hand and are about to stop doing. What the announcement creates demand for is the stage immediately after: somebody who can take a prioritised finding in a real repository and close it. Scaling detection without scaling remediation does not make an organisation safer. It makes the backlog visible.

The Bottleneck Moved, and Job Specifications Did Not

For roughly a decade, the scarce skill in application security was finding things. Static analysis produced noise, so the valuable person was the one who could tell a false positive from a real one and maintain the tooling that generated them. Hiring reflected that. Look at any Dubai security job advert written in the last two years and count how much of it is tool names.

An AI system that reads code, reasons about reachability and ranks what matters attacks exactly that skill. I am not claiming it does the job perfectly — it does not, and the National AI Test and Validation Lab exists in this programme precisely because somebody has to validate the output. But it does change the shape of the work queue. Instead of forty findings a quarter that somebody triages carefully, you get a continuously refreshed, ranked list that is longer than your capacity to act on it.

At that point the constraint is not knowing what is wrong. It is how many fixes your team can write, review, test and ship per week without breaking production. That number is a software engineering number. It has almost nothing to do with how many security certifications the team holds.

Where the Constraint Sits, Before and AfterThe job advert should describe the narrow stage, not the wide one.BEFORE — scanner-era pipelineraw findingstriagefixes shippednarrow stage = triageAFTER — AI-assisted pipeline (MDASH and equivalents)ranked findings, refreshed continuouslyvalidationfix & shipnarrow stageThe role you now need to fill is the amber box. In most specifications I read, it is not described at all.Old advert: tool names, certifications, “experience with SAST/DAST”.New advert: merged pull requests that fixed a real class of vulnerability, under review, without a regression.

The Word “Sovereign” Is a Hiring Filter

Core42 is not delivering this as a generic SaaS subscription. It is delivering it through a sovereign public cloud with a sovereign controls platform, and the Cyber Security Council is routing adoption through the National AI Test and Validation Lab. That matters for anyone who will hire engineers who touch this chain, directly or as a supplier.

The difference is not technical depth. It is working habit. An engineer whose entire career has been spent in environments where any external service was one API key away tends to freeze the first time a dependency needs a data residency answer, an approval trail and a validation record before it can ship. I have watched capable engineers lose three weeks to that transition, and I have watched others handle it in two days because they had done it before.

You cannot screen for this with a question about compliance frameworks, because every candidate has read the same page. You screen for it by asking for a story: a control that blocked them, and what they did next.

Our expert take #2

The most expensive mistake in UAE security hiring right now is paying a premium for AI vocabulary. A candidate who can discuss model-assisted triage fluently and has never merged a security fix into a service with real traffic is worth less to you than a mid-level backend engineer who has. One of those profiles is being bid up by every employer in the country; the other is sitting in your existing engineering team, one internal conversation away. Check inside before you post the advert — roughly a third of the security roles we are asked to source turn out to be promotions nobody offered.

Writing a security role this quarter?

We screen UAE candidates on merged remediation work and on how they behave inside a controlled environment — before they reach your calendar, and before you pay a premium for the wrong half of the pipeline.

Discutons-en — talk to our Dubai team

The 4 Questions I Added to the First Call

These replaced a tool checklist. They take about ten minutes together, and they sort the market more reliably than any take-home exercise I have used.

1. “Walk me through the last security finding you personally fixed, from the report to the merge.”

Note the two anchors: personally, and to the merge. The strong answer contains a file, a reviewer, a test and an argument about blast radius. The weak answer describes a ticket being raised and assigned to someone else. This single question moves about half of a shortlist, and it is the reason I now ask for a repository link in the application rather than a certification list.

2. “Show me a finding you decided not to fix. What was your reasoning?”

This is the question that identifies judgement, and it is the one almost nobody prepares for. An engineer who has never declined a finding has never owned a backlog; they have been handed one. A good answer names the exploitability condition that was not met, the compensating control that already existed, or the fact that the fix would have introduced a worse failure mode. In an environment where an AI system generates more findings than you can action, the ability to defend a deliberate no is the core competence, not an edge case.

3. “Describe a control that stopped you shipping, and what you did about it.”

The sovereign-environment screen from the previous section. I am listening for whether the candidate treats a control as an obstacle to route around or a requirement to design against. The phrase I do not want to hear is “we got an exception” delivered as a success story. In a government-adjacent chain, exceptions are what you spend when you have planned badly.

4. “Your scanner now produces 400 ranked findings a week instead of 40. What changes about your week?”

A hypothetical, which I normally avoid, but it works because the honest answers are specific. Strong candidates immediately talk about grouping findings by root cause rather than processing them individually, about fixing a pattern once in a shared library, about setting a policy for what gets auto-closed, and about where the review capacity comes from. Weak candidates talk about needing a better dashboard. The difference is visible in about twenty seconds.

Our expert take #3

If you take one thing from this announcement, take the root-cause answer to question four. An organisation that closes AI-generated findings one at a time will never catch up, no matter how many engineers it hires — the queue refills faster than it drains. An organisation that groups findings by cause and fixes the cause once in a shared dependency closes hundreds with one change. That is an architectural instinct, it is rare, and it is worth more than two additional headcount. It is also the single clearest thing to interview for, because candidates who have it bring it up unprompted.

The Same Role, Specified TwiceLeft column attracts the whole market. Right column attracts four people, and you want one of them.WHAT I USED TO ASK FORWHAT I ASK FOR NOW“Hands-on with leading SAST/DASTtooling”“Link us to a merged fix for a realvulnerability class”“Relevant security certificationsrequired”“Be ready to defend a finding youchose not to fix”“Familiarity with complianceframeworks”“Tell us about a control that blockeda release”“Monitor and report on securityposture”“Group findings by root cause andfix the cause once”

What I Would Do This Week

  • Count your remediation throughput before you post anything. How many security fixes did your team merge last month? If the answer is single digits, hiring a second detector will not help you, and the role you have written is the wrong one. Our method for building an AI cybersecurity engineering team in Dubai starts from that number deliberately.
  • Look inside first. The mid-level backend engineer who already ships in your codebase is three weeks of mentoring away from the role you are about to advertise at a premium.
  • Separate the cloud profile from the code profile. Securing a sovereign deployment and securing an application are different jobs with different candidate pools; our guide to hiring cloud security engineers in Dubai covers the infrastructure half of this properly.
  • Re-benchmark before the first offer. A national programme of this size moves bands within a quarter. The current structure, including the allowances that move total package more than base does, is in our Dubai salary negotiation guide.

If you are building the system rather than the team, the licensing and architecture sequence in our walkthrough of building a fintech app in the UAE is the closest analogue for a regulated deployment. And if the same role is open on your Singapore roadmap, the constraints genuinely differ — our colleagues covered exactly this profile under a patching deadline in the four questions they now ask every Singapore infrastructure hire.

Hiring into the narrow stage, not the wide one?

We source security engineers across the UAE and screen them on merged remediation work, declined findings and behaviour inside controlled environments — and we will tell you when the role you have written is really a promotion you have not offered yet.

Discutons-en — brief our Dubai team

Frequently Asked Questions

What exactly did Microsoft, the UAE Cyber Security Council and Core42 announce on 30 September 2026?

The three parties announced a collaboration to deploy MDASH, Microsoft’s AI-powered cybersecurity capability, across UAE government entities. MDASH uses advanced AI models and automated analysis to identify vulnerabilities, prioritise risks and improve security posture at speed and scale. Microsoft provides technical expertise, onboarding and implementation guidance; the Cyber Security Council supports government adoption and responsible use of AI for cybersecurity through the UAE’s National AI Test and Validation Lab; and Core42, a G42 company, provides local expertise, integration with its sovereign controls platform and implementation services. The rollout is phased, beginning with awareness sessions, pilots and technical workshops rather than a single switch-on date.

Why does an AI code security rollout change who a Dubai company should hire?

Because it moves the bottleneck. For most of the last decade the scarce skill was finding vulnerabilities, so employers hired people who could run and interpret scanners. When an AI system produces findings continuously and at scale, detection stops being the constraint and remediation capacity becomes it. The engineer who creates value in that environment is one who can read a finding, decide whether it is real in your specific codebase, write the fix, and ship it through review without breaking the service. That is a software engineering profile with security judgement, not a security analyst profile with tool certifications, and the two are sourced from completely different pools at different price points.

Does the sovereign cloud element change the candidate profile?

Yes, in a way that is easy to underestimate. Core42 is delivering MDASH through its sovereign public cloud platform, and the Cyber Security Council is routing adoption through the National AI Test and Validation Lab. Any engineer working near a government entity in that chain will operate under data residency, approval and evidence requirements that do not exist in a commercial SaaS environment. The practical difference is not technical depth but working habit: candidates who have only shipped in environments where they could reach for any external service tend to stall when every dependency needs a residency answer. Ask for a concrete example of a control that blocked them and what they did about it.

Should a small Dubai company care about a government cybersecurity programme?

Only for one reason, and it is a commercial one rather than a technical one. A national programme of this size pulls experienced security engineers towards the entities inside it, directly through hiring and indirectly through the integrators and consultancies that service them. If you are a thirty-person company in Dubai Internet City competing for the same people, you will not win on salary against a programme with national backing. You win by offering work that is less constrained and more visible, and by shortening your process. The companies that lose candidates in this market almost always lose them to a slower second interview, not to a higher number.

William

William

Talent Sourcing Expert at HireDeveloper.ae. Sources and screens security and platform engineers for UAE employers, and rewrites the job specifications that were attracting the wrong half of the market.