
COGNNA
Medina, Saudi ArabiaPosted 6 days ago
- Own end-to-end forensic investigations across endpoints, cloud platforms, and network infrastructure — from initial triage to root cause, including IoC identification, data exfiltration, and unauthorized access - Coordinate and lead the DFIR team across active investigations, ensuring consistent methodology, evidence integrity, and investigative velocity - Pull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateway platforms to reconstruct precise attack and user activity timelines - Acquire forensic images from laptops, mobile devices, servers, and cloud repositories with full chain of custody - Go deep on artifacts — file systems, memory, registry, logs, config states — to reconstruct exactly what happened and when - Correlate endpoint, network, and identity telemetry into a coherent picture of attacker behavior and system access - Build AI-assisted workflows that automate evidence collection, pattern detection, and timeline generation to scale investigative capacity - Translate technical findings into clear, chronological narratives for executives and cross-functional stakeholders — no jargon, no ambiguity - Close the loop: feed investigation outcomes back into detection rules, access controls, and policy improvements. Benefits 🚀 Impact that Matters – Build products that shape the future of cybersecurity and protect organizations globally. 🏢 On-Site Collaboration – Be at the heart of innovation in our Almadina office, working side by side with passionate experts. 💡 Continuous Growth – Access to certifications, trainings, and opportunities to sharpen your expertise. 📈 Ownership Mindset – Benefit from our ESOP program and grow with COGNNA’s success. 🤝 Culture of Trust – We empower talent, encourage ownership, and celebrate real outcomes.
Own end-to-end forensic investigations across endpoints, cloud platforms, and network infrastructure — from initial triage to root cause, including IoC identification, data exfiltration, and unauthorized access. Coordinate and lead the DFIR team across active investigations, ensuring consistent methodology, evidence integrity, and investigative velocity. Pull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateway platforms to reconstruct precise attack and user activity timelines. Acquire forensic images from laptops, mobile devices, servers, and cloud repositories with full chain of custody. Go deep on artifacts — file systems, memory, registry, logs, config states — to reconstruct exactly what happened and when. Correlate endpoint, network, and identity telemetry into a coherent picture of attacker behavior and system access. Build AI-assisted workflows that automate evidence collection, pattern detection, and timeline generation to scale investigative capacity. Translate technical findings into clear, chronological narratives for executives and cross-functional stakeholders — no jargon, no ambiguity. Close the loop: feed investigation outcomes back into detection rules, access controls, and policy improvements.
Not sure you fit this role?
Upload your CV and see how you score against COGNNA and every other live job. It's free.
Get my free matchesAED 24,500 – 44,100 a monthest.
Senior DFIR Guardian - Madinah
COGNNAMedina, Saudi Arabia
AED 24,500 – 41,160/mo
Staff DFIR - COGNNA
COGNNARiyadh, Saudi Arabia
AED 17,640 – 29,400/mo
Senior DFIR & Incident Response Expert - Saudi National
Robert WaltersRiyadh, Saudi Arabia
AED 44,100 – 68,600/mo
Senior Threat Detection Engineer - Madinah
COGNNA
AED 24,500 – 44,100/mo