
Senior DFIR Guardian - Madinah
At a Glance
- Category
- ๐ป Technology
- Level
- Senior
- Type
- Full-time
Before You Apply
- Test your resume against COGNNA's ATS
- Get AI-rewritten bullet points
- Download Gulf-ready CV
60 seconds. $5.88 one-time.
- Own end-to-end forensic investigations across endpoints, cloud platforms, and network infrastructure โ from initial triage to root cause, including IoC identification, data exfiltration, and unauthorized access
- Coordinate and lead the DFIR team across active investigations, ensuring consistent methodology, evidence integrity, and investigative velocity
- Pull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateway platforms to reconstruct precise attack and user activity timelines
- Acquire forensic images from laptops, mobile devices, servers, and cloud repositories with full chain of custody
- Go deep on artifacts โ file systems, memory, registry, logs, config states โ to reconstruct exactly what happened and when
- Correlate endpoint, network, and identity telemetry into a coherent picture of attacker behavior and system access
- Build AI-assisted workflows that automate evidence collection, pattern detection, and timeline generation to scale investigative capacity
- Translate technical findings into clear, chronological narratives for executives and cross-functional stakeholders โ no jargon, no ambiguity
- Close the loop: feed investigation outcomes back into detection rules, access controls, and policy improvements.
๐ Education
- Bachelorโs in Cybersecurity, International Relations, Computer Science, or related field.
๐ผ Experience
- 5+ years in digital forensics, incident response, or security investigations, with a track record leading or coordinating DFIR engagements
- Exceptional written and verbal communication in both English & Arabic.
- Hands-on proficiency with forensic tooling: FTK, X-Ways, Cellebrite, Axiom, or equivalent platforms
- Strong command of network protocols (TCP/IP, HTTP/S, DNS) and log analysis across SIEM platforms
- Scripting ability in Python, PowerShell, or Bash โ used to automate evidence processing, not just theoretically
- Deep working knowledge of Windows, macOS, and Linux/Unix environments at the artifact and system level
- Proven experience integrating AI tools into investigative workflows to accelerate triage, pattern detection, or reporting
- Clear, confident communicator โ able to brief executives and work alongside legal, HR, and compliance teams without losing technical precision
- Compliance: Ensuring all operations align with NCA ECC and SAMA CSF regulations.
- Saudi nationality is required๐ Certifications (Highly Preferred)
- SANS / GIAC (GCFA, GCFE, GNFA, GCIA or similar)
- IACIS CFCE
- EC-Council CHFI
- Offsec (OSDA, OSIR)
๐ Impact that Matters โ Build products that shape the future of cybersecurity and protect organizations globally.
๐ข On-Site Collaboration โ Be at the heart of innovation in our Almadina office, working side by side with passionate experts.
๐ก Continuous Growth โ Access to certifications, trainings, and opportunities to sharpen your expertise.
๐ Ownership Mindset โ Benefit from our ESOP program and grow with COGNNAโs success.
๐ค Culture of Trust โ We empower talent, encourage ownership, and celebrate real outcomes.
Requirements
- โขBachelorโs in Cybersecurity, International Relations, Computer Science, or related field
- โข5+ years in digital forensics, incident response, or security investigations
- โขExperience leading or coordinating DFIR engagements
- โขExceptional written and verbal communication in English and Arabic
- โขHands-on proficiency with forensic tooling: FTK, X-Ways, Cellebrite, Axiom, or equivalent
- โขStrong command of network protocols (TCP/IP, HTTP/S, DNS) and log analysis
- โขScripting ability in Python, PowerShell, or Bash
- โขDeep working knowledge of Windows, macOS, and Linux/Unix environments
Nice to Have
- โขSANS / GIAC (GCFA, GCFE, GNFA, GCIA or similar)
- โขIACIS CFCE
- โขEC-Council CHFI
- โขOffsec (OSDA, OSIR)
Responsibilities
- โขOwn end-to-end forensic investigations from initial triage to root cause
- โขCoordinate and lead the DFIR team across active investigations
- โขPull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateway platforms
- โขAcquire forensic images from laptops, mobile devices, servers, and cloud repositories
- โขCorrelate endpoint, network, and identity telemetry into coherent attacker behavior pictures
- โขBuild AI-assisted workflows to automate evidence collection and pattern detection
- โขTranslate technical findings into clear narratives for executives and stakeholders
- โขFeed investigation outcomes back into detection rules, access controls, and policy improvements
Related Jobs4 similar jobs
Browse Similar
- Test your resume against COGNNA's ATS
- Get AI-rewritten bullet points
- Download Gulf-ready CV
60 seconds. $5.88 one-time.

COGNNA offers AI-driven solutions for business process automation, specializing in intelligent document processing and data extraction for various sectors.


