COGNNA is shaping the future of cybersecurity through innovation, intelligence, and a relentless drive to protect. Our platforms integrate cutting-edge AI, real-time threat detection, and deep security insights to help organizations proactively defend against evolving cyber threats.
Responsibilities
Own end-to-end forensic investigations across endpoints, cloud platforms, and network infrastructure — from initial triage to root cause, including IoC identification, data exfiltration, and unauthorized access
Coordinate and lead the DFIR team across active investigations, ensuring consistent methodology, evidence integrity, and investigative velocity
Pull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateway platforms to reconstruct precise attack and user activity timelines
Acquire forensic images from laptops, mobile devices, servers, and cloud repositories with full chain of custody
Go deep on artifacts — file systems, memory, registry, logs, config states — to reconstruct exactly what happened and when
Correlate endpoint, network, and identity telemetry into a coherent picture of attacker behavior and system access
Build AI-assisted workflows that automate evidence collection, pattern detection, and timeline generation to scale investigative capacity
Translate technical findings into clear, chronological narratives for executives and cross-functional stakeholders — no jargon, no ambiguity
Close the loop: feed investigation outcomes back into detection rules, access controls, and policy improvements.
Requirements
Education
Bachelor’s in Cybersecurity, International Relations, Computer Science, or related field.
Experience
3+ years in digital forensics, incident response, or security investigations, with a track record leading or coordinating DFIR engagements
Exceptional written and verbal communication in both English & Arabic.
Hands-on proficiency with forensic tooling: FTK, X-Ways, Cellebrite, Axiom, or equivalent platforms
Strong command of network protocols (TCP/IP, HTTP/S, DNS) and log analysis across SIEM platforms
Scripting ability in Python, PowerShell, or Bash — used to automate evidence processing, not just theoretically
Deep working knowledge of Windows, macOS, and Linux/Unix environments at the artifact and system level
Proven experience integrating AI tools into investigative workflows to accelerate triage, pattern detection, or reporting
Clear, confident communicator — able to brief executives and work alongside legal, HR, and compliance teams without losing technical precision
Compliance: Ensuring all operations align with NCA ECC and SAMA CSF regulations.
Certifications (Highly Preferred)
SANS / GIAC (GCFA, GCFE, GNFA, GCIA or similar)
IACIS CFCE
EC-Council CHFI
Offsec (OSDA, OSIR)
Benefits
Impact that Matters – Build products that shape the future of cybersecurity and protect organizations globally.
On-Site Collaboration – Be at the heart of innovation in our Riyadh office, working side by side with passionate experts.
Continuous Growth – Access to certifications, trainings, and opportunities to sharpen your expertise.
Ownership Mindset – Benefit from our ESOP program and grow with COGNNA’s success.
Culture of Trust – We empower talent, encourage ownership, and celebrate real outcomes.
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in Saudi Arabia.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in Saudi Arabia, connecting you to thousands of jobs fast!
Find the best jobs in Saudi Arabia, apply in 1 click and get a job today!