Senior DFIR Guardian - Madinah

Posted 10 Days Ago
Be an Early Applicant
Madinah, SAU
In-Office
Senior level
Information Technology • Software • Cybersecurity
The Role
Leads end-to-end digital forensics and incident response investigations across endpoints, cloud, and networks. Coordinates DFIR teams, analyzes security telemetry and forensic artifacts, maintains evidence chain of custody, reconstructs attacker activity, and communicates findings to executives and stakeholders. Develops AI-assisted workflows to automate investigative processes and feeds outcomes into detection, access control, and policy improvements while ensuring compliance with NCA ECC and SAMA CSF requirements.
Summary Generated by Built In
  • Own end-to-end forensic investigations across endpoints, cloud platforms, and network infrastructure — from initial triage to root cause, including IoC identification, data exfiltration, and unauthorized access
  • Coordinate and lead the DFIR team across active investigations, ensuring consistent methodology, evidence integrity, and investigative velocity
  • Pull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateway platforms to reconstruct precise attack and user activity timelines
  • Acquire forensic images from laptops, mobile devices, servers, and cloud repositories with full chain of custody
  • Go deep on artifacts — file systems, memory, registry, logs, config states — to reconstruct exactly what happened and when
  • Correlate endpoint, network, and identity telemetry into a coherent picture of attacker behavior and system access
  • Build AI-assisted workflows that automate evidence collection, pattern detection, and timeline generation to scale investigative capacity
  • Translate technical findings into clear, chronological narratives for executives and cross-functional stakeholders — no jargon, no ambiguity
  • Close the loop: feed investigation outcomes back into detection rules, access controls, and policy improvements.

Requirements🎓 Education
  • Bachelor’s in Cybersecurity, International Relations, Computer Science, or related field.
💼 Experience
    • 5+ years in digital forensics, incident response, or security investigations, with a track record leading or coordinating DFIR engagements
    • Exceptional written and verbal communication in both English & Arabic.
    • Hands-on proficiency with forensic tooling: FTK, X-Ways, Cellebrite, Axiom, or equivalent platforms
    • Strong command of network protocols (TCP/IP, HTTP/S, DNS) and log analysis across SIEM platforms
    • Scripting ability in Python, PowerShell, or Bash — used to automate evidence processing, not just theoretically
    • Deep working knowledge of Windows, macOS, and Linux/Unix environments at the artifact and system level
    • Proven experience integrating AI tools into investigative workflows to accelerate triage, pattern detection, or reporting
    • Clear, confident communicator — able to brief executives and work alongside legal, HR, and compliance teams without losing technical precision
    • Compliance: Ensuring all operations align with NCA ECC and SAMA CSF regulations.
    • Saudi nationality is required

🏅 Certifications (Highly Preferred)

  • SANS / GIAC (GCFA, GCFE, GNFA, GCIA or similar)
  • IACIS CFCE
  • EC-Council CHFI
  • Offsec (OSDA, OSIR)

Benefits

🚀 Impact that Matters – Build products that shape the future of cybersecurity and protect organizations globally.

🏢 On-Site Collaboration – Be at the heart of innovation in our Almadina office, working side by side with passionate experts.

💡 Continuous Growth – Access to certifications, trainings, and opportunities to sharpen your expertise.

📈 Ownership Mindset – Benefit from our ESOP program and grow with COGNNA’s success.

🤝 Culture of Trust – We empower talent, encourage ownership, and celebrate real outcomes.

Skills Required

  • Bachelor's degree in Cybersecurity, International Relations, Computer Science, or a related field
  • 5+ years of experience in digital forensics, incident response, or security investigations
  • Experience leading or coordinating DFIR engagements
  • Exceptional written and verbal communication in English and Arabic
  • Hands-on proficiency with FTK, X-Ways, Cellebrite, Axiom, or equivalent forensic platforms
  • Strong knowledge of TCP/IP, HTTP/S, DNS, and SIEM log analysis
  • Scripting ability in Python, PowerShell, or Bash for evidence-processing automation
  • Deep working knowledge of Windows, macOS, and Linux/Unix at the artifact and system level
  • Experience integrating AI tools into investigative workflows
  • Ability to brief executives and collaborate with legal, HR, and compliance teams
  • Compliance experience with NCA ECC and SAMA CSF regulations
  • Saudi nationality
  • SANS/GIAC certification such as GCFA, GCFE, GNFA, or GCIA
  • IACIS CFCE certification
  • EC-Council CHFI certification
  • OffSec OSDA or OSIR certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
50 Employees
Year Founded: 2022

What We Do

Detect the Undetectable. Defeat the Unpredictable.

Similar Jobs

Hilton Logo Hilton

Receptionist

Software • Hospitality
In-Office or Remote
2 Locations
121228 Employees

Hilton Logo Hilton

Front Office Supervisor

Software • Hospitality
In-Office or Remote
2 Locations
121228 Employees

Hilton Logo Hilton

Office Manager

Software • Hospitality
In-Office or Remote
2 Locations
121228 Employees

Hilton Logo Hilton

Training Manager

Software • Hospitality
In-Office or Remote
2 Locations
121228 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account