Senior DFIR Guardian
COGNNA · Médine
Job description
About the role
We are looking for a Senior DFIR Guardian to lead end-to-end forensic investigations across endpoints, cloud platforms and network infrastructure. The role combines hands-on evidence collection with strategic coordination of the DFIR team to deliver rapid, high-quality incident response for our organization.
Key responsibilities
- Own the full investigation lifecycle from triage to root-cause analysis, including IoC identification, data exfiltration tracking and unauthorized access detection.
- Coordinate and lead the DFIR team, ensuring consistent methodology, evidence integrity and fast investigative velocity.
- Pull and analyse logs from EDR/XDR, SIEM, DLP, IdP and email gateways to build precise attack timelines.
- Acquire forensic images from laptops, mobile devices, servers and cloud repositories while maintaining chain of custody.
- Deep-dive into file systems, memory, registry, logs and configuration states to reconstruct events.
- Correlate endpoint, network and identity telemetry into a coherent attacker behavior picture.
- Design AI-assisted workflows that automate evidence collection, pattern detection and timeline generation.
- Translate technical findings into clear, chronological narratives for executives and cross-functional stakeholders.
- Feed investigation outcomes back into detection rules, access controls and policy improvements.
Required profile
- 5+ years of experience in digital forensics, incident response or security investigations, with proven leadership of DFIR engagements.
- Bachelor’s degree in Cybersecurity, Computer Science, International Relations or a related field.
- Fluent written and spoken English and Arabic.
- Saudi nationality and ability to work in compliance with NCA ECC and SAMA CSF regulations.
- Relevant certifications such as GCFA, GCFE, GNFA, GCIA, CFCE, CHFIO, OSDA or OSIR are highly preferred.
Required skills
- Hands-on experience with forensic tools: FTK, X-Ways, Cellebrite, Axiom or equivalents.
- Strong knowledge of Windows, macOS and Linux/Unix environments at the artifact level.
- Proficiency in scripting languages: Python, PowerShell, Bash.
- Deep understanding of network protocols (TCP/IP, HTTP/S, DNS) and log analysis across SIEM platforms.
- Experience integrating AI tools into investigative workflows.
What we offer
- Opportunity to shape the future of cybersecurity and protect organizations globally.
- On-site collaboration in our Almadina office with a passionate expert team.
- Continuous growth through certifications, trainings and ESOP participation.
- A culture of trust that empowers ownership and celebrates real outcomes.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Saudi Arabia.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 3 weeks ago
Expires 1 month from now
28 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
COGNNA
Médine