Jobiglo

No results.

Senior DFIR Guardian

COGNNA · Médine

Onsite Senior 🇬🇧 English
FTK X-Ways Cellebrite Axiom Python PowerShell Bash Windows macOS Linux TCP/IP HTTP/S DNS SIEM EDR XDR DLP IdP AI tools

Job description

About the role

We are looking for a Senior DFIR Guardian to lead end-to-end forensic investigations across endpoints, cloud platforms and network infrastructure. The role combines hands-on evidence collection with strategic coordination of the DFIR team to deliver rapid, high-quality incident response for our organization.

Key responsibilities

  • Own the full investigation lifecycle from triage to root-cause analysis, including IoC identification, data exfiltration tracking and unauthorized access detection.
  • Coordinate and lead the DFIR team, ensuring consistent methodology, evidence integrity and fast investigative velocity.
  • Pull and analyse logs from EDR/XDR, SIEM, DLP, IdP and email gateways to build precise attack timelines.
  • Acquire forensic images from laptops, mobile devices, servers and cloud repositories while maintaining chain of custody.
  • Deep-dive into file systems, memory, registry, logs and configuration states to reconstruct events.
  • Correlate endpoint, network and identity telemetry into a coherent attacker behavior picture.
  • Design AI-assisted workflows that automate evidence collection, pattern detection and timeline generation.
  • Translate technical findings into clear, chronological narratives for executives and cross-functional stakeholders.
  • Feed investigation outcomes back into detection rules, access controls and policy improvements.

Required profile

  • 5+ years of experience in digital forensics, incident response or security investigations, with proven leadership of DFIR engagements.
  • Bachelor’s degree in Cybersecurity, Computer Science, International Relations or a related field.
  • Fluent written and spoken English and Arabic.
  • Saudi nationality and ability to work in compliance with NCA ECC and SAMA CSF regulations.
  • Relevant certifications such as GCFA, GCFE, GNFA, GCIA, CFCE, CHFIO, OSDA or OSIR are highly preferred.

Required skills

  • Hands-on experience with forensic tools: FTK, X-Ways, Cellebrite, Axiom or equivalents.
  • Strong knowledge of Windows, macOS and Linux/Unix environments at the artifact level.
  • Proficiency in scripting languages: Python, PowerShell, Bash.
  • Deep understanding of network protocols (TCP/IP, HTTP/S, DNS) and log analysis across SIEM platforms.
  • Experience integrating AI tools into investigative workflows.

What we offer

  • Opportunity to shape the future of cybersecurity and protect organizations globally.
  • On-site collaboration in our Almadina office with a passionate expert team.
  • Continuous growth through certifications, trainings and ESOP participation.
  • A culture of trust that empowers ownership and celebrates real outcomes.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec COGNNA.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in Saudi Arabia.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 3 weeks ago

Expires 1 month from now

28 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

COGNNA

Médine