📢 New: get today's jobs on our WhatsApp Channel
Jobiglo

No results.

Senior DFIR Guardian - Madinah

COGNNA · Madinah

New
Onsite Senior 🇬🇧 English
Digital Forensics Incident Response Security Investigations FTK Cellebrite Axiom EDR/XDR SIEM DLP IdP Python PowerShell Bash TCP/IP HTTP/S DNS Windows macOS Linux/Unix

Job description

About the role

COGNNA is seeking a Senior DFIR Guardian to own end‑to‑end forensic investigations across endpoints, cloud platforms and network infrastructure. You will lead the DFIR team, ensure evidence integrity and translate technical findings into clear executive briefings.

Key responsibilities

  • Conduct full lifecycle forensic investigations from triage to root‑cause analysis, including IoC identification and data exfiltration tracing.
  • Coordinate and lead the DFIR team across active cases, maintaining consistent methodology and investigative velocity.
  • Pull and analyze logs from EDR/XDR, SIEM, DLP, IdP and email gateways to reconstruct precise attack timelines.
  • Acquire forensic images from laptops, mobile devices, servers and cloud repositories with full chain of custody.
  • Build AI‑assisted workflows to automate evidence collection, pattern detection and timeline generation.
  • Feed investigation outcomes back into detection rules, access controls and policy improvements.

Required profile

  • Bachelor’s degree in Cybersecurity, Computer Science, International Relations or a related field.
  • 5+ years of experience in digital forensics, incident response or security investigations, with proven leadership of DFIR engagements.
  • Fluent in English and Arabic, with strong written and verbal communication skills.
  • Saudi nationality and compliance with NCA ECC and SAMA CSF regulations.
  • Relevant certifications such as SANS/GIAC, IACIS, EC‑Council or OffSec are highly preferred.

Required skills

  • Hands‑on proficiency with forensic tools (FTK, X‑Ways, Cellebrite, Axiom).
  • Strong command of network protocols (TCP/IP, HTTP/S, DNS) and log analysis across SIEM platforms.
  • Scripting in Python, PowerShell or Bash for automated evidence processing.
  • Deep knowledge of Windows, macOS and Linux/Unix artifact analysis.
  • Experience integrating AI tools into investigative workflows.

What we offer

  • Impactful work shaping the future of cybersecurity on a global scale.
  • On‑site collaboration at our Al‑Madinah office with passionate experts.
  • Continuous growth through certifications, trainings and career development.
  • Ownership mindset supported by an ESOP program.
  • Culture of trust that empowers talent and celebrates real outcomes.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec COGNNA.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in Saudi Arabia.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

Apply now →

By continuing, you accept our terms of use.

Already have an account? Login

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 5 days ago

Expires 1 month from now

17 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

COGNNA

Madinah