Threat Detection Engineer
COGNNA · Médine
Job description
About the role
COGNNA is looking for a Threat Detection Engineer to design high‑impact detection strategies, build automation, and raise the SOC to a world‑class level. You will mentor junior talent and work closely with threat intel, incident response, and platform engineering teams.
Key responsibilities
- Develop high‑fidelity correlation rules and behavioral detections on COGNNA security platforms.
- Translate MITRE ATT&CK techniques, threat intel, and vulnerability data into actionable detection logic.
- Identify detection gaps, add new data sources, and automate testing to maintain detection quality.
- Lead architecture and optimisation of XDR, SIEM, and SOC tech stacks for scalability and resilience.
- Streamline log ingestion pipelines, from parsing to enrichment, and build automation scripts (Python, PowerShell).
- Integrate tools across the SOC stack to enable seamless workflows and response.
- Collaborate with intel and IR teams to enrich use cases, support threat hunts, and provide Tier‑3+ incident investigation support.
- Improve SOC playbooks, SOPs, and detection engineering workflows while ensuring compliance with regional standards.
Required profile
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field.
- Hands‑on experience creating and maintaining complex detection use cases.
- Strong understanding of attacker behaviour, incident response fundamentals, and digital forensics.
- Excellent analytical thinking, problem‑solving, and communication skills in English and Arabic.
- Mentorship mindset and ability to work under high‑pressure situations.
Required skills
- SIEM query languages (SPL, KQL, Lucene) and rule tuning.
- UEBA concepts and scaling SIEM deployments.
- EDR platforms and endpoint detection tactics.
- Network packet analysis with Wireshark, IDS/IPS, NetFlow.
- Advanced scripting in Python and PowerShell.
- Deep knowledge of Windows, Linux, and macOS logging and forensic artifacts.
- Threat intelligence integration and MITRE ATT&CK mapping.
- Cloud security monitoring for IaaS, PaaS, and SaaS environments.
What we offer
- Opportunity to shape the future of cybersecurity on a global scale.
- On‑site collaboration in our Almadina office.
- Professional growth through mentorship and cutting‑edge projects.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Saudi Arabia.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 2 weeks ago
Expires 1 month from now
23 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
COGNNA
Médine