📢 New: get today's jobs on our WhatsApp Channel
Jobiglo

No results.

This job is no longer available

This job expired on 20/08/2026. It no longer accepts applications.

Threat Detection Engineer

COGNNA · Riyad

Onsite 🇬🇧 English
Python PowerShell UEBA EDR Wireshark IDS IPS NetFlow macOS logging

Job description

About the role

As a Threat Detection Engineer at COGNNA you will design and implement high‑impact detection strategies, automate SOC workflows and raise the overall maturity of the security operations centre. You will work closely with threat intel, incident response and platform engineering teams while mentoring junior cyber talent.

Key responsibilities

  • Develop high‑fidelity correlation rules and behavioural detections on COGNNA XDR, SIEM and SOC platforms.
  • Translate MITRE ATT&CK techniques, threat‑intel feeds and vulnerability data into actionable detection logic.
  • Identify detection gaps, add new data sources and automate testing to maintain detection quality.
  • Lead architecture, scaling and optimisation of XDR, SIEM and log‑ingestion pipelines.
  • Build automation scripts (Python, PowerShell) to improve SOC efficiency and integrate tools across the stack.
  • Collaborate with intel and IR teams on threat‑hunting use cases and provide Tier‑3+ incident investigation support.
  • Improve SOC playbooks, SOPs and detection engineering workflows.

Required profile

  • Bachelor’s degree in Computer Science, Cybersecurity or a related field.
  • Hands‑on experience creating and maintaining complex detection use cases.
  • Strong understanding of attacker behaviour, incident response fundamentals and digital forensics.
  • Excellent analytical thinking, communication in English (Arabic optional) and mentorship abilities.

Required skills

  • SIEM query languages (SPL, KQL, Lucene) and UEBA tuning.
  • EDR platforms and endpoint detection techniques.
  • Network analysis tools (Wireshark, IDS/IPS, NetFlow).
  • Advanced scripting in Python and/or PowerShell.
  • Deep knowledge of Windows, Linux and macOS logging and forensic artefacts.
  • Threat‑intel integration into real‑time detection logic.
  • Cloud security monitoring for IaaS, PaaS and SaaS environments.

What we offer

  • Opportunity to shape world‑class SOC capabilities.
  • On‑site collaboration in a modern Riyadh office.
  • Access to cutting‑edge security platforms and continuous learning.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec COGNNA.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in Saudi Arabia.

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 3 months ago

25 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

COGNNA

Riyad