Senior DFIR Guardian - Madinah

COGNNA

As Sudiyah

On-site

OMR 18,000 - 30,000

Full time

13 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

ESOP program
Certifications & trainings
On-site collaboration at Almadina

Job summary

COGNNA in Oman seeks a senior DFIR investigator to own end-to-end forensic investigations across endpoints, cloud and network, from triage to root cause, including IoC and data exfiltration.

You will coordinate and lead the DFIR team, pulling logs from EDR/XDR, SIEM, DLP, IdP and email gateways, and acquire forensic images with full chain of custody for comprehensive timelines.

Qualifications

  • Own end-to-end forensic investigations across endpoints, cloud platforms, and network infrastructure.
  • Coordinate and lead the DFIR team across active investigations with consistent methodology and evidence integrity.
  • Pull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateway platforms to reconstruct attack timelines.
  • Acquire forensic images from laptops, mobile devices, servers, and cloud repositories with full chain of custody.
  • Deep-dive on artifacts to reconstruct what happened and when.
  • Correlate telemetry into a coherent picture of attacker behavior and system access.
  • Build AI-assisted workflows to scale investigative capacity.
  • Translate findings into clear narratives for executives and cross-functional stakeholders.

Responsibilities

  • Own end-to-end forensic investigations across endpoints, cloud platforms, and network infrastructure.
  • Coordinate and lead the DFIR team across active investigations, ensuring consistent methodology and evidence integrity.
  • Pull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateway platforms to reconstruct precise timelines.
  • Acquire forensic images from laptops, mobile devices, servers, and cloud repositories with full chain of custody.
  • Go deep on artifacts to reconstruct exactly what happened and when.
  • Correlate endpoint, network, and identity telemetry into a coherent picture of attacker behavior.
  • Build AI-assisted workflows to automate evidence collection and timeline generation.
  • Translate technical findings into clear, chronological narratives for executives.

Skills

End-to-end DFIR
DFIR team leadership
Log analysis
Forensic tooling proficiency
Python scripting
PowerShell
Bash
Windows macOS Linux
Executive briefings
Compliance knowledge
English & Arabic
Incident response
AI-assisted workflows

Education

Bachelor’s degree in Cybersecurity, International Relations, Computer Science, or related field

Tools

FTK
X-Ways
Cellebrite
Axiom
SIEM

Job description

  • Own end-to-end forensic investigations across endpoints, cloud platforms, and network infrastructure — from initial triage to root cause, including IoC identification, data exfiltration, and unauthorized access
  • Coordinate and lead the DFIR team across active investigations, ensuring consistent methodology, evidence integrity, and investigative velocity
  • Pull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateway platforms to reconstruct precise attack and user activity timelines
  • Acquire forensic images from laptops, mobile devices, servers, and cloud repositories with full chain of custody
  • Go deep on artifacts — file systems, memory, registry, logs, config states — to reconstruct exactly what happened and when
  • Correlate endpoint, network, and identity telemetry into a coherent picture of attacker behavior and system access
  • Build AI-assisted workflows that automate evidence collection, pattern detection, and timeline generation to scale investigative capacity
  • Translate technical findings into clear, chronological narratives for executives and cross-functional stakeholders — no jargon, no ambiguity
  • Close the loop: feed investigation outcomes back into detection rules, access controls, and policy improvements.
Education
  • Bachelor’s in Cybersecurity, International Relations, Computer Science, or related field.
Experience
  • 5+ years in digital forensics, incident response, or security investigations, with a track record leading or coordinating DFIR engagements
  • Exceptional written and verbal communication in both English & Arabic.
  • Hands-on proficiency with forensic tooling: FTK, X-Ways, Cellebrite, Axiom, or equivalent platforms
  • Strong command of network protocols (TCP/IP, HTTP/S, DNS) and log analysis across SIEM platforms
  • Scripting ability in Python, PowerShell, or Bash — used to automate evidence processing, not just theoretically
  • Deep working knowledge of Windows, macOS, and Linux/Unix environments at the artifact and system level
  • Proven experience integrating AI tools into investigative workflows to accelerate triage, pattern detection, or reporting
  • Clear, confident communicator — able to brief executives and work alongside legal, HR, and compliance teams without losing technical precision
  • Compliance: Ensuring all operations align with NCA ECC and SAMA CSF regulations.
  • Saudi nationality is required

Certifications (Highly Preferred)

  • SANS / GIAC (GCFA, GCFE, GNFA, GCIA or similar)
  • IACIS CFCE
  • EC-Council CHFI
  • Offsec (OSDA, OSIR)

Impact that Matters – Build products that shape the future of cybersecurity and protect organizations globally.

On-Site Collaboration – Be at the heart of innovation in our Almadina office, working side by side with passionate experts.

Continuous Growth – Access to certifications, trainings, and opportunities to sharpen your expertise.

Ownership Mindset – Benefit from our ESOP program and grow with COGNNA’s success.

Culture of Trust – We empower talent, encourage ownership, and celebrate real outcomes.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Threat Detection Engineer - Madinah
Senior Threat Detection Engineer - Madinah

COGNNA • As Sudiyah

On-site
OMR 18,000 - 30,000
ESOP program
Certifications and trainings
On-site Almadina office
Senior DFIR Lead: Incident Response & Digital Forensics
Senior DFIR Lead: Incident Response & Digital Forensics

cloud consultancy - ccds • As Sudiyah

On-site
OMR 31,000 - 43,000
Lead Consultant - FortiGuard Incident Response
Lead Consultant - FortiGuard Incident Response

Fortinet, Inc. • As Sudiyah

On-site
OMR 60,000 - 100,000
Business Development Lead Cyber Security
Business Development Lead Cyber Security

Royal World Group • Muscat

Hybrid
OMR 10,000 - 20,000
Cybersecurity Admin & Office Operations Specialist
Cybersecurity Admin & Office Operations Specialist

Hyperproof • As Sudiyah

On-site
Confidential
Senior Cybersecurity Specialist
Senior Cybersecurity Specialist

UNKNOWN • As Sudiyah

On-site
OMR 25,000 - 37,000
Senior Threat Detection Engineer: Lead SOC & ESOP
Senior Threat Detection Engineer: Lead SOC & ESOP

COGNNA • As Sudiyah

On-site
OMR 18,000 - 30,000
ESOP program
Certifications and trainings
On-site Almadina office
Identity & Access Management (IAM/PAM) Specialist
Identity & Access Management (IAM/PAM) Specialist

cloud consultancy - ccds • As Sudiyah

On-site
OMR 18,000 - 29,000
OQ8 - Expert, Cybersecurity & GRC
OQ8 - Expert, Cybersecurity & GRC

oq8.om • Muscat

On-site
OMR 30,760 - 46,140
Senior MS Engineer
Senior MS Engineer

Atriasolutions • As Sudiyah

On-site
OMR 15,000 - 40,000