Senior Threat Detection Engineer - Madinah

COGNNA

As Sudiyah

On-site

OMR 18,000 - 30,000

Full time

13 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

ESOP program
Certifications and trainings
On-site Almadina office

Job summary

COGNNA is seeking a Threat Detection Engineer to design high-impact detection strategies, automate detection, and elevate SOC operations within our Almadina office. You will mentor talent and collaborate across threat intel, incident response, and platform engineering to strengthen detection capabilities.

Join us to advance SOC maturity, implement scalable detection, and contribute to post-incident analyses while staying ahead of evolving threats.

Qualifications

  • Bachelor’s in Computer Science, Cybersecurity, or related field.
  • Minimum 3 years of experience developing complex detection use cases.
  • Strong understanding of attacker behavior, IR fundamentals, and digital forensics.
  • Experience turning threat intel into actionable detection logic.

Responsibilities

  • Build high-fidelity correlation rules and behavioral detections.
  • Translate MITRE ATT&CK into actionable detection logic.
  • Lead architecture and optimization of SIEM/EDR/SOC stacks for scale.
  • Automate detection testing and maintain detection quality.
  • Mentor rising cyber talent and evolve SOC maturity.
  • Collaborate with intel and IR teams on hunts.

Skills

Threat detection expertise
Incident response fundamentals
Digital forensics
Mentorship
English & Arabic communication

Education

Bachelor's in Computer Science or Cybersecurity

Tools

SIEM platforms (Splunk, QRadar)
EDR tools
Wireshark / Network analysis
Python / PowerShell scripting
Windows/Linux/macOS logging
Threat intel integration
Cloud security monitoring

Job description

As a Threat Detection Engineer at COGNNA, you’ll design high-impact detection strategies, build powerful automation, and elevate SOC operations to a world-class standard. You’ll also mentor rising cyber talent and collaborate with teams across threat intel, incident response, and platform engineering.

Advanced Threat Detection Engineering
  • Build high-fidelity correlation rules and behavioral detections within the COGNNA security platforms.
  • Translate adversary TTPs (MITRE ATT&CK), threat intel, and vulnerability data into actionable logic.
  • Identify detection gaps and introduce new data sources to cover evolving threat landscapes.
  • Automate detection testing and maintain detection quality over time.
Platform Engineering & Optimization
  • Lead architecture and optimization of XDR, SIEM, and SOC tech stacks for scale and resilience.
  • Streamline log ingestion pipelines — from parsing to normalization and enrichment.
  • Build scripts and automations (Python, PowerShell) to enhance SOC efficiency.
  • Integrate tools across the SOC stack to enable seamless workflows and response.
Threat Hunting & Incident Response
  • Collaborate with intel and IR teams to enrich detection use cases and support threat hunts.
  • Provide Tier-3+ support for incident investigations and post-mortem analysis.
Mentorship & SOC Maturity
  • Improve SOC playbooks, SOPs, and detection engineering workflows.
  • Stay updated on global and regional threats — and evolve detection accordingly.
  • Ensure compliance alignment (e.g., NCA ECC, SAMA CSF).
Education
  • Bachelor’s in Computer Science, Cybersecurity, or related field.
Experience
  • Minimum 3 years of experience with hands-on expertise in developing and maintaining complex detection use cases.
  • Strong understanding of attacker behavior, IR fundamentals, and digital forensics.
Technical Skills (You’re a Power User!)
  • SIEM: Expert in SIEM queries (SPL, KQL, Lucene), rule tuning, UEBA, and scaling.
  • EDR: Deep knowledge of EDR tools and endpoint detection tactics.
  • Network Security: Pro at packet analysis (Wireshark), IDS/IPS, and NetFlow.
  • Scripting: Advanced skills in Python and/or PowerShell for automation and integration.
  • OS Internals: Mastery of Windows/Linux/macOS logging, artifacts, and forensic value.
  • Threat Intelligence: Skilled in turning threat intel into real-time detection logic.
  • Cloud Security: Strong command of monitoring IaaS/PaaS/SaaS environments.
Certifications (Highly Preferred)
  • SANS GIAC (GDAT, GMON, GCIA, GCTI, GCIH)
  • Offsec (OSDA)
  • INE (eCTHP, eCIR)
  • (ISC)² CISSP, CSSLP
Soft Skills
  • Exceptional analytical thinking and creative problem-solving.
  • Excellent communication (English & Arabic), including technical reporting.
  • Strong mentorship abilities and a collaborative spirit.
  • Self-motivated, focused, and passionate about cyber defense.
  • Capable of juggling priorities under high-pressure situations.

Impact that Matters – Build products that shape the future of cybersecurity and protect organizations globally.

On-Site Collaboration – Be at the heart of innovation in our Almadina office, working side by side with passionate experts.

Continuous Growth – Access to certifications, trainings, and opportunities to sharpen your expertise.

Ownership Mindset – Benefit from our ESOP program and grow with COGNNA’s success.

Culture of Trust – We empower talent, encourage ownership, and celebrate real outcomes.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Threat Detection Engineer: Lead SOC & ESOP
Senior Threat Detection Engineer: Lead SOC & ESOP

COGNNA • As Sudiyah

On-site
OMR 18,000 - 30,000
ESOP program
Certifications and trainings
On-site Almadina office
Senior DFIR Guardian - Madinah
Senior DFIR Guardian - Madinah

COGNNA • As Sudiyah

On-site
OMR 18,000 - 30,000
ESOP program
Certifications & trainings
On-site collaboration at Almadina
Senior Cybersecurity Lead
Senior Cybersecurity Lead

NTG • Muscat

On-site
OMR 20,000 - 30,000
Cyber Defense Specialist — Detection & Monitoring Lead
Cyber Defense Specialist — Detection & Monitoring Lead

cloud consultancy - ccds • As Sudiyah

On-site
OMR 31,000 - 62,000
Senior Specialist SOC
Senior Specialist SOC

Experience • Muscat

On-site
OMR 12,000 - 18,000
OQ8 - Expert, Cybersecurity & GRC
OQ8 - Expert, Cybersecurity & GRC

oq8.om • Muscat

On-site
OMR 30,760 - 46,140
i3 Insider Risk Analyst - Dammam, Saudi Arabia
i3 Insider Risk Analyst - Dammam, Saudi Arabia

DTEX Systems Inc. • As Sudiyah

On-site
OMR 18,000 - 24,000
Cybersecurity Specialist
Cybersecurity Specialist

Al-Qadsiah Club Company • As Sudiyah

On-site
OMR 7,689 - 10,253
Opportunity to shape the future of Saudi sports
Thriving work culture focused on innovation
On-Site Senior Cybersecurity Lead – Sovereign Platform
On-Site Senior Cybersecurity Lead – Sovereign Platform

NTG • Muscat

On-site
OMR 20,000 - 30,000
Channel / Alliances Manager
Channel / Alliances Manager

Cybersecit • As Sudiyah

On-site
OMR 36,000 - 56,000