Senior DFIR Guardian

COGNNA

Riyadh

On-site

SAR 90,000 - 130,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Impact that Matters
On-Site Collaboration
Continuous Growth
Ownership Mindset
Culture of Trust

Job summary

COGNNA is seeking an experienced Digital Forensics and Incident Response (DFIR) professional to own end-to-end investigations across endpoints, cloud, and networks. You will lead a DFIR team, ensure evidence integrity, and extract precise timelines from complex log data.

Ideal candidates bring 3+ years in security investigations, strong English/Arabic communication, and hands-on use of FTK, X-Ways, Cellebrite, and Axiom. AIS tools in investigations are a plus.

Qualifications

  • Bachelor's in Cybersecurity, International Relations, Computer Science, or related field.
  • 3+ years in digital forensics, incident response, or security investigations with leadership or coordination experience.
  • Excellent written and verbal communication in English and Arabic.
  • Hands-on proficiency with forensic tooling: FTK, X-Ways, Cellebrite, Axiom, or equivalent.
  • Strong command of TCP/IP, HTTP/S, DNS and log analysis across SIEM platforms.
  • Scripting in Python/PowerShell/Bash to automate evidence processing.
  • Experience integrating AI tools into investigative workflows.
  • Clear communicator able to brief executives and partner with legal/compliance teams.
  • Compliance with NCA ECC and SAMA CSF requirements.

Responsibilities

  • Own end-to-end forensic investigations across endpoints, cloud, and network infrastructure.
  • Lead the DFIR team across active investigations ensuring consistent methodology and evidence integrity.
  • Pull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateways for precise timelines.
  • Acquire forensic images from laptops, mobiles, servers, and cloud repos with full chain of custody.
  • Analyze artifacts—files, memory, registries, logs, configs—to reconstruct events.
  • Correlate telemetry to map attacker behavior and access patterns.
  • Build AI-assisted workflows to automate evidence collection and timeline generation.
  • Translate findings into clear narratives for executives and cross-functional teams.
  • Close the loop by feeding outcomes back into detection rules and policies.

Skills

Python scripting
OS knowledge
Executive communication
Network log analysis

Education

Bachelor's in Cybersecurity or related field

Tools

FTK
X-Ways
Cellebrite
Axiom

Job description

  • Own end-to-end forensic investigations across endpoints, cloud platforms, and network infrastructure — from initial triage to root cause, including IoC identification, data exfiltration, and unauthorized access
  • Coordinate and lead the DFIR team across active investigations, ensuring consistent methodology, evidence integrity, and investigative velocity
  • Pull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateway platforms to reconstruct precise attack and user activity timelines
  • Acquire forensic images from laptops, mobile devices, servers, and cloud repositories with full chain of custody
  • Go deep on artifacts — file systems, memory, registry, logs, config states — to reconstruct exactly what happened and when
  • Correlate endpoint, network, and identity telemetry into a coherent picture of attacker behavior and system access
  • Build AI-assisted workflows that automate evidence collection, pattern detection, and timeline generation to scale investigative capacity
  • Translate technical findings into clear, chronological narratives for executives and cross-functional stakeholders — no jargon, no ambiguity
  • Close the loop: feed investigation outcomes back into detection rules, access controls, and policy improvements
  • Own end-to-end forensic investigations across endpoints, cloud platforms, and network infrastructure — from initial triage to root cause, including IoC identification, data exfiltration, and unauthorized access
  • Coordinate and lead the DFIR team across active investigations, ensuring consistent methodology, evidence integrity, and investigative velocity
  • Pull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateway platforms to reconstruct precise attack and user activity timelines
  • Acquire forensic images from laptops, mobile devices, servers, and cloud repositories with full chain of custody
  • Go deep on artifacts — file systems, memory, registry, logs, config states — to reconstruct exactly what happened and when
  • Correlate endpoint, network, and identity telemetry into a coherent picture of attacker behavior and system access
  • Build AI-assisted workflows that automate evidence collection, pattern detection, and timeline generation to scale investigative capacity
  • Translate technical findings into clear, chronological narratives for executives and cross-functional stakeholders — no jargon, no ambiguity
  • Close the loop: feed investigation outcomes back into detection rules, access controls, and policy improvements
Requirements
Education
  • Bachelor's in Cybersecurity, International Relations, Computer Science, or related field
Experience
  • 3+ years in digital forensics, incident response, or security investigations, with a track record leading or coordinating DFIR engagements
  • Exceptional written and verbal communication in both English & Arabic
  • Hands-on proficiency with forensic tooling: FTK, X-Ways, Cellebrite, Axiom, or equivalent platforms
  • Strong command of network protocols (TCP/IP, HTTP/S, DNS) and log analysis across SIEM platforms
  • Scripting ability in Python, PowerShell, or Bash — used to automate evidence processing, not just theoretically
  • Deep working knowledge of Windows, macOS, and Linux/Unix environments at the artifact and system level
  • Proven experience integrating AI tools into investigative workflows to accelerate triage, pattern detection, or reporting
  • Clear, confident communicator — able to brief executives and work alongside legal, HR, and compliance teams without losing technical precision
  • Compliance: Ensuring all operations align with NCA ECC and SAMA CSF regulations
Certifications (Highly Preferred)
  • SANS / GIAC (GCFA, GCFE, GNFA, GCIA or similar)
  • IACIS CFCE
  • EC-Council CHFI
  • Offsec (OSDA, OSIR)
Benefits
  • Impact that Matters - Build products that shape the future of cybersecurity and protect organizations globally.
  • On-Site Collaboration - Be at the heart of innovation in our Riyadh office, working side by side with passionate experts.
  • Continuous Growth - Access to certifications, trainings, and opportunities to sharpen your expertise.
  • Ownership Mindset - Benefit from our ESOP program and grow with COGNNA's success.
  • Culture of Trust - We empower talent, encourage ownership, and celebrate real outcomes.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DFIR Guardian
Senior DFIR Guardian

COGNNA • Medina

On-site
SAR 540,000 - 720,000
ESOP program
Certifications & trainings
Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist
Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist

CCDS • Riyadh

On-site
SAR 300,000 - 420,000
Senior DFIR Lead: End-to-End Investigations & AI Workflows
Senior DFIR Lead: End-to-End Investigations & AI Workflows

COGNNA • Riyadh

On-site
SAR 90,000 - 130,000
Impact that Matters
On-Site Collaboration
Continuous Growth
+2
Threat Detection Engineer
Threat Detection Engineer

COGNNA • Medina

On-site
SAR 1,000,000 - 1,800,000
ESOP program
On-site Almadina office
Certifications support
Senior DFIR Lead: End-to-End Forensics & AI Workflows
Senior DFIR Lead: End-to-End Forensics & AI Workflows

COGNNA • Medina

On-site
SAR 540,000 - 720,000
ESOP program
Certifications & trainings
Threat Detection Engineer - L2
Threat Detection Engineer - L2

COGNNA • Medina

On-site
SAR 180,000 - 240,000
ESOP program
SOC Manager
SOC Manager

Managed Services • Riyadh

On-site
SAR 240,000 - 360,000
SOC Manager
SOC Manager

Managed • Riyadh

On-site
SAR 240,000 - 360,000
Saudi Arabia Cybersecurity, Threat Intelligence & Fraud Protection Manager, Unified Cybersecurity Services
Saudi Arabia Cybersecurity, Threat Intelligence & Fraud Protection Manager, Unified Cybersecurity Services

Group-IB • Saudi Arabia

On-site
SAR 240,000 - 380,000
Cybersecurity GRC Specialist(Saudi National only)
Cybersecurity GRC Specialist(Saudi National only)

sifiapp • Riyadh

On-site
SAR 120,000 - 190,000