Senior DFIR Guardian - Madinah

COGNNA

Medina

On-site

SAR 240,000 - 360,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Impact-driven work
On-site collaboration in Almadina
Certifications & growth
ESOP program

Job summary

COGNNA in Medina, Saudi Arabia is seeking a Senior DFIR Investigator to lead end-to-end digital forensics engagements across endpoints, cloud, and networks. You will coordinate the DFIR team, ensure evidence integrity, and drive investigative velocity.

You will pull logs from EDR/XDR, SIEM, DLP, IdP, and email gateways, acquire forensic images, and translate findings into clear narratives for executives. On-site collaboration and growth opportunities are offered.

Qualifications

  • Bachelor’s degree in a related field like Cybersecurity, Computer Science, or Information Security.
  • 5+ years in digital forensics, incident response, or security investigations with leadership/coordination experience.
  • Excellent written and verbal communication in English and Arabic.
  • Hands-on proficiency with forensic tooling (FTK, X-Ways, Cellebrite, Axiom).
  • Strong knowledge of Windows, macOS, Linux artifacts and network log analysis.

Responsibilities

  • Lead end-to-end DFIR investigations across endpoints, cloud, and network infrastructure.
  • Coordinate and oversee the DFIR team to ensure evidence integrity and investigative velocity.
  • Pull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateways for precise timelines.
  • Acquire forensic images from devices and cloud repositories with full chain of custody.
  • Analyze artifacts (file systems, memory, registry, logs) to reconstruct events, times, and attacker behavior.
  • Translate technical findings into clear executive narratives and cross-functional updates.

Skills

DFIR leadership
Forensic tooling FTK
Python/Powershell/Bash
English & Arabic communication
Windows/macOS/Linux artifacts

Education

Bachelor’s in Cybersecurity
Bachelor’s in Computer Science
Bachelor’s in Information Security

Tools

FTK
X-Ways
Cellebrite
Axiom

Job description

  • Own end-to-end forensic investigations across endpoints, cloud platforms, and network infrastructure — from initial triage to root cause, including IoC identification, data exfiltration, and unauthorized access
  • Coordinate and lead the DFIR team across active investigations, ensuring consistent methodology, evidence integrity, and investigative velocity
  • Pull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateway platforms to reconstruct precise attack and user activity timelines
  • Acquire forensic images from laptops, mobile devices, servers, and cloud repositories with full chain of custody
  • Go deep on artifacts — file systems, memory, registry, logs, config states — to reconstruct exactly what happened and when
  • Correlate endpoint, network, and identity telemetry into a coherent picture of attacker behavior and system access
  • Build AI-assisted workflows that automate evidence collection, pattern detection, and timeline generation to scale investigative capacity
  • Translate technical findings into clear, chronological narratives for executives and cross-functional stakeholders — no jargon, no ambiguity
  • Close the loop: feed investigation outcomes back into detection rules, access controls, and policy improvements.
Education
  • Bachelor’s in Cybersecurity, International Relations, Computer Science, or related field.
Experience
  • 5+ years in digital forensics, incident response, or security investigations, with a track record leading or coordinating DFIR engagements
  • Exceptional written and verbal communication in both English & Arabic.
  • Hands-on proficiency with forensic tooling: FTK, X-Ways, Cellebrite, Axiom, or equivalent platforms
  • Strong command of network protocols (TCP/IP, HTTP/S, DNS) and log analysis across SIEM platforms
  • Scripting ability in Python, PowerShell, or Bash — used to automate evidence processing, not just theoretically
  • Deep working knowledge of Windows, macOS, and Linux/Unix environments at the artifact and system level
  • Proven experience integrating AI tools into investigative workflows to accelerate triage, pattern detection, or reporting
  • Clear, confident communicator — able to brief executives and work alongside legal, HR, and compliance teams without losing technical precision
  • Compliance: Ensuring all operations align with NCA ECC and SAMA CSF regulations.
  • Saudi nationality is required
Certifications (Highly Preferred)
  • SANS / GIAC (GCFA, GCFE, GNFA, GCIA or similar)
  • IACIS CFCE
  • EC-Council CHFI
  • Offsec (OSDA, OSIR)

Impact that Matters – Build products that shape the future of cybersecurity and protect organizations globally.

On-Site Collaboration – Be at the heart of innovation in our Almadina office, working side by side with passionate experts.

Continuous Growth – Access to certifications, trainings, and opportunities to sharpen your expertise.

Ownership Mindset – Benefit from our ESOP program and grow with COGNNA’s success.

Culture of Trust – We empower talent, encourage ownership, and celebrate real outcomes.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Assistant Manager - Digital Forensics and Incident Response
Assistant Manager - Digital Forensics and Incident Response

Red Sea Global • Riyadh

On-site
SAR 600,000 - 1,000,000
Senior Threat Detection Engineer - Madinah
Senior Threat Detection Engineer - Madinah

COGNNA • Medina

On-site
SAR 240,000 - 400,000
ESOP program
On-site Almadina office
DFIR Lead: End-to-End Investigations & AI Workflows
DFIR Lead: End-to-End Investigations & AI Workflows

COGNNA • Medina

On-site
SAR 240,000 - 360,000
Impact-driven work
On-site collaboration in Almadina
Certifications & growth
+1
Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist
Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist

cloud consultancy - ccds • Saudi Arabia

On-site
OMR 31,000 - 43,000
Senior Threat Detection Engineer
Senior Threat Detection Engineer

COGNNA • Medina Province

On-site
SAR 180,000 - 320,000
ESOP program
Regional Technical Lead DFIR
Regional Technical Lead DFIR

Group-IB • Riyadh

On-site
SAR 400,000 - 650,000
Funding for professionalCertifications
Global opportunities across Group-IB's
Career growth in DFIR leadership
SOC Manager
SOC Manager

Managed • Riyadh

On-site
SAR 240,000 - 360,000
SOC Manager
SOC Manager

Managed Services • Riyadh

On-site
SAR 240,000 - 360,000
Senior Cybersecurity Engineer | Global Technologies GT – التقنيات العالمية | Riyadh, Saudi Arabia
Senior Cybersecurity Engineer | Global Technologies GT – التقنيات العالمية | Riyadh, Saudi Arabia

Global Technologies GT - التقنيات العالمية • Riyadh

On-site
SAR 200,000 - 360,000
Cybersecurity GRC Specialist(Saudi National only)
Cybersecurity GRC Specialist(Saudi National only)

sifiapp • Riyadh

On-site
SAR 120,000 - 190,000