Senior Threat Detection Engineer

COGNNA

Medina

On-site

SAR 180,000 - 300,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

ESOP program
On-site Almadina office
Certifications & trainings
Ownership culture

Job summary

COGNNA in Almadina is seeking a Threat Detection Engineer to design high-impact detection strategies, build automation, and elevate SOC operations. You will mentor rising cyber talent and collaborate with threat intel, incident response, and platform engineering teams.

The role focuses on building high-fidelity detections, translating attacker techniques into actionable logic, and advancing SOC maturity. Fluency in English and Arabic is valued for cross-team collaboration.

Qualifications

  • Bachelor's in Computer Science, Cybersecurity, or related field.

Responsibilities

  • Design high-impact detection strategies and automate detection testing.
  • Build correlation rules and behavioral detections within COGNNA security platforms.
  • Lead platform engineering for XDR, SIEM, and SOC stacks.
  • Mentor junior team members and collaborate with threat intel, IR, and platform engineering teams.
  • Stay updated on global and regional threats and ensure compliance alignment.

Skills

SIEM
EDR
Network security
Scripting (Python/PowerShell)
OS internals
Threat intelligence
Cloud security

Education

Bachelor's in Computer Science, Cybersecurity, or related field

Job description

As a Threat Detection Engineer at COGNNA, you'll design high-impact detection strategies, build powerful automation, and elevate SOC operations to a world-class standard. You'll also mentor rising cyber talent and collaborate with teams across threat intel, incident response, and platform engineering.

Advanced Threat Detection Engineering
  • Build high-fidelity correlation rules and behavioral detections within the COGNNA security platforms
  • Translate adversary TTPs (MITRE ATT&CK), threat intel, and vulnerability data into actionable logic
  • Identify detection gaps and introduce new data sources to cover evolving threat landscapes
  • Automate detection testing and maintain detection quality over time
Platform Engineering & Optimization
  • Lead architecture and optimization of XDR, SIEM, and SOC tech stacks for scale and resilience
  • Streamline log ingestion pipelines — from parsing to normalization and enrichment
  • Build scripts and automations (Python, PowerShell) to enhance SOC efficiency
  • Integrate tools across the SOC stack to enable seamless workflows and response.
Threat Hunting & Incident Response
  • Collaborate with intel and IR teams to enrich detection use cases and support threat hunts
  • Provide Tier-3+ support for incident investigations and post-mortem analysis
Mentorship & SOC Maturity
  • Improve SOC playbooks, SOPs, and detection engineering workflows
  • Stay updated on global and regional threats — and evolve detection accordingly
  • Ensure compliance alignment (e.g., NCA ECC, SAMA CSF)
Requirements
Education
  • Bachelor's in Computer Science, Cybersecurity, or related field.
Experience
  • Minimum 3 years of experience with hands–on expertise in developing and maintaining complex detection use cases
  • Strong understanding of attacker behavior, IR fundamentals, and digital forensics.
Technical Skills (You're a Power User!)
  • SIEM: Expert in SIEM queries (SPL, KQL, Lucene), rule tuning, UEBA, and scaling
  • EDR: Deep knowledge of EDR tools and endpoint detection tactics
  • Network Security: Pro at packet analysis (Wireshark), IDS/IPS, and NetFlow
  • Scripting: Advanced skills in Python and/or PowerShell for automation and integration
  • OS Internals: Mastery of Windows/Linux/macOS logging, artifacts, and forensic value
  • Threat Intelligence: Skilled in turning threat intel into real-time detection logic
  • Cloud Security: Strong command of monitoring IaaS/PaaS/SaaS environments
Certifications (Highly Preferred)
  • SANS GIAC (GDAT, GMON, GCIA, GCTI, GCIH)
  • Offsec (OSDA)
  • INE (eCTHP, eCIR)
  • (ISC)² CISSP, CSSLP
Soft Skills
  • Exceptional analytical thinking and creative problem-solving
  • Excellent communication (English & Arabic), including technical reporting
  • Strong mentorship abilities and a collaborative spirit
  • Self-motivated, focused, and passionate about cyber defense
  • Capable of juggling priorities under high-pressure situations
Benefits
  • Impact that Matters - Build products that shape the future of cybersecurity and protect organizations globally.
  • On-Site Collaboration - Be at the heart of innovation in our Almadina office, working side by side with passionate experts.
  • Continuous Growth - Access to certifications, trainings, and opportunities to sharpen your expertise.
  • Ownership Mindset - Benefit from our ESOP program and grow with COGNNA's success.
  • Culture of Trust - We empower talent, encourage ownership, and celebrate real outcomes.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Threat Detection Engineer
Senior Threat Detection Engineer

COGNNA • Medina Province

On-site
SAR 180,000 - 300,000
ESOP program
Certifications & trainings
Growth opportunities
Threat Detection Engineer
Threat Detection Engineer

COGNNA • Medina

On-site
SAR 1,000,000 - 1,800,000
ESOP program
On-site Almadina office
Certifications support
Threat Detection - COOP
Threat Detection - COOP

COGNNA • Medina

On-site
SAR 45,000 - 76,000
Senior Threat Detection Engineer — SIEM/EDR Automation Leader
Senior Threat Detection Engineer — SIEM/EDR Automation Leader

COGNNA • Medina

On-site
SAR 180,000 - 300,000
ESOP program
On-site Almadina office
Certifications & trainings
+1
Senior Threat Detection Engineer — SOC Leadership (ESOP)
Senior Threat Detection Engineer — SOC Leadership (ESOP)

COGNNA • Medina Province

On-site
SAR 180,000 - 300,000
ESOP program
Certifications & trainings
Growth opportunities
Senior DFIR Guardian
Senior DFIR Guardian

COGNNA • Riyadh

On-site
SAR 250,000 - 360,000
ESOP program
Certifications and trainings
On-site collaboration
Senior DFIR Guardian
Senior DFIR Guardian

COGNNA • Medina

On-site
SAR 540,000 - 720,000
ESOP program
Certifications & trainings
Threat Detection Co-op: Build, Automate, Impact SOC
Threat Detection Co-op: Build, Automate, Impact SOC

COGNNA • Medina

On-site
SAR 45,000 - 76,000
SOC Manager
SOC Manager

Managed Services • Riyadh

On-site
SAR 240,000 - 360,000
SOC Manager
SOC Manager

Managed • Riyadh

On-site
SAR 240,000 - 360,000