Threat Detection - COOP

COGNNA

Medina

On-site

SAR 45,000 - 76,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

COGNNA seeks a Threat Detection COOP to design high-impact detection strategies and automation, elevating SOC operations. You will mentor rising cyber talent and collaborate with threat intel, IR, and platform engineering.

Responsibilities include building high-fidelity detection rules, translating adversary data into actionable logic, and automating detection testing while improving SOC maturity and compliance alignment.

Qualifications

  • Enrolled in final year of a Bachelor's degree in CS, cybersecurity or IT with graduation planned within 6 months.
  • Foundational cybersecurity knowledge including attack vectors and OS internals.
  • Familiarity with writing simple scripts in Python or PowerShell to automate tasks.
  • Basic understanding of logs (Windows Event Logs, Syslog) and data collection concepts.
  • Commitment to a full-time (or near full-time) 6-month co-op.

Responsibilities

  • Design high-impact threat detection strategies and correlations.
  • Translate MITRE ATT&CK, threat intel, and vulnerability data into logic.
  • Lead platform engineering efforts to optimize SOC tech stacks.
  • Mentor rising cyber talent and collaborate across teams.

Skills

Basic cybersecurity concepts
Scripting basics

Education

Bachelor’s degree in Computer Science or related field (final year)

Tools

Python
PowerShell

Job description

As a Threat Detection COOP at COGNNA, you’ll design high-impact detection strategies, build powerful automation, and elevate SOC operations to a world-class standard. You’ll also mentor rising cyber talent and collaborate with teams across threat intel, incident response, and platform engineering.

Advanced Threat Detection Engineering
  • Build high-fidelity correlation rules and behavioral detections within the COGNNA security platforms.
  • Translate adversary TTPs (MITRE ATT&CK), threat intel, and vulnerability data into actionable logic.
  • Identify detection gaps and introduce new data sources to cover evolving threat landscapes.
  • Automate detection testing and maintain detection quality over time.
Platform Engineering & Optimization
  • Lead architecture and optimization of XDR, SIEM, and SOC tech stacks for scale and resilience.
  • Streamline log ingestion pipelines — from parsing to normalization and enrichment.
  • Build scripts and automations (Python, PowerShell) to enhance SOC efficiency.
  • Integrate tools across the SOC stack to enable seamless workflows and response.
Threat Hunting & Incident Response
  • Collaborate with intel and IR teams to enrich detection use cases and support threat hunts.
  • Provide Tier-3+ support for incident investigations and post-mortem analysis.
Mentorship & SOC Maturity
  • Improve SOC playbooks, SOPs, and detection engineering workflows.
  • Stay updated on global and regional threats — and evolve detection accordingly.
  • Ensure compliance alignment (e.g., NCA ECC, SAMA CSF).
Minimum Requirements (Must Haves):
  • Education: Currently enrolled in their final year of a Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a closely related field, with graduation planned within or immediately following the 6-month co-op.
  • Foundational Security Knowledge: Basic understanding of cybersecurity concepts, including common attack vectors, the Windows/Linux operating system internals, and network protocols.
  • Programming/Scripting Basics: Familiarity with writing simple scripts in Python or PowerShell to automate repetitive tasks or parse data.
  • Log & System Familiarity: Basic understanding of what logs are (e.g., Windows Event Logs, Syslog) and an interest in how they are collected and analyzed.
  • Duration: Availability to commit to a full-time (or near full-time, depending on university rules) 6-month continuous Co-op assignment.
Preferred Qualifications (Nice to Haves / Big Plusses):
  • Framework Familiarity: Conceptual knowledge of the MITRE ATT&CK framework and how it maps to adversary behaviors.
  • Hands-on Exposure: Previous experience using SIEM/XDR platforms, or building a home lab (e.g., Splunk, Elastic, Wireshark).
  • Regulatory Awareness: A general awareness of cybersecurity frameworks or local compliance standards (like NCA ECC or SAMA CSF).
  • Soft Skills: Strong analytical mindset, a high level of curiosity to dig into threat trends, and excellent written documentation skills.

Impact that Matters – Build products that shape the future of cybersecurity and protect organizations globally.

On-Site Collaboration – Be at the heart of innovation in our Almadina office, working side by side with passionate experts.

Continuous Growth – Access to certifications, trainings, and opportunities to sharpen your expertise.

Culture of Trust – We empower talent, encourage ownership, and celebrate real outcomes.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Detection Engineer
Threat Detection Engineer

COGNNA • Medina

On-site
SAR 1,000,000 - 1,800,000
ESOP program
On-site Almadina office
Certifications support
Threat Detection Co-op: Build, Automate, Impact SOC
Threat Detection Co-op: Build, Automate, Impact SOC

COGNNA • Medina

On-site
SAR 45,000 - 76,000
Cybersecurity Threat Monitoring and Response Analyst
Cybersecurity Threat Monitoring and Response Analyst

Jobs for Humanity • Riyadh

On-site
SAR 167,000 - 279,000
Senior DFIR Guardian
Senior DFIR Guardian

COGNNA • Riyadh

On-site
SAR 90,000 - 130,000
Impact that Matters
On-Site Collaboration
Continuous Growth
+2
Senior DFIR Guardian
Senior DFIR Guardian

COGNNA • Medina

On-site
SAR 540,000 - 720,000
ESOP program
Certifications & trainings
Cyber Defense Specialist - Detection & Monitoring
Cyber Defense Specialist - Detection & Monitoring

CCDS • Riyadh

On-site
SAR 268,000 - 469,000
Intern Cybersecurity Engineer
Intern Cybersecurity Engineer

Managed.sa • Riyadh

On-site
SAR 56,000 - 113,000
Mentorship from experienced professionals
Real-world experience with industry tools
Potential pathway to full-time opportunities
Senior Cyber Defense: Detection & Monitoring Expert
Senior Cyber Defense: Detection & Monitoring Expert

CCDS • Riyadh

On-site
SAR 268,000 - 469,000
SOC Manager
SOC Manager

Managed • Riyadh

On-site
SAR 240,000 - 360,000
SOC Manager
SOC Manager

Managed Services • Riyadh

On-site
SAR 240,000 - 360,000