Threat Detection Engineer - L2

🏢 COGNNA
📍 Madinah, Saudi ArabiaFull-timeOn-site
📅 Posted: Today🔄 Updated: Today
CV%
✨ AI Summary
COGNNA is seeking a Threat Detection Engineer (L2) to design advanced detection strategies, build automation, and enhance SOC operations. This role involves creating high-fidelity detection rules, translating adversary TTPs into actionable logic, and identifying detection gaps. The engineer will also lead the architecture and optimization of XDR, SIEM, and SOC tech stacks, streamline log ingestion, and build automation scripts using Python and PowerShell. Collaboration with threat intelligence and incident response teams, providing Tier-3+ support, and improving SOC maturity are key responsibilities. The position requires a Bachelor's degree in Computer Science or Cybersecurity, a minimum of 3 years of experience in detection use case development, and strong technical skills in SIEM, EDR, network security, scripting, OS internals, threat intelligence, and cloud security. Excellent analytical, communication, and mentorship skills are also essential.
Required Skills
Information Technology
SIEMEDRWiresharkIDS/IPSPythonPowerShellLoggingIaaSMonitoringSaaSTechnical Documentation
Other
SPLKQLLucenerule tuningUEBAendpoint detection tacticspacket analysisNetFlowthreat intel analysiscyber defense passionpriority juggling
Soft Skills & Professional Competencies
Analytical SkillsProblem SolvingCollaborationSelf-Motivation
Business, Sales & Management
Mentoring
Nice to have:
Information Technology
SIEMScriptingAI IntegrationThreat HuntingIncident Response
Other
log ingestion pipelineslog parsinglog normalizationlog enrichmentdigital forensics analysisSOC playbooksdetection engineering workflows
Operations, Logistics & Supply Chain
SOPs
Finance, Legal & Governance
HR Compliance
🎁 Benefits & Perks

🚀 Impact that Matters – Build products that shape the future of cybersecurity and protect organizations globally.

🏢 On-Site Collaboration – Be at the heart of innovation in our Almadina office, working side by side with passionate experts.

💡 Continuous Growth – Access to certifications, trainings, and opportunities to sharpen your expertise.

📈 Ownership Mindset – Benefit from our ESOP program and grow with COGNNA’s success.

🤝 Culture of Trust – We empower talent, encourage ownership, and celebrate real outcomes.

Requirements
🎓 EducationBachelor’s in Computer Science, Cybersecurity, or related field. 💼 ExperienceMinimum 3 years of experience with hands-on expertise in developing and maintaining complex detection use cases.Strong understanding of attacker behavior, IR fundamentals, and digital forensics. 🔧 Technical Skills (You’re a Power User!)SIEM: Expert in SIEM queries (SPL, KQL, Lucene), rule tuning, UEBA, and scaling.EDR: Deep knowledge of EDR tools and endpoint detection tactics.Network Security: Pro at packet analysis (Wireshark), IDS/IPS, and NetFlow.Scripting: Advanced skills in Python and/or PowerShell for automation and integration.OS Internals: Mastery of Windows/Linux/macOS logging, artifacts, and forensic value.Threat Intelligence: Skilled in turning threat intel into real-time detection logic.Cloud Security: Strong command of monitoring IaaS/PaaS/SaaS environments.🏅 Certifications (Highly Preferred)🎓 SANS GIAC (GDAT, GMON, GCIA, GCTI, GCIH)🐉 Offsec (OSDA)🏫 INE (eCTHP, eCIR)🧩 (ISC)² CISSP, CSSLP 🤝 Soft SkillsExceptional analytical thinking and creative problem-solving.Excellent communication (English & Arabic), including technical reporting.Strong mentorship abilities and a collaborative spirit.Self-motivated, focused, and passionate about cyber defense.Capable of juggling priorities under high-pressure situations.
Description
As a Threat Detection Engineer at COGNNA, you’ll design high-impact detection strategies, build powerful automation, and elevate SOC operations to a world-class standard. You’ll also mentor rising cyber talent and collaborate with teams across threat intel, incident response, and platform engineering.🔐 Advanced Threat Detection EngineeringBuild high-fidelity correlation rules and behavioral detections within the COGNNA security platforms.Translate adversary TTPs (MITRE ATT&CK), threat intel, and vulnerability data into actionable logic.Identify detection gaps and introduce new data sources to cover evolving threat landscapes.Automate detection testing and maintain detection quality over time.⚙️ Platform Engineering & OptimizationLead architecture and optimization of XDR, SIEM, and SOC tech stacks for scale and resilience.Streamline log ingestion pipelines — from parsing to normalization and enrichment.Build scripts and automations (Python, PowerShell) to enhance SOC efficiency.Integrate tools across the SOC stack to enable seamless workflows and response. 🕵️‍♂️ Threat Hunting & Incident ResponseCollaborate with intel and IR teams to enrich detection use cases and support threat hunts.Provide Tier-3+ support for incident investigations and post-mortem analysis.👥 Mentorship & SOC MaturityImprove SOC playbooks, SOPs, and detection engineering workflows.Stay updated on global and regional threats — and evolve detection accordingly.Ensure compliance alignment (e.g., NCA ECC, SAMA CSF).
✨ Premium Match Details
Deep-dive CV analysis, customized Cover Letters, and Interview prep!
📊 Match Analysis
Insights against your active CV
📊
Personalized Match Analysis
Upload your CV to see exact matching percentages, detailed skills mapping, and gap analysis for this role.
🎯 Overalli74%
⚡ Skillsi85%
View Breakdown
Ontology Match: 85.0
Matched:✓ Requirements Matching✓ Ontology Skills Mapping
📜 Eligibilityi49%
View Breakdown
Local: 19600%
🏗️ Career Fiti91%
View Breakdown
Seniority: 91.0
📋 Requirementsi67%
View Breakdown
Domain: 67.0
🔥 Motivationi78%
View Breakdown
Title Fit: 78.00