Senior DFIR Guardian

🏢 COGNNA
📍 Riyadh, Saudi ArabiaFull-timeOn-site
📅 Posted: 2w ago🔄 Updated: 2w ago
CV%
✨ AI Summary
The Senior DFIR Guardian is responsible for leading end-to-end forensic investigations across endpoints, cloud, and network infrastructure. This role involves coordinating the DFIR team, ensuring evidence integrity, and analyzing logs from various security platforms to reconstruct attack timelines. The position requires hands-on acquisition of forensic images and deep artifact analysis. A key aspect is building AI-assisted workflows to automate evidence collection and analysis. The role also demands translating technical findings into clear narratives for executives and stakeholders, and feeding outcomes back into security improvements. Requirements include a Bachelor's degree in Cybersecurity, International Relations, or Computer Science, and 3+ years of experience in digital forensics, incident response, or security investigations. Exceptional communication skills in English and Arabic are mandatory, along with proficiency in forensic tooling, network protocols, log analysis, and scripting (Python, PowerShell, Bash). Deep working knowledge of Windows, macOS, and Linux/Unix environments, and experience with AI tools in investigations are also required. Compliance with NCA ECC and SAMA CSF regulations is a must.
Required Skills
Other
digital forensicsFTKX-WaysCellebriteAxiomHTTP/SBashNCA ECCSAMA CSF
Information Technology
Incident ResponseTCP/IPDNSSIEMPythonPowerShellWindows ServermacOSLinuxGenerative AI
Soft Skills & Professional Competencies
Communication
🎁 Benefits & Perks

🚀 Impact that Matters – Build products that shape the future of cybersecurity and protect organizations globally.

🏢 On-Site Collaboration – Be at the heart of innovation in our Riyadh office, working side by side with passionate experts.

💡 Continuous Growth – Access to certifications, trainings, and opportunities to sharpen your expertise.

📈 Ownership Mindset – Benefit from our ESOP program and grow with COGNNA’s success.

🤝 Culture of Trust – We empower talent, encourage ownership, and celebrate real outcomes.

Requirements
🎓 EducationBachelor’s in Cybersecurity, International Relations, Computer Science, or related field.💼 Experience3+ years in digital forensics, incident response, or security investigations, with a track record leading or coordinating DFIR engagementsExceptional written and verbal communication in both English & Arabic.Hands-on proficiency with forensic tooling: FTK, X-Ways, Cellebrite, Axiom, or equivalent platformsStrong command of network protocols (TCP/IP, HTTP/S, DNS) and log analysis across SIEM platformsScripting ability in Python, PowerShell, or Bash — used to automate evidence processing, not just theoreticallyDeep working knowledge of Windows, macOS, and Linux/Unix environments at the artifact and system levelProven experience integrating AI tools into investigative workflows to accelerate triage, pattern detection, or reportingClear, confident communicator — able to brief executives and work alongside legal, HR, and compliance teams without losing technical precisionCompliance: Ensuring all operations align with NCA ECC and SAMA CSF regulations.🏅 Certifications (Highly Preferred)SANS / GIAC (GCFA, GCFE, GNFA, GCIA or similar)IACIS CFCEEC-Council CHFIOffsec (OSDA, OSIR)
Description
Own end-to-end forensic investigations across endpoints, cloud platforms, and network infrastructure — from initial triage to root cause, including IoC identification, data exfiltration, and unauthorized accessCoordinate and lead the DFIR team across active investigations, ensuring consistent methodology, evidence integrity, and investigative velocityPull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateway platforms to reconstruct precise attack and user activity timelinesAcquire forensic images from laptops, mobile devices, servers, and cloud repositories with full chain of custodyGo deep on artifacts — file systems, memory, registry, logs, config states — to reconstruct exactly what happened and whenCorrelate endpoint, network, and identity telemetry into a coherent picture of attacker behavior and system accessBuild AI-assisted workflows that automate evidence collection, pattern detection, and timeline generation to scale investigative capacityTranslate technical findings into clear, chronological narratives for executives and cross-functional stakeholders — no jargon, no ambiguityClose the loop: feed investigation outcomes back into detection rules, access controls, and policy improvements.
✨ Premium Match Details
Deep-dive CV analysis, customized Cover Letters, and Interview prep!
📊 Match Analysis
Insights against your active CV
📊
Personalized Match Analysis
Upload your CV to see exact matching percentages, detailed skills mapping, and gap analysis for this role.
🎯 Overalli74%
⚡ Skillsi85%
View Breakdown
Ontology Match: 85.0
Matched:✓ Requirements Matching✓ Ontology Skills Mapping
📜 Eligibilityi49%
View Breakdown
Local: 19600%
🏗️ Career Fiti91%
View Breakdown
Seniority: 91.0
📋 Requirementsi67%
View Breakdown
Domain: 67.0
🔥 Motivationi78%
View Breakdown
Title Fit: 78.00