Staff DFIR - COGNNA

🏢 COGNNA
📍 Riyadh, Saudi ArabiaFull-timeOn-site
📅 Posted: 1mo ago🔄 Updated: 1mo ago
CV%
✨ AI Summary
COGNNA is seeking a Staff DFIR professional to lead end-to-end forensic investigations across various platforms. Responsibilities include coordinating the DFIR team, analyzing logs, acquiring forensic images, and reconstructing attack timelines. The role involves building AI-assisted workflows to automate evidence collection and translating technical findings into clear narratives for stakeholders. A key aspect is feeding investigation outcomes back into security improvements. The position requires a Bachelor's degree, 5+ years of relevant experience, and exceptional communication skills in English and Arabic.
Required Skills
Other
digital forensicsFTKX-WaysCellebriteAxiomHTTP/SBashUnixpattern detectiontimeline generationhandling priorities
Information Technology
Incident ResponseTCP/IPDNSSIEMPythonPowerShellWindows ServermacOSLinuxAI IntegrationTechnical Documentation
Finance, Legal & Governance
Investigations
Hospitality, Retail & Customer Service
Collections
Soft Skills & Professional Competencies
Analytical SkillsProblem SolvingCommunicationCollaborationSelf-Motivation
Business, Sales & Management
Mentoring
Nice to have:
Finance, Legal & Governance
HR Compliance
🎁 Benefits & Perks

🚀 Impact that Matters – Build products that shape the future of cybersecurity and protect organizations globally.

🏢 On-Site Collaboration – Be at the heart of innovation in our Riyadh office, working side by side with passionate experts.

💡 Continuous Growth – Access to certifications, trainings, and opportunities to sharpen your expertise.

📈 Ownership Mindset – Benefit from our ESOP program and grow with COGNNA’s success.

🤝 Culture of Trust – We empower talent, encourage ownership, and celebrate real outcomes.

Requirements
🎓 Education & ExperienceBachelor’s in Cybersecurity, International Relations, Computer Science, or related field.5+ years in digital forensics, incident response, or security investigations, with a track record leading or coordinating DFIR engagementsExceptional written and verbal communication in both English & Arabic.Hands-on proficiency with forensic tooling: FTK, X-Ways, Cellebrite, Axiom, or equivalent platformsStrong command of network protocols (TCP/IP, HTTP/S, DNS) and log analysis across SIEM platformsScripting ability in Python, PowerShell, or Bash — used to automate evidence processing, not just theoreticallyDeep working knowledge of Windows, macOS, and Linux/Unix environments at the artifact and system levelProven experience integrating AI tools into investigative workflows to accelerate triage, pattern detection, or reportingClear, confident communicator — able to brief executives and work alongside legal, HR, and compliance teams without losing technical precisionCompliance: Ensuring all operations align with NCA ECC and SAMA CSF regulations.Previous leadership experience is a must.🏅 Certifications (Highly Preferred)SANS / GIAC (GCFA, GCFE, GNFA, GCIA or similar)IACIS CFCEEC-Council CHFIOffsec (OSDA, OSIR) 🤝 Soft SkillsExceptional analytical thinking and creative problem-solving.Excellent communication (English & Arabic), including technical reporting.Strong mentorship abilities and a collaborative spirit.Self-motivated, focused, and passionate about cyber defense.Capable of juggling priorities under high-pressure situations.
Description
🔍 Who We AreCOGNNA is shaping the future of cybersecurity through innovation, intelligence, and a relentless drive to protect. Our platforms integrate cutting-edge AI, real-time threat detection, and deep security insights to help organizations proactively defend against evolving cyber threats.ResponsibilitiesOwn end-to-end forensic investigations across endpoints, cloud platforms, and network infrastructure — from initial triage to root cause, including IoC identification, data exfiltration, and unauthorized accessCoordinate and lead the DFIR team across active investigations, ensuring consistent methodology, evidence integrity, and investigative velocityPull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateway platforms to reconstruct precise attack and user activity timelinesAcquire forensic images from laptops, mobile devices, servers, and cloud repositories with full chain of custodyGo deep on artifacts — file systems, memory, registry, logs, config states — to reconstruct exactly what happened and whenCorrelate endpoint, network, and identity telemetry into a coherent picture of attacker behavior and system accessBuild AI-assisted workflows that automate evidence collection, pattern detection, and timeline generation to scale investigative capacityTranslate technical findings into clear, chronological narratives for executives and cross-functional stakeholders — no jargon, no ambiguityClose the loop: feed investigation outcomes back into detection rules, access controls, and policy improvements.
✨ Premium Match Details
Deep-dive CV analysis, customized Cover Letters, and Interview prep!
📊 Match Analysis
Insights against your active CV
📊
Personalized Match Analysis
Upload your CV to see exact matching percentages, detailed skills mapping, and gap analysis for this role.
🎯 Overalli74%
⚡ Skillsi85%
View Breakdown
Ontology Match: 85.0
Matched:✓ Requirements Matching✓ Ontology Skills Mapping
📜 Eligibilityi49%
View Breakdown
Local: 19600%
🏗️ Career Fiti91%
View Breakdown
Seniority: 91.0
📋 Requirementsi67%
View Breakdown
Domain: 67.0
🔥 Motivationi78%
View Breakdown
Title Fit: 78.00