Senior DFIR Guardian - Madinah
AI Summary
Lead end-to-end digital forensic investigations across endpoints, cloud, and network infrastructure, coordinating the DFIR team to identify root causes, preserve evidence integrity, and translate technical findings into clear executive narratives.
About this role
- Own end-to-end forensic investigations across endpoints, cloud platforms, and network infrastructure β from initial triage to root cause, including IoC identification, data exfiltration, and unauthorized access
- Coordinate and lead the DFIR team across active investigations, ensuring consistent methodology, evidence integrity, and investigative velocity
- Pull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateway platforms to reconstruct precise attack and user activity timelines
- Acquire forensic images from laptops, mobile devices, servers, and cloud repositories with full chain of custody
- Go deep on artifacts β file systems, memory, registry, logs, config states β to reconstruct exactly what happened and when
- Correlate endpoint, network, and identity telemetry into a coherent picture of attacker behavior and system access
- Build AI-assisted workflows that automate evidence collection, pattern detection, and timeline generation to scale investigative capacity
- Translate technical findings into clear, chronological narratives for executives and cross-functional stakeholders β no jargon, no ambiguity
- Close the loop: feed investigation outcomes back into detection rules, access controls, and policy improvements.
Requirements
π Education
- Bachelorβs in Cybersecurity, International Relations, Computer Science, or related field.
πΌ Experience
- 5+ years in digital forensics, incident response, or security investigations, with a track record leading or coordinating DFIR engagements
- Exceptional written and verbal communication in both English & Arabic.
- Hands-on proficiency with forensic tooling: FTK, X-Ways, Cellebrite, Axiom, or equivalent platforms
- Strong command of network protocols (TCP/IP, HTTP/S, DNS) and log analysis across SIEM platforms
- Scripting ability in Python, PowerShell, or Bash β used to automate evidence processing, not just theoretically
- Deep working knowledge of Windows, macOS, and Linux/Unix environments at the artifact and system level
- Proven experience integrating AI tools into investigative workflows to accelerate triage, pattern detection, or reporting
- Clear, confident communicator β able to brief executives and work alongside legal, HR, and compliance teams without losing technical precision
- Compliance: Ensuring all operations align with NCA ECC and SAMA CSF regulations.
- Saudi nationality is required
π Certifications (Highly Preferred)
- SANS / GIAC (GCFA, GCFE, GNFA, GCIA or similar)
- IACIS CFCE
- EC-Council CHFI
- Offsec (OSDA, OSIR)
Benefits
π Impact that Matters β Build products that shape the future of cybersecurity and protect organizations globally.
π’ On-Site Collaboration β Be at the heart of innovation in our Almadina office, working side by side with passionate experts.
π‘ Continuous Growth β Access to certifications, trainings, and opportunities to sharpen your expertise.
π Ownership Mindset β Benefit from our ESOP program and grow with COGNNAβs success.
π€ Culture of Trust β We empower talent, encourage ownership, and celebrate real outcomes.
Skills
Explore related jobs
More jobs at COGNNA
Browse these categories
Market data for this role
All reports β- SeriesRole reportsOne role family at a time: how many openings, what changed this week, who is hiring, what it pays.
- SeriesSalary reportsWhat employers publish in job postings, by level and workplace. Not self-reported pay.
- Market overviewState of tech hiring, September 2026: up 4.8%Tech hiring rose 4.8% month over month in September 2026, with 411,122 new listings. Customer support and account executive roles led the growth.