C
Staff Digital Forensics and Incident Response (DFIR) Specialist
Riyadh, Riyadh Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 2 weeks ago
- Work mode
- In office
- Education
- Bachelor's degree in Cybersecurity or related field
- Resume
- Required to apply
Where you'll work
Job description
About COGNNA
COGNNA is innovating the cybersecurity landscape by combining advanced AI technologies, real-time threat monitoring, and deep security analytics to empower organizations in proactively defending against modern cyber threats.
Role Responsibilities
- Manage end-to-end forensic investigations spanning endpoints, cloud environments, and network infrastructure, from initial analysis through root cause identification including indicators of compromise, data breaches, and unauthorized accesses.
- Lead and coordinate the Digital Forensics and Incident Response (DFIR) team during live investigations ensuring standardized processes, integrity of evidence, and efficient progress.
- Extract and examine logs from various security platforms such as EDR/XDR, SIEM, DLP, Identity Providers, and email gateways to accurately reconstruct attack vectors and user behavior timelines.
- Obtain forensic images from devices including laptops, mobiles, servers, and cloud storage while maintaining comprehensive chain of custody documentation.
- Conduct in-depth analysis of forensic artifacts including file systems, memory, registry, logs, and configuration states to precisely establish what occurred and when.
- Integrate telemetry from endpoints, networks, and identities to create a unified view of attacker actions and system accesses.
- Develop AI-powered workflows to automate steps like evidence gathering, pattern recognition, and timeline generation, thereby enhancing investigative throughput.
- Convert complex technical results into clear, chronological reports suitable for executives and cross-functional teams without technical jargon or ambiguity.
- Apply findings from investigations to improve detection rules, access policies, and overall security posture.
Qualifications & Experience
- Bachelor's degree in Cybersecurity, International Relations, Computer Science, or a related discipline.
- At least 5 years of practical experience in digital forensics, incident response, or security investigations, including leadership or coordination roles within DFIR projects.
- Fluency in both English and Arabic with excellent written and verbal communication skills.
- Proficient with forensic tools such as FTK, X-Ways, Cellebrite, Axiom, or their equivalents.
- Strong understanding of network protocols like TCP/IP, HTTP/S, DNS, and experienced in SIEM log analysis.
- Hands-on scripting skills in Python, PowerShell, or Bash used for automating evidence analysis tasks.
- Thorough knowledge of Windows, macOS, and Linux/Unix operating environments at artifact and system levels.
- Demonstrated experience integrating AI technologies into investigative processes to speed up triage, detection, and reporting.
- Ability to communicate complex findings confidently to executives and liaise effectively with legal, HR, and compliance departments while maintaining technical accuracy.
- Ensure all processes conform to NCA ECC and SAMA CSF compliance frameworks.
- Prior leadership experience within DFIR teams is mandatory.
Preferred Certifications
- SANS/GIAC certifications such as GCFA, GCFE, GNFA, GCIA or similar qualifications.
- IACIS CFCE certification.
- EC-Council CHFI credentials.
- Offensive Security certifications like OSDA or OSIR.
Key Personal Attributes
- Highly analytical with strong creative problem-solving capabilities.
- Exceptional communication skills in both English and Arabic, including technical documentation.
- Experienced mentor with a collaborative and team-oriented approach.
- Self-driven, focused, with a dedicated passion for cybersecurity defense.
- Able to manage multiple priorities effectively in demanding, high-pressure environments.
Perks and Benefits
- Opportunity to contribute to impactful cybersecurity products that safeguard organizations worldwide.
- Engage in collaborative on-site work from the Riyadh office alongside industry experts.
- Access to continuous professional development including certifications and training programs.
- Ownership mindset fostered with participation in the Employee Stock Ownership Plan (ESOP).
- Cultivation of a trustworthy, empowering culture that values accountability and recognizes achievements.
Skills
Digital Forensics
Incident Response
PowerShell Scripting
Bash Scripting
Python Scripting
Cybersecurity investigations
Bilingual communication English and Arabic
forensic analysis tools (FTK, X-Ways, Cellebrite, Axiom)
network protocols (TCP/IP, HTTP/S, DNS)
SIEM log analysis
Windows/macOS/Linux system knowledge
AI integration in cybersecurity investigations
leadership in DFIR teams
regulatory compliance (NCA ECC, SAMA CSF)