C

Staff Digital Forensics and Incident Response (DFIR) Specialist

COGNNA

Riyadh, Riyadh Province, Saudi Arabia · Full Time

Be the first to apply

Experience
5+ yrs
Salary
Openings
1
Posted
2 weeks ago
Work mode
In office
Education
Bachelor's degree in Cybersecurity or related field
Resume
Required to apply

Where you'll work

Job description

About COGNNA

COGNNA is innovating the cybersecurity landscape by combining advanced AI technologies, real-time threat monitoring, and deep security analytics to empower organizations in proactively defending against modern cyber threats.

Role Responsibilities

  • Manage end-to-end forensic investigations spanning endpoints, cloud environments, and network infrastructure, from initial analysis through root cause identification including indicators of compromise, data breaches, and unauthorized accesses.
  • Lead and coordinate the Digital Forensics and Incident Response (DFIR) team during live investigations ensuring standardized processes, integrity of evidence, and efficient progress.
  • Extract and examine logs from various security platforms such as EDR/XDR, SIEM, DLP, Identity Providers, and email gateways to accurately reconstruct attack vectors and user behavior timelines.
  • Obtain forensic images from devices including laptops, mobiles, servers, and cloud storage while maintaining comprehensive chain of custody documentation.
  • Conduct in-depth analysis of forensic artifacts including file systems, memory, registry, logs, and configuration states to precisely establish what occurred and when.
  • Integrate telemetry from endpoints, networks, and identities to create a unified view of attacker actions and system accesses.
  • Develop AI-powered workflows to automate steps like evidence gathering, pattern recognition, and timeline generation, thereby enhancing investigative throughput.
  • Convert complex technical results into clear, chronological reports suitable for executives and cross-functional teams without technical jargon or ambiguity.
  • Apply findings from investigations to improve detection rules, access policies, and overall security posture.

Qualifications & Experience

  • Bachelor's degree in Cybersecurity, International Relations, Computer Science, or a related discipline.
  • At least 5 years of practical experience in digital forensics, incident response, or security investigations, including leadership or coordination roles within DFIR projects.
  • Fluency in both English and Arabic with excellent written and verbal communication skills.
  • Proficient with forensic tools such as FTK, X-Ways, Cellebrite, Axiom, or their equivalents.
  • Strong understanding of network protocols like TCP/IP, HTTP/S, DNS, and experienced in SIEM log analysis.
  • Hands-on scripting skills in Python, PowerShell, or Bash used for automating evidence analysis tasks.
  • Thorough knowledge of Windows, macOS, and Linux/Unix operating environments at artifact and system levels.
  • Demonstrated experience integrating AI technologies into investigative processes to speed up triage, detection, and reporting.
  • Ability to communicate complex findings confidently to executives and liaise effectively with legal, HR, and compliance departments while maintaining technical accuracy.
  • Ensure all processes conform to NCA ECC and SAMA CSF compliance frameworks.
  • Prior leadership experience within DFIR teams is mandatory.

Preferred Certifications

  • SANS/GIAC certifications such as GCFA, GCFE, GNFA, GCIA or similar qualifications.
  • IACIS CFCE certification.
  • EC-Council CHFI credentials.
  • Offensive Security certifications like OSDA or OSIR.

Key Personal Attributes

  • Highly analytical with strong creative problem-solving capabilities.
  • Exceptional communication skills in both English and Arabic, including technical documentation.
  • Experienced mentor with a collaborative and team-oriented approach.
  • Self-driven, focused, with a dedicated passion for cybersecurity defense.
  • Able to manage multiple priorities effectively in demanding, high-pressure environments.

Perks and Benefits

  • Opportunity to contribute to impactful cybersecurity products that safeguard organizations worldwide.
  • Engage in collaborative on-site work from the Riyadh office alongside industry experts.
  • Access to continuous professional development including certifications and training programs.
  • Ownership mindset fostered with participation in the Employee Stock Ownership Plan (ESOP).
  • Cultivation of a trustworthy, empowering culture that values accountability and recognizes achievements.

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help