As a Threat Detection Engineer at COGNNA, you ll design high-impact detection strategies, build powerful automation, and elevate SOC operations to a world-class standard. You ll also mentor rising cyber talent and collaborate with teams across threat intel, incident response, and platform engineering.
Advanced Threat Detection Engineering
Build high-fidelity correlation rules and behavioral detections within the COGNNA security platforms. Translate adversary TTPs (MITRE ATT&CK), threat intel, and vulnerability data into actionable logic. Identify detection gaps and introduce new data sources to cover evolving threat landscapes. Automate detection testing and maintain detection quality over time.
Platform Engineering & Optimization
Lead architecture and optimization of XDR, SIEM, and SOC tech stacks for scale and resilience. Streamline log ingestion pipelines from parsing to normalization and enrichment. Build scripts and automations (Python, PowerShell) to enhance SOC efficiency. Integrate tools across the SOC stack to enable seamless workflows and response.
Threat Hunting & Incident Response
Collaborate with intel and IR teams to enrich detection use cases and support threat hunts. Provide Tier-3+ support for incident investigations and post-mortem analysis.
Mentorship & SOC Maturity
Improve SOC playbooks, SOPs, and detection engineering workflows. Stay updated on global and regional threats and evolve detection accordingly. Ensure compliance alignment (e.g., NCA ECC, SAMA CSF).
Desired Candidate Profile
Education
Bachelor s in Computer Science, Cybersecurity, or related field.
Experience
Minimum 3 years of experience with hands-on expertise in developing and maintaining complex detection use cases. Strong understanding of attacker behavior, IR fundamentals, and digital forensics.
Technical Skills (You re a Power User!)
- SIEM: Expert in SIEM queries (SPL, KQL, Lucene), rule tuning, UEBA, and scaling.
- EDR: Deep knowledge of EDR tools and endpoint detection tactics.
- Network Security: Pro at packet analysis (Wireshark), IDS/IPS, and NetFlow.
- Scripting: Advanced skills in Python and/or PowerShell for automation and integration.
- OS Internals: Mastery of Windows/Linux/macOS logging, artifacts, and forensic value.
- Threat Intelligence: Skilled in turning threat intel into real-time detection logic.
- Cloud Security: Strong command of monitoring IaaS/PaaS/SaaS environments.
Certifications (Highly Preferred)
- SANS GIAC (GDAT, GMON, GCIA, GCTI, GCIH)
- Offsec (OSDA)
- INE (eCTHP, eCIR)
- (ISC) CISSP, CSSLP
Soft Skills
- Exceptional analytical thinking and creative problem-solving.
- Excellent communication (English & Arabic), including technical reporting.
- Strong mentorship abilities and a collaborative spirit.
- Self-motivated, focused, and passionate about cyber defense.
- Capable of juggling priorities under high-pressure situations.
Impact that Matters
Build products that shape the future of cybersecurity and protect organizations globally.
On-Site Collaboration
Be at the heart of innovation in our Almadina office, working side by side with passionate experts.
Continuous Growth
Access to certifications, trainings, and opportunities to sharpen your expertise.
Ownership Mindset
Benefit from our ESOP program and grow with COGNNA s success.
Culture of Trust
We empower talent, encourage ownership, and celebrate real outcomes.
بصفتك مهندس كشف التهديدات في COGNNA، ستصمم استراتيجيات كشف عالية التأثير، وتبني أتمتة قوية، وترتقي بعمليات مركز عمليات الأمن الرقمي (SOC) إلى مستوى عالمي. وستقوم أيضًا بتوجيه المواهب السيبرانية الواعدة والتعاون مع فرق معلومات التهديدات والاستجابة للحوادث وهندسة المنصات.
هندسة كشف التهديدات المتقدمة
بناء قواعد ارتباط عالية الدقة وآليات كشف سلوكي ضمن منصات COGNNA الأمنية. ترجمة التكتيكات والتقنيات والإجراءات (TTPs) للمهاجمين (MITRE ATT&CK)، ومعلومات التهديدات، وبيانات الثغرات الأمنية إلى منطق قابل للتنفيذ. تحديد ثغرات الكشف وإدخال مصادر بيانات جديدة لتغطية مشهد التهديدات المتطور. أتمتة اختبار الكشف والحفاظ على جودة الكشف بمضي الوقت.
هندسة المنصات وتحسينها
قيادة بنية وتحسين منظومة تقنيات XDR وSIEM وSOC من أجل التوسع والمرونة. تبسيط أنابيب استيعاب السجلات من التحليل إلى التوحيد والإثراء. بناء برامج نصية وأتمتة (Python, PowerShell) لتعزيز كفاءة SOC. دمج الأدوات عبر منظومة SOC لتمكين سير العمل والاستجابة السلسة.
صيد التهديدات والاستجابة للحوادث
التعاون مع فرق معلومات التهديدات والاستجابة للحوادث لإثراء حالات استخدام الكشف ودعم عمليات صيد التهديدات. تقديم دعم من المستوى الثالث فما فوق (Tier-3+) للتحقيق في الحوادث والتحليل الجنائي بعد وقوع الحادث.
التوجيه ونضج مركز عمليات الأمن (SOC)
تحسين أدلة العمليات (playbooks) في SOC، وإجراءات التشغيل القياسية (SOPs)، وسير عمل هندسة الكشف. البقاء على اطلاع بالتهديدات العالمية والإقليمية وتطوير الكشف وفقًا لذلك. ضمان التوافق مع متطلبات الامتثال (مثل NCA ECC وSAMA CSF).
الملف الشخصي للمرشح المطلوب
التعليم
درجة البكالوريوس في علوم الحاسوب، أو الأمن السيبراني، أو أي مجال ذي صلة.
الخبرة
خبرة لا تقل عن 3 سنوات مع خبرة عملية في تطوير وحفظ حالات استخدام الكشف المعقدة. فهم قوي لسلوك المهاجمين، وأساسيات الاستجابة للحوادث، والتحقيق الجنائي الرقمي.
المهارات التقنية (أنت مستخدم خبير!)
- SIEM: خبير في استعلامات SIEM (مثل SPL وKQL وLucene)، وضبط القواعد، وUEBA، والتوسع.
- EDR: معرفة عميقة بأدوات EDR وتكتيكات كشف الأجهزة الطرفية.
- أمن الشبكات: محترف في تحليل حزم البيانات (Wireshark)، وأنظمة IDS/IPS، وNetFlow.
- البرمجة النصية: مهارات متقدمة في Python و/أو PowerShell للأتمتة والتكامل.
- أحشاء نظم التشغيل (OS Internals): إتقان تسجيل أحداث Windows/Linux/macOS، والآثار الرقمية، والقيمة الجنائية.
- معلومات التهديدات: مهارة في تحويل معلومات التهديدات إلى منطق كشف في الوقت الفعلي.
- الأمن السحابي: إتقان قوي لمراقبة بيئات IaaS/PaaS/SaaS.
الشهادات (مفضلة بشدة)
- SANS GIAC (GDAT, GMON, GCIA, GCTI, GCIH)
- Offsec (OSDA)
- INE (eCTHP, eCIR)
- (ISC) CISSP, CSSLP
المهارات الشخصية
- تفكير تحليلي استثنائي وحل إبداعي للمشكلات.
- تواصل ممتاز (باللغتين الإنجليزية والعربية)، بما في ذلك إعداد التقارير الفنية.
- قدرات توجيه قوية وروح تعاونية.
- ذاتي الدافع، ومتمكن، وشغوف بالدفاع السيبراني.
- قدرة على إدارة الأولويات المتعددة تحت ضغط العمل.
تأثير ذو قيمة
بناء منتجات تشكل مستقبل الأمن السيبراني وتحمي المؤسسات عالميًا.
التعاون الميداني (في المقر)
كن في قلب الابتكار في مكتبنا بالمدينة المنورة، والعمل جنباً إلى جنب مع خبراء شغوفين.
النمو المستمر
الحصول على الشهادات والتدريبات والفرص لتعزيز خبرتك وتطويرها.
عقلية الملكية والمسؤولية
الاستفادة من برنامج تملك الأسهم للموظفين (ESOP) والنمو مع نجاح COGNNA.
ثقافة الثقة
نحن نمكّن المواهب، ونشجع روح المسؤولية، ونحتفي بالنتائج الحقيقية.