img
Contract TypeFull-time
Workplace typeOn-site
LocationMadinah

Job Description

About the Role

Cognna is seeking a Threat Detection Engineer to join its team in Medina, Al Madinah. This full-time role involves designing high-impact detection strategies, building automation, and enhancing Security Operations Center (SOC) capabilities. The position requires 2-5 years of experience in a relevant field.

Key Responsibilities

  • Design and implement high-fidelity correlation rules and behavioral detections within Cognna's security platforms.
  • Translate adversary Tactics, Techniques, and Procedures (TTPs) based on MITRE ATT&CK, threat intelligence, and vulnerability data into actionable detection logic.
  • Identify detection gaps and integrate new data sources to address evolving threat landscapes.
  • Automate detection testing processes and ensure the sustained quality of detections.

Platform Engineering and Optimization

  • Lead the architecture and optimization of XDR, SIEM, and SOC technology stacks to ensure scalability and resilience.
  • Streamline log ingestion pipelines, covering parsing, normalization, and enrichment processes.
  • Develop scripts and automations using Python and PowerShell to enhance SOC operational efficiency.
  • Integrate various tools across the SOC stack to facilitate seamless workflows and incident response.

Threat Hunting and Incident Response Support

  • Collaborate with threat intelligence and incident response teams to enrich detection use cases and support threat hunting activities.
  • Provide Tier-3+ support for incident investigations and post-mortem analysis.

SOC Maturity and Mentorship

  • Contribute to the improvement of SOC playbooks, Standard Operating Procedures (SOPs), and detection engineering workflows.
  • Stay informed about global and regional threat landscapes and adapt detection strategies accordingly.
  • Ensure alignment with compliance standards such as NCA ECC and SAMA CSF.
  • Mentor junior cyber talent within the team.

Experience and Qualifications

Candidates should possess 2-5 years of experience in threat detection engineering or a related cybersecurity field. The role requires a strong understanding of security platforms, automation, and incident response principles.


Requirements

  • No experience required

Similar Jobs