img
Contract TypeFull-time
Workplace typeOn-site
LocationMadinah

Job Description

About the Role

Cognna is seeking a Threat Detection Engineer to join their team in Medina, Al Madinah, Saudi Arabia. This full-time role involves designing high-impact detection strategies, building automation, and enhancing Security Operations Center (SOC) capabilities. The engineer will also mentor cyber talent and collaborate with various internal teams.

Advanced Threat Detection Engineering

  • Develop high-fidelity correlation rules and behavioral detections within Cognna's security platforms.
  • Translate adversary Tactics, Techniques, and Procedures (TTPs) based on MITRE ATT&CK, threat intelligence, and vulnerability data into actionable logic.
  • Identify detection gaps and integrate new data sources to address evolving threat landscapes.
  • Automate detection testing and ensure sustained detection quality.

Platform Engineering and Optimization

  • Lead the architecture and optimization of XDR, SIEM, and SOC technology stacks to ensure scalability and resilience.
  • Streamline log ingestion pipelines, covering parsing, normalization, and enrichment processes.
  • Develop scripts and automations using Python and PowerShell to improve SOC efficiency.
  • Integrate tools across the SOC stack to facilitate seamless workflows and response capabilities.

Threat Hunting and Incident Response Support

  • Collaborate with threat intelligence and incident response teams to enhance detection use cases and support threat hunting activities.
  • Provide Tier-3+ support for incident investigations and post-mortem analysis.

SOC Maturity and Compliance

  • Improve SOC playbooks, Standard Operating Procedures (SOPs), and detection engineering workflows.
  • Stay informed on global and regional threats and adapt detection strategies accordingly.
  • Ensure alignment with compliance standards such as NCA ECC and SAMA CSF.

Collaboration and Mentorship

This role involves mentoring emerging cyber talent and working closely with teams specializing in threat intelligence, incident response, and platform engineering to foster a collaborative and skilled security environment.


Requirements

  • No experience required

Similar Jobs