وظيفة مهندس كشف التهديدات - المستوى الثاني لدى COGNNA في المدينة
تفاصيل الوظيفة
في شركة COGNNA، نبحث عن مهندس كشف التهديدات من المستوى الثاني (L2) للعمل في مكتبنا بالمدينة المنورة، حيث ستصمم استراتيجيات كشف عالية التأثير، وتبني أتمتة قوية، وترفع مستوى عمليات مركز العمليات الأمنية (SOC) إلى معايير عالمية، مع الإشراف على المواهب الصاعدة والتعاون مع فرق استخبارات التهديدات والاستجابة للحوادث وهندسة المنصات.
المهام والمسؤوليات
- هندسة كشف التهديدات المتقدمة: بناء قواعد ارتباط عالية الدقة وكشف سلوكي داخل منصات COGNNA الأمنية، وترجمة تقنيات الخصوم (MITRE ATT&CK) ومعلومات التهديدات وبيانات الثغرات إلى منطق قابل للتنفيذ، وتحديد فجوات الكشف وإدخال مصادر بيانات جديدة لمواكبة المشهد المتطور للتهديدات، وأتمتة اختبار الكشف والحفاظ على جودته مع مرور الوقت.
- هندسة المنصات والتحسين: قيادة بنية وتحسين حزم التقنيات XDR وSIEM وSOC لتحقيق قابلية التوسع والمرونة، وتبسيط خطوط أنابيب استيعاب السجلات (من التحليل إلى التطبيع والإثراء)، وكتابة سكريبتات وأتمتة (Python, PowerShell) لتعزيز كفاءة SOC، ودمج الأدوات عبر حزمة SOC لتمكين سير العمل السلس والاستجابة.
- صيد التهديدات والاستجابة للحوادث: التعاون مع فرق الاستخبارات والاستجابة للحوادث لإثراء حالات استخدام الكشف ودعم عمليات صيد التهديدات، وتقديم دعم من المستوى الثالث أو أعلى في تحقيقات الحوادث وتحليلات ما بعد الحادثة.
- الإرشاد ونضج SOC: تحسين كتيبات التشغيل (Playbooks) وإجراءات التشغيل القياسية (SOPs) وسير عمل هندسة الكشف في SOC، والبقاء على اطلاع على التهديدات العالمية والإقليمية وتطوير الكشف وفقاً لذلك، وضمان الامتثال للمعايير التنظيمية (مثل NCA ECC وSAMA CSF).
الشروط والمتطلبات
- درجة البكالوريوس في علوم الحاسب أو الأمن السيبراني أو مجال ذي صلة.
- خبرة لا تقل عن 3 سنوات مع خبرة عملية في تطوير وصيانة حالات استخدام كشف معقدة.
- فهم قوي لسلوك المهاجمين وأساسيات الاستجابة للحوادث والأدلة الرقمية.
- الشهادات التالية مرغوب بشدة: SANS GIAC (GDAT, GMON, GCIA, GCTI, GCIH)، Offsec (OSDA)، INE (eCTHP, eCIR)، (ISC)² CISSP, CSSLP.
المهارات المطلوبة
- خبير في استعلامات SIEM (SPL, KQL, Lucene) وضبط القواعد وUEBA وتوسيع النطاق.
- معرفة عميقة بأدوات EDR وتكتيكات الكشف على نقاط النهاية.
- متمكن في تحليل الحزم (Wireshark)، وأنظمة IDS/IPS، وNetFlow.
- مهارات متقدمة في Python و/أو PowerShell للأتمتة والتكامل.
- إتقان سجلات وأدوات أنظمة التشغيل Windows/Linux/macOS وقيمتها الجنائية.
- مهارة في تحويل معلومات التهديدات إلى منطق كشف في الوقت الفعلي.
- إلمام قوي بمراقبة بيئات IaaS/PaaS/SaaS.
- تفكير تحليلي استثنائي وحل مشكلات إبداعي.
- تواصل ممتاز باللغتين الإنجليزية والعربية، بما في ذلك إعداد التقارير الفنية.
- قدرات إرشادية قوية وروح تعاونية.
- دافع ذاتي ومركز وشغوف بالدفاع السيبراني.
- القدرة على التعامل مع أولويات متعددة تحت الضغط.
المزايا
- تأثير يهم - بناء منتجات تشكل مستقبل الأمن السيبراني وتحمي المؤسسات عالمياً.
- تعاون في الموقع - كن في قلب الابتكار في مكتبنا بالمدينة المنورة، جنباً إلى جنب مع خبراء شغوفين.
- نمو مستمر - الوصول إلى الشهادات والتدريبات وفرص صقل خبراتك.
- عقلية الملكية - استفد من برنامج ملكية أسهم الموظفين (ESOP) وانمو مع نجاح COGNNA.
- ثقافة الثقة - نمكن المواهب، ونشجع الملكية، ونحتفل بالنتائج الحقيقية.
عرض النص الأصلي للإعلان
🔐 Advanced Threat Detection Engineering
- Build high-fidelity correlation rules and behavioral detections within the COGNNA security platforms
- Translate adversary TTPs (MITRE ATT&CK), threat intel, and vulnerability data into actionable logic
- Identify detection gaps and introduce new data sources to cover evolving threat landscapes
- Automate detection testing and maintain detection quality over time
- Lead architecture and optimization of XDR, SIEM, and SOC tech stacks for scale and resilience
- Streamline log ingestion pipelines - from parsing to normalization and enrichment
- Build scripts and automations (Python, PowerShell) to enhance SOC efficiency
- Integrate tools across the SOC stack to enable seamless workflows and response.
- Collaborate with intel and IR teams to enrich detection use cases and support threat hunts
- Provide Tier-3+ support for incident investigations and post-mortem analysis
- Improve SOC playbooks, SOPs, and detection engineering workflows
- Stay updated on global and regional threats - and evolve detection accordingly
- Ensure compliance alignment (e.g., NCA ECC, SAMA CSF)
🎓 Education
- Bachelor's in Computer Science, Cybersecurity, or related field.
- Minimum 3 years of experience with hands-on expertise in developing and maintaining complex detection use cases
- Strong understanding of attacker behavior, IR fundamentals, and digital forensics.
- SIEM: Expert in SIEM queries (SPL, KQL, Lucene), rule tuning, UEBA, and scaling
- EDR: Deep knowledge of EDR tools and endpoint detection tactics
- Network Security: Pro at packet analysis (Wireshark), IDS/IPS, and NetFlow
- Scripting: Advanced skills in Python and/or PowerShell for automation and integration
- OS Internals: Mastery of Windows/Linux/macOS logging, artifacts, and forensic value
- Threat Intelligence: Skilled in turning threat intel into real-time detection logic
- Cloud Security: Strong command of monitoring IaaS/PaaS/SaaS environments
- 🎓 SANS GIAC (GDAT, GMON, GCIA, GCTI, GCIH)
- 🐉 Offsec (OSDA)
- 🏫 INE (eCTHP, eCIR)
- 🧩 (ISC)² CISSP, CSSLP
- Exceptional analytical thinking and creative problem-solving
- Excellent communication (English & Arabic), including technical reporting
- Strong mentorship abilities and a collaborative spirit
- Self-motivated, focused, and passionate about cyber defense
- Capable of juggling priorities under high-pressure situations
🚀 Impact that Matters - Build products that shape the future of cybersecurity and protect organizations globally.
🏢 On-Site Collaboration - Be at the heart of innovation in our Almadina office, working side by side with passionate experts.
💡 Continuous Growth - Access to certifications, trainings, and opportunities to sharpen your expertise.
📈 Ownership Mindset - Benefit from our ESOP program and grow with COGNNA's success.
🤝 Culture of Trust - We empower talent, encourage ownership, and celebrate real outcomes.
رقم الإعلان لدى المصدر: 4464619176