📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

كوجنا تعلن عن وظيفة مهندس أول لكشف التهديدات في المدينة المنورة

Senior Threat Detection Engineer - Madinah
🏢 كوجنا (Cognna)
🕒 نُشرت: (منذ 15 يوماً) 📍 المدينة المنورة وظائف الهندسة والتقنية

تفاصيل الوظيفة

كوجنا تبحث عن مهندس كشف تهديدات أول (Senior Threat Detection Engineer) في المدينة المنورة.

نبذة عن الوظيفة

بصفتك مهندس كشف تهديدات في كوجنا، ستقوم بتصميم استراتيجيات كشف عالية التأثير، وبناء أتمتة قوية، والارتقاء بعمليات مركز عمليات الأمن (SOC) إلى مستوى عالمي. كما ستقوم بتوجيه المواهب السيبرانية الصاعدة والتعاون مع فرق عبر مجالات استخبارات التهديدات والاستجابة للحوادث وهندسة المنصات.

المهام والمسؤوليات

  • بناء قواعد ارتباط عالية الدقة وكشف سلوكي ضمن منصات كوجنا الأمنية.
  • ترجمة تكتيكات وتقنيات وإجراءات المهاجمين (MITRE ATT&CK) وبيانات استخبارات التهديدات ونقاط الضعف إلى منطق قابل للتنفيذ.
  • تحديد فجوات الكشف وإدخال مصادر بيانات جديدة لتغطية مشهد التهديدات المتطور.
  • أتمتة اختبار الكشف والحفاظ على جودة الكشف مع مرور الوقت.
  • قيادة بنية وتحسين حزم XDR و SIEM وحلول SOC لتحقيق قابلية التوسع والمرونة.
  • تبسيط خطوط أنابيب استيعاب السجلات - من التحليل إلى التطبيع والإثراء.
  • بناء سكريبتات وأتمتة (Python, PowerShell) لتعزيز كفاءة SOC.
  • دمج الأدوات عبر حزمة SOC لتمكين سير العمل والاستجابة السلسة.
  • التعاون مع فرق استخبارات التهديدات والاستجابة للحوادث لإثراء حالات الكشف ودعم عمليات الصيد.
  • تقديم دعم المستوى الثالث+ لتحقيقات الحوادث وتحليلات ما بعد الحادث.
  • تحسين دفاتر تشغيل SOC وإجراءات التشغيل القياسية وسير عمل هندسة الكشف.
  • البقاء على اطلاع على التهديدات العالمية والإقليمية - وتطوير الكشف وفقًا لذلك.
  • ضمان الامتثال للمعايير (مثل NCA ECC و SAMA CSF).

الشروط والمتطلبات

  • بكالوريوس في علوم الحاسب، الأمن السيبراني أو مجال ذي صلة.
  • خبرة لا تقل عن 3 سنوات مع خبرة عملية في تطوير وصيانة حالات كشف معقدة.
  • فهم قوي لسلوك المهاجمين وأساسيات الاستجابة للحوادث والتحقيق الرقمي.
  • الشهادات التالية مرغوب فيها بشدة: SANS GIAC (GDAT, GMON, GCIA, GCTI, GCIH)، Offsec (OSDA)، INE (eCTHP, eCIR)، (ISC)² CISSP، CSSLP.

المهارات المطلوبة

  • خبرة متقدمة في SIEM: استعلامات (SPL, KQL, Lucene)، ضبط القواعد، UEBA، وتوسيع النطاق.
  • معرفة عميقة بأدوات EDR وتكتيكات الكشف على نقاط النهاية.
  • خبرة متقدمة في أمن الشبكات: تحليل الحزم (Wireshark)، IDS/IPS، و NetFlow.
  • مهارات متقدمة في Python و/أو PowerShell للأتمتة والتكامل.
  • إتقان سجلات Windows/Linux/macOS والقطع الأثرية وقيمتها الجنائية.
  • مهارة في تحويل استخبارات التهديدات إلى منطق كشف في الوقت الفعلي.
  • إلمام قوي بمراقبة بيئات IaaS/PaaS/SaaS.
  • تفكير تحليلي استثنائي وحل مشكلات إبداعي.
  • تواصل ممتاز (الإنجليزية والعربية) بما في ذلك التقارير الفنية.
  • قدرات توجيهية قوية وروح تعاونية.
  • دافع ذاتي، مركز، وشغوف بالدفاع السيبراني.
  • القدرة على إدارة الأولويات تحت الضغط.

المزايا

  • بناء منتجات تشكل مستقبل الأمن السيبراني وحماية المؤسسات عالميًا.
  • التعاون المباشر في مكتب المدينة المنورة مع خبراء شغوفين.
  • الوصول إلى الشهادات والتدريبات وفرص صقل الخبرات.
  • برنامج ملكية أسهم الموظفين (ESOP) والنمو مع نجاح كوجنا.
  • ثقافة الثقة التي تمكن المواهب وتشجع الملكية وتحتفل بالنتائج الحقيقية.
عرض النص الأصلي للإعلان

As a Threat Detection Engineer at COGNNA, you’ll design high-impact detection strategies, build powerful automation, and elevate SOC operations to a world-class standard. You’ll also mentor rising cyber talent and collaborate with teams across threat intel, incident response, and platform engineering.

🔐 Advanced Threat Detection Engineering

  • Build high-fidelity correlation rules and behavioral detections within the COGNNA security platforms.
  • Translate adversary TTPs (MITRE ATT&CK), threat intel, and vulnerability data into actionable logic.
  • Identify detection gaps and introduce new data sources to cover evolving threat landscapes.
  • Automate detection testing and maintain detection quality over time.

⚙️ Platform Engineering & Optimization

  • Lead architecture and optimization of XDR, SIEM, and SOC tech stacks for scale and resilience.
  • Streamline log ingestion pipelines - from parsing to normalization and enrichment.
  • Build scripts and automations (Python, PowerShell) to enhance SOC efficiency.
  • Integrate tools across the SOC stack to enable seamless workflows and response.

🕵️‍♂️ Threat Hunting & Incident Response

  • Collaborate with intel and IR teams to enrich detection use cases and support threat hunts.
  • Provide Tier-3+ support for incident investigations and post-mortem analysis.

👥 Mentorship & SOC Maturity

  • Improve SOC playbooks, SOPs, and detection engineering workflows.
  • Stay updated on global and regional threats - and evolve detection accordingly.
  • Ensure compliance alignment (e.g., NCA ECC, SAMA CSF).

Requirements

🎓 Education

  • Bachelor’s in Computer Science, Cybersecurity, or related field.

💼 Experience

  • Minimum 3 years of experience with hands-on expertise in developing and maintaining complex detection use cases.
  • Strong understanding of attacker behavior, IR fundamentals, and digital forensics.

🔧 Technical Skills (You’re a Power User!)

  • SIEM: Expert in SIEM queries (SPL, KQL, Lucene), rule tuning, UEBA, and scaling.
  • EDR: Deep knowledge of EDR tools and endpoint detection tactics.
  • Network Security: Pro at packet analysis (Wireshark), IDS/IPS, and NetFlow.
  • Scripting: Advanced skills in Python and/or PowerShell for automation and integration.
  • OS Internals: Mastery of Windows/Linux/macOS logging, artifacts, and forensic value.
  • Threat Intelligence: Skilled in turning threat intel into real-time detection logic.
  • Cloud Security: Strong command of monitoring IaaS/PaaS/SaaS environments.

🏅 Certifications (Highly Preferred)

  • 🎓 SANS GIAC (GDAT, GMON, GCIA, GCTI, GCIH)
  • 🐉 Offsec (OSDA)
  • 🏫 INE (eCTHP, eCIR)
  • 🧩 (ISC)² CISSP, CSSLP

🤝 Soft Skills

  • Exceptional analytical thinking and creative problem-solving.
  • Excellent communication (English & Arabic), including technical reporting.
  • Strong mentorship abilities and a collaborative spirit.
  • Self-motivated, focused, and passionate about cyber defense.
  • Capable of juggling priorities under high-pressure situations.

Benefits

🚀 Impact that Matters - Build products that shape the future of cybersecurity and protect organizations globally.

🏢 On-Site Collaboration - Be at the heart of innovation in our Almadina office, working side by side with passionate experts.

💡 Continuous Growth - Access to certifications, trainings, and opportunities to sharpen your expertise.

📈 Ownership Mindset - Benefit from our ESOP program and grow with COGNNA’s success.

🤝 Culture of Trust - We empower talent, encourage ownership, and celebrate real outcomes.

المصدر: الموقع الرسمي للجهة - أُضيفت للموقع في 3 أكتوبر 2026
رقم الإعلان لدى المصدر: D3A82C9418