تفاصيل الوظيفة
تعلن شركة كوجنا (COGNNA) عن توفر وظيفة محقق جنائي رقمي واستجابة للحوادث (Staff DFIR) في الرياض، المملكة العربية السعودية.
نبذة عن الوظيفة
تعمل كوجنا على تشكيل مستقبل الأمن السيبراني من خلال الابتكار والذكاء والحماية المتطورة. تدمج منصاتها تقنيات الذكاء الاصطناعي المتطورة، والكشف عن التهديدات في الوقت الفعلي، ورؤى أمنية عميقة لمساعدة المؤسسات على الدفاع بشكل استباقي ضد التهديدات السيبرانية المتطورة.
المهام والمسؤوليات
- إدارة التحقيقات الجنائية الرقمية من البداية إلى النهاية عبر نقاط النهاية والمنصات السحابية والبنية التحتية للشبكة - من الفرز الأولي إلى السبب الجذري، بما في ذلك تحديد مؤشرات الاختراق (IoC) وسرقة البيانات والوصول غير المصرح به.
- تنسيق وقيادة فريق DFIR عبر التحقيقات النشطة، وضمان منهجية متسقة، وسلامة الأدلة، وسرعة التحقيق.
- سحب وتحليل السجلات من منصات EDR/XDR وSIEM وDLP وIdP وبوابات البريد الإلكتروني لإعادة بناء جداول زمنية دقيقة للهجمات وأنشطة المستخدمين.
- الحصول على صور جنائية من أجهزة الكمبيوتر المحمولة والأجهزة المحمولة والخوادم والمستودعات السحابية مع سلسلة حفظ كاملة.
- التعمق في القطع الأثرية - أنظمة الملفات، والذاكرة، والسجل، والسجلات، وحالات التكوين - لإعادة بناء ما حدث ومتى بدقة.
- ربط القياسات عن بُعد من نقاط النهاية والشبكة والهوية في صورة متماسكة لسلوك المهاجم والوصول إلى النظام.
- بناء سير عمل مدعوم بالذكاء الاصطناعي يعمل على أتمتة جمع الأدلة واكتشاف الأنماط وإنشاء الجداول الزمنية لزيادة قدرة التحقيق.
- ترجمة النتائج التقنية إلى سرد زمني واضح للمديرين التنفيذيين وأصحاب المصلحة عبر الأقسام - دون غموض.
- إغلاق الحلقة: تغذية نتائج التحقيق في قواعد الكشف، وضوابط الوصول، وتحسينات السياسات.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني أو العلاقات الدولية أو علوم الحاسب أو مجال ذي صلة.
- 5+ سنوات من الخبرة في التحقيق الجنائي الرقمي أو الاستجابة للحوادث أو التحقيقات الأمنية، مع سجل حافل في قيادة أو تنسيق مهام DFIR.
- مهارات استثنائية في التواصل الكتابي والشفوي باللغتين الإنجليزية والعربية.
- كفاءة عملية في أدوات التحقيق الجنائي: FTK، X-Ways، Cellebrite، Axiom أو منصات مكافئة.
- إلمام قوي ببروتوكولات الشبكة (TCP/IP، HTTP/S، DNS) وتحليل السجلات عبر منصات SIEM.
- القدرة على البرمجة بلغة Python أو PowerShell أو Bash - لاستخدامها في أتمتة معالجة الأدلة، وليس فقط من الناحية النظرية.
- معرفة عملية متعمقة ببيئات Windows وmacOS وLinux/Unix على مستوى القطع الأثرية والنظام.
- خبرة مثبتة في دمج أدوات الذكاء الاصطناعي في سير عمل التحقيق لتسريع الفرز أو اكتشاف الأنماط أو إعداد التقارير.
- متصل واضح وواثق - قادر على إيجاز المديرين التنفيذيين والعمل جنبًا إلى جنب مع فرق الشؤون القانونية والموارد البشرية والامتثال دون فقدان الدقة التقنية.
- الامتثال: ضمان توافق جميع العمليات مع لوائح هيئة الاتصالات والفضاء والتقنية (NCA ECC) وإطار عمل البنك المركزي السعودي (SAMA CSF).
- خبرة سابقة في القيادة - شرط أساسي.
المهارات المطلوبة
- تفكير تحليلي استثنائي وحل المشكلات بإبداع.
- مهارات تواصل ممتازة (الإنجليزية والعربية)، بما في ذلك إعداد التقارير الفنية.
- قدرات إرشادية قوية وروح تعاونية.
- تحفيز ذاتي، وتركيز، وشغف بالدفاع السيبراني.
- القدرة على إدارة الأولويات في ظل ظروف الضغط العالي.
المزايا
- تأثير ذو معنى - بناء منتجات تشكل مستقبل الأمن السيبراني وتحمي المؤسسات عالميًا.
- تعاون في الموقع - كن في قلب الابتكار في مكتبنا بالرياض، جنبًا إلى جنب مع خبراء متحمسين.
- نمو مستمر - الوصول إلى الشهادات والدورات التدريبية وفرص صقل الخبرات.
- عقلية الملكية - استفد من برنامج أسهم الموظفين (ESOP) وازدهار مع نجاح كوجنا.
- ثقافة الثقة - نحن نمكن المواهب، ونشجع الملكية، ونحتفل بالنتائج الحقيقية.
عرض النص الأصلي للإعلان
🔍 Who We Are
COGNNA is shaping the future of cybersecurity through innovation, intelligence, and a relentless drive to protect. Our platforms integrate cutting-edge AI, real-time threat detection, and deep security insights to help organizations proactively defend against evolving cyber threats.
Responsibilities
- Own end-to-end forensic investigations across endpoints, cloud platforms, and network infrastructure - from initial triage to root cause, including IoC identification, data exfiltration, and unauthorized access
- Coordinate and lead the DFIR team across active investigations, ensuring consistent methodology, evidence integrity, and investigative velocity
- Pull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateway platforms to reconstruct precise attack and user activity timelines
- Acquire forensic images from laptops, mobile devices, servers, and cloud repositories with full chain of custody
- Go deep on artifacts - file systems, memory, registry, logs, config states - to reconstruct exactly what happened and when
- Correlate endpoint, network, and identity telemetry into a coherent picture of attacker behavior and system access
- Build AI-assisted workflows that automate evidence collection, pattern detection, and timeline generation to scale investigative capacity
- Translate technical findings into clear, chronological narratives for executives and cross-functional stakeholders - no jargon, no ambiguity
- Close the loop: feed investigation outcomes back into detection rules, access controls, and policy improvements.
Requirements
🎓 Education & Experience
- Bachelor’s in Cybersecurity, International Relations, Computer Science, or related field.
- 5+ years in digital forensics, incident response, or security investigations, with a track record leading or coordinating DFIR engagements
- Exceptional written and verbal communication in both English & Arabic.
- Hands-on proficiency with forensic tooling: FTK, X-Ways, Cellebrite, Axiom, or equivalent platforms
- Strong command of network protocols (TCP/IP, HTTP/S, DNS) and log analysis across SIEM platforms
- Scripting ability in Python, PowerShell, or Bash - used to automate evidence processing, not just theoretically
- Deep working knowledge of Windows, macOS, and Linux/Unix environments at the artifact and system level
- Proven experience integrating AI tools into investigative workflows to accelerate triage, pattern detection, or reporting
- Clear, confident communicator - able to brief executives and work alongside legal, HR, and compliance teams without losing technical precision
- Compliance: Ensuring all operations align with NCA ECC and SAMA CSF regulations.
- Previous leadership experience is a must.
🏅 Certifications (Highly Preferred)
- SANS / GIAC (GCFA, GCFE, GNFA, GCIA or similar)
- IACIS CFCE
- EC-Council CHFI
- Offsec (OSDA, OSIR)
🤝 Soft Skills
- Exceptional analytical thinking and creative problem-solving.
- Excellent communication (English & Arabic), including technical reporting.
- Strong mentorship abilities and a collaborative spirit.
- Self-motivated, focused, and passionate about cyber defense.
- Capable of juggling priorities under high-pressure situations.
Benefits
🚀 Impact that Matters - Build products that shape the future of cybersecurity and protect organizations globally.
🏢 On-Site Collaboration - Be at the heart of innovation in our Riyadh office, working side by side with passionate experts.
💡 Continuous Growth - Access to certifications, trainings, and opportunities to sharpen your expertise.
📈 Ownership Mindset - Benefit from our ESOP program and grow with COGNNA’s success.
🤝 Culture of Trust - We empower talent, encourage ownership, and celebrate real outcomes.
رقم الإعلان لدى المصدر: 80490F1037
كوجنا تعلن عن وظيفة مهندس أول لكشف التهديدات في المدينة المنورة