COGNNA تعلن عن وظيفة أخصائي أول DFIR Guardian في الرياض
Senior DFIR Guardian
🏢 COGNNA
تفاصيل الوظيفة
تعلن شركة COGNNA عن توفر وظيفة كبير محققي التحقيقات الرقمية والاستجابة للحوادث (Senior DFIR Guardian) في الرياض.
المهام والمسؤوليات
- إدارة التحقيقات الجنائية الرقمية من البداية إلى النهاية عبر نقاط النهاية والمنصات السحابية والبنية التحتية للشبكة - من الفرز الأولي إلى السبب الجذري، بما في ذلك تحديد مؤشرات الاختراق (IoC) وسرقة البيانات والوصول غير المصرح به.
- تنسيق وقيادة فريق DFIR أثناء التحقيقات النشطة، مع ضمان منهجية متسقة وسلامة الأدلة وسرعة التحقيق.
- سحب وتحليل السجلات من منصات EDR/XDR وSIEM وDLP وIdP وبوابات البريد الإلكتروني لإعادة بناء خطوط زمنية دقيقة للهجمات ونشاط المستخدمين.
- الحصول على صور جنائية من أجهزة الكمبيوتر المحمولة والأجهزة المحمولة والخوادم والمستودعات السحابية مع سلسلة حفظ كاملة.
- التعمق في القطع الأثرية - أنظمة الملفات والذاكرة والسجل والسجلات وحالات التكوين - لإعادة بناء ما حدث ومتى بالضبط.
- ربط تتبع نقاط النهاية والشبكة والهوية في صورة متماسكة لسلوك المهاجم والوصول إلى النظام.
- بناء سير عمل مدعوم بالذكاء الاصطناعي يعمل على أتمتة جمع الأدلة واكتشاف الأنماط وإنشاء الخط الزمني لتوسيع نطاق القدرة الاستقصائية.
- ترجمة النتائج التقنية إلى روايات زمنية واضحة لأصحاب المصلحة التنفيذيين ومتعددي الوظائف - دون غموض أو مصطلحات معقدة.
- إغلاق الحلقة: تغذية نتائج التحقيق في قواعد الكشف وضوابط الوصول وتحسينات السياسات.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني أو العلاقات الدولية أو علوم الحاسب أو مجال ذي صلة.
- خبرة لا تقل عن 3 سنوات في التحقيقات الرقمية أو الاستجابة للحوادث أو تحقيقات الأمن، مع سجل حافل في قيادة أو تنسيق عمليات DFIR.
- مهارات استثنائية في التواصل الكتابي والشفوي باللغتين الإنجليزية والعربية.
- إتقان عملي لأدوات التحقيقات الرقمية: FTK، X-Ways، Cellebrite، Axiom أو منصات مكافئة.
- إلمام قوي ببروتوكولات الشبكة (TCP/IP، HTTP/S، DNS) وتحليل السجلات عبر منصات SIEM.
- القدرة على كتابة النصوص البرمجية بلغة Python أو PowerShell أو Bash - تُستخدم لأتمتة معالجة الأدلة وليس فقط نظريًا.
- معرفة عملية عميقة ببيئات Windows وmacOS وLinux/Unix على مستوى القطع الأثرية والنظام.
- خبرة مثبتة في دمج أدوات الذكاء الاصطناعي في سير العمل الاستقصائي لتسريع الفرز أو اكتشاف الأنماط أو إعداد التقارير.
- مُتواصِل واضح وواثق - قادر على إيجاز المسؤولين التنفيذيين والعمل جنبًا إلى جنب مع فرق الشؤون القانونية والموارد البشرية والامتثال دون فقدان الدقة التقنية.
- الامتثال: ضمان توافق جميع العمليات مع لوائح الهيئة الوطنية للأمن السيبراني (NCA ECC) وإطار عمل البنك المركزي السعودي (SAMA CSF).
- الشهادات (مفضلة للغاية): SANS / GIAC (GCFA, GCFE, GNFA, GCIA أو ما يعادلها)، IACIS CFCE، EC-Council CHFI، Offsec (OSDA, OSIR).
المزايا
- تأثير مُهم - بناء منتجات تشكل مستقبل الأمن السيبراني وتحمي المؤسسات عالميًا.
- تعاون في الموقع - كن في قلب الابتكار في مكتبنا بالرياض، وعمل جنبًا إلى جنب مع خبراء شغوفين.
- نمو مستمر - الوصول إلى الشهادات والتدريبات والفرص لصقل خبراتك.
- عقلية الملكية - استفد من برنامج خيارات أسهم الموظفين (ESOP) وانمو مع نجاح COGNNA.
- ثقافة الثقة - نحن نُمكّن المواهب، ونشجع الملكية، ونحتفل بالنتائج الحقيقية.
عرض النص الأصلي للإعلان
- Own end-to-end forensic investigations across endpoints, cloud platforms, and network infrastructure - from initial triage to root cause, including IoC identification, data exfiltration, and unauthorized access
- Coordinate and lead the DFIR team across active investigations, ensuring consistent methodology, evidence integrity, and investigative velocity
- Pull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateway platforms to reconstruct precise attack and user activity timelines
- Acquire forensic images from laptops, mobile devices, servers, and cloud repositories with full chain of custody
- Go deep on artifacts - file systems, memory, registry, logs, config states - to reconstruct exactly what happened and when
- Correlate endpoint, network, and identity telemetry into a coherent picture of attacker behavior and system access
- Build AI-assisted workflows that automate evidence collection, pattern detection, and timeline generation to scale investigative capacity
- Translate technical findings into clear, chronological narratives for executives and cross-functional stakeholders - no jargon, no ambiguity
- Close the loop: feed investigation outcomes back into detection rules, access controls, and policy improvements
🎓 Education
- Bachelor's in Cybersecurity, International Relations, Computer Science, or related field
- 3+ years in digital forensics, incident response, or security investigations, with a track record leading or coordinating DFIR engagements
- Exceptional written and verbal communication in both English & Arabic
- Hands-on proficiency with forensic tooling: FTK, X-Ways, Cellebrite, Axiom, or equivalent platforms
- Strong command of network protocols (TCP/IP, HTTP/S, DNS) and log analysis across SIEM platforms
- Scripting ability in Python, PowerShell, or Bash - used to automate evidence processing, not just theoretically
- Deep working knowledge of Windows, macOS, and Linux/Unix environments at the artifact and system level
- Proven experience integrating AI tools into investigative workflows to accelerate triage, pattern detection, or reporting
- Clear, confident communicator - able to brief executives and work alongside legal, HR, and compliance teams without losing technical precision
- Compliance: Ensuring all operations align with NCA ECC and SAMA CSF regulations
- SANS / GIAC (GCFA, GCFE, GNFA, GCIA or similar)
- IACIS CFCE
- EC-Council CHFI
- Offsec (OSDA, OSIR)
🚀 Impact that Matters - Build products that shape the future of cybersecurity and protect organizations globally.
🏢 On-Site Collaboration - Be at the heart of innovation in our Riyadh office, working side by side with passionate experts.
💡 Continuous Growth - Access to certifications, trainings, and opportunities to sharpen your expertise.
📈 Ownership Mindset - Benefit from our ESOP program and grow with COGNNA's success.
🤝 Culture of Trust - We empower talent, encourage ownership, and celebrate real outcomes.
المصدر: LinkedIn - أُضيفت للموقع في 17 أغسطس 2026