freehire launches on Product Hunt on 26 August.

Follow →

Threat Detection

Open 44d

Description

As a threat detection co-op at Cognna, you’ll design high-impact detection strategies, build powerful automation, and elevate SOC operations to a world-class standard. You’ll also mentor rising cyber talent and collaborate with teams across threat intel, incident response, and platform engineering.

Advanced threat detection engineering

  • Build high-fidelity correlation rules and behavioral detections within the Cognna security platforms.
  • Translate adversary TTPs (MITRE ATT&CK), threat intel, and vulnerability data into actionable logic.
  • Identify detection gaps and introduce new data sources to cover evolving threat landscapes.
  • Automate detection testing and maintain detection quality over time.

Platform engineering & optimization

  • Lead architecture and optimization of XDR, SIEM, and SOC tech stacks for scale and resilience.
  • Streamline log ingestion pipelines — from parsing to normalization and enrichment.
  • Build scripts and automations (Python, PowerShell) to enhance SOC efficiency.
  • Integrate tools across the SOC stack to enable seamless workflows and response.

Threat hunting & incident response

  • Collaborate with intel and IR teams to enrich detection use cases and support threat hunts.
  • Provide Tier-3+ support for incident investigations and post-mortem analysis.

Mentorship & SOC maturity

  • Improve SOC playbooks, SOPs, and detection engineering workflows.
  • Stay updated on global and regional threats — and evolve detection accordingly.
  • Ensure compliance alignment (e.g., NCA ECC, SAMA CSF).

Requirements

Minimum requirements (must haves):

  • Education: Currently enrolled in their final year of a bachelor’s degree in computer science, cybersecurity, information technology, or a closely related field, with graduation planned within or immediately following the 6-month co-op.
  • Foundational security knowledge: Basic understanding of cybersecurity concepts, including common attack vectors, the Windows/Linux operating system internals, and network protocols.
  • Programming/scripting basics: Familiarity with writing simple scripts in Python or PowerShell to automate repetitive tasks or parse data.
  • Log & system familiarity: Basic understanding of what logs are (e.g., Windows Event Logs, Syslog) and an interest in how they are collected and analyzed.
  • Duration: Availability to commit to a full-time (or near full-time, depending on university rules) 6-month continuous co-op assignment.

Preferred qualifications (nice to haves / big plusses):

  • Framework familiarity: Conceptual knowledge of the MITRE ATT&CK framework and how it maps to adversary behaviors.
  • Hands-on exposure: Previous experience using SIEM/XDR platforms, or building a home lab (e.g., Splunk, Elastic, Wireshark).
  • Regulatory awareness: A general awareness of cybersecurity frameworks or local compliance standards (like NCA ECC or SAMA CSF).
  • Soft skills: Strong analytical mindset, a high level of curiosity to dig into threat trends, and excellent written documentation skills.

Benefits

  • Impact that matters – build products that shape the future of cybersecurity and protect organizations globally.
  • On-site collaboration – be at the heart of innovation in our Riyadh office, working side by side with passionate experts.
  • Continuous growth – access to certifications, trainings, and opportunities to sharpen your expertise.
  • Culture of trust – we empower talent, encourage ownership, and celebrate real outcomes.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available