freehire launches on Product Hunt on 26 August.

Follow →

Threat Detection Engineer

Open 44d

Description

As a threat detection engineer at COGNNA, you’ll design high-impact detection strategies, build powerful automation, and elevate SOC operations to a world-class standard. You’ll also mentor rising cyber talent and collaborate with teams across threat intel, incident response, and platform engineering.

Advanced threat detection engineering

  • Build high-fidelity correlation rules and behavioral detections within the COGNNA security platforms.
  • Translate adversary TTPs (MITRE ATT&CK), threat intel, and vulnerability data into actionable logic.
  • Identify detection gaps and introduce new data sources to cover evolving threat landscapes.
  • Automate detection testing and maintain detection quality over time.

Platform engineering & optimization

  • Lead architecture and optimization of XDR, SIEM, and SOC tech stacks for scale and resilience.
  • Streamline log ingestion pipelines — from parsing to normalization and enrichment.
  • Build scripts and automations (Python, PowerShell) to enhance SOC efficiency.
  • Integrate tools across the SOC stack to enable seamless workflows and response.

Threat hunting & incident response

  • Collaborate with intel and IR teams to enrich detection use cases and support threat hunts.
  • Provide Tier-3+ support for incident investigations and post-mortem analysis.

Mentorship & SOC maturity

  • Improve SOC playbooks, SOPs, and detection engineering workflows.
  • Stay updated on global and regional threats — and evolve detection accordingly.
  • Ensure compliance alignment (e.g., NCA ECC, SAMA CSF).

Requirements

Education

Bachelor’s in computer science, cybersecurity, or related field.

Experience

  • Hands-on expertise in developing and maintaining complex detection use cases.
  • Strong understanding of attacker behavior, IR fundamentals, and digital forensics.

Technical skills (you’re a power user!)

  • SIEM: Expert in SIEM queries (SPL, KQL, Lucene), rule tuning, UEBA, and scaling.
  • EDR: Deep knowledge of EDR tools and endpoint detection tactics.
  • Network security: Pro at packet analysis (Wireshark), IDS/IPS, and NetFlow.
  • Scripting: Advanced skills in Python and/or PowerShell for automation and integration.
  • OS internals: Mastery of Windows/Linux/macOS logging, artifacts, and forensic value.
  • Threat intelligence: Skilled in turning threat intel into real-time detection logic.
  • Cloud security: Strong command of monitoring IaaS/PaaS/SaaS environments.

Certifications (highly preferred)

  • SANS GIAC (GDAT, GMON, GCIA, GCTI, GCIH)
  • Offsec (OSDA)
  • INE (eCTHP, eCIR)
  • (ISC)² CISSP, CSSLP

Soft skills

  • Exceptional analytical thinking and creative problem-solving.
  • Excellent communication (English & Arabic), including technical reporting.
  • Strong mentorship abilities and a collaborative spirit.
  • Self-motivated, focused, and passionate about cyber defense.
  • Capable of juggling priorities under high-pressure situations.

Benefits

  • Impact that matters – Build products that shape the future of cybersecurity and protect organizations globally.
  • On-site collaboration – Be at the heart of innovation in our Riyadh office, working side by side with passionate experts.
  • Continuous growth – Access to certifications, trainings, and opportunities to sharpen your expertise.
  • Ownership mindset – Benefit from our ESOP program and grow with COGNNA’s success.
  • Culture of trust – We empower talent, encourage ownership, and celebrate real outcomes.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available