{"id":1173353,"url":"https://alion.io/job/cognna-senior-threat-detection-engineer-madinah","title":"Senior Threat Detection Engineer - Madinah","company":{"id":674261,"name":"COGNNA","domain":"cognna.com","url":"https://alion.io/company/cognna","size_band":null,"is_staffing_agency":false,"is_intermediary":false,"listed_via":null,"ats_vendor":"Workable","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Medina, Saudi Arabia"],"countries":["SA"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":52000,"max_usd":117000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":1098},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Linux","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"Platform Engineering","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"SIEM","optional":false},{"name":"Windows","optional":false},{"name":"Wireshark","optional":false}],"status":"live","first_seen_at":"2026-09-24T09:19:23Z","employer_posted_date":"2026-09-24","last_verified_at":"2026-09-24T20:34:25Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"As a Threat Detection Engineer at COGNNA, you’ll design high-impact detection strategies, build powerful automation, and elevate SOC operations to a world-class standard. You’ll also mentor rising cyber talent and collaborate with teams across threat intel, incident response, and platform engineering.\nAdvanced Threat Detection Engineering\nBuild high-fidelity correlation rules and behavioral detections within the COGNNA security platforms.\nTranslate adversary TTPs (MITRE ATT&CK), threat intel, and vulnerability data into actionable logic.\nIdentify detection gaps and introduce new data sources to cover evolving threat landscapes.\nAutomate detection testing and maintain detection quality over time.\nPlatform Engineering & Optimization\nLead architecture and optimization of XDR, SIEM, and SOC tech stacks for scale and resilience.\nStreamline log ingestion pipelines - from parsing to normalization and enrichment.\nBuild scripts and automations (Python, PowerShell) to enhance SOC efficiency.\nIntegrate tools across the SOC stack to enable seamless workflows and response.\nThreat Hunting & Incident Response\nCollaborate with intel and IR teams to enrich detection use cases and support threat hunts.\nProvide Tier-3+ support for incident investigations and post-mortem analysis.\nMentorship & SOC Maturity\nImprove SOC playbooks, SOPs, and detection engineering workflows.\nStay updated on global and regional threats - and evolve detection accordingly.\nEnsure compliance alignment (e.g., NCA ECC, SAMA CSF).\nRequirements\nEducation\nBachelor’s in Computer Science, Cybersecurity, or related field.\nExperience\nMinimum 3 years of experience with hands-on expertise in developing and maintaining complex detection use cases.\nStrong understanding of attacker behavior, IR fundamentals, and digital forensics.\nTechnical Skills (You’re a Power User!)\nSIEM: Expert in SIEM queries (SPL, KQL, Lucene), rule tuning, UEBA, and scaling.\nEDR: Deep knowledge of EDR tools and endpoint detection tactics.\nNetwork Security: Pro at packet analysis (Wireshark), IDS/IPS, and NetFlow.\nScripting: Advanced skills in Python and/or PowerShell for automation and integration.\nOS Internals: Mastery of Windows/Linux/macOS logging, artifacts, and forensic value.\nThreat Intelligence: Skilled in turning threat intel into real-time detection logic.\nCloud Security: Strong command of monitoring IaaS/PaaS/SaaS environments.\nCertifications (Highly Preferred)\n SANS GIAC (GDAT, GMON, GCIA, GCTI, GCIH)\n Offsec (OSDA)\n INE (eCTHP, eCIR)\n (ISC)² CISSP, CSSLP\nSoft Skills\nExceptional analytical thinking and creative problem-solving.\nExcellent communication (English & Arabic), including technical reporting.\nStrong mentorship abilities and a collaborative spirit.\nSelf-motivated, focused, and passionate about cyber defense.\nCapable of juggling priorities under high-pressure situations.\nBenefits\nImpact that Matters - Build products that shape the future of cybersecurity and protect organizations globally.\nOn-Site Collaboration - Be at the heart of innovation in our Almadina office, working side by side with passionate experts.\nContinuous Growth - Access to certifications, trainings, and opportunities to sharpen your expertise.\nOwnership Mindset - Benefit from our ESOP program and grow with COGNNA’s success.\nCulture of Trust - We empower talent, encourage ownership, and celebrate real outcomes.","description_format":"text","description_chars":3373,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[{"language":"English","level":"All levels","optional":false}]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Security Operations","Embedded Systems","Semiconductors","Incident Response"],"lifecycle":[{"event":"open","at":"2026-09-24T09:19:23Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":24,"reasons":["conf:1","win:early"],"computed_at":"2026-09-24T21:59:40Z"},"pay":null,"html_url":"https://alion.io/job/cognna-senior-threat-detection-engineer-madinah","json_url":"https://alion.io/job/cognna-senior-threat-detection-engineer-madinah.json","meta":{"generated_at":"2026-09-24T21:59:40Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"subnet","units_charged":1,"used_today":295,"day_limit":5000,"remaining_today":4705,"minute_limit":60,"resets_at":"2026-09-25T00:00:00Z"}}}