Threat Detection Engineer - L2

🗓️ Posted 2026-09-08 Al Madinah, Eastern Province, Madinah, Al Madinah Province, Saudi Arabia, Saudi Arabia Full-time Hybrid ICT

Company shared salary

NA

Market rate

SAR 8,000–SAR 13,000/mo (SAR 96,000–SAR 156,000/yr)

Based on similar roles (title + domain + location).

Responsibilities

  • As a Threat Detection Engineer at COGNNA, you'll design high-impact detection strategies, build powerful automation, and elevate SOC operations to a world-class standard. You'll also mentor rising cyber talent and collaborate with teams across threat intel, incident response, and platform engineering.
  • Advanced Threat Detection Engineering
  • Build high-fidelity correlation rules and behavioral detections within the COGNNA security platforms.
  • Translate adversary TTPs (MITRE ATT&CK), threat intel, and vulnerability data into actionable logic.
  • Identify detection gaps and introduce new data sources to cover evolving threat landscapes.
  • Automate detection testing and maintain detection quality over time.
  • Platform Engineering & Optimization
  • Lead architecture and optimization of XDR, SIEM, and SOC tech stacks for scale and resilience.
  • Streamline log ingestion pipelines - from parsing to normalization and enrichment.
  • Build scripts and automations (Python, PowerShell) to enhance SOC efficiency.
  • Integrate tools across the SOC stack to enable seamless workflows and response.
  • Threat Hunting & Incident Response
  • Collaborate with intel and IR teams to enrich detection use cases and support threat hunts.
  • Provide Tier-3+ support for incident investigations and post-mortem analysis.
  • Mentorship & SOC Maturity
  • Improve SOC playbooks, SOPs, and detection engineering workflows.
  • Stay updated on global and regional threats - and evolve detection accordingly.
  • Ensure compliance alignment (e.g., NCA ECC, SAMA CSF).
  • Education
  • Bachelor's in Computer Science, Cybersecurity, or related field.