Staff DFIR
COGNNA
5–10 years of experience
Who We Are COGNNA is shaping the future of cybersecurity through innovation, intelligence, and a relentless drive to protect. Our platforms integrate cutting-edge AI, real-time threat detection, and deep security insights to help organizations proactively defend against evolving cyber threats. Responsibilities Own end-to-end forensic investigations across endpoints, cloud platforms, and network infrastructure from initial triage to root cause, including IoC identification, data exfiltration, and unauthorized access Coordinate and lead the DFIR team across active investigations, ensuring consistent methodology, evidence integrity, and investigative velocity Pull and analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateway platforms to reconstruct precise attack and user activity timelines Acquire forensic images from laptops, mobile devices, servers, and cloud repositories with full chain of custody Go deep on artifacts file systems, memory, registry, logs, config states to reconstruct exactly what happened and when Correlate endpoint, network, and identity telemetry into a coherent picture of attacker behavior and system access Build AI-assisted workflows that automate evidence collection, pattern detection, and timeline generation to scale investigative capacity Translate technical findings into clear, chronological narratives for executives and cross-functional stakeholders no jargon, no ambiguity Close the loop: feed investigation outcomes back into detection rules, access controls, and policy improvements.