At least 5 years of solid, hands-on experience in cybersecurity.
Minimum 2 years of direct involvement in incident response, digital forensics, or malware analysis.
Alternatively, visible public research or open-source projects in DFIR or malware analysis are perfectly acceptable — we value results over titles.
Strong technical foundation in Windows, Linux, and network investigations.
Comfortable using tools like NetWitness, Volatility, Velociraptor, or your own custom scripts.
Scripting skills in Python, PowerShell, or Bash – bonus points if you’ve written something that made your teammates both grateful and slightly afraid.
SANS certifications (GCFA, GREM, GNFA, GCFE, etc.) are definite pluses, as is a calm demeanor during incidents that make others panic.
Fluency in English; Arabic proficiency is a welcome advantage.