Information Security Engineer (SOC Level 2)
Riyadh, Riyadh Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- 2–3 yrs
- Salary
- —
- Openings
- 1
- Posted
- 2 weeks ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Company and Role
Tabby is revolutionizing financial freedom by enabling shoppers to split payments without interest or fees, partnering with over 70,000 global brands such as Amazon, Noon, IKEA, and SHEIN. Established in 2019, the company has rapidly expanded, generating over $18 billion in annual transaction volume and securing valuation of $6.5 billion backed by more than $1 billion in fundings. The Information Security Engineer position based in Riyadh, Saudi Arabia, is critical for strengthening Tabby’s infrastructure, applications, and cloud environments against cyber threats.
Key Duties and Responsibilities
- Supervise and interpret logs and alerts from firewalls, IDS/IPS, endpoints, servers, and cloud platforms.
- Correlate alerts across various sources to recognize sophisticated threats and abnormal behavioral trends.
- Adjust alert parameters and detection methodologies to minimize false alarms and boost detection accuracy.
- Maintain real-time security dashboards and regular reporting to reflect the security status.
- Lead and manage the lifecycle of security incidents including detection, containment, resolution, recovery, and post-event evaluation.
- Collaborate internally and externally during high-impact incidents and data breach investigations.
- Conduct root cause and forensic analysis using endpoint and network data.
- Document incidents meticulously and assist in preparing post-incident reports.
- Stay abreast of emerging cybersecurity threats and contribute to crafting and refining detection rules and threat hunting processes across platforms.
- Maintain and integrate Cyber Threat Intelligence platforms with security controls for active detection.
- Work closely with IT, DevOps, Risk, and Compliance teams, facilitating clear communication during incidents.
- Provide mentoring and training support to junior SOC team members.
Qualifications and Experience
- 2 to 3 years of hands-on experience in SOC or cybersecurity operations, preferably within fast-moving fintech or enterprise settings.
- Deep understanding of security incident handling, alert prioritization, log analysis, and threat modeling.
- Knowledgeable about REST APIs, microservices, and advanced application architectures.
- Experience collaborating across culturally diverse teams.
- Operational familiarity with DLP, antivirus, and anti-malware monitoring.
- Exposure to phishing detection techniques, user behavior analytics, and security awareness initiatives.
- Certifications like Security+, CySA+, eCIR, eCTHPv2, GCIA, or GMON are considered an advantage but not mandatory.
- Skilled communicative abilities for incident coordination and reporting.
- Proficient in SIEM, SOAR, EDR/XDR, and Threat Intelligence platforms.
- Acquainted with cloud frameworks and native logging/monitoring tools.
- Experience scripting in Python or similar languages for task automation and efficiency enhancement.