Tabby | تابي

Lead Information Security Engineer (Defensive)

Tabby | تابي

Riyadh, Riyadh Province, Saudi Arabia · Full Time

Be the first to apply

Experience
5+ yrs
Salary
Openings
1
Posted
10 seconds ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About Tabby

Tabby empowers over 17 million users by offering financial freedom through smart spending, earning, and saving options. It enables customers to pay in flexible installments with no interest or fees in-store and online, partnering with more than 40,000 brands worldwide including Amazon, Noon, IKEA, and SHEIN. Generating over $10 billion in yearly transaction volume and recognized as the largest and fastest-growing fintech in the GCC, Tabby was founded in 2019 and has secured over $1 billion in funding, with a current valuation of $4.5 billion.

Role Overview

We are seeking a Lead Cybersecurity Engineer to join our Information Security team in Riyadh. The role involves leading defensive security efforts, managing a team of security professionals, and steering security initiatives across various departments.

Key Responsibilities

  • Lead architecture and design security reviews for IT, cloud, and product projects.
  • Manage cloud security across Google Cloud Platform (GCP) and AWS, focusing on Identity and Access Management, security posture, and infrastructure protection.
  • Own and drive the Secure Software Development Lifecycle and DevSecOps practices, including static and dynamic application security testing, software composition analysis, and container security.
  • Lead vulnerability management initiatives and coordinate penetration testing and red team operations.
  • Oversee security measures for endpoints, infrastructure, and firewalls.
  • Guide detection engineering, threat intelligence activities, and handle complex incident response.
  • Provide mentorship and development to cybersecurity engineers and analysts.
  • Collaborate with Engineering, IT, Compliance, and other teams to enhance the overall security posture of the organization.

Qualifications and Expertise

  • Minimum 5 years of experience in cybersecurity, with leadership or senior-level responsibilities.
  • Proven expertise in security architecture, cloud security, application security (AppSec), DevSecOps, and vulnerability management.
  • Practical knowledge of offensive and defensive security operations including penetration testing, red and purple teaming, and incident response.
  • Experience with security platforms such as SIEM, EDR/XDR, Cloud Security Posture Management (CSPM), Data Loss Prevention (DLP), and vulnerability management tools.
  • Strong familiarity with GCP, AWS, Identity and Access Management (IAM), Terraform, Kubernetes, and CI/CD security measures.
  • Hands-on experience with SAST, DAST, SCA, and secure coding lifecycle procedures.
  • Understanding of compliance frameworks including SAMA CSF, NCA ECC, PCI-DSS, and ISO 27001.
  • Excellent leadership capability, stakeholder engagement, and team-building skills.
  • Mandatory certifications include CISSP or CISM and OSCP or their equivalents.

Tools & software

Kubernetes required Terraform required

How they work

Teamwork & Collaboration Leadership Strategic Thinking Relationship Building
🤖
Online · instant AI help
Broxer