img
نوع العقددوام كامل
طبيعة الوظيفةبالموقع
الموقعالرياض

وصف الوظيفة

About Tabby

Tabby is a FinTech company focused on reshaping financial interactions for shopping, earning, and saving. The platform serves over 17 million users, enabling them to manage spending and optimize their finances. Tabby's core offering allows customers to split payments online and in-store without interest or fees. Over 40,000 global brands and small businesses, including Amazon, Noon, IKEA, and SHEIN, utilize Tabby to facilitate flexible payments, driving growth and customer loyalty. Since its launch in 2019, Tabby has raised over $1 billion in funding and is currently valued at $ billion, generating over $10 billion in annual transaction volume for its partners. It is recognized as a leading and rapidly expanding FinTech in the GCC region.

The Opportunity

Tabby is seeking a Lead Cyber Security Engineer to join the Information Security team in Riyadh. This full-time role involves providing technical leadership in defensive security, managing a team of security engineers and analysts, and driving security initiatives across the organization.

Key Responsibilities

  • Lead security architecture and design reviews for IT, cloud, and product initiatives.
  • Drive cloud security efforts across GCP and AWS, including IAM, security posture management, and infrastructure security.
  • Oversee the Secure SDLC / DevSecOps program, encompassing SAST, DAST, SCA, and container security.
  • Lead vulnerability management, penetration testing, and red team engagements.
  • Manage endpoint, infrastructure, and firewall security.
  • Drive detection engineering, threat intelligence, and complex incident response.
  • Develop and mentor a team of cybersecurity engineers and analysts.
  • Collaborate with Engineering, IT, Compliance, and other teams to enhance Tabby’s overall security posture.

Required Qualifications and Experience

  • 5-10 years of cybersecurity experience, including technical leadership or senior-level responsibilities.
  • Strong experience in security architecture, cloud security, AppSec/DevSecOps, and vulnerability management.
  • Hands-on understanding of offensive and defensive security, including penetration testing, red/purple teaming, and incident response.
  • Experience with SIEM, EDR/XDR, CSPM, DLP, and vulnerability management platforms.
  • Strong knowledge of GCP/AWS, IAM, Terraform, Kubernetes, and CI/CD security.
  • Experience with SAST, DAST, SCA, and secure SDLC practices.
  • Knowledge of SAMA CSF, NCA ECC, PCI-DSS, and ISO 27001.
  • CISSP/CISM and OSCP or equivalent certifications are required.

Skills and Attributes

  • Strong technical leadership abilities.
  • Proven stakeholder management skills.
  • Demonstrated capability in team development and mentorship.

Work Location

This position is based in Riyadh.


متطلبات الوظيفة

  • تتطلب ٥-١٠ سنوات خبرة

وظائف مشابهة