
Analyst, Information Security📣 Job Ad
| Contract Type | Full-time | |
| Workplace type | On-site | |
| Location | Riyadh |
About the Role
Tabby is seeking a motivated Analyst, Information Security to join its growing team in Riyadh, Saudi Arabia. This full-time position is designed for recent graduates and individuals with 0-1 years of experience looking to establish a foundational career in defensive cybersecurity within the fast-paced Fintech environment. As a member of the InfoSec Monitoring department, you will work under the guidance of senior security architects and engineers, gaining exposure to critical security functions.
This role provides comprehensive experience across infrastructure security, cloud security, secure software development lifecycle (SDLC) practices, and security monitoring. You will contribute to the organization's security architecture and infrastructure protection, safeguarding systems and data while developing the technical depth and collaborative skills necessary for growth into a security engineer role.
Key Responsibilities
- Assist senior architects in documenting and maintaining security architecture designs for IT projects, ensuring alignment with security standards and regulatory requirements.
- Support the review of proposed system designs and configurations against established security baselines and flag gaps for senior review.
- Help maintain up-to-date architecture diagrams, design documentation, and security control mappings across assigned systems and platforms.
- Participate in cross-functional meetings with IT, DevOps, and Risk Management teams as an observer and note-taker, gaining exposure to security strategy discussions.
- Assist in monitoring cloud environments (GCP/AWS) for misconfigurations and security posture issues using Cloud Security Posture Management (CSPM) tools.
- Support the review and documentation of cloud infrastructure configurations (*, GCP, Terraform, Kubernetes) against security best practices under senior guidance.
- Help track and document CI/CD pipeline security findings and assist in preparing remediation recommendations for engineering teams.
- Learn and apply foundational cloud security concepts including identity and access management, network segmentation, and secrets management in cloud-native environments.
- Assist in integrating and operating security tools within CI/CD pipelines (*, SAST, DAST, dependency scanning) under the direction of senior engineers.
- Help review and triage automated security scan results from SAST and DAST tools, categorizing findings and escalating critical issues for senior review.
- Support source code review activities by following established checklists and flagging common vulnerability patterns (*, OWASP Top 10) for senior validation.
- Assist in maintaining documentation of security checkpoints and tool configurations across the development pipeline.
- Assist in executing pre-defined vulnerability assessment test cases for web, mobile, API, and infrastructure targets under close senior supervision.
- Support infrastructure vulnerability scanning activities using approved tools, helping to collect, organize, and document scan outputs.
- Help maintain the vulnerability register by tracking identified findings, their severity, assigned owners, and remediation status.
- Assist in re-testing patched vulnerabilities to confirm effective remediation, documenting results accurately.
- Assist in the administration and monitoring of enterprise endpoint protection solutions (AV/EDR), including alert triage and basic incident escalation.
- Support infrastructure security reviews by gathering configuration data, running approved audit scripts, and documenting findings against security baselines.
- Help maintain firewall ruleset documentation and assist in identifying outdated or unnecessary rules for senior review.
- Support Data Loss Prevention (DLP) monitoring activities, escalating triggered alerts per defined procedures.
- Assist in backup and disaster recovery documentation, helping verify that recovery procedures are current and accurately recorded.
- Assist in developing and maintaining security assessment checklists and testing models for application security, network architecture reviews, and configuration audits.
- Support project management activities by tracking security-related tasks, action items, and remediation tickets across DevOps and engineering teams.
- Help prepare status updates and progress reports on security control implementation for review by senior staff.
- Assist in prioritizing security bugs and features by gathering data and supporting triage discussions led by senior engineers.
- Assist in the planning and execution of phishing simulation campaigns by helping configure scenarios, distribute materials, and collect results data.
- Support the preparation and delivery of security awareness training materials and communication content.
- Assist in security monitoring activities by reviewing alerts from SIEM and other monitoring platforms, escalating anomalies per defined playbooks.
- Help maintain and update incident response playbooks and procedure documentation under senior direction.
- Support threat intelligence gathering from internal and publicly available sources, summarizing findings for the security team.
- Assist in developing and tuning basic detection rules under the guidance of senior security engineers.
Qualifications and Requirements
- Bachelor's degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, or a related field.
- Academic projects, capstone work, or self-directed labs involving networking, cloud, or application security will be considered favorably.
- Internship, academic project, or personal lab experience related to cybersecurity, networking, or software development is a strong advantage.
- Exposure to regulated environments (Fintech, banking) is a plus but not required.
Required Skills
- Cloud Security
- Security Monitoring
- Incident Response
- Infrastructure Security
- Endpoint Protection
- Secure Software Development Lifecycle (SDLC)
- Cloud Security Posture Management (CSPM)
- CI/CD
- SAST and DAST
- Vulnerability Assessment
- Firewall Ruleset Management
- Data Loss Prevention (DLP)
- Backup and Disaster Recovery
- Security Awareness
- Threat Intelligence
- SIEM
Work Environment and Details
This is a full-time position based in Riyadh, Saudi Arabia. Recent graduates and individuals with 0-1 years of experience are encouraged to apply, with no prior professional experience required.
Requirements
- No experience required
Similar Jobs
You may also like
- Related Analyst, Information Security Opportunities
- Sales Manager Jobs in Riyadh
- Real Estate Marketer Jobs in Riyadh
- Sales Supervisor Jobs in Riyadh
- Teleseller Jobs in Riyadh
- Content Creator Jobs in Riyadh
- Other Job Fields in Riyadh
- Sales Manager Jobs in Riyadh
- Real Estate Marketer Jobs in Riyadh
- Sales Supervisor Jobs in Riyadh
- Teleseller Jobs in Riyadh
- Content Creator Jobs in Riyadh
- Cafe Manager Jobs in Riyadh
- Administrative Assistant Jobs in Riyadh
- Sales Representative Jobs in Riyadh
- Marketing Specialist Jobs in Riyadh
- Sales Specialist Jobs in Riyadh
- Explore Jobs Across Saudi Arabia
- Direct Seller Jobs in Jeddah
- eCommerce Specialist Jobs in Riyadh
- Certified Trainer Jobs in Al Jubail
- Data Collector Jobs in Tabuk
- Purchase Specialist Jobs in Al Qassim
- Meal maker for a food cart Jobs in Riyadh
- Sales Manager Jobs in Hail
- Seller Jobs in Najran
- Internal Audit Manager Jobs in Riyadh
- Administrative Assistant Jobs in Jeddah