
Analyst, Information Security📣 Job Ad
| Contract Type | Full-time | |
| Workplace type | On-site | |
| Location | Riyadh |
About the Role
Tabby is seeking a motivated and detail-oriented Analyst, Information Security to join our InfoSec Monitoring department. This full-time position is based in Riyadh, Saudi Arabia, and is suitable for recent graduates or individuals with 0-1 years of experience looking to establish a career in cybersecurity within the Fintech sector. The Analyst will collaborate with senior security architects and engineers, gaining practical experience in defensive security areas including infrastructure protection, cloud security, secure software development, and incident response.
As a foundational member of the defensive security team, this role offers an opportunity to develop technical depth and cross-functional collaboration skills. You will contribute to securing cloud environments, maintaining endpoint protection, supporting secure development practices, and assisting in security monitoring and incident response activities, preparing you for growth into a security engineer role.
Key Responsibilities
- Assist senior architects in documenting and maintaining security architecture designs for IT projects, ensuring alignment with organizational security standards and regulatory requirements.
- Support the review of proposed system designs and configurations against established security baselines, flagging gaps for senior review.
- Help maintain up-to-date architecture diagrams, design documentation, and security control mappings across assigned systems and platforms.
- Participate in cross-functional meetings with IT, DevOps, and Risk Management teams as an observer and note-taker.
- Assist in monitoring cloud environments (GCP/AWS) for misconfigurations and security posture issues using Cloud Security Posture Management (CSPM) tools.
- Support the review and documentation of cloud infrastructure configurations (*, GCP, Terraform, Kubernetes) against security best practices.
- Help track and document CI/CD pipeline security findings and assist in preparing remediation recommendations.
- Learn and apply foundational cloud security concepts including identity and access management, network segmentation, and secrets management.
- Assist in integrating and operating security tools within CI/CD pipelines (*, SAST, DAST, dependency scanning).
- Help review and triage automated security scan results from SAST and DAST tools, categorizing findings and escalating critical issues.
- Support source code review activities by following established checklists and flagging common vulnerability patterns (*, OWASP Top 10).
- Assist in maintaining documentation of security checkpoints and tool configurations across the development pipeline.
- Assist in executing pre-defined vulnerability assessment test cases for web, mobile, API, and infrastructure targets under senior supervision.
- Support infrastructure vulnerability scanning activities using approved tools, helping to collect, organize, and document scan outputs.
- Help maintain the vulnerability register by tracking identified findings, their severity, assigned owners, and remediation status.
- Assist in re-testing patched vulnerabilities to confirm effective remediation, documenting results.
- Assist in the administration and monitoring of enterprise endpoint protection solutions (AV/EDR), including alert triage and basic incident escalation.
- Support infrastructure security reviews by gathering configuration data, running approved audit scripts, and documenting findings against security baselines.
- Help maintain firewall ruleset documentation and assist in identifying outdated or unnecessary rules.
- Support Data Loss Prevention (DLP) monitoring activities, escalating triggered alerts per defined procedures.
- Assist in backup and disaster recovery documentation, helping verify that recovery procedures are current and accurately recorded.
- Assist in developing and maintaining security assessment checklists and testing models for application security, network architecture reviews, and configuration audits.
- Support project management activities by tracking security-related tasks, action items, and remediation tickets across DevOps and engineering teams.
- Help prepare status updates and progress reports on security control implementation for review by senior staff.
- Assist in prioritizing security bugs and features by gathering data and supporting triage discussions.
- Assist in the planning and execution of phishing simulation campaigns by helping configure scenarios, distribute materials, and collect results data.
- Support the preparation and delivery of security awareness training materials and communication content.
- Assist in security monitoring activities by reviewing alerts from SIEM and other monitoring platforms, escalating anomalies per defined playbooks.
- Help maintain and update incident response playbooks and procedure documentation.
- Support threat intelligence gathering from internal and publicly available sources, summarizing findings for the security team.
- Assist in developing and tuning basic detection rules.
Qualifications and Requirements
- Bachelor's degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, or a related field.
- Academic projects, capstone work, or self-directed labs involving networking, cloud, or application security are considered favorably.
- Internship, academic project, or personal lab experience related to cybersecurity, networking, or software development is an advantage.
- Exposure to regulated environments (Fintech, banking) is a plus but not required.
Required Skills
- Proficiency with Cloud Security Posture Management (CSPM) tools.
- Familiarity with cloud platforms such as GCP and AWS.
- Experience with infrastructure as code tools like Terraform.
- Understanding of containerization technologies like Kubernetes.
- Knowledge of CI/CD pipelines and associated security tools (SAST, DAST).
- Familiarity with OWASP Top 10 vulnerabilities.
- Experience with endpoint protection solutions including AV/EDR.
- Understanding of firewall configurations.
- Knowledge of Data Loss Prevention (DLP) principles.
- Familiarity with backup and disaster recovery processes.
- Understanding of SIEM systems for security monitoring.
- Experience with phishing simulation campaigns.
- Ability to gather and summarize threat intelligence.
- Strong communication skills.
- Effective teamwork and collaboration abilities.
- Solid problem-solving capabilities.
Work Environment and Experience
This is a full-time position located in Riyadh, Saudi Arabia. Recent graduates and individuals with 0-1 years of experience are encouraged to apply, as no prior professional experience is required. The role offers exposure to a fast-paced Fintech environment.
Requirements
- No experience required
Similar Jobs
You may also like
- Related Analyst, Information Security Opportunities
- Business Development Manager Jobs in Riyadh
- Sales Manager Jobs in Riyadh
- Digital Marketing Specialist Jobs in Riyadh
- Sales Representative Jobs in Riyadh
- Marketing Specialist Jobs in Riyadh
- Other Job Fields in Riyadh
- Business Development Manager Jobs in Riyadh
- Sales Manager Jobs in Riyadh
- Digital Marketing Specialist Jobs in Riyadh
- Sales Representative Jobs in Riyadh
- Marketing Specialist Jobs in Riyadh
- Executive Assistant Jobs in Riyadh
- Human Resources Specialist Jobs in Riyadh
- Truck Driver Jobs in Riyadh
- Logistics Pricing & Sales Support Coordinator Jobs in Riyadh
- Sales Specialist Jobs in Riyadh
- Explore Jobs Across Saudi Arabia
- Business Development Manager Jobs in Jeddah
- Project Coordinator Jobs in Jeddah
- Housekeeper Jobs in Al Khobar
- Cashier Jobs in Abu Arish
- Sales Engineer Jobs in Dhahran
- Supply Manager Jobs in Dammam
- Quality Controller Jobs in Sakaka
- Public Relations Specialist Jobs in Taif
- Assistant Branch Manger Jobs in Makkah
- Legal Secretary Jobs in Riyadh