img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About Tabby

Tabby is a FinTech company that provides financial freedom through its shopping, earning, and saving solutions. With over 25 million users, Tabby enables customers to manage their spending effectively. The company's primary offering allows shoppers to split payments online and in-store without interest or fees. Over 70,000 global brands and small businesses, including Amazon, Noon, IKEA, and SHEIN, utilize Tabby to enhance growth and customer loyalty through flexible payment options. Tabby generates over $18 billion in annual transaction volume for its partners and is recognized as a leading FinTech in the GCC region. Established in 2019, Tabby has secured over $1 billion in equity and debt funding, achieving a valuation of $ billion.

The Role of Information Security Engineer

As an Information Security Engineer, you will be responsible for monitoring and defending Tabby's infrastructure, applications, and cloud environments against cyber threats. This full-time role involves leading incident response efforts, developing and refining detection rules, investigating security events, and collaborating with various teams to enhance the overall security posture of the organization. The position requires 2-5 years of relevant experience.

Key Responsibilities

  • Monitor and analyze logs and alerts from diverse sources, including firewalls, intrusion detection/prevention systems (IDS/IPS), endpoints, servers, and cloud platforms.
  • Correlate events from multiple sources to identify advanced threats and unusual behavioral patterns.
  • Fine-tune alert thresholds and detection logic to reduce false positives and improve the signal-to-noise ratio.
  • Maintain dashboards and reporting to provide real-time visibility into the security posture.
  • Serve as a frontline responder for security incidents, managing them through their lifecycle: detection, containment, eradication, recovery, and lessons learned.
  • Coordinate with internal stakeholders and external vendors during high-severity incidents or data breaches.
  • Perform root cause analysis and forensic investigations using endpoint and network-based artifacts.
  • Maintain detailed incident documentation and contribute to post-mortem analysis and reports.
  • Research emerging threats and trends.
  • Contribute to the creation and tuning of detection rules, threat-hunting queries, and use cases across multiple platforms, including cloud environments.
  • Maintain the Cyber Threat Intelligence (CTI) Platform and integrate CTI feeds with security controls for active CTI-driven detections.

Collaboration and Communication

  • Communicate effectively with cross-functional teams, including IT, DevOps, Risk, and Compliance, during incidents and investigations.
  • Provide concise and clear updates to stakeholders and management during incident handling.
  • Mentor junior analysts and assist in training efforts within the Security Operations Center (SOC) team.

Experience Required

Candidates should possess 2-5 years of experience in information security, with a focus on monitoring, detection, and incident response.

Work Type

This is a full-time position.


Requirements

  • No experience required

Similar Jobs