img
Contract TypeInternship
Workplace typeOn-site
LocationRiyadh

Job Description

About the Information Security Internship

Tabby | تابي is seeking an Information Security Intern to join its team in Riyadh. This is a paid internship designed for early-career engineers, offering real engineering responsibilities within a high-load, security-critical environment with strict regulatory requirements. The Information Security function is crucial for protecting Tabby's mobile applications, backend services, payment integrations, and cloud infrastructure.

This program is structured as an engineering role, not solely educational, and interns are expected to contribute to production tasks under senior review from day one.

Role Context and Tracks

Information Security at Tabby covers two primary, complementary tracks. Candidates will be matched to the track that best fits their skills and interests during the interview process:

  • Vulnerability Assessment & Penetration Testing (VAPT): Focuses on application security testing, security architecture reviews, threat modeling, secure code review, vulnerability triage, and incident response.
  • Governance, Risk & Compliance (GRC): Involves policy and control frameworks, compliance program support (PCI DSS, ISO 27001, SAMA), risk assessments, audit support, vendor security reviews, and security awareness.

Interns will be embedded within the security team, working closely with product engineering, risk engineering, and platform / SRE teams.

Key Responsibilities

Interns will work on real production tasks under senior review. Specific responsibilities vary by track:

  • On the VAPT track:
    • Triage findings from SAST, DAST, SCA, and dependency scanners across mobile and backend repositories.
    • Reproduce and document vulnerabilities; write clear remediation tickets for product teams.
    • Contribute to secure code reviews on selected merge requests (*, authentication, input validation, data handling).
    • Participate in threat-modeling sessions for new features and produce write-ups.
    • Run scoped assessments against staging environments under senior sign-off.
    • Assist in maintaining security tooling: scanner configurations, baseline rules, dashboards, and false-positive triage queues.
    • Support security checks during release cycles.
    • Contribute to DevSecOps: security gates in CI/CD pipelines, and dependency and container image scanning.
    • Gain exposure to logging, monitoring, and alert triage workflows alongside the SOC.
    • Participate in incident response exercises and post-mortems alongside senior engineers.
  • On the GRC track:
    • Support compliance programs against frameworks like PCI DSS, ISO 27001, and SAMA: evidence collection, control mapping, and gap analysis.
    • Assist in maintaining security policies, standards, and procedures across domains (*, access control, cryptography, asset management, change management, third-party security, vulnerability management, awareness and training).
    • Contribute to risk assessments: risk registers, control testing, and treatment plans.
    • Support vendor and third-party security assessments.
    • Help prepare for internal and external audits: workpapers, evidence packages, and response coordination.
    • Contribute to security awareness content, training rollouts, and metrics tracking.
    • Work alongside engineering teams to translate policy requirements into concrete technical controls.
  • On both tracks, interns will:
    • Collaborate with risk and platform engineers on PII handling, secrets management, and encryption reviews.
    • Contribute to the internal security knowledge base (runbooks, playbooks, and awareness content).

Eligibility and Program Details

  • This internship is open to Saudi nationals only; a Saudi passport is required.
  • Candidates should have 0-1 years of experience.
  • Both current students and recent graduates are welcome to apply.
  • The program is a paid internship, self-funded by Tabby.
  • A full-time level of engagement is expected throughout the internship, requiring contribution at a full working-day pace. Flexibility for classes or exams may be arranged with a mentor in advance.

Location and Work Arrangement

  • The primary location for this role is Riyadh, with an office-first approach where possible.
  • The engineering team is distributed across multiple countries, and location may be flexible, allowing candidates to be based outside KSA.
  • Interns will be fully integrated into the Information Security team.

Career Progression

This demanding internship is designed for candidates seeking fast professional growth in information security within a regulated fintech environment. There is a clear path to a Junior Information Security Engineer role based on performance.


Requirements

  • For Saudis Only
  • No experience required

Similar Jobs