img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About Tabby

Tabby is a FinTech company focused on providing financial freedom through shopping, earning, and saving solutions. With over 17 million users, Tabby enables control over spending and optimizes financial management. The company's core offering allows customers to split payments online and in-store without interest or fees, serving over 40,000 brands including Amazon, Noon, IKEA, and SHEIN. Tabby generates over $10 billion in annual transaction volume and is recognized as a leading FinTech in the GCC region, having launched in 2019 and secured over $1 billion in funding, valuing the company at $ billion.

The Opportunity: Lead, Information Security (Defensive)

Tabby is seeking a Lead, Information Security (Defensive) to join the Information Security team in Riyadh. This full-time role involves providing technical leadership in defensive security, managing a team of security engineers and analysts, and driving security initiatives across the organization. The successful candidate will play a key role in enhancing Tabby's overall security posture.

Key Responsibilities

  • Lead security architecture and design reviews across IT, cloud, and product initiatives.
  • Drive cloud security efforts for GCP and AWS, including IAM, security posture management, and infrastructure security.
  • Oversee the Secure SDLC / DevSecOps program, encompassing SAST, DAST, SCA, and container security.
  • Lead vulnerability management, penetration testing, and red team engagements.
  • Manage endpoint, infrastructure, and firewall security.
  • Drive detection engineering, threat intelligence, and complex incident response.
  • Develop and mentor a team of cybersecurity engineers and analysts.
  • Collaborate with Engineering, IT, Compliance, and other teams to enhance Tabby’s security posture.

Required Qualifications and Experience

  • 5-10 years of experience in information security, with a focus on defensive strategies.
  • Demonstrated technical leadership in cybersecurity.
  • Experience managing security teams and driving security initiatives.
  • Proficiency in cloud security principles and practices, particularly with GCP and AWS.
  • Strong understanding of Secure SDLC / DevSecOps methodologies and tools.
  • Expertise in vulnerability management, penetration testing, and incident response.

Work Location

This role is based in Riyadh and is a full-time position.

Application Process

Candidates interested in this role are encouraged to apply.


Requirements

  • Requires 5-10 Years experience

Similar Jobs