Information Security Lead (Defensive)
Posted
Tabby creates financial freedom in the way people shop, earn and save by reshaping their relationship with money. Over 25 million users choose Tabby to stay in control of their spending and make the most out of their money.
The company’s flagship offering allows shoppers to split their payments online and in-store with no interest or fees. Over 70,000 global brands and small businesses, including Amazon, Noon, IKEA, and SHEIN use Tabby to accelerate growth and gain loyal customers by offering easy and flexible payments online and in stores.
Tabby generates over $18 billion in annual transaction volume for its partner brands and is the highest-rated, most-reviewed, largest, and fastest-growing FinTech in the GCC region.
Tabby launched in 2019 and has since raised +$1 billion in equity and debt funding from global and regional investors, and is now valued at $6,5 billion.
We are looking for a Cyber Security Lead to join our Information Security team in Riyadh. You will provide technical leadership across defensive security, while managing a team of security engineers and analysts and driving security initiatives across the organization.
The company’s flagship offering allows shoppers to split their payments online and in-store with no interest or fees. Over 70,000 global brands and small businesses, including Amazon, Noon, IKEA, and SHEIN use Tabby to accelerate growth and gain loyal customers by offering easy and flexible payments online and in stores.
Tabby generates over $18 billion in annual transaction volume for its partner brands and is the highest-rated, most-reviewed, largest, and fastest-growing FinTech in the GCC region.
Tabby launched in 2019 and has since raised +$1 billion in equity and debt funding from global and regional investors, and is now valued at $6,5 billion.
We are looking for a Cyber Security Lead to join our Information Security team in Riyadh. You will provide technical leadership across defensive security, while managing a team of security engineers and analysts and driving security initiatives across the organization.
- Lead security architecture and design reviews across IT, cloud, and product initiatives.
- Drive cloud security across GCP and AWS, including IAM, cloud security posture, and infrastructure security.
- Lead the Secure SDLC / DevSecOps programme, including application security and security tooling across CI/CD.
- Own vulnerability management, including vulnerability remediation, penetration testing and red team engagements.
- Oversee endpoint, infrastructure and network security, including EDR, DLP and firewall security.
- Lead detection engineering, threat intelligence and incident response, including complex security investigations.
- Manage and develop a team of security engineers and analysts, including mentoring, performance management and career development.
- Partner with Engineering, IT, Compliance and other teams to improve Tabby’s overall security posture and security standards.
- 5+ years of experience in cybersecurity / information security, including technical leadership or senior-level responsibilities.
- Experience leading security programmes across security architecture, cloud security, vulnerability management and application security.
- Strong understanding of defensive and offensive security, including penetration testing, red/purple teaming, threat hunting and incident response.
- Hands-on experience with SIEM, EDR/XDR, vulnerability management, CSPM, DLP and security monitoring platforms.
- Strong knowledge of GCP and/or AWS, IAM, cloud security and infrastructure security.
- Experience with DevSecOps, Secure SDLC, SAST, DAST, SCA and container security.
- Strong scripting and automation skills and the ability to develop or oversee security tooling and integrations.
- Knowledge of SAMA CSF, NCA ECC, PCI-DSS and ISO 27001.
- Experience working in a regulated FinTech or banking environment.
- Strong technical leadership, stakeholder management and team development skills.
- CISSP/CISM and OSCP or equivalent certifications are required.