Information Security Analyst l (PenTester)
الوصف الوظيفي
About Tabby
Tabby is revolutionizing financial freedom by empowering individuals to take control of their spending, earning, and saving. With over 15 million users, Tabby provides innovative payment solutions that enable seamless online and in-store transactions without interest or fees. Trusted by more than 40,000 global brands and small businesses—including industry leaders like Amazon, Noon, IKEA, and SHEIN—Tabby accelerates growth and fosters customer loyalty through flexible payment options. The company processes over $10 billion in annual transaction volume, making it the highest-rated, most-reviewed, largest, and fastest-growing FinTech in the GCC region. Founded in 2019, Tabby has secured over $1 billion in equity and debt funding from global and regional investors, achieving a valuation of $4.5 billion.
Role Overview
As an Information Security Analyst I (Penetration Tester), you will play a pivotal role in strengthening Tabby’s security posture by supporting offensive security initiatives. This entry-level position is designed to provide hands-on experience in industry-standard tools, methodologies, and frameworks such as the OWASP Top 10 and MITRE ATT&CK. You will collaborate with senior engineers to conduct penetration tests, vulnerability assessments, and red team exercises, ensuring that potential weaknesses are identified and addressed before malicious actors can exploit them. This role offers a structured learning environment where you can develop technical depth while contributing to Tabby’s mission of safeguarding its digital ecosystem.
Key Responsibilities
Technical Security Assessment Support
- Assist senior engineers in executing penetration tests across web applications, APIs, and network infrastructure by performing assigned test cases and documenting findings with precision.
- Support vulnerability assessments using automated scanning tools such as Nmap and vulnerability scanners, while verifying results through basic manual techniques under supervision.
- Participate in Red Team exercises as a supporting team member, gaining exposure to adversary simulation methodologies and contributing to pre-agreed test scenarios.
- Execute controlled offensive testing tasks, including running scripts, setting up test environments, and assisting with phishing simulations, as directed by senior staff.
- Contribute to the identification, documentation, and tracking of vulnerabilities throughout the assessment lifecycle, ensuring thorough and accurate reporting.
- Support the development and maintenance of basic scripts and testing utilities to enhance offensive security activities.
Risk Documentation & Reporting
- Assist in analyzing and documenting assessment findings, including reproduction steps, evidence, and initial severity observations for review by senior engineers.
- Support the preparation of penetration test reports by compiling findings, screenshots, and tool outputs into structured report templates.
- Help track the status of identified vulnerabilities and remediation progress, maintaining accurate records in relevant tracking systems.
- Assist in validating patched vulnerabilities by re-testing affected systems following confirmed remediation, under the guidance of senior team members.
Collaboration & Program Support
- Participate in Purple Team exercises as an observer and support role, gaining exposure to detection logic and incident response workflows.
- Provide basic log collection and organizational support to the incident response team during active security incidents, as directed.
- Maintain up-to-date documentation on offensive security tools, tactics, and methodologies used by the team.
- Support compliance testing efforts by executing pre-defined test cases to validate controls required by regulations such as SAMA CSF and PCI-DSS.
- Engage in self-directed learning of offensive security Tactics, Techniques, and Procedures (TTPs), emerging vulnerabilities, and attack vectors to build technical depth.
Qualifications & Skills
To excel in this role, you should possess a foundational understanding of cybersecurity principles, penetration testing methodologies, and common security tools. While prior experience in offensive security is beneficial, this role is designed to accommodate entry-level professionals eager to develop their skills. Proficiency in scripting languages (e.g., Python, Bash) and familiarity with networking concepts are advantageous. Strong analytical skills, attention to detail, and the ability to document findings clearly are essential. Candidates should demonstrate a proactive approach to learning and a commitment to staying current with evolving threats and security trends.
Why Join Tabby?
As part of Tabby’s dynamic and innovative team, you will have the opportunity to contribute to a high-impact FinTech organization that is reshaping the financial landscape in the GCC and beyond. This role offers a unique blend of structured learning, hands-on experience, and the chance to work alongside industry experts in a fast-paced environment. Tabby values collaboration, creativity, and a growth mindset, providing employees with the resources and support needed to thrive in their careers. If you are passionate about cybersecurity and eager to make a tangible difference in protecting Tabby’s digital assets, this is the ideal opportunity for you.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.