Information Security Intern

Tabby | تابي
الرياض, الرياض تدريب
نشر: 1448/1/22 | 2026/07/07 ينتهي: 1448/2/23 | 2026/08/06 ✨ وصف بالذكاء الاصطناعي
تقدم للوظيفة الآن

الوصف الوظيفي

About the Role

Join Tabby, a leading financial technology company in the GCC, as an Information Security Intern within our dynamic InfoSec GRC department. Tabby delivers cutting-edge financial solutions to millions of users across the region, operating high-load, security-critical systems that adhere to stringent regulatory standards. This internship is designed for early-career engineers seeking hands-on experience in a real-world security environment, where you will take on meaningful responsibilities from day one.

Your Impact

At Tabby, the Information Security team operates across two specialized tracks: Vulnerability Assessment & Penetration Testing (VAPT) and Governance, Risk & Compliance (GRC). You will collaborate closely with product engineering, risk engineering, and platform/SRE teams to safeguard Tabby’s mobile applications, backend services, payment integrations, and cloud infrastructure. This is not a shadowing role—you will be embedded within the security team, contributing to real assessments, remediation tasks, and compliance initiatives under the guidance of senior professionals.

Key Responsibilities

Vulnerability Assessment & Penetration Testing (VAPT) Track:

  • Triage and analyze findings from SAST, DAST, SCA, and dependency scanners across mobile and backend repositories.
  • Reproduce and document vulnerabilities, then create detailed remediation tickets for product teams to address security gaps.
  • Participate in secure code reviews, focusing on critical areas such as authentication, input validation, and data handling.
  • Contribute to threat-modelling sessions for new features and produce comprehensive write-ups to guide security measures.
  • Conduct scoped security assessments against staging environments under senior oversight.
  • Assist in maintaining and improving security tooling, including scanner configurations, baseline rules, dashboards, and false-positive triage processes.
  • Support security checks during release cycles to ensure compliance with security standards.
  • Contribute to DevSecOps initiatives, including security gates in CI/CD pipelines, dependency scanning, and container image security.
  • Gain exposure to logging, monitoring, and alert triage workflows in collaboration with the Security Operations Center (SOC).
  • Participate in incident response exercises and post-mortem analyses alongside senior engineers.

Governance, Risk & Compliance (GRC) Track:

  • Support compliance programs against frameworks such as PCI DSS, ISO 27001, and SAMA through evidence collection, control mapping, and gap analysis.
  • Assist in maintaining and updating security policies, standards, and procedures across domains, including access control, cryptography, asset management, change management, third-party security, vulnerability management, and security awareness.
  • Contribute to risk assessments by maintaining risk registers, conducting control testing, and developing treatment plans.
  • Support vendor and third-party security assessments to ensure external partners meet Tabby’s security requirements.
  • Assist in preparing for internal and external audits by compiling workpapers, evidence packages, and coordinating responses.
  • Develop and deploy security awareness content, training programs, and metrics tracking to foster a culture of security within the organization.
  • Collaborate with engineering teams to translate policy requirements into actionable technical controls.

Across both tracks, you will:

  • Work with risk and platform engineers to review PII handling, secrets management, and encryption practices.
  • Contribute to the internal security knowledge base by creating and updating runbooks, playbooks, and awareness content.

Skills and Qualifications

Required:

  • A solid understanding of information security fundamentals, including confidentiality, integrity, and availability, as well as common attack categories (e.g., OWASP Top 10) and control categories.
  • Familiarity with core networking concepts such as HTTP, TLS, DNS, and TCP/IP.
  • Knowledge of authentication and authorization patterns, including sessions, cookies, OAuth 2.0, and JWT.
  • Proficiency with the Linux command line and POSIX-like environments.
  • Strong ability to read technical material and articulate complex concepts clearly in writing.
  • Experience with Git and standard development workflows.
  • Basic scripting or programming skills (e.g., Python, Bash, or similar) are a plus.
  • Strong problem-solving skills and a proactive approach to learning and adaptation.

Preferred:

  • Prior exposure to security tools such as Burp Suite, OWASP ZAP, Nessus, or similar.
  • Experience with containerization technologies (e.g., Docker, Kubernetes) and cloud platforms (e.g., AWS, GCP, Azure).
  • Familiarity with compliance frameworks such as PCI DSS, ISO 27001, or NIST.

Why Join Tabby?

As an Information Security Intern at Tabby, you will gain invaluable experience in a fast-paced, innovative environment where security is a top priority. You will work alongside industry experts, contribute to critical security initiatives, and develop skills that will set you apart in your career. This role offers a unique opportunity to make a tangible impact while growing as a security professional in the financial technology sector.

يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.

المصدر: لينكد إن ↗ • 8 مشاهدة

وظائف مشابهة

تقدم للوظيفة الآن