Information Security Intern
الوصف الوظيفي
About Tabby
Tabby is a rapidly growing financial technology company powering secure, high-performance financial products for millions of users across the GCC. Our platforms—spanning mobile applications, backend services, payment integrations, and cloud infrastructure—operate under stringent regulatory requirements and high-load conditions. The Information Security team at Tabby is responsible for safeguarding these critical systems, ensuring robust protection against evolving threats while maintaining compliance with global security standards.
Internship Overview
This is not a conventional educational internship; it is a hands-on engineering role designed for early-career professionals eager to develop expertise in information security. Interns will be embedded within the Information Security team, working on real-world security assessments, compliance initiatives, and risk management tasks under the guidance of senior security practitioners. Each candidate will be matched to one of two specialized tracks—Vulnerability Assessment & Penetration Testing (VAPT) or Governance, Risk & Compliance (GRC)—based on their skills and interests during the interview process. From day one, interns are expected to meet the same engineering standards as full-time team members, contributing meaningfully to Tabby’s security posture.
Key Responsibilities
Interns will be assigned real production tasks with direct impact on Tabby’s security operations. Responsibilities vary by track but include:
Vulnerability Assessment & Penetration Testing (VAPT) Track
- Triage and analyze security findings from automated scanners (SAST, DAST, SCA, and dependency scanners) across mobile and backend repositories.
- Reproduce and document vulnerabilities, then create detailed remediation tickets for engineering teams to address.
- Participate in secure code reviews, focusing on critical areas such as authentication, input validation, and data handling.
- Contribute to threat modeling sessions for new features, producing comprehensive write-ups to guide secure development.
- Conduct scoped security assessments in staging environments, under the supervision of senior engineers.
- Assist in maintaining and improving security tooling, including scanner configurations, baseline rules, dashboards, and false-positive triage workflows.
- Support DevSecOps initiatives by enhancing security gates in CI/CD pipelines, including dependency and container image scanning.
- Collaborate with the Security Operations Center (SOC) on logging, monitoring, and alert triage workflows.
- Participate in incident response exercises and post-mortem analyses to strengthen Tabby’s resilience against security incidents.
Governance, Risk & Compliance (GRC) Track
- Assist in compliance programs for frameworks such as PCI DSS, ISO 27001, and SAMA, including evidence collection, control mapping, and gap analysis.
- Help maintain and update security policies, standards, and procedures across key domains, including access control, cryptography, asset management, change management, third-party security, vulnerability management, and security awareness training.
- Support risk assessments by contributing to risk registers, control testing, and treatment plan development.
- Participate in vendor and third-party security assessments to ensure external partners meet Tabby’s security requirements.
- Assist in preparing for internal and external audits, including compiling workpapers, evidence packages, and coordinating responses.
- Contribute to security awareness initiatives by developing training content, rolling out programs, and tracking metrics to measure effectiveness.
- Work alongside engineering teams to translate policy requirements into actionable technical controls.
All interns, regardless of track, will:
- Collaborate with risk and platform engineers on critical initiatives such as PII handling, secrets management, and encryption reviews.
- Contribute to the internal security knowledge base by creating and updating runbooks, playbooks, and awareness content.
Skills, Knowledge & Expertise
We seek candidates with a strong foundation in information security principles and a passion for hands-on technical work. Ideal candidates will possess:
- A solid understanding of core security concepts, including confidentiality, integrity, and availability, as well as common attack vectors outlined in the OWASP Top 10.
- Familiarity with fundamental networking protocols such as HTTP, TLS, DNS, and TCP/IP.
- Knowledge of authentication and authorization mechanisms, including sessions, cookies, OAuth 2.0, and JWT.
- Proficiency with the Linux command line and POSIX-like environments.
- The ability to read technical documentation and articulate complex concepts clearly in writing.
- Experience with Git and familiarity with standard software development workflows.
- A strong ethical mindset and a commitment to responsible disclosure and security best practices.
Why Join Tabby?
As an Information Security Intern at Tabby, you will gain invaluable experience working on cutting-edge security challenges in a fast-paced, high-impact environment. You will collaborate with industry-leading security professionals, contribute to real-world projects, and develop skills that will set you on a path to a successful career in cybersecurity. This internship offers a unique opportunity to make a tangible difference while learning from the best in the field.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.