Lead, Information Security (Defensive)
الوصف الوظيفي
Lead, Information Security (Defensive) – Drive Tabby’s Vision for Uncompromising Cybersecurity Leadership
At Tabby, we empower millions of users to transform their financial journeys—enabling smarter spending, seamless earning, and strategic saving through innovative payment solutions. As a trailblazer in the FinTech landscape, we’ve redefined financial control for over 17 million users while fostering growth for 40,000+ global brands, including industry giants like Amazon, Noon, IKEA, and SHEIN. With an annual transaction volume exceeding $10 billion, Tabby stands as the highest-rated, fastest-growing, and most trusted FinTech platform in the GCC region, backed by a robust valuation of $4.5 billion and over $1 billion in strategic funding.
We are seeking a visionary Lead, Information Security (Defensive) to spearhead Tabby’s cybersecurity initiatives in Riyadh. In this pivotal role, you will provide strategic technical leadership across defensive security, overseeing a high-performing team of security engineers and analysts while driving industry-leading security standards across the organization. Your expertise will be instrumental in safeguarding Tabby’s cutting-edge financial infrastructure, ensuring compliance, and fostering a culture of proactive threat mitigation.
Key Responsibilities
As the architect of Tabby’s defensive security framework, your responsibilities will include:
- Strategic Security Leadership: Lead comprehensive security architecture and design reviews for IT, cloud, and product initiatives, ensuring alignment with Tabby’s scalable growth and regulatory demands.
- Cloud Security Excellence: Drive cloud security across Google Cloud Platform (GCP) and Amazon Web Services (AWS), with a focus on Identity and Access Management (IAM), security posture assessments, and infrastructure hardening to mitigate evolving threats.
- DevSecOps and Secure SDLC: Own and champion Tabby’s Secure Software Development Lifecycle (SDLC) and DevSecOps program, integrating Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Supply Chain Attack (SCA) analysis, and container security into every phase of development.
- Proactive Threat Defense: Oversee vulnerability management, penetration testing, and red team engagements to identify and neutralize potential threats before they materialize. Lead detection engineering, threat intelligence, and incident response to ensure rapid, effective mitigation of security incidents.
- Endpoint and Network Security: Manage endpoint security, infrastructure protections, and firewall configurations to create an impenetrable perimeter for Tabby’s systems and user data.
- Team Development and Stakeholder Collaboration: Develop and mentor a high-impact team of cybersecurity engineers and analysts, fostering a culture of continuous learning and innovation. Collaborate closely with Engineering, IT, Compliance, and other cross-functional teams to elevate Tabby’s overall security posture and ensure seamless integration of security best practices.
This role is ideal for a seasoned security professional who thrives at the intersection of technical expertise and strategic vision, with a passion for shaping the future of cybersecurity in a high-growth FinTech environment.
Required Skills, Knowledge, and Expertise
To excel in this leadership position, you will bring:
- Proven Leadership: Five or more years of cybersecurity experience, with a track record of technical leadership or senior-level responsibilities in defensive security frameworks.
- Cloud and Infrastructure Security: Deep expertise in security architecture, cloud security (GCP/AWS), and infrastructure protection, including IAM, Terraform, Kubernetes, and CI/CD security.
- Offensive and Defensive Security: Hands-on experience with penetration testing, red/purple teaming, and incident response, ensuring a balanced approach to threat detection and mitigation.
- Security Platforms and Tools: Proficiency with SIEM, Endpoint Detection and Response (EDR)/Extended Detection and Response (XDR), Cloud Security Posture Management (CSPM), Data Loss Prevention (DLP), and vulnerability management platforms.
- Secure Development Practices: Strong knowledge of SAST, DAST, SCA, and secure SDLC methodologies to embed security into the core of Tabby’s development lifecycle.
- Regulatory Compliance: Familiarity with critical frameworks such as SAMA CSF, NCA ECC, PCI-DSS, and ISO 27001 to ensure Tabby’s operations meet the highest standards of compliance and security.
- Leadership and Stakeholder Management: Exceptional technical leadership, stakeholder engagement, and team development skills to inspire and guide a team toward achieving ambitious security goals.
- Certifications: Industry-recognized certifications such as CISSP, CISM, or OSCP, or equivalent, to validate your expertise and commitment to cybersecurity excellence.
Join Tabby and play a crucial role in defining the future of secure financial technology. Your leadership will not only protect our users and partners but also drive innovation in a dynamic and rapidly evolving industry.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.
ℹ️ إخلاء مسؤولية توظيف:
موقع وظائف السعودية (ksajobshub.com) هو محرك بحث ومجمع لإعلانات الوظائف من المصادر والشركات الرسمية في المملكة العربية السعودية. نحن لا نتقاضى أي مبالغ مالية أو رسوم من الباحثين عن عمل، وتتم عمليات التقديم مباشرة عبر الانتقال للرابط الأصلي للجهة المعلنة.