Lead, Information Security (Defensive)
الوصف الوظيفي
Lead, Information Security (Defensive) – Drive Cybersecurity Excellence at Tabby
At Tabby, we empower millions of users to take control of their financial journeys by revolutionizing how they shop, earn, and save. As a leading FinTech platform in the GCC region, we process over $10 billion in annual transaction volume, supporting over 40,000 global and local brands—from industry giants like Amazon and IKEA to innovative startups. Our mission is to redefine financial freedom, and we’re backed by a $4.5 billion valuation and over $1 billion in equity and debt funding, reflecting our rapid growth and industry leadership.
We are seeking a visionary Lead, Information Security (Defensive) to spearhead our cybersecurity initiatives in Riyadh. In this pivotal role, you will provide strategic technical leadership across defensive security, overseeing a high-performing team of security engineers and analysts while driving industry-leading security practices across the organization. This is an opportunity to shape Tabby’s security posture, protect our users’ financial data, and ensure compliance in a fast-evolving digital landscape.
Key Responsibilities
As the Lead, Information Security (Defensive), your responsibilities will include:
- Strategic Security Leadership: Lead comprehensive security architecture and design reviews for IT, cloud, and product initiatives, ensuring alignment with global best practices and regulatory requirements.
- Cloud Security Excellence: Drive cloud security initiatives across Google Cloud Platform (GCP) and Amazon Web Services (AWS), with a focus on Identity and Access Management (IAM), security posture assessments, and infrastructure hardening.
- DevSecOps and Secure SDLC: Own and champion the Secure Software Development Lifecycle (SDLC) and DevSecOps program, integrating Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Supply Chain Attack (SCA) analysis, and container security into our development pipelines.
- Vulnerability and Threat Management: Lead vulnerability management, penetration testing, and red team engagements to proactively identify and mitigate security risks before they materialize.
- Endpoint and Network Security: Oversee endpoint security, infrastructure security, and firewall configurations to safeguard Tabby’s digital assets and user data.
- Threat Detection and Incident Response: Develop and enhance detection engineering frameworks, leverage threat intelligence, and lead complex incident response efforts to minimize impact and ensure rapid recovery.
- Team Development and Mentorship: Build and mentor a high-impact team of cybersecurity engineers and analysts, fostering a culture of continuous learning and innovation.
- Cross-Functional Collaboration: Partner closely with Engineering, IT, Compliance, and other stakeholders to elevate Tabby’s overall security posture, ensuring alignment with industry standards like SAMA CSF, NCA ECC, PCI-DSS, and ISO 27001.
Skills, Knowledge, and Expertise
We are looking for a seasoned cybersecurity professional with:
- 5+ Years of Cybersecurity Experience: Proven track record in technical leadership or senior-level roles, with a deep understanding of both offensive and defensive security strategies.
- Cloud Security Expertise: Hands-on experience with GCP and AWS, including IAM, security posture management, and infrastructure security, with proficiency in Terraform, Kubernetes, and CI/CD security.
- Application Security and DevSecOps: Strong knowledge of SAST, DAST, SCA, and secure SDLC practices to embed security into every stage of development.
- Threat Intelligence and Incident Response: Experience with SIEM, EDR/XDR, CSPM, and DLP platforms, as well as expertise in penetration testing, red/purple teaming, and incident response.
- Regulatory Compliance: In-depth knowledge of SAMA CSF, NCA ECC, PCI-DSS, and ISO 27001 to ensure alignment with global and regional compliance frameworks.
- Leadership and Stakeholder Management: Exceptional technical leadership skills, coupled with the ability to collaborate effectively with cross-functional teams and drive security initiatives at scale.
- Certifications: CISSP, CISM, or OSCP (or equivalent certifications) are required to validate your expertise and commitment to cybersecurity excellence.
Join Tabby and be at the forefront of shaping the future of financial technology security. Your leadership will not only protect our users but also drive innovation in a dynamic and high-growth environment.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.
ℹ️ إخلاء مسؤولية توظيف:
موقع وظائف السعودية (ksajobshub.com) هو محرك بحث ومجمع لإعلانات الوظائف من المصادر والشركات الرسمية في المملكة العربية السعودية. نحن لا نتقاضى أي مبالغ مالية أو رسوم من الباحثين عن عمل، وتتم عمليات التقديم مباشرة عبر الانتقال للرابط الأصلي للجهة المعلنة.