Lead Information Security Engineer (Defensive)
الوصف الوظيفي
Lead Information Security Engineer (Defensive) – Drive Tabby’s Vision for Secure Financial Innovation
At Tabby, we empower millions of users to transform their financial journeys by simplifying spending, earning, and saving. Our mission is to redefine how people interact with money, enabling over 17 million users to take control of their financial futures. As a leading FinTech platform, Tabby powers seamless, interest-free payment solutions for over 40,000 global brands—including industry giants like Amazon, Noon, IKEA, and SHEIN—driving over $10 billion in annual transaction volume. Recognized as the highest-rated and fastest-growing FinTech in the GCC region, Tabby is reshaping the financial landscape with cutting-edge technology and innovative solutions.
As a Lead Information Security Engineer (Defensive) based in Riyadh, you will play a pivotal role in fortifying Tabby’s security infrastructure while leading a high-impact team of security engineers and analysts. This position demands a strategic mindset, technical expertise, and a commitment to elevating Tabby’s security posture across all critical domains—from cloud environments to secure software development and incident response. If you thrive in a fast-paced, mission-driven environment and are passionate about safeguarding financial systems, we invite you to join our team and contribute to the future of secure financial technology.
Key Responsibilities
In this leadership role, you will:
- Architect and oversee security frameworks by leading comprehensive security design reviews for IT, cloud, and product initiatives, ensuring alignment with industry best practices and regulatory compliance.
- Drive cloud security excellence across Google Cloud Platform (GCP) and Amazon Web Services (AWS), with a focus on Identity and Access Management (IAM), security posture assessments, and infrastructure hardening to mitigate risks proactively.
- Champion DevSecOps and Secure SDLC practices by implementing and managing Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Supply Chain Attack (SCA) assessments, and container security measures to embed security into every phase of development.
- Lead vulnerability management and offensive-defensive security initiatives, including penetration testing, red teaming, and purple team exercises, to identify and neutralize threats before they impact our systems.
- Oversee endpoint, infrastructure, and firewall security, ensuring robust defenses against evolving cyber threats while maintaining operational resilience.
- Develop and mentor a high-performing security team, fostering a culture of continuous learning, collaboration, and innovation to elevate Tabby’s security capabilities.
- Collaborate cross-functionally with Engineering, IT, Compliance, and other stakeholders to integrate security into product development, operational workflows, and strategic initiatives, thereby strengthening Tabby’s overall security posture.
Skills, Knowledge, and Expertise
We are seeking a seasoned professional with:
- 5+ years of cybersecurity experience, including hands-on technical leadership or senior-level responsibilities in defensive security, security architecture, or related domains.
- Deep expertise in security architecture, cloud security, Application Security (AppSec), DevSecOps, and vulnerability management, with a proven ability to translate technical insights into actionable security strategies.
- Practical experience in both offensive and defensive security, encompassing penetration testing, red teaming, purple teaming, and incident response to enhance Tabby’s threat detection and mitigation capabilities.
- Proficiency with security tools and platforms, including SIEM (Security Information and Event Management), EDR/XDR (Endpoint Detection and Response), Cloud Security Posture Management (CSPM), Data Loss Prevention (DLP), and vulnerability management solutions.
- Technical mastery of GCP and AWS environments, with in-depth knowledge of IAM, Terraform, Kubernetes, and CI/CD security to ensure secure cloud operations.
- Familiarity with secure software development practices, including SAST, DAST, SCA, and Secure SDLC methodologies to embed security into the development lifecycle.
- Compliance expertise, with a strong understanding of frameworks such as SAMA CSF, NCA ECC, PCI-DSS, and ISO 27001 to ensure regulatory adherence and risk mitigation.
- Exceptional leadership and stakeholder management skills, coupled with a passion for team development and mentorship to nurture a skilled and motivated security team.
- Certifications such as CISSP, CISM, or OSCP, or equivalent credentials, to validate your expertise and commitment to the field.
Join Tabby and be at the forefront of securing the future of financial technology. Your leadership will not only protect our users and partners but also drive innovation in the ever-evolving landscape of cybersecurity.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.
ℹ️ إخلاء مسؤولية توظيف:
موقع وظائف السعودية (ksajobshub.com) هو محرك بحث ومجمع لإعلانات الوظائف من المصادر والشركات الرسمية في المملكة العربية السعودية. نحن لا نتقاضى أي مبالغ مالية أو رسوم من الباحثين عن عمل، وتتم عمليات التقديم مباشرة عبر الانتقال للرابط الأصلي للجهة المعلنة.