Lead Information Security Engineer (Defensive)
الوصف الوظيفي
Lead Information Security Engineer (Defensive) – Shape the Future of Secure Financial Technology at Tabby
At Tabby, we are revolutionizing the way millions of people interact with money by empowering financial freedom through innovative, flexible, and fee-free payment solutions. Our platform enables over 17 million users to manage their spending with confidence while driving over $10 billion in annual transaction volume for 40,000+ global brands, including industry leaders like Amazon, Noon, IKEA, and SHEIN. As a rapidly scaling FinTech powerhouse in the GCC region, we are valued at $4.5 billion and backed by over $1 billion in global and regional investment, positioning us as the highest-rated and fastest-growing financial technology company in the region.
We are seeking a visionary Lead Information Security Engineer (Defensive) to join our dynamic Information Security team in Riyadh. In this pivotal role, you will lead our defensive security strategy, architect robust security frameworks, and mentor a high-performing team of security engineers and analysts. Your expertise will be instrumental in elevating Tabby’s security posture, ensuring compliance, and safeguarding our mission-critical infrastructure and user data.
Key Responsibilities
As the Lead Information Security Engineer, your responsibilities will include:
- Technical Leadership in Security Architecture: Drive comprehensive security architecture and design reviews across IT, cloud, and product initiatives, ensuring alignment with industry best practices and regulatory requirements.
- Cloud Security Expertise: Lead security initiatives across Google Cloud Platform (GCP) and Amazon Web Services (AWS), with a focus on Identity and Access Management (IAM), security posture assessments, and infrastructure hardening.
- DevSecOps and Secure SDLC: Own and champion the Secure Software Development Lifecycle (SDLC) and DevSecOps program, integrating Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Supply Chain Attack (SCA) assessments, and container security into our development pipelines.
- Vulnerability Management and Penetration Testing: Oversee vulnerability management, penetration testing, and red team engagements to proactively identify and mitigate security risks before they materialize.
- Endpoint and Network Security: Manage endpoint security, infrastructure security, and firewall configurations to create a resilient defense perimeter against evolving threats.
- Threat Detection and Incident Response: Develop and refine detection engineering frameworks, leverage threat intelligence, and lead complex incident response efforts to minimize impact and ensure rapid recovery.
- Team Development and Mentorship: Build and mentor a skilled team of cybersecurity engineers and analysts, fostering a culture of continuous learning and innovation.
- Cross-Functional Collaboration: Partner closely with Engineering, IT, Compliance, and other stakeholders to enhance Tabby’s overall security posture, ensuring seamless integration of security practices across the organization.
Why This Role Matters
In today’s rapidly evolving threat landscape, the role of a Lead Information Security Engineer is more critical than ever. At Tabby, you will not only shape our security strategy but also contribute to the trust and confidence of millions of users and thousands of partner brands. Your leadership will help us maintain our position as a leader in FinTech security, ensuring that Tabby remains a safe and reliable platform for financial transactions.
Skills, Knowledge, and Expertise
We are looking for a seasoned professional with:
- 5+ Years of Cybersecurity Experience: A proven track record of technical leadership or senior-level responsibilities in defensive security, with a deep understanding of offensive and defensive security principles.
- Cloud Security Mastery: Extensive experience with GCP and AWS security, including IAM, security posture management, and infrastructure security, with hands-on expertise in Terraform, Kubernetes, and CI/CD security.
- Application Security and DevSecOps: Strong knowledge of SAST, DAST, SCA, and secure SDLC practices to embed security into the development lifecycle.
- Threat Intelligence and Incident Response: Expertise in SIEM, Endpoint Detection and Response (EDR)/Extended Detection and Response (XDR), Cloud Security Posture Management (CSPM), Data Loss Prevention (DLP), and vulnerability management platforms.
- Regulatory Compliance: In-depth knowledge of regional frameworks such as SAMA CSF, NCA ECC, PCI-DSS, and international standards like ISO 27001.
- Leadership and Stakeholder Management: Exceptional technical leadership, stakeholder management, and team development skills to drive security initiatives and mentor high-potential talent.
- Certifications: CISSP, CISM, or OSCP certifications, or equivalent qualifications, to validate your expertise in cybersecurity.
Join Tabby and be at the forefront of transforming financial technology with cutting-edge security solutions. Your expertise will not only protect our users and partners but also drive innovation in the FinTech industry.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.
ℹ️ إخلاء مسؤولية توظيف:
موقع وظائف السعودية (ksajobshub.com) هو محرك بحث ومجمع لإعلانات الوظائف من المصادر والشركات الرسمية في المملكة العربية السعودية. نحن لا نتقاضى أي مبالغ مالية أو رسوم من الباحثين عن عمل، وتتم عمليات التقديم مباشرة عبر الانتقال للرابط الأصلي للجهة المعلنة.