Information Security Lead (Defensive)
الوصف الوظيفي
Information Security Lead (Defensive) – Drive Tabby’s Vision of Financial Empowerment with Robust Cybersecurity Leadership
At Tabby, we are revolutionizing the way millions of people manage their finances by fostering financial freedom through innovative payment solutions. Our mission is to empower users to spend, earn, and save with confidence, enabling over 70,000 global brands—including industry leaders like Amazon, Noon, IKEA, and SHEIN—to accelerate growth and cultivate loyal customer relationships. With an annual transaction volume exceeding $18 billion, Tabby stands as the highest-rated and fastest-growing FinTech in the GCC region, backed by a valuation of $6.5 billion and over $1 billion in equity and debt funding.
We are seeking a visionary Information Security Lead (Defensive) to spearhead our Information Security team in Riyadh. In this pivotal role, you will provide strategic technical leadership in defensive cybersecurity, overseeing a team of security engineers and analysts while driving impactful security initiatives across the organization. Your expertise will be instrumental in safeguarding Tabby’s cutting-edge financial infrastructure, ensuring compliance, and fostering a culture of security excellence.
Key Responsibilities
As the Information Security Lead, your responsibilities will include:
- Strategic Security Architecture and Design: Lead comprehensive security architecture and design reviews for IT, cloud, and product initiatives, ensuring alignment with industry best practices and Tabby’s evolving business needs.
- Cloud Security Leadership: Drive security initiatives across Google Cloud Platform (GCP) and Amazon Web Services (AWS), with a focus on Identity and Access Management (IAM), security posture assessments, and robust infrastructure security measures.
- DevSecOps and Secure SDLC: Own and champion Tabby’s Secure Software Development Lifecycle (SDLC) and DevSecOps program, integrating tools such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Supply Chain Attack (SCA) analysis, and container security to mitigate risks at every stage of development.
- Vulnerability Management and Penetration Testing: Oversee vulnerability management, penetration testing, and red team engagements to proactively identify and address security weaknesses, ensuring Tabby’s systems remain resilient against evolving threats.
- Endpoint and Infrastructure Security: Manage endpoint, infrastructure, and firewall security to create a layered defense strategy that protects Tabby’s digital assets and user data.
- Threat Detection and Incident Response: Lead detection engineering efforts, threat intelligence gathering, and the handling of complex security incidents, ensuring rapid response and minimal disruption to our services.
- Team Development and Mentorship: Develop and mentor a high-performing team of cybersecurity engineers and analysts, fostering a collaborative environment that drives innovation and continuous improvement.
- Cross-Functional Collaboration: Partner closely with Engineering, IT, Compliance, and other teams to enhance Tabby’s overall security posture, ensuring seamless integration of security practices into all aspects of the business.
Skills, Knowledge, and Expertise
We are looking for a seasoned cybersecurity professional with:
- 5+ Years of Cybersecurity Experience: A proven track record of technical leadership or senior-level responsibilities in defensive cybersecurity, with a focus on security architecture, cloud security, Application Security (AppSec), DevSecOps, and vulnerability management.
- Hands-On Offensive and Defensive Security: Deep expertise in penetration testing, red/purple teaming, and incident response, enabling you to balance proactive threat mitigation with reactive crisis management.
- Cloud Security Proficiency: Extensive knowledge of GCP and AWS, including IAM, Terraform, Kubernetes, and CI/CD security, to ensure secure cloud operations.
- Security Tooling and Platforms: Familiarity with SIEM, Endpoint Detection and Response (EDR)/Extended Detection and Response (XDR), Cloud Security Posture Management (CSPM), Data Loss Prevention (DLP), and vulnerability management platforms.
- Secure Development Practices: Strong understanding of SAST, DAST, SCA, and secure SDLC practices to embed security into the development lifecycle.
- Regulatory Compliance: Knowledge of key frameworks such as SAMA CSF, NCA ECC, PCI-DSS, and ISO 27001 to ensure compliance and risk mitigation.
- Leadership and Stakeholder Management: Exceptional technical leadership, stakeholder management, and team development skills to drive security initiatives and inspire a culture of security awareness.
- Certifications: CISSP, CISM, or OSCP certifications, or equivalent, to validate your expertise and commitment to the field.
Join Tabby and play a critical role in shaping the future of financial technology security. Your leadership will not only protect our users and partners but also contribute to Tabby’s mission of creating a more financially empowered world.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.
ℹ️ إخلاء مسؤولية توظيف:
موقع وظائف السعودية (ksajobshub.com) هو محرك بحث ومجمع لإعلانات الوظائف من المصادر والشركات الرسمية في المملكة العربية السعودية. نحن لا نتقاضى أي مبالغ مالية أو رسوم من الباحثين عن عمل، وتتم عمليات التقديم مباشرة عبر الانتقال للرابط الأصلي للجهة المعلنة.