Tabby creates financial freedom in the way people shop, earn and save by reshaping their relationship with money. Over 17 million users choose Tabby to stay in control of their spending and make the most out of their money.
The company’s flagship offering allows shoppers to split their payments online and in-store with no interest or fees. Over 40,000 global brands and small businesses, including Amazon, Noon, IKEA, and SHEIN use Tabby to accelerate growth and gain loyal customers by offering easy and flexible payments online and in stores.
Tabby generates over $10 billion in annual transaction volume for its partner brands and is the highest-rated, most-reviewed, largest, and fastest-growing FinTech in the GCC region.
Tabby launched in 2019 and has since raised +$1 billion in equity and debt funding from global and regional investors, and is now valued at $4.5 billion.
We are looking for a
Lead Cyber Security Engineer to join our Information Security team in Riyadh. You will provide technical leadership across defensive security, while managing a team of security engineers and analysts and driving security initiatives across the organization.
- Lead security architecture and design reviews across IT, cloud, and product initiatives.
- Drive cloud security across GCP and AWS, including IAM, security posture, and infrastructure security.
- Own the Secure SDLC / DevSecOps program, including SAST, DAST, SCA and container security.
- Lead vulnerability management, penetration testing and red team engagements.
- Oversee endpoint, infrastructure and firewall security.
- Drive detection engineering, threat intelligence and complex incident response.
- Develop and mentor a team of cybersecurity engineers and analysts.
- Partner with Engineering, IT, Compliance and other teams to improve Tabby’s overall security posture.
- 5+ years of cybersecurity experience, including technical leadership or senior-level responsibilities.
- Strong experience across security architecture, cloud security, AppSec/DevSecOps and vulnerability management.
- Hands-on understanding of offensive and defensive security, including penetration testing, red/purple teaming and incident response.
- Experience with SIEM, EDR/XDR, CSPM, DLP and vulnerability management platforms.
- Strong knowledge of GCP/AWS, IAM, Terraform, Kubernetes and CI/CD security.
- Experience with SAST, DAST, SCA and secure SDLC practices.
- Knowledge of SAMA CSF, NCA ECC, PCI-DSS and ISO 27001.
- Strong technical leadership, stakeholder management and team development skills.
- CISSP/CISM and OSCP or equivalent certifications are required.