Lead Information Security Engineer (Defensive)

Tabby
Riyadh
Workplace: OnsiteFull timeFunction: CybersecuritySkills: ["Technical leadership","Stakeholder management","Team development","Incident response","Security architecture","Detection engineering"]

Lead and manage Tabby’s defensive security efforts in Riyadh, providing technical leadership across security architecture, cloud security, AppSec/DevSecOps, and vulnerability management. Drive secure SDLC and DevSecOps programs (SAST/DAST/SCA and container security), oversee vulnerability management and red-team testing, and enhance detection engineering, threat intelligence, and incident response. Partner with Engineering, IT, and Compliance to strengthen Tabby’s overall security posture while mentoring security engineers and analysts.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Tabby
Tabby
23 hours ago

Lead Information Security Engineer (Defensive)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 9 hours agoStatus: Live

Job Summary

Lead and manage Tabby’s defensive security efforts in Riyadh, providing technical leadership across security architecture, cloud security, AppSec/DevSecOps, and vulnerability management. Drive secure SDLC and DevSecOps programs (SAST/DAST/SCA and container security), oversee vulnerability management and red-team testing, and enhance detection engineering, threat intelligence, and incident response. Partner with Engineering, IT, and Compliance to strengthen Tabby’s overall security posture while mentoring security engineers and analysts.
Location: Riyadh
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Manager level

Key Responsibilities

  • •Lead security architecture and design reviews across IT, cloud, and product initiatives.
  • •Drive cloud security across GCP and AWS, including IAM, security posture, and infrastructure security.
  • •Own the Secure SDLC/DevSecOps program, covering SAST, DAST, SCA, and container security.
  • •Lead vulnerability management, penetration testing, and red team engagements; oversee endpoint, infrastructure, and firewall security.
  • •Develop and mentor a team of security engineers and analysts, and partner cross-functionally to improve overall security posture.

Key Requirements

  • •5+ years of cybersecurity experience with technical leadership or senior-level responsibilities.
  • •Strong security architecture experience across cloud security, AppSec/DevSecOps, and vulnerability management.
  • •Hands-on experience with offensive and defensive security, including penetration testing, red/purple teaming, and incident response.
  • •Experience with SIEM, EDR/XDR, CSPM, DLP, and vulnerability management platforms; strong knowledge of GCP/AWS, IAM, Terraform, Kubernetes, and CI/CD security.
  • •CISSP/CISM and OSCP (or equivalent) certifications are required.
Experience:FintechGCCSecurity leadershipCloud security
Skills:Technical leadershipStakeholder managementTeam developmentIncident responseSecurity architectureDetection engineering
Certifications:CISSPCISMOSCP
Tech Stack:GCPAWSIAMTerraformKubernetesCI/CDDevSecOpsSecure SDLCSASTDASTSCASIEMEDR/XDRCSPMDLPContainer securityThreat intelligence

Company Brief

Tabby
Tabby is a MENA buy‑now‑pay‑later and fintech platform that enables customers to split purchases into installments, offers in‑store and online payment products, a consumer app, and merchant services across Saudi Arabia, UAE, Kuwait and the wider region.
Industry: Lending
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series E+
Headquarters: Riyadh, Saudi Arabia
Founded: 2019
Glassdoor
Glassdoor: 4.0
WebsiteLinkedInGlassdoor