📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

تابي تعلن عن وظيفة محلل أمن معلومات (SOC) في الرياض

Analyst, Information Security (SOC)
🕒 نُشرت: (منذ 29 يوماً) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

تعلن شركة تابي، إحدى شركات التكنولوجيا المالية الرائدة في منطقة الخليج، عن وظيفة محلل أمن المعلومات (SOC) في الرياض، السعودية. سيكون المحلل مسؤولاً عن إدارة منصة عمليات الأمن والاستخبارات السيبرانية، والعمل كمحور داخلي للإشراف على الخدمات المدارة وضمان التغطية التشغيلية الكاملة.

المهام والمسؤوليات

  • إدارة منصة Elastic SIEM: مراقبة صحة الكتلة، إدارة دورة حياة المؤشرات، معدلات إدخال السجلات، وصيانة الاستمرارية التشغيلية لجميع مصادر السجلات المتصلة.
  • امتلاك عملية إدخال مصادر السجلات الجديدة: التنسيق مع فرق تقنية المعلومات والـ DevOps والتطبيقات لربط الأصول الجديدة عبر syslog وAPI وBeats والعملاء المخصصين.
  • الحفاظ على جرد الأصول ومصادر السجلات: تتبع حالة الإدخال وحجم السجلات وفجوات التغطية ورفعها إلى رئيس الفريق.
  • تنفيذ الصيانة الدورية للـ SIEM: مراجعة صحة المؤشرات، إدارة سياسات الاحتفاظ، التحقق من تفعيل قواعد الكشف وخلوها من الأخطاء، وحل مشكلات التحليل أو فقدان السجلات.
  • دعم أنشطة ضبط الـ SIEM تحت إشراف الخبراء: ضبط خرائط الحقول، حل مشكلات خطوط الإدخال، والتحقق من تطبيع البيانات وإمكانية الاستعلام من قبل الفريق المُدار.
  • توثيق تكوينات SIEM: تسجيل أنماط المؤشرات، مواصفات دمج مصادر السجلات، معايير نشر العوامل، وملاحظات بنية المنصة.
  • الإشراف على الهندسة الكشفية وإدارة حالات الاستخدام: مراجعة واختبار قواعد الكشف المقدمة من مزود الخدمة المُدارة قبل النشر، والموافقة عليها بعد التحقق من دقتها وتوافقها مع نموذج التهديد.
  • الحفاظ على مكتبة حالات الاستخدام: تتبع جميع قواعد الكشف النشطة والمعلقة والملغاة مع سجل المنطق ونتائج المراجعة وتردد التشغيل.
  • مراقبة تقارير أداء حالات الاستخدام الأسبوعية من مزود الخدمة: الإبلاغ عن القواعد ذات النسب العالية من الإيجابيات الكاذبة أو القواعد غير المُفعّلة.
  • تطوير متطلبات كشف خاصة بالتهديدات المالية: ترجمة المخاطر التنظيمية والتجارية (اختراق الحسابات، الاحتيال، إساءة استخدام API) إلى مواصفات حالات استخدام.
  • ضمان توافق تغطية الكشف مع أطر عمل مثل MITRE ATT&CK وSAMA CSF وNCA ECC.
  • إدارة منصة Cyble للاستخبارات السيبرانية وحماية العلامة التجارية: التكوين، إدارة المستخدمين، دمج التغذيات، وربط API مع Elastic SIEM.
  • مراقبة التهديدات الناشئة: تتبع تكتيكات المهاجمين، الكشف عن الثغرات ذات الصلة بمكدس تكنولوجيا تابي، والتهديدات الخاصة بالقطاع المالي.
  • إدارة سجل مؤشرات الاختراق (IOC): جمع وتصنيف وتدوين مؤشرات بدقة (عناوين IP، نطاقات، تجزئات ملفات، روابط) مع سياق ومستويات ثقة وتواريخ انتهاء.
  • الإشراف على تفعيل IOC في قواعد الكشف: التنسيق مع الفريق المُدار لضمان إدخال المؤشرات المؤكدة ضمن أطر زمنية متفق عليها.
  • مراقبة إنذارات حماية العلامة التجارية: مراجعة نتائج انتحال النطاقات، التطبيقات المزيفة، الحسابات الوهمية، تسرب البيانات على الويب المظلم، وتسريب بيانات الاعتماد.
  • إعداد وتوزيع توجيهات دورية للاستخبارات: تجميع النتائج البارزة، حالة حماية العلامة، تغذيات IOC النشطة، واتجاهات التهديدات لفريق SOC.
  • العمل كحلقة وصل داخلية مع مزود خدمة SOC المُدارة: مراجعة ملخصات التنبيهات اليومية وتقارير الصيد الأسبوعية والتقارير الشهرية.
  • التحقق من التصعيدات: مراجعة الحوادث المرفوعة من مزود الخدمة للتأكد من كفاية أدلة التحقيق، دقة تصنيف الخطورة، واكتمال توصيات المعالجة.
  • امتلاك عملية إغلاق الحوادث: مراجعة توصيات الإغلاق، تأكيد إتمام المعالجة، توثيق الأدلة، وإغلاق الحوادث رسميًا في نظام إدارة الحوادث.
  • تتبع أداء SLA لمزود الخدمة المُدارة: مراقبة مؤشرات جودة التصعيد، توقيت تسليم الصيد، وتيرة تحديث حالات الاستخدام، والإبلاغ عن الانحرافات لرئيس الفريق.
  • الحفاظ على سجل الحوادث: ضمان دقة وسجل الحوادث الرئيسي وتحديثه وجاهزيته للتدقيق وفقًا لـ SAMA CSF والمتطلبات الداخلية.
  • المشاركة في مراجعات ما بعد الحادث: مراجعة تقارير ما بعد الحادث من مزود الخدمة، التحقق من نتائج تحليل الأسباب الجذرية، وتتبع الإجراءات التصحيحية حتى الاكتمال.
عرض النص الأصلي للإعلان

Department: InfoSec Monitoring

Location: KSA

Description

Tabby creates financial freedom in the way people shop, earn and save by reshaping their relationship with money. Over 17 million users choose Tabby to stay in control of their spending and make the most out of their money.

The company’s flagship offering allows shoppers to split their payments online and in-store with no interest or fees. Over 40,000 global brands and small businesses, including Amazon, Noon, IKEA, and SHEIN use Tabby to accelerate growth and gain loyal customers by offering easy and flexible payments online and in stores.

Tabby generates over $10 billion in annual transaction volume for its partner brands and is the highest-rated, most-reviewed, largest, and fastest-growing FinTech in the GCC region.
Tabby launched in 2019 and has since raised +$1 billion in equity and debt funding from global and regional investors, and is now valued at $4.5 billion.

The Cyber Security Analyst (SOC/CTI) is an internal Tabby role responsible for owning and administering Tabby's security operations platform and cyber threat intelligence capability. With 24x7 security monitoring and alert triage delivered by Tabby's managed SOC service provider, the internal SOC/CTI Analyst focuses on the functions Tabby retains in-house: administering Elastic SIEM, managing the Cyble CTI and brand protection platform, governing detection engineering and use case quality, overseeing managed SOC service performance, and serving as the internal authority for incident validation and closure. Working under the guidance of senior SOC engineers and the SOC/CTI Lead, the role ensures Tabby maintains full operational visibility, controls the quality of the managed service, and progressively builds internal SOC and detection engineering expertise aligned to Tabby's Fintech threat landscape.

Key Responsibilities

SIEM Administration & Log Source Management
  • Administer Tabby's Elastic SIEM deployment - monitoring platform health, index lifecycle management, cluster performance, and log ingestion rates to maintain continuous operational visibility across all connected log sources.
  • Own the log source onboarding process - coordinating with IT, Cloud, DevOps, and application teams to integrate new assets into Elastic SIEM via syslog, API connectors, Beats agents, or custom parsers.
  • Maintain and continuously improve Tabby's asset and log source inventory - tracking onboarding status, ingestion volumes, and coverage gaps, and escalating visibility deficiencies to the SOC Lead for prioritisation.
  • Perform routine SIEM housekeeping - reviewing index health, managing retention policies, verifying that critical detection rules are active and firing correctly, and resolving parsing errors or dropped log sources promptly.
  • Support SIEM tuning activities under senior guidance - adjusting field mappings, resolving ingest pipeline issues, and validating that log data is correctly normalised and queryable by the managed SOC team.
  • Maintain SIEM configuration documentation - recording index patterns, log source integration specifications, agent deployment standards, and platform architecture notes.
Detection Engineering & Use Case Governance
  • Serve as Tabby's internal point of contact for detection engineering - reviewing, testing, and formally approving correlation rules and use cases submitted by the managed SOC provider before production deployment.
  • Validate detection logic submitted by the vendor - testing use cases against sample log data in a staging environment to confirm accuracy, alignment with Tabby's threat model, and false positive risk before go-live.
  • Maintain Tabby's use case library - tracking all active, pending, and retired detection rules with their logic, use case ID, last review date, trigger frequency, and approval status.
  • Monitor weekly use case performance reports from the managed SOC - flagging rules with high false positive rates, untriggered rules, or detection gaps for remediation with the vendor.
  • Assist in developing Tabby-specific detection requirements for Fintech threats - translating business and regulatory risks (ATO, payment fraud, API abuse, credential stuffing) into detection use case specifications.
  • Ensure detection coverage aligns with relevant frameworks - reviewing use case libraries against MITRE ATT&CK, SAMA CSF controls, and NCA ECC requirements.
Cyber Threat Intelligence & Brand Protection (Cyble)
  • Administer and manage Tabby's Cyble CTI platform - maintaining platform configuration, user access, feed integrations, and API connectivity between Cyble and the Elastic SIEM environment.
  • Monitor Cyble for emerging threat intelligence relevant to Tabby - tracking new threat actor TTPs, CVE disclosures targeting Tabby's technology stack, and Fintech-specific threats including ATO campaigns, payment fraud schemes, and mobile app threats.
  • Manage Tabby's IOC registry - collecting, categorising, and maintaining accurate IOC entries (IP addresses, domains, file hashes, URLs) from Cyble and other feeds, with context, confidence levels, and expiry dates correctly recorded.
  • Oversee IOC operationalisation - coordinating with the managed SOC team to ensure confirmed IOCs are ingested into Elastic SIEM detection rules within agreed timeframes, and tracking coverage confirmation.
  • Monitor brand protection alerts via Cyble - reviewing findings for domain spoofing, counterfeit mobile applications, fake social media profiles, dark web data exposure, and leaked credentials; escalating confirmed threats per defined procedures.
  • Prepare and distribute periodic CTI briefings - compiling notable intelligence findings, brand protection status, active IOC feeds, and sector-relevant threat trends for the SOC Lead and relevant stakeholders.
Managed SOC Oversight & Incident Closure
  • Act as Tabby's primary internal liaison with the managed SOC service provider - reviewing daily alert summaries, weekly threat hunting reports, and monthly management reports submitted by the vendor.
  • Validate vendor escalations - reviewing incidents escalated by the managed SOC to confirm sufficient investigation evidence, accurate severity classification, and completeness of remediation recommendations before internal action.
  • Own Tabby's incident closure process - reviewing vendor-recommended closures, confirming remediation actions have been completed, ensuring evidence is properly documented, and formally closing incidents in the incident management system.
  • Track managed SOC SLA performance - monitoring key metrics including escalation quality, threat hunting deliverable timeliness, and use case update frequency; flagging deviations to the SOC Lead.
  • Maintain Tabby's incident register - ensuring the master incident log is accurate, current, and audit-ready in line with SAMA CSF and internal governance requirements.
  • Participate in post-incident reviews - reviewing vendor post-incident reports, validating root cause analysis findings, and tracking agreed corrective actions to completion.
SOC Reporting & Continuous Improvement
  • Maintain SOC operational documentation - escalation records, tool status trackers, runbook libraries, and detection playbooks - ensuring records are accurate, current, and audit-ready.
  • Support the preparation of SOC performance reports and metrics dashboards - compiling MTTD/MTTR statistics, SLA adherence data, IOC registry accuracy, and use case coverage metrics.
  • Contribute to SOC process improvement initiatives - identifying gaps in detection coverage, tooling, or process and raising improvement recommendations to the SOC Lead.
  • Actively invest in continuous self-development - studying SIEM administration, detection engineering, Cyble platform capabilities, and the MITRE ATT&CK framework to build independent expertise and progress toward the next grade.

Skills, Knowledge and Expertise

  • Bachelor's degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, or a related field.
  • Recent graduates and fresh university leavers are encouraged to apply - no prior professional SOC experience is required.
  • Academic projects, home labs (e.g., TryHackMe Blue Team paths, HackTheBox, Elastic Stack builds), or internship experience in security operations or monitoring are viewed favorably.
  • No mandatory professional experience required. Any internship, academic project, or personal lab experience related to security operations, log analysis, SIEM platforms, or threat intelligence is a strong advantage. Hands-on exposure to Elastic Stack, even in a self-study context, is a distinct advantage
  • Foundational understanding of SIEM platforms - ability to navigate Elastic Stack (Kibana dashboards, KQL/Lucene queries, ES|QL) consoles to review alerts, investigate events, and query log data across multiple sources.
  • Basic understanding of network security fundamentals - TCP/IP protocols, DNS, HTTP/S, common attack traffic patterns (port scans, brute force, C2 beaconing), and how they manifest in SIEM log sources.
  • Foundational awareness of endpoint security monitoring - Windows Event Log analysis (logon events, process creation, registry changes), Linux syslog, and common persistence and lateral movement indicators.
المصدر: LinkedIn - أُضيفت للموقع في 10 سبتمبر 2026
رقم الإعلان لدى المصدر: 4465650466