📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

وظيفة قائد أمن المعلومات (دفاعي) شاغرة لدى تابي بالرياض

Lead, Information Security (Defensive)
🕒 نُشرت: (منذ 29 يوماً) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

تابي تبحث عن قائد أمن المعلومات (دفاعي) للانضمام إلى فريق أمن المعلومات في الرياض، حيث سيوفر القيادة التقنية عبر الأمن الدفاعي ويدير فريقاً من مهندسي ومحللي الأمن.

نبذة عن الوظيفة

تابي هي منصة مالية رائدة تخلق حرية مالية في طريقة تسوق الأشخاص وكسبهم وادخارهم. مع أكثر من 17 مليون مستخدم و40,000 علامة تجارية شريكة مثل أمازون ونون وإيكيا، تتيح تابي تقسيط المدفوعات بدون فوائد. نبحث عن قائد أمن سيبراني لديه خبرة في الأمن الدفاعي لقيادة فريق الأمن في الرياض.

المهام والمسؤوليات

  • قيادة مراجعات الهندسة الأمنية وتصميمها عبر مبادرات تكنولوجيا المعلومات والسحابة والمنتجات.
  • قيادة أمن السحابة عبر GCP وAWS، بما في ذلك IAM والوضع الأمني وأمن البنية التحتية.
  • امتلاك برنامج Secure SDLC / DevSecOps، بما في ذلك SAST وDAST وSCA وأمن الحاويات.
  • قيادة إدارة الثغرات واختبار الاختراق ومشاركات الفريق الأحمر.
  • الإشراف على أمن نقاط النهاية والبنية التحتية وجدار الحماية.
  • قيادة هندسة الكشف والاستخبارات التهديدية والاستجابة للحوادث المعقدة.
  • تطوير وتوجيه فريق من مهندسي ومحللي الأمن السيبراني.
  • الشراكة مع فرق الهندسة وتكنولوجيا المعلومات والامتثال وغيرها لتحسين الوضع الأمني العام لتابي.

المهارات المطلوبة

  • 5+ سنوات من الخبرة في الأمن السيبراني، بما في ذلك مسؤوليات قيادية تقنية أو على مستوى كبير.
  • خبرة قوية في هندسة الأمن وأمن السحابة وأمن التطبيقات/DevSecOps وإدارة الثغرات.
  • فهم عملي للأمن الهجومي والدفاعي، بما في ذلك اختبار الاختراق والفريق الأحمر/الأرجواني والاستجابة للحوادث.
  • خبرة مع SIEM وEDR/XDR وCSPM وDLP ومنصات إدارة الثغرات.
  • معرفة قوية بـ GCP/AWS وIAM وTerraform وKubernetes وأمن CI/CD.
  • خبرة مع SAST وDAST وSCA وممارسات SDLC الآمنة.
  • معرفة بـ SAMA CSF وNCA ECC وPCI-DSS وISO 27001.
  • مهارات قيادية تقنية قوية وإدارة أصحاب المصلحة وتطوير الفريق.
  • مطلوب شهادات CISSP/CISM وOSCP أو ما يعادلها.
عرض النص الأصلي للإعلان

Department: InfoSec Monitoring

Location: KSA

Description

Tabby creates financial freedom in the way people shop, earn and save by reshaping their relationship with money. Over 17 million users choose Tabby to stay in control of their spending and make the most out of their money.

The company’s flagship offering allows shoppers to split their payments online and in-store with no interest or fees. Over 40,000 global brands and small businesses, including Amazon, Noon, IKEA, and SHEIN use Tabby to accelerate growth and gain loyal customers by offering easy and flexible payments online and in stores.

Tabby generates over $10 billion in annual transaction volume for its partner brands and is the highest-rated, most-reviewed, largest, and fastest-growing FinTech in the GCC region.
Tabby launched in 2019 and has since raised +$1 billion in equity and debt funding from global and regional investors, and is now valued at $4.5 billion.

We are looking for a Lead Cyber Security Engineer to join our Information Security team in Riyadh. You will provide technical leadership across defensive security, while managing a team of security engineers and analysts and driving security initiatives across the organization.

Key Responsibilities

  • Lead security architecture and design reviews across IT, cloud, and product initiatives.
  • Drive cloud security across GCP and AWS, including IAM, security posture, and infrastructure security.
  • Own the Secure SDLC / DevSecOps program, including SAST, DAST, SCA and container security.
  • Lead vulnerability management, penetration testing and red team engagements.
  • Oversee endpoint, infrastructure and firewall security.
  • Drive detection engineering, threat intelligence and complex incident response.
  • Develop and mentor a team of cybersecurity engineers and analysts.
  • Partner with Engineering, IT, Compliance and other teams to improve Tabby’s overall security posture.

Skills, Knowledge and Expertise

  • 5+ years of cybersecurity experience, including technical leadership or senior-level responsibilities.
  • Strong experience across security architecture, cloud security, AppSec/DevSecOps and vulnerability management.
  • Hands-on understanding of offensive and defensive security, including penetration testing, red/purple teaming and incident response.
  • Experience with SIEM, EDR/XDR, CSPM, DLP and vulnerability management platforms.
  • Strong knowledge of GCP/AWS, IAM, Terraform, Kubernetes and CI/CD security.
  • Experience with SAST, DAST, SCA and secure SDLC practices.
  • Knowledge of SAMA CSF, NCA ECC, PCI-DSS and ISO 27001.
  • Strong technical leadership, stakeholder management and team development skills.
  • CISSP/CISM and OSCP or equivalent certifications are required.
المصدر: LinkedIn - أُضيفت للموقع في 10 سبتمبر 2026
رقم الإعلان لدى المصدر: 4465808427