تابي تعلن عن وظيفة قائد أمن المعلومات (دفاعي) في المملكة العربية السعودية
تفاصيل الوظيفة
تابي هي شركة تكنولوجيا مالية رائدة في منطقة الخليج، تخدم أكثر من 25 مليون مستخدم، وتتخذ من الرياض مقراً لها. نبحث عن قائد أمن معلومات (دفاعي) للانضمام إلى فريق أمن المعلومات لدينا والمساهمة في تعزيز الوضع الأمني للمنظمة.
المهام والمسؤوليات
- قيادة مراجعات تصميم وهندسة الأمن عبر مبادرات تقنية المعلومات، السحابة، والمنتجات.
- إدارة أمن السحابة على GCP و AWS، بما يشمل إدارة الهوية والوصول (IAM)، وضع أمن السحابة، وأمن البنية التحتية.
- قيادة برنامج Secure SDLC و DevSecOps، بما في ذلك أمن التطبيقات وأدوات الأمن عبر CI/CD.
- إدارة الثغرات الأمنية، بما يشمل معالجة الثغرات، اختبار الاختراق، وتمارين الفريق الأحمر.
- الإشراف على أمن نقاط النهاية والبنية التحتية والشبكات، بما في ذلك EDR و DLP وجدران الحماية.
- قيادة هندسة الكشف، استخبارات التهديدات، والاستجابة للحوادث، بما في ذلك التحقيقات الأمنية المعقدة.
- إدارة وتطوير فريق من مهندسي ومحللي الأمن، بما في ذلك التوجيه وإدارة الأداء والتطوير المهني.
- التعاون مع فرق الهندسة وتقنية المعلومات والامتثال وغيرها لتحسين الوضع الأمني والمعايير الأمنية لتاي.
الشروط والمتطلبات
- خبرة لا تقل عن 5 سنوات في مجال الأمن السيبراني / أمن المعلومات، مع مسؤوليات قيادية تقنية أو على مستوى عالٍ.
- خبرة في قيادة برامج أمنية تشمل هندسة الأمن، أمن السحابة، إدارة الثغرات، وأمن التطبيقات.
- فهم قوي للأمن الدفاعي والهجومي، بما في ذلك اختبار الاختراق، تمارين الفريق الأحمر/الأرجواني، صيد التهديدات، والاستجابة للحوادث.
- خبرة عملية مع SIEM، EDR/XDR، إدارة الثغرات، CSPM، DLP، ومنصات مراقبة الأمن.
- معرفة قوية بـ GCP و/أو AWS، IAM، أمن السحابة، وأمن البنية التحتية.
- خبرة مع DevSecOps، Secure SDLC، SAST، DAST، SCA، وأمن الحاويات.
- مهارات قوية في البرمجة النصية والأتمتة، والقدرة على تطوير أو الإشراف على أدوات وتكاملات أمنية.
- معرفة بمعايير SAMA CSF، NCA ECC، PCI-DSS، و ISO 27001.
- خبرة في العمل في بيئة تكنولوجيا مالية منظمة أو بيئة مصرفية.
- مهارات قيادية تقنية قوية، وإدارة أصحاب المصلحة، وتطوير الفريق.
- شهادات CISSP/CISM و OSCP أو ما يعادلها مطلوبة.
عرض النص الأصلي للإعلان
The company’s flagship offering allows shoppers to split their payments online and in-store with no interest or fees. Over 70,000 global brands and small businesses, including Amazon, Noon, IKEA, and SHEIN use Tabby to accelerate growth and gain loyal customers by offering easy and flexible payments online and in stores.
Tabby generates over $18 billion in annual transaction volume for its partner brands and is the highest-rated, most-reviewed, largest, and fastest-growing FinTech in the GCC region.
Tabby launched in 2019 and has since raised +$1 billion in equity and debt funding from global and regional investors, and is now valued at $6,5 billion.
We are looking for a Cyber Security Lead to join our Information Security team in Riyadh. You will provide technical leadership across defensive security, while managing a team of security engineers and analysts and driving security initiatives across the organization.
Key Responsibilities
- Lead security architecture and design reviews across IT, cloud, and product initiatives.
- Drive cloud security across GCP and AWS, including IAM, cloud security posture, and infrastructure security.
- Lead the Secure SDLC / DevSecOps programme, including application security and security tooling across CI/CD.
- Own vulnerability management, including vulnerability remediation, penetration testing and red team engagements.
- Oversee endpoint, infrastructure and network security, including EDR, DLP and firewall security.
- Lead detection engineering, threat intelligence and incident response, including complex security investigations.
- Manage and develop a team of security engineers and analysts, including mentoring, performance management and career development.
- Partner with Engineering, IT, Compliance and other teams to improve Tabby’s overall security posture and security standards.
Skills, Knowledge and Expertise
- 5+ years of experience in cybersecurity / information security, including technical leadership or senior-level responsibilities.
- Experience leading security programmes across security architecture, cloud security, vulnerability management and application security.
- Strong understanding of defensive and offensive security, including penetration testing, red/purple teaming, threat hunting and incident response.
- Hands-on experience with SIEM, EDR/XDR, vulnerability management, CSPM, DLP and security monitoring platforms.
- Strong knowledge of GCP and/or AWS, IAM, cloud security and infrastructure security.
- Experience with DevSecOps, Secure SDLC, SAST, DAST, SCA and container security.
- Strong scripting and automation skills and the ability to develop or oversee security tooling and integrations.
- Knowledge of SAMA CSF, NCA ECC, PCI-DSS and ISO 27001.
- Experience working in a regulated FinTech or banking environment.
- Strong technical leadership, stakeholder management and team development skills.
- CISSP/CISM and OSCP or equivalent certifications are required.
رقم الإعلان لدى المصدر: 577561