تابي تعلن عن وظيفة مهندس أمن معلومات (SOC L2) في السعودية
تفاصيل الوظيفة
تابي، الشركة الرائدة في مجال التكنولوجيا المالية بالمنطقة، تبحث عن مهندس أمن معلومات (SOC L2) للعمل في المملكة العربية السعودية. سيكون دورك محوريًا في مراقبة الدفاع عن البنية التحتية والتطبيقات والبيئات السحابية ضد التهديدات السيبرانية، وقيادة جهود الاستجابة للحوادث، وتطوير قواعد الكشف، والتعاون مع الفرق المختلفة لتعزيز الوضع الأمني.
المهام والمسؤوليات
- مراقبة وتحليل السجلات والتنبيهات من مصادر متعددة تشمل جدران الحماية، أنظمة كشف/منع الاختراق (IDS/IPS)، نقاط النهاية، الخوادم، والمنصات السحابية.
- إجراء ربط الأحداث من مصادر متعددة لتحديد التهديدات المتقدمة والأنماط غير المعتادة.
- ضبط حدود التنبيهات ومنطق الكشف لتقليل الإنذارات الكاذبة وتحسين نسبة الإشارة إلى الضوضاء.
- صيانة لوحات المعلومات والتقارير لتوفير رؤية فورية للوضع الأمني.
- العمل كخط استجابة أول للحوادث الأمنية وإدارتها عبر دورة حياتها (الكشف، الاحتواء، الاستئصال، التعافي، والدروس المستفادة).
- التنسيق مع الجهات الداخلية والموردين الخارجيين أثناء الحوادث عالية الخطورة أو خروقات البيانات.
- إجراء تحليل السبب الجذري وتحقيقات جنائية باستخدام أدلة من نقاط النهاية والشبكة.
- توثيق الحوادث بالتفصيل والمساهمة في تقارير التحليل اللاحق.
- البحث في التهديدات والاتجاهات الناشئة والمساهمة في إنشاء وضبط قواعد الكشف واستعلامات صيد التهديدات عبر منصات متعددة بما فيها البيئات السحابية.
- صيانة منصة معلومات التهديدات (CTI) ودمج خلاصاتها مع الضوابط الأمنية لتفعيل الكشف القائم على معلومات التهديدات.
- التواصل الفعّال مع فرق تكنولوجيا المعلومات و DevOps والمخاطر والامتثال أثناء الحوادث والتحقيقات.
- تقديم تحديثات واضحة وموجزة لأصحاب المصلحة والإدارة أثناء التعامل مع الحوادث.
- إرشاد المحللين المبتدئين والمساعدة في جهود التدريب داخل فريق SOC.
المهارات المطلوبة
- خبرة من 2-3 سنوات في SOC أو أدوار عمليات الأمن السيبراني، ويفضل في بيئة تقنية مالية سريعة أو مؤسساتية.
- معرفة قوية بأفضل الممارسات الأمنية بما في ذلك التعامل مع الحوادث، فرز التنبيهات، تحليل السجلات، ونمذجة التهديدات.
- فهم التقنيات الحديثة عبر الإنترنت، REST APIs، الخدمات المصغرة، وبُنى التطبيقات الحديثة.
- خبرة في العمل ضمن بيئة متنوعة ثقافياً وتعاونية.
- الإلمام بأنظمة منع فقدان البيانات (DLP)، مضادات الفيروسات، ومضادات البرامج الضارة من منظور المراقبة التشغيلية.
- خبرة في اكتشاف التصيد، تحليلات سلوك المستخدم، وحملات التوعية الأمنية.
- شهادات أمنية مثل Security+ أو CySA+ أو eCIR أو eCTHPv2 أو GCIA أو GMON (مفضلة ولكن غير مطلوبة).
- مهارات تواصل قوية خاصة لتنسيق الاستجابة للحوادث وكتابة تقارير حوادث واضحة.
- خبرة مع منصات SIEM وأدوات SOAR و EDR/XDR ومنصات معلومات التهديدات.
- الإلمام بالبيئات السحابية وأدوات المراقبة والتسجيل السحابية الأصلية.
- خبرة في كتابة السكريبتات (مثل Python) لأتمتة المهام ورفع كفاءة فريق SOC.
عرض النص الأصلي للإعلان
The company’s flagship offering allows shoppers to split their payments online and in-store with no interest or fees. Over 70,000 global brands and small businesses, including Amazon, Noon, IKEA, and SHEIN use Tabby to accelerate growth and gain loyal customers by offering easy and flexible payments online and in stores.
Tabby generates over $18 billion in annual transaction volume for its partner brands and is the highest-rated, most-reviewed, largest, and fastest-growing FinTech in the GCC region.
Tabby launched in 2019 and has since raised +$1 billion in equity and debt funding from global and regional investors, and is now valued at $6,5 billion.
As Information Security Engineer, you’ll play a key part in monitoring and defending our infrastructure, applications, and cloud environments from cyber threats.
Key Responsibilities
- Monitor and analyze logs and alerts from a wide range of sources including firewalls, intrusion detection/prevention systems (IDS/IPS), endpoints, servers, and cloud platforms.
- Perform correlation of events from multiple sources to identify advanced threats and unusual patterns of behavior.
- Fine-tune alert thresholds and detection logic to reduce false positives and improve signal-to-noise ratio.
- Maintain dashboards and reporting to provide real-time visibility into security posture.
- Serve as a frontline responder for security incidents, managing incidents through their lifecycle - detection, containment, eradication, recovery, and lessons learned.
- Coordinate with internal stakeholders and external vendors during high-severity incidents or data breaches.
- Perform root cause analysis and forensic investigations using endpoint and network-based artifacts.
- Maintain detailed incident documentation and contribute to post-mortem analysis and reports.
- Research emerging threats and trends.
- Contribute to the creation and tuning of detection rules, threat-hunting queries, and use cases across multiple platforms including cloud environments.
- Maintaining CTI Platform along with the integration of the CTI feeds with the security controls to have active CTI driven detections.
- Communicate effectively with cross-functional teams including IT, DevOps, Risk, and Compliance during incidents and investigations.
- Provide concise and clear updates during incident handling to stakeholders and management.
- Mentor junior analysts and assist in training efforts within the SOC team.
Skills, Knowledge and Expertise
- 2-3 years of experience in a SOC or cybersecurity operations role, ideally in a fast-paced fintech or enterprise environment.
- Strong knowledge of security best practices, including incident handling, alert triage, log analysis, and threat modeling.
- Understanding of online technologies, REST APIs, microservices, and modern application architectures.
- Experience working in a culturally diverse and collaborative environment.
- Familiarity with DLP, AV, and anti-malware systems from an operational monitoring perspective.
- Experience with phishing detection, user behavior analytics, and security awareness campaigns.
- Security certifications such as Security+, CySA+, eCIR, eCTHPv2, GCIA, or GMON (preferred but not required).
- Strong communication skills, especially for coordinating incident response and writing clear incident reports.
- Experience with SIEM platforms, SOAR tools, EDR/XDR, and Threat Intelligence platforms.
- Familiarity with cloud environments and cloud-native logging and monitoring tools.
- Scripting experience (e.g., Python) to automate tasks and improve SOC efficiency.
رقم الإعلان لدى المصدر: 577553