SlipstreamJobsFresh Startup & VC-Backed Jobs

Lead, Information Security (Defensive)

Tabby - Riyadh, Saudi Arabia - In-office

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Tabby, a $4.5B-valued fintech unicorn operating across the GCC region, is seeking a Lead Cyber Security Engineer to join its Information Security team in Riyadh. With over 17 million users and $10B in annual transaction volume, Tabby is reshaping how people shop, earn, and save through flexible payment solutions. In this role, you will provide technical leadership across the organization's defensive security posture while managing a team of security engineers and analysts. You will lead security architecture and design reviews across IT, cloud, and product initiatives, ensuring robust protection across the enterprise. Key responsibilities include: - Drive cloud security strategy across GCP and AWS, managing IAM, security posture, and infrastructure security - Own the Secure SDLC / DevSecOps program, including SAST, DAST, SCA, and container security - Lead vulnerability management, penetration testing, and red team engagements - Oversee endpoint, infrastructure, and firewall security - Drive detection engineering, threat intelligence, and complex incident response - Develop and mentor a team of cybersecurity engineers and analysts - Partner with Engineering, IT, Compliance, and other teams to improve overall security posture Requirements: - 5+ years of cybersecurity experience, including technical leadership or senior-level responsibilities - Strong experience across security architecture, cloud security, AppSec/DevSecOps, and vulnerability management - Hands-on understanding of offensive and defensive security, including penetration testing, red/purple teaming, and incident response - Experience with SIEM, EDR/XDR, CSPM, DLP, and vulnerability management platforms - Strong knowledge of GCP/AWS, IAM, Terraform, Kubernetes, and CI/CD security - Experience with SAST, DAST, SCA, and secure SDLC practices - Knowledge of SAMA CSF, NCA ECC, PCI-DSS, and ISO 27001 - Strong technical leadership, stakeholder management, and team development skills - CISSP/CISM and OSCP or equivalent certifications required

Similar roles