SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Tabby is a fintech platform that enables flexible payment solutions, serving over 17 million users and processing $10 billion in annual transaction volume. The company is valued at $4.5 billion and operates across the GCC region and globally.
You will lead Tabby's information security function, managing a team of security professionals and owning strategic and technical security programs. This is a hands-on leadership role where you will drive security architecture, cloud security, application security, vulnerability management, threat detection, and incident response initiatives.
Key responsibilities include:
- Lead security architecture and technical reviews across cloud (GCP/AWS), infrastructure, and product initiatives
- Design and implement security controls including IAM, CSPM, and cloud-native security
- Drive Secure SDLC and DevSecOps programs (SAST, DAST, SCA, container security)
- Lead vulnerability management, penetration testing, VAPT, and red/purple team engagements
- Design threat detection, SIEM use cases, and security monitoring
- Lead complex security incident investigations and response
- Drive endpoint, infrastructure, network, and firewall security initiatives
- Automate security processes and develop security tooling
- Establish technical standards, security best practices, and operating procedures
- Manage, mentor, and develop a team of security engineers and analysts
- Collaborate with Engineering, Infrastructure, Product, IT, Legal, and Compliance teams
Requirements:
- 5+ years of information security or cybersecurity experience, with at least 2 years in a technical leadership or senior individual contributor role
- Prior people management or team leadership experience strongly preferred
- Deep expertise in cloud security, security architecture, VAPT, AppSec/DevSecOps, and defensive security
- Experience leading security programs and managing cross-functional initiatives
- Strong knowledge of GCP/AWS, IAM, CSPM, SIEM, EDR/XDR, and vulnerability management
- Strong understanding of penetration testing, red/purple teaming, threat hunting, and incident response
- Experience with SAST, DAST, SCA, and container security in CI/CD environments
- Strong understanding of security architecture, threat modeling, and enterprise security controls
- Experience in regulated FinTech or banking environments
- Knowledge of CBUAE, UAE PDPL, PCI-DSS, ISO 27001, and SOC 2
- Proven people leadership, stakeholder management, and strategic decision-making skills
- CISSP/CISM and OSCP or equivalent certifications preferred/required