Généré automatiquement par Postule AI à partir de l’offre.
About Tabby
Tabby is a leading FinTech platform in the GCC region with over 25 million users, enabling flexible payment solutions for shoppers and businesses. The company has raised over $1 billion in funding and is valued at $6.5 billion.
Role Overview
As an Information Security Engineer (SOC L2), you will be a key defender of Tabby's infrastructure, applications, and cloud environments. You'll lead incident response efforts, develop detection rules, investigate security events, and collaborate with cross-functional teams to strengthen our security posture.
Main Responsibilities
Security Monitoring & Detection
- Monitor and analyze logs and alerts from firewalls, IDS/IPS, endpoints, servers, and cloud platforms
- Perform event correlation across multiple sources to identify advanced threats and unusual behavior patterns
- Fine-tune alert thresholds and detection logic to reduce false positives and improve signal-to-noise ratio
- Maintain dashboards and reporting for real-time visibility into security posture
Incident Response & Investigation
- Serve as frontline responder for security incidents, managing full lifecycle from detection through recovery
- Coordinate with internal stakeholders and external vendors during high-severity incidents or data breaches
- Perform root cause analysis and forensic investigations using endpoint and network artifacts
- Maintain detailed incident documentation and contribute to post-mortem analysis
Threat Intelligence & Detection Rule Development
- Research emerging threats and trends to inform detection strategies
- Create and tune detection rules, threat-hunting queries, and use cases across multiple platforms
- Maintain CTI Platform and integrate CTI feeds with security controls for active threat-driven detections
Collaboration and Communication
- Communicate effectively with IT, DevOps, Risk, and Compliance teams during incidents
- Provide clear updates to stakeholders and management during incident handling
- Mentor junior analysts and assist in SOC team training efforts
Required Skills & Experience
- 2–3 years in SOC or cybersecurity operations role, preferably in fintech or enterprise environment
- Strong knowledge of incident handling, alert triage, log analysis, and threat modeling
- Experience with SIEM platforms, SOAR tools, EDR/XDR, and Threat Intelligence platforms
- Familiarity with DLP, AV, and anti-malware systems from operational perspective
- Experience with phishing detection, user behavior analytics, and security awareness
- Understanding of REST APIs, microservices, and modern application architectures
- Scripting experience (Python) to automate tasks and improve SOC efficiency
- Familiarity with cloud environments and cloud-native logging and monitoring tools
Security certifications (Security+, CySA+, eCIR, eCTHPv2, GCIA, GMON) are preferred but not required.
Cette description d'emploi a pu être reformatée par Postule pour améliorer sa lisibilité et sa présentation. Le contenu et les informations restent fidèles à l'offre d'emploi originale. .
