logo

Lead Cyber Security Engineer - Defensive Security

localisationTanger-Tétouan-Al Hoceïma, Morocco

Décryptage du poste par Postule AI

About Tabby

Tabby is a leading FinTech company in the GCC region that creates financial freedom by reshaping how people shop, earn, and save. With over 17 million users and partnerships with 40,000+ global brands including Amazon, Noon, IKEA, and SHEIN, Tabby generates over $10 billion in annual transaction volume. Founded in 2019, the company has raised over $1 billion in funding and is valued at $4.5 billion.

Role Overview

We are seeking a Lead Cyber Security Engineer to join our Information Security team in Riyadh. You will provide technical leadership across defensive security initiatives, manage a team of security engineers and analysts, and drive security improvements across the organization.

Key Responsibilities

  • Lead security architecture and design reviews across IT, cloud, and product initiatives
  • Drive cloud security across GCP and AWS, including IAM, security posture, and infrastructure security
  • Own the Secure SDLC / DevSecOps program, including SAST, DAST, SCA, and container security
  • Lead vulnerability management, penetration testing, and red team engagements
  • Oversee endpoint, infrastructure, and firewall security
  • Drive detection engineering, threat intelligence, and complex incident response
  • Develop and mentor a team of cybersecurity engineers and analysts
  • Partner with Engineering, IT, Compliance, and other teams to improve security posture

Required Skills and Experience

  • 5+ years of cybersecurity experience with technical leadership or senior-level responsibilities
  • Strong expertise in security architecture, cloud security, AppSec/DevSecOps, and vulnerability management
  • Hands-on understanding of offensive and defensive security, including penetration testing, red/purple teaming, and incident response
  • Experience with SIEM, EDR/XDR, CSPM, DLP, and vulnerability management platforms
  • Strong knowledge of GCP/AWS, IAM, Terraform, Kubernetes, and CI/CD security
  • Experience with SAST, DAST, SCA, and secure SDLC practices
  • Knowledge of SAMA CSF, NCA ECC, PCI-DSS, and ISO 27001 compliance frameworks
  • Strong technical leadership, stakeholder management, and team development skills
  • CISSP/CISM and OSCP or equivalent certifications required

Cette description d'emploi a pu être reformatée par Postule pour améliorer sa lisibilité et sa présentation. Le contenu et les informations restent fidèles à l'offre d'emploi originale. .