Senior Manager Information Security
About the role
Tabbycreates financial freedom in the way people shop, earn and save by reshaping their relationship with money. Over 17 million users choose Tabby to stay in control of their spending and make the most out of their money.
The company's flagship offering allows shoppers to split their payments online and in-store with no interest or fees. Over 40,000 global brands and small businesses, including Amazon, Noon, IKEA, and SHEIN use Tabby to accelerate growth and gain loyal customers by offering easy and flexible payments online and in stores.
Tabby generates over $10 billion in annual transaction volume for its partner brands and is the highest-rated, most-reviewed, largest, and fastest-growing FinTech in the GCC region.
Tabby launched in 2019 and has since raised +$1 billion in equity and debt funding from global and regional investors, and is now valued at $4.5 billion.
We are looking for aSenior Manager Information Securityto lead and shape Tabby's information security function across both strategic and technical domains. This role will lead a team of security professionals and own key security programmes across cloud security, security architecture, application security, vulnerability management, threat detection and incident response.
Responsibilities
- Lead and contribute hands-on to security architecture and technical security reviews across cloud, infrastructure and product initiatives.
- Design and implement security controls acrossGCP and AWS, including IAM, CSPM and cloud-native security.
- Drive and contribute toSecure SDLC / DevSecOps, including SAST, DAST, SCA and container security.
- Lead vulnerability management and actively participate in penetration testing, VAPT and red/purple team engagements.
- Design and improve threat detection, SIEM use cases and security monitoring.
- Lead and participate in complex security incident investigations and response.
- Drive endpoint, infrastructure, network and firewall security initiatives.
- Automate security processes and develop security tooling where needed.
- Establish technical standards, security best practices and operating procedures.
- Manage, mentor and develop a team of security engineers and analysts.
- Work closely with Engineering, Infrastructure, Product, IT, Legal and Compliance teams to embed security across Tabby.
Requirements
- Strong experience leadingInformation Security / Cyber Securityfunctions in a senior technical or management role.
- 5+ yearsof experience in Information Security or Cybersecurity, with at least2 yearsin a technical leadership or senior individual contributor role. Prior people management or team leadership experience is strongly preferred.
- Deep expertise acrossCloud Security, Security Architecture, VAPT, AppSec/DevSecOps and Defensive Security.
- Experience leading security programmes and managing cross-functional initiatives.
- Strong knowledge ofGCP/AWS, IAM, CSPM, SIEM, EDR/XDR and vulnerability management.
- Strong understanding ofpenetration testing, red/purple teaming, threat hunting and incident response.
- Experience withSAST, DAST, SCA and container securitywithin CI/CD environments.
- Strong understanding of security architecture, threat modelling and enterprise security controls.
- Experience working within aregulated FinTech or banking environment.
- Knowledge ofCBUAE, UAE PDPL, PCI-DSS, ISO 27001 and SOC 2.
- Proven people leadership, stakeholder management and strategic decision-making skills.
- CISSP/CISM and OSCP or equivalentcertifications are preferred/required depending on the final hiring criteria.