高级信息安全管理经理
Senior Manager Information Security
Tabby通过重新定义人们与金钱的关系,为人们提供财务自由,改变他们的购物、赚钱和储蓄方式。超过1700万用户选择Tabby来掌控自己的消费,并让每一分钱都发挥最大价值。
公司的旗舰产品允许消费者在线上和线下进行无利息、无费用的分期付款。包括Amazon、Noon、IKEA和SHEIN在内的40000多个全球品牌和小型企业使用Tabby,通过提供便捷灵活的支付方式加速增长并赢得忠实客户。
Tabby为其合作伙伴品牌带来每年超过100亿美元的交易量,是海湾合作委员会(GCC)地区评级最高、评价最多、规模最大且增长最快的金融科技公司。
Tabby于2019年推出,此后从全球和地区投资者处筹集了超过10亿美元的股权和债务融资,目前估值达45亿美元。
我们正在寻找一位高级信息安全经理,负责领导和塑造Tabby在战略和技术领域的信息安全职能。该职位将领导一支安全专业人员团队,并负责云安全、安全架构、应用安全、漏洞管理、威胁检测和事件响应等关键安全项目。
主要职责
- 领导并亲自参与跨云、基础设施和产品计划的安全架构和技术安全评审。
- 在GCP和AWS上设计并实施安全控制措施,包括IAM、CSPM和原生云安全。
- 推动并参与安全的SDLC/DevSecOps,包括SAST、DAST、SCA和容器安全。
- 领导漏洞管理并积极参与渗透测试、VAPT和红/紫队演练。
- 设计并改进威胁检测、SIEM用例和安全监控。
- 领导并参与复杂的安全事件调查和响应。
- 推动端点、基础设施、网络和防火墙安全项目。
- 自动化安全流程并在需要时开发安全工具。
- 建立技术标准、安全最佳实践和操作流程。
- 管理、指导和发展安全工程师和分析师团队。
- 与工程、基础设施、产品、IT、法律和合规团队紧密合作,将安全嵌入Tabby的各个方面。
技能、知识和专长
- 在高级技术或管理岗位上拥有丰富的信息安全管理/网络安全经验
查看英文原文
Tabby creates financial freedom in the way people shop, earn and save by reshaping their relationship with money. Over 17 million users choose Tabby to stay in control of their spending and make the most out of their money.
The company’s flagship offering allows shoppers to split their payments online and in-store with no interest or fees. Over 40,000 global brands and small businesses, including Amazon, Noon, IKEA, and SHEIN use Tabby to accelerate growth and gain loyal customers by offering easy and flexible payments online and in stores.
Tabby generates over $10 billion in annual transaction volume for its partner brands and is the highest-rated, most-reviewed, largest, and fastest-growing FinTech in the GCC region.
Tabby launched in 2019 and has since raised +$1 billion in equity and debt funding from global and regional investors, and is now valued at $4.5 billion.
We are looking for a Senior Manager Information Security to lead and shape Tabby’s information security function across both strategic and technical domains. This role will lead a team of security professionals and own key security programmes across cloud security, security architecture, application security, vulnerability management, threat detection and incident response.
Key Responsibilities
- Lead and contribute hands-on to security architecture and technical security reviews across cloud, infrastructure and product initiatives.
- Design and implement security controls across GCP and AWS, including IAM, CSPM and cloud-native security.
- Drive and contribute to Secure SDLC / DevSecOps, including SAST, DAST, SCA and container security.
- Lead vulnerability management and actively participate in penetration testing, VAPT and red/purple team engagements.
- Design and improve threat detection, SIEM use cases and security monitoring.
- Lead and participate in complex security incident investigations and response.
- Drive endpoint, infrastructure, network and firewall security initiatives.
- Automate security processes and develop security tooling where needed.
- Establish technical standards, security best practices and operating procedures.
- Manage, mentor and develop a team of security engineers and analysts.
- Work closely with Engineering, Infrastructure, Product, IT, Legal and Compliance teams to embed security across Tabby.
Skills, Knowledge and Expertise
- Strong experience leading Information Security / Cyber Security functions in a senior technical or management role.
- Deep expertise across Cloud Security, Security Architecture, VAPT, AppSec/DevSecOps and Defensive Security.
- Experience leading security programmes and managing cross-functional initiatives.
- Strong knowledge of GCP/AWS, IAM, CSPM, SIEM, EDR/XDR and vulnerability management.
- Strong understanding of penetration testing, red/purple teaming, threat hunting and incident response.
- Experience with SAST, DAST, SCA and container security within CI/CD environments.
- Strong understanding of security architecture, threat modelling and enterprise security controls.
- Experience working within a regulated FinTech or banking environment.
- Knowledge of CBUAE, UAE PDPL, PCI-DSS, ISO 27001 and SOC 2.
- Proven people leadership, stakeholder management and strategic decision-making skills.
- CISSP/CISM and OSCP or equivalent certifications are preferred/required depending on the final hiring criteria.
Originally posted on Himalayas