T

Information Security Engineer (SOC L2) (Python)

Tabby creates financial freedom in the way people shop, earn and save by reshaping their relationship with money. Over 25 million users choose Tabby to stay in control of their spending and make the most out of their money.

tabby На сервисе с: 05.10.26 13:47

Зарплата не указанаСаудовская АравияRiyadhОфис

About the role

Tabby creates financial freedom in the way people shop, earn and save by reshaping their relationship with money. Over 25 million users choose Tabby to stay in control of their spending and make the most out of their money.

The company’s flagship offering allows shoppers to split their payments online and in-store with no interest or fees. Over 70,000 global brands and small businesses, including Amazon, Noon, IKEA, and SHEIN use Tabby to accelerate growth and gain loyal customers by offering easy and flexible payments online and in stores.
Tabby generates over $18 billion in annual transaction volume for its partner brands and is the highest-rated, most-reviewed, largest, and fastest-growing FinTech in the GCC region.

Tabby launched in 2019 and has since raised +$1 billion in equity and debt funding from global and regional investors, and is now valued at $6,5 billion.

As Information Security Engineer, you’ll play a key part in monitoring and defending our infrastructure, applications, and cloud environments from cyber threats. 

You’ll lead incident response efforts, develop and tune detection rules, investigate security events, and collaborate with cross-functional teams to strengthen our security posture.

Responsibilities

Security Monitoring & Detection
  • Monitor and analyze logs and alerts from a wide range of sources including firewalls, intrusion detection/prevention systems (IDS/IPS), endpoints, servers, and cloud platforms.
  • Perform correlation of events from multiple sources to identify advanced threats and unusual patterns of behavior.
  • Fine-tune alert thresholds and detection logic to reduce false positives and improve signal-to-noise ratio.
  • Maintain dashboards and reporting to provide real-time visibility into security posture.

Incident Response & Investigation
  • Serve as a frontline responder for security incidents, managing incidents through their lifecycle – detection, containment, eradication, recovery, and lessons learned.
  • Coordinate with internal stakeholders and external vendors during high-severity incidents or data breaches.
  • Perform root cause analysis and forensic investigations using endpoint and network-based artifacts.
  • Maintain detailed incident documentation and contribute to post-mortem analysis and reports.

Threat Intelligence & Detection Rule Development
  • Research emerging threats and trends. 
  • Contribute to the creation and tuning of detection rules, threat-hunting queries, and use cases across multiple platforms including cloud environments.
  • Maintaining CTI Platform along with the integration of the CTI feeds with the security controls to have active CTI driven detections.

Collaboration and Communication
  • Communicate effectively with cross-functional teams including IT, DevOps, Risk, and Compliance during incidents and investigations.
  • Provide concise and clear updates during incident handling to stakeholders and management.
  • Mentor junior analysts and assist in training efforts within the SOC team.

Qualifications

  • 2–3 years of experience in a SOC or cybersecurity operations role, ideally in a fast-paced fintech or enterprise environment.
  • Strong knowledge of security best practices, including incident handling, alert triage, log analysis, and threat modeling.
  • Understanding of online technologies, REST APIs, microservices, and modern application architectures.
  • Experience working in a culturally diverse and collaborative environment.
  • Familiarity with DLP, AV, and anti-malware systems from an operational monitoring perspective.
  • Experience with phishing detection, user behavior analytics, and security awareness campaigns.
  • Security certifications such as Security+, CySA+, eCIR, eCTHPv2, GCIA, or GMON (preferred but not required).
  • Strong communication skills, especially for coordinating incident response and writing clear incident reports.
  • Experience with SIEM platforms, SOAR tools, EDR/XDR, and Threat Intelligence platforms.
  • Familiarity with cloud environments and cloud-native logging and monitoring tools.
  • Scripting experience (e.g., Python) to automate tasks and improve SOC efficiency.

Похожие вакансии Кибербезопасность

Сайты компаний
andersen

Penetration Tester

andersenНа сервисе с: 05.10.26 15:15
Зарплата не указанаКипрГерманияИспанияПортугалияЧехияЛюксембургЛатвияЛитваЭстонияВенгрияФинляндияФранцияАвстрияДанияИталияГибрид

Andersen is hiring a Penetration Tester for a project strengthening cybersecurity, identifying vulnerabilities, and mitigating security risks across complex digital environments.

Our customer is a technology and consulting organization providing digital infrastructure, cloud services, cybersecurity, data-driven solutions, and managed IT support. It helps organizations modernize complex technology environments, strengthen security, and improve the reliability and scalability of their digital operations. By combining technical expertise with modern technologies and service-oriented delivery, the company supports digital transformation, operational efficiency, and the continuous improvement of critical IT systems across multiple markets.

The project is focused on providing cybersecurity and digital services for international organizations within a large, heterogeneous, multi-tenant environment. It includes developing and strengthening vulnerability management capabilities to identify, assess, prioritize, and mitigate security risks across multiple organizations worldwide.

  • Planning and performing penetration tests of web applications, APIs, internal and external networks, Active Directory and cloud environments.
  • Carrying out manual testing beyond automated scanning, including exploitation and privilege escalation within the agreed rules of engagement.
  • Validating findings, assessing business risk and producing clear technical and executive reports.
  • Presenting results to system owners and management, and supporting remediation and retesting.
  • Contributing to red teaming or purple teaming exercises with SOC and detection teams.
  • Maintaining testing methodologies, tools and templates.
  • Experience in cybersecurity for 5+ years, including 3+ years in hands-on penetration testing.
  • Experience with web application and API testing according to OWASP (Top 10, WSTG, ASVS).
  • Experience conducting internal and external infrastructure testing, including Active Directory attacks
  • Working knowledge of standard tools (Burp Suite Pro, Nmap, Metasploit, BloodHound, Impacket, etc.).
  • At least one recognized hands-on certification: OSCP, OSWE, OSEP, CRTO, eWPTX, GPEN or GWAPT.
  • Clean professional records and willingness to undergo background verification.
  • Level of English – from Upper-Intermediate and above.
  • Hands-on experience with cloud penetration testing (Azure, Microsoft 365, AWS).
  • Experience with mobile application testing (Android, iOS).
  • Red Teaming or Purple Teaming experience, including familiarity with C2 frameworks.
  • Strong scripting and security tooling skills (Python, PowerShell, Bash).
  • Experience with PTES, OSSTMM or NIST SP 800-115 methodologies.
  • Proven security research track record, such as published CVEs or recognized bug bounty findings.
  • Experience in teamwork with leaders in FinTech, Healthcare, Retail, Telecom, and others. Andersen cooperates with such businesses as Samsung, Siemens, Johnson & Johnson, BNP Paribas, Ryanair, Mercedes, TUI, Verivox, Allianz, T-Systems, etc..
  • The opportunity to change the project and/or develop expertise in an interesting business domain.
  • Job conditions – you can work both fully remotely and from the office or can choose a hybrid variant.
  • Guarantee of professional, financial, and career growth! The company has introduced systems of mentoring and adaptation for each new employee.
  • The opportunity to earn up to an additional 1,000 EUR per month, depending on the level of expertise, which will be included in the annual bonus, by participating in the company's activities.
  • Access to the corporate training portal, where the entire knowledge base of the company is collected and which is constantly updated.
  • Bright corporate life (parties / pizza days / PlayStation / fruits / coffee / snacks / movies).
  • Certification compensation (AWS, PMP, etc).
  • Referral program.
  • Private health insurance and sports compensation, depending on the type of employment.

Join us!

Сайты компаний
andersen

Cyber Threat Intelligence Analyst

andersenНа сервисе с: 05.10.26 15:14
Зарплата не указанаКипрГерманияИспанияПортугалияЧехияЛюксембургЛатвияЛитваЭстонияВенгрияФинляндияФранцияАвстрияДанияИталия

Andersen is hiring a Cyber Threat Intelligence Analyst for a project strengthening cybersecurity capabilities and identifying, assessing, and mitigating security risks.

Our customer is a technology and consulting organization providing digital infrastructure, cloud services, cybersecurity, data-driven solutions, and managed IT support. It helps organizations modernize complex technology environments, strengthen security, and improve the reliability and scalability of their digital operations. By combining technical expertise with modern technologies and service-oriented delivery, the company supports digital transformation, operational efficiency, and the continuous improvement of critical IT systems across multiple markets.

The project is focused on providing cybersecurity and digital services for international organizations within a large, heterogeneous, multi-tenant environment. It includes developing and strengthening vulnerability management capabilities to identify, assess, prioritize, and mitigate security risks across multiple organizations worldwide.

  • Collecting, analyzing and correlating threat intelligence from open, commercial and community sources (OSINT, ISACs, vendor feeds).
  • Tracking threat actors, campaigns and TTPs relevant to international organizations, including state-sponsored groups.
  • Producing strategic, operational and tactical intelligence reports and briefings for technical and management audiences.
  • Mapping threats to MITRE ATT&CK and turning intelligence into detection use cases together with SOC and SIEM teams.
  • Managing IOCs and their lifecycle in the TIP and enriching SOC alerts and incident investigations.
  • Supporting incident response with actor attribution and context.
  • Sharing intelligence with partner organizations under agreed sharing protocols (TLP).
  • Experience in cybersecurity for 5+ years, including 3+ years in a dedicated CTI role.
  • Hands-on work with a threat intelligence platform (e.g. MISP, OpenCTI, ThreatConnect, Anomali, Recorded Future).
  • Strong command of MITRE ATT&CK, the Diamond Model and the Cyber Kill Chain.
  • Experience conducting OSINT research and analysis of malware and phishing campaigns at indicator and TTP level.
  • Experience turning intelligence into detections together with a SOC or SIEM team.
  • Clean professional records and willingness to undergo background verification.
  • Level of English – from Upper-Intermediate and above.
  • Certifications: GCTI, CTIA, GCIH.
  • Experience with STIX/TAXII, YARA and Sigma.
  • Experience in a public sector, international organization, NGO or financial sector environment.
  • Skills scripting in Python for automation and data enrichment.
  • Additional languages (French, Spanish, Arabic, Russian, Chinese).
  • Andersen cooperates with such companies as Siemens, Johnson & Johnson, AstraZeneca, BNP Paribas, Allianz, Ryanair, TUI, Verivox, Media Markt, etc..
  • For the past four years, our company has been growing annually by 60–100%, and we constantly involve top-notch specialists in our team.
  • Andersen has mentoring and adaptation systems for new employees, and transparent performance review and assessment systems will allow you to determine your development path and plan your growth.
  • The most important thing that we value in our employees is a commitment to continuous learning. The company supports them in this and gives them access to the best educational platforms, seminars, and practices. In addition, for over 19 years, Andersen has assembled a huge knowledge base and established a robust resource management institution.
  • We have been strengthening our expertise since 2007. During this time, we have formed excellent teams with streamlined processes, where you can learn something new from your colleagues every day and enjoy your work.
  • We are a cool young team of like-minded people communicating informally.
  • You'll have a stable and competitive salary and an extensive benefits package.
  • At Andersen, we have many different ways to grow. You can improve as a specialist or a manager, and all your activities will be decently rewarded.

Join us!

Сайты компаний
andersen

SIEM Administrator / Engineer

andersenНа сервисе с: 05.10.26 15:14
Зарплата не указанаКипрГерманияИспанияПортугалияЧехияЛюксембургЛатвияЛитваЭстонияВенгрияФинляндияФранцияАвстрияДанияИталия

Andersen is hiring a SIEM Administrator / Engineer for a project enhancing a SIEM platform and supporting centralized security monitoring and threat detection.

Our customer is a technology and consulting organization providing digital infrastructure, cloud services, cybersecurity, data-driven solutions, and managed IT support. It helps organizations modernize complex technology environments, strengthen security, and improve the reliability and scalability of their digital operations. By combining technical expertise with modern technologies and service-oriented delivery, the company supports digital transformation, operational efficiency, and the continuous improvement of critical IT systems across multiple markets.

The project is focused on providing cybersecurity and digital services for international organizations within a complex multi-tenant environment. It includes managing and enhancing the SIEM platform to support centralized security monitoring, threat detection, and reliable cyber defense operations across multiple organizations worldwide.

  • Administering, maintaining and upgrading the SIEM platform, including health, performance, capacity and licensing.
  • Onboarding and normalizing new log sources (network, endpoint, cloud, identity, applications), including in multi-tenant setups.
  • Developing, tuning and maintaining detection rules, correlation searches, dashboards and reports.
  • Reducing false positives together with SOC analysts and implementing new use cases.
  • Building and maintaining SOAR playbooks and integrations.
  • Maintaining documentation, data retention policies and access control.
  • Supporting audits and compliance reporting.
  • Experience in IT or cybersecurity for 5+ years, including 3+ years administering an enterprise SIEM in production.
  • Deep hands-on experience with at least one major SIEM: Microsoft Sentinel, Splunk ES, IBM QRadar or Elastic Security.
  • Hands-on experience with log source onboarding, parsing, and normalization using Syslog, CEF, Windows Event Forwarding (WEF), and API-based cloud connectors.
  • Experience writing detection content in the platform's query language (KQL, SPL, AQL or equivalent).
  • Understanding of MITRE ATT&CK for mapping detection coverage.
  • Clean professional records and willingness to undergo background verification.
  • Level of English – from Upper-Intermediate and above.
  • Vendor certifications (e.g. Microsoft SC-200, Splunk Certified Admin/Architect, IBM QRadar).
  • SOAR experience (Sentinel Logic Apps, Splunk SOAR, Cortex XSOAR).
  • Multi-tenant SIEM or MSSP experience.
  • Experience in scripting and automation (Python, PowerShell) and Infrastructure as Code.
  • Experience working with detection-as-code practices (Sigma, Git-based rule management).
  • Andersen cooperates with such companies as Siemens, Johnson & Johnson, AstraZeneca, BNP Paribas, Allianz, Ryanair, TUI, Verivox, Media Markt, etc..
  • For the past four years, our company has been growing annually by 60–100%, and we constantly involve top-notch specialists in our team.
  • Andersen has mentoring and adaptation systems for new employees, and transparent performance review and assessment systems will allow you to determine your development path and plan your growth.
  • The most important thing that we value in our employees is a commitment to continuous learning. The company supports them in this and gives them access to the best educational platforms, seminars, and practices. In addition, for over 19 years, Andersen has assembled a huge knowledge base and established a robust resource management institution.
  • We have been strengthening our expertise since 2007. During this time, we have formed excellent teams with streamlined processes, where you can learn something new from your colleagues every day and enjoy your work.
  • We are a cool young team of like-minded people communicating informally.
  • You'll have a stable and competitive salary and an extensive benefits package.
  • At Andersen, we have many different ways to grow. You can improve as a specialist or a manager, and all your activities will be decently rewarded.

Join us!

HireSeeker собирает вакансии со всех площадок и присылает только релевантные. Бесплатно.