- Location
- Remote/Uzbekistan
- Workplace
- Remote
- Type
- Full-time
- Department
- Security
- Seniority
- Senior
- Experience
- 5+ years
- Source
- Pinpoint
Description
Senior Manager Information Security
Department: InfoSec Monitoring
Employment Type: Full Time
Location: Remote/Uzbekistan
Reporting To: Rajat Rao
Description
The company’s flagship offering allows shoppers to split their payments online and in-store with no interest or fees. Over 40,000 global brands and small businesses, including Amazon, Noon, IKEA, and SHEIN use Tabby to accelerate growth and gain loyal customers by offering easy and flexible payments online and in stores.
Tabby generates over $10 billion in annual transaction volume for its partner brands and is the highest-rated, most-reviewed, largest, and fastest-growing FinTech in the GCC region.
Tabby launched in 2019 and has since raised +$1 billion in equity and debt funding from global and regional investors, and is now valued at $4.5 billion.
We are looking for a Senior Manager Information Security to lead and shape Tabby’s information security function across both strategic and technical domains. This role will lead a team of security professionals and own key security programmes across cloud security, security architecture, application security, vulnerability management, threat detection and incident response.
Key Responsibilities
- Lead and contribute hands-on to security architecture and technical security reviews across cloud, infrastructure and product initiatives.
- Design and implement security controls across GCP and AWS, including IAM, CSPM and cloud-native security.
- Drive and contribute to Secure SDLC / DevSecOps, including SAST, DAST, SCA and container security.
- Lead vulnerability management and actively participate in penetration testing, VAPT and red/purple team engagements.
- Design and improve threat detection, SIEM use cases and security monitoring.
- Lead and participate in complex security incident investigations and response.
- Drive endpoint, infrastructure, network and firewall security initiatives.
- Automate security processes and develop security tooling where needed.
- Establish technical standards, security best practices and operating procedures.
- Manage, mentor and develop a team of security engineers and analysts.
- Work closely with Engineering, Infrastructure, Product, IT, Legal and Compliance teams to embed security across Tabby.
Skills, Knowledge and Expertise
- Strong experience leading Information Security / Cyber Security functions in a senior technical or management role.
- 5+ years of experience in Information Security or Cybersecurity, with at least 2 years in a technical leadership or senior individual contributor role. Prior people management or team leadership experience is strongly preferred.
- Deep expertise across Cloud Security, Security Architecture, VAPT, AppSec/DevSecOps and Defensive Security.
- Experience leading security programmes and managing cross-functional initiatives.
- Strong knowledge of GCP/AWS, IAM, CSPM, SIEM, EDR/XDR and vulnerability management.
- Strong understanding of penetration testing, red/purple teaming, threat hunting and incident response.
- Experience with SAST, DAST, SCA and container security within CI/CD environments.
- Strong understanding of security architecture, threat modelling and enterprise security controls.
- Experience working within a regulated FinTech or banking environment.
- Knowledge of CBUAE, UAE PDPL, PCI-DSS, ISO 27001 and SOC 2.
- Proven people leadership, stakeholder management and strategic decision-making skills.
- CISSP/CISM and OSCP or equivalent certifications are preferred/required depending on the final hiring criteria.