×
Register Here to Apply for Jobs or Post Jobs. X

Information Security Intern

Job in Riyadh, Riyadh Region, Saudi Arabia
Listing for: Tabby | تابي
Apprenticeship/Internship position
Listed on 2026-07-15
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security
Salary/Wage Range or Industry Benchmark: 27900 - 50220 SAR Yearly SAR 27900.00 50220.00 YEAR
Job Description & How to Apply Below

About the company

Tabby builds financial products used by millions of users across the GCC. We work on high-load, security-critical systems with strict regulatory requirements. The Information Security function protects Tabby across mobile apps, backend services, payment integrations and cloud infrastructure.

Department

Info Sec GRC

Location

KSA (office‑first in Riyadh; candidates may be based outside KSA)

Key Responsibilities On the VAPT track
  • Triage findings from SAST, DAST, SCA and dependency scanners across mobile and backend repositories.
  • Reproduce and document vulnerabilities; write clear remediation tickets for product teams.
  • Contribute to secure code reviews on selected merge requests (auth, input validation, data handling).
  • Participate in threat‑modelling sessions for new features and produce write‑ups.
  • Run scoped assessments against staging environments under senior sign‑off.
  • Help maintain security tooling: scanner configs, baseline rules, dashboards and false‑positive triage queues.
  • Assist with security checks during release cycles.
  • Contribute to Dev Sec Ops  – security gates in CI/CD pipelines, dependency and container image scanning.
  • Exposure to logging, monitoring and alert triage workflows alongside the SOC.
  • Participate in incident response exercises and post‑mortems alongside senior engineers.
On the GRC track
  • Support compliance programs against frameworks such as PCI DSS, ISO 27001 and SAMA – evidence collection, control mapping and gap analysis.
  • Help maintain security policies, standards and procedures across domains – access control, cryptography, asset management, change management, third‑party security, vulnerability management, awareness and training; track owners and review cycles.
  • Contribute to risk assessments – risk registers, control testing and treatment plans.
  • Support vendor and third‑party security assessments.
  • Help prepare for internal and external audits – work papers, evidence packages and response coordination.
  • Contribute to security awareness content, training rollouts and metrics tracking.
  • Work alongside engineering teams to translate policy requirements into concrete technical controls.
Both tracks
  • Work with risk and platform engineers on PII handling, secrets management and encryption reviews.
  • Contribute to the internal security knowledge base – runbooks, playbooks and awareness content.
Skills, Knowledge & Expertise Required
  • Solid understanding of information security fundamentals: confidentiality, integrity, availability and common attack categories (OWASP Top 10) as well as common control categories.
  • Understanding of HTTP, TLS, DNS and TCP/IP fundamentals.
  • Understanding of authentication and authorization patterns (sessions, cookies, OAuth 2.0, JWT).
  • Familiarity with Linux command line and POSIX‑like environments.
  • Ability to read technical material and explain it clearly in writing.
  • Experience with Git and standard development workflows.
  • Strong ethical mindset and discretion – security findings and compliance evidence are sensitive by default; non‑disclosure outside the team is non‑negotiable.
  • Open to constructive feedback.
  • English sufficient for documentation and team communication.
Strong plus
  • Working knowledge of a programming language (Python or Go preferred).
  • CTF participation (Hack The Box, Try Hack Me , picoCTF, SAFCSP CTFs) with documented solves or write‑ups.
  • Hands‑on experience with Burp Suite Community, OWASP ZAP or similar interception proxies.
  • Familiarity with vulnerability scanners (Nessus, OpenVAS, Trivy, Grype) or SAST/SCA tools (Semgrep, CodeQL, Snyk).
  • Familiarity with mobile app security basics (iOS and Android – certificate pinning, secure storage, deep‑link risks).
  • Exposure to container and orchestration security (Docker, Kubernetes – image scanning, RBAC).
  • Bug bounty submissions on any public program (Hacker One, Bugcrowd, Intigriti).
  • Familiarity with Dev Sec Ops  tooling – CI/CD security gates, IaC scanning and container image scanning.
  • Exposure to SIEM or SOC tooling – log analysis and alert triage.
  • Basic knowledge of SQL and how queries can be abused.
  • Familiarity with cryptography fundamentals (symmetric vs asymmetric, hashing, signing – conceptual).
What we do not expect
  • Prio…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary