More jobs:
Information Security Intern
Job in
Riyadh, Riyadh Region, Saudi Arabia
Listed on 2026-07-15
Listing for:
Tabby | تابي
Apprenticeship/Internship
position Listed on 2026-07-15
Job specializations:
-
IT/Tech
Cybersecurity, Information Security
Job Description & How to Apply Below
About the company
Tabby builds financial products used by millions of users across the GCC. We work on high-load, security-critical systems with strict regulatory requirements. The Information Security function protects Tabby across mobile apps, backend services, payment integrations and cloud infrastructure.
DepartmentInfo Sec GRC
LocationKSA (office‑first in Riyadh; candidates may be based outside KSA)
Key Responsibilities On the VAPT track- Triage findings from SAST, DAST, SCA and dependency scanners across mobile and backend repositories.
- Reproduce and document vulnerabilities; write clear remediation tickets for product teams.
- Contribute to secure code reviews on selected merge requests (auth, input validation, data handling).
- Participate in threat‑modelling sessions for new features and produce write‑ups.
- Run scoped assessments against staging environments under senior sign‑off.
- Help maintain security tooling: scanner configs, baseline rules, dashboards and false‑positive triage queues.
- Assist with security checks during release cycles.
- Contribute to Dev Sec Ops – security gates in CI/CD pipelines, dependency and container image scanning.
- Exposure to logging, monitoring and alert triage workflows alongside the SOC.
- Participate in incident response exercises and post‑mortems alongside senior engineers.
- Support compliance programs against frameworks such as PCI DSS, ISO 27001 and SAMA – evidence collection, control mapping and gap analysis.
- Help maintain security policies, standards and procedures across domains – access control, cryptography, asset management, change management, third‑party security, vulnerability management, awareness and training; track owners and review cycles.
- Contribute to risk assessments – risk registers, control testing and treatment plans.
- Support vendor and third‑party security assessments.
- Help prepare for internal and external audits – work papers, evidence packages and response coordination.
- Contribute to security awareness content, training rollouts and metrics tracking.
- Work alongside engineering teams to translate policy requirements into concrete technical controls.
- Work with risk and platform engineers on PII handling, secrets management and encryption reviews.
- Contribute to the internal security knowledge base – runbooks, playbooks and awareness content.
- Solid understanding of information security fundamentals: confidentiality, integrity, availability and common attack categories (OWASP Top 10) as well as common control categories.
- Understanding of HTTP, TLS, DNS and TCP/IP fundamentals.
- Understanding of authentication and authorization patterns (sessions, cookies, OAuth 2.0, JWT).
- Familiarity with Linux command line and POSIX‑like environments.
- Ability to read technical material and explain it clearly in writing.
- Experience with Git and standard development workflows.
- Strong ethical mindset and discretion – security findings and compliance evidence are sensitive by default; non‑disclosure outside the team is non‑negotiable.
- Open to constructive feedback.
- English sufficient for documentation and team communication.
- Working knowledge of a programming language (Python or Go preferred).
- CTF participation (Hack The Box, Try Hack Me , picoCTF, SAFCSP CTFs) with documented solves or write‑ups.
- Hands‑on experience with Burp Suite Community, OWASP ZAP or similar interception proxies.
- Familiarity with vulnerability scanners (Nessus, OpenVAS, Trivy, Grype) or SAST/SCA tools (Semgrep, CodeQL, Snyk).
- Familiarity with mobile app security basics (iOS and Android – certificate pinning, secure storage, deep‑link risks).
- Exposure to container and orchestration security (Docker, Kubernetes – image scanning, RBAC).
- Bug bounty submissions on any public program (Hacker One, Bugcrowd, Intigriti).
- Familiarity with Dev Sec Ops tooling – CI/CD security gates, IaC scanning and container image scanning.
- Exposure to SIEM or SOC tooling – log analysis and alert triage.
- Basic knowledge of SQL and how queries can be abused.
- Familiarity with cryptography fundamentals (symmetric vs asymmetric, hashing, signing – conceptual).
- Prio…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×