Tabby
Tabby
201 – 500 Employees
eCommerceFintech
Tabby is a fintech and eCommerce company that develops payment solutions for more flexible shopping. Its service lets customers divide eligible purchases into four interest-free monthly payments and includes an app for discovering products, brands, and deals across categories such as fashion, beauty, and electronics. Tabby also provides commerce tools designed to help businesses reduce price barriers and increase sales, while Tabby Care supports returns and payment holds when purchase issues arise. The service integrates with Visa to support broad merchant acceptance.

Senior Information Security Manager — Onsite in Serbia

Lead Tabby’s information security function across cloud, application, and defensive security for its fintech payments platform. Oversee security programmes, incident response, and the development of a security engineering and analyst team.

Description

  • Own hands-on security architecture and technical reviews spanning cloud, infrastructure, and product initiatives
  • Design and deploy security controls across GCP and AWS, including IAM, CSPM, and cloud-native protections
  • Advance Secure SDLC and DevSecOps practices using SAST, DAST, SCA, and container security
  • Lead vulnerability management and contribute to penetration tests, VAPT, and red or purple team exercises
  • Develop threat-detection capabilities, SIEM use cases, and security-monitoring improvements
  • Direct and support investigations into complex security incidents and coordinate response activities
  • Lead security initiatives covering endpoints, infrastructure, networks, and firewalls
  • Automate security workflows and build internal security tools where appropriate
  • Define technical standards, security practices, and operational procedures
  • Manage, mentor, and grow a team of security engineers and analysts
  • Partner with Engineering, Infrastructure, Product, IT, Legal, and Compliance to integrate security throughout Tabby

Requirements

  • Substantial experience leading information security or cybersecurity functions in a senior technical or management capacity
  • At least five years of professional experience in information security or cybersecurity
  • At least two years in technical leadership or as a senior individual contributor
  • People management or team leadership experience is strongly preferred
  • Broad expertise in cloud security, security architecture, VAPT, application security, DevSecOps, and defensive security
  • Experience directing security programmes and cross-functional initiatives
  • Strong knowledge of GCP and AWS, IAM, CSPM, SIEM, EDR/XDR, and vulnerability management
  • Solid understanding of penetration testing, red and purple teaming, threat hunting, and incident response
  • Experience applying SAST, DAST, SCA, and container security in CI/CD environments
  • Strong grasp of security architecture, threat modelling, and enterprise security controls
  • Experience in a regulated fintech or banking environment
  • Knowledge of CBUAE, UAE PDPL, PCI-DSS, ISO 27001, and SOC 2
  • Demonstrated ability in people leadership, stakeholder management, and strategic decision-making
  • CISSP or CISM and OSCP or equivalent certifications are preferred or may be required based on final hiring criteria

Related Jobs

ZACO Robot

B2B Sales Setter for Commercial Cleaning Robotics

ZACO Robot

Qualify leads and book sales calls for RV-Tech’s professional cleaning robots, selling remotely to business decision-makers. The role focuses on automation and robotics in a growing commercial market.

Open