Job Search and Career Advice Platform

Enable job alerts via email!

Information Security Engineer (Pen Tester)

Tabby

Riyadh

On-site

SAR 200,000 - 300,000

Full time

7 days ago
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading Fintech company in Saudi Arabia is looking for an Information Security Engineer to enhance its cybersecurity measures. This role involves penetration testing, vulnerability assessments, and conducting Red Team engagements to evaluate and improve security protocols. The candidate should have a strong background in IT security, be able to generate high-quality technical reports, and possess excellent communication skills. This position supports the mission of making financial services smarter and more secure in a diverse working environment.

Qualifications

  • Bachelor's degree in a related field is required.
  • 2-3 years experience in information security.
  • Excellent communication and influencing skills necessary.

Responsibilities

  • Perform Dynamic and Static Application Security Testing for various applications.
  • Engage in Red Team operations to simulate real-world threats.
  • Conduct vulnerability assessments to identify security risks.
  • Develop high-quality reports outlining technical findings.
  • Run controlled offensive tests such as phishing simulations.
  • Create custom scripts to enhance security tool capabilities.

Skills

Dynamic Application Security Testing (DAST)
Static Application Security Testing (SAST)
Conducting Red Team engagements
Vulnerability assessments
Report development
Security awareness training
Programming (Bash, Python)
Stakeholder management

Education

Degree in Information Technology, Computer Science, Software Engineering

Tools

Automated vulnerability assessment tools
Job description

We are thrilled to announce an opportunity for a skilled Information Security Engineer to join our team and play a role in enhancing our security measures by utilizing your abilities and deep knowledge of information security methodologies. Paying attention to details and efficiently solving problems will be crucial in ensuring the safety of Tabby’s systems. The role you will be involved in both operations and important implementation projects contributing to the growth and maintenance of our technology infrastructure. If you have a passion for cybersecurity, possess technical skills and aspire to make a significant impact we strongly encourage you to apply and become an essential part of our dedicated cybersecurity team.

Department: InfoSec Monitoring, Employment Type: Full Time, Location: KSA, Workplace type: Onsite.

Key Responsibilities
  • Penetration Testing: Perform Dynamic Application Security Testing (DAST) and Static Application Security Testing (SAST) for Web, Mobile, and API applications. Plan and conduct Infrastructure Vulnerability Assessment and Penetration Testing of systems, switches, servers, and more.
  • Adversary Simulation (Red Teaming): Participate in sophisticated Red Team engagements, emulating real‑world threat actor Tactics, Techniques, and Procedures (TTPs) to assess the detection and response capabilities of the Blue Team/SOC.
  • Vulnerability & Application Security Analysis: Conduct both Dynamic (DAST) and Static (SAST) Application Security Testing, and perform systematic vulnerability assessments using automated tools combined with meticulous manual verification.
  • Report Development: Produce actionable, high‑quality assessment reports that clearly articulate technical findings, business risk, and remediation strategies for both technical implementers and non‑technical executives.
  • Control Evasion & Social Engineering: Conduct controlled offensive testing, including Breach & Attack Simulations (BAS) and targeted phishing campaigns, to assess the resilience and bypassability of technical and human controls.
  • Tool Development & Reporting: Develop and maintain custom scripts and tools to enhance offensive security capabilities, and produce high‑quality, actionable reports detailing discovered threats and validated vulnerabilities on an ongoing basis.
  • Security Awareness: Experience in conducting phishing simulations and other awareness exercises to evaluate employee susceptibility to social engineering attacks and provide targeted training to enhance resilience.
Skills, Knowledge & Expertise
  • Degree in Information Technology, Computer Science, Software Engineering, or related field.
  • Knowledge of Information Technology security issues and approaches to manage Information Technology security with a fast‑paced Fintech environment.
  • Security qualification good to have: Offensive Security Certified Professional (OSCP), GIAC Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), CREST Registered Penetration Tester (CRT) or equivalent.
  • Excellent communication, influencing and stakeholder management skills.
  • 2‑3 years of experience working across teams to deliver solutions and generate high levels of internal buy‑in.
  • Experience of working in a culturally diverse environment.
  • Knowledge of online technologies, payment methods, content delivery networks, REST APIs, microservices, and application development.
  • Programming and scripting understanding (Bash, Python, etc.).
About Tweeq

Tweeq is a Saudi fintech on a mission to reshape how people manage their money. Now part of Tabby, the largest BNPL provider in the Middle East, we’re building the next generation of financial products for the Kingdom. From payments to everyday money management, our goal is to make financial services faster, smarter, and more accessible for everyone in Saudi Arabia.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.