Information Security Intern

Tabby | تابي

Riyadh

On-site

SAR 27,900 - 50,220

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Paid internship
Office-based in Riyadh
Mentorship and growth

Job summary

Tabby is seeking a paid Information Security intern to join the GRC and risk tracks. You will work with risk, engineering, and security teams across SAST/DAST tooling, vulnerability management, and compliance.

Office-first in Riyadh with possible international coordination. Open to students and fresh graduates, full‑time engagement, with a clear path to junior Information Security roles based on performance.

Qualifications

  • Solid understanding of information security fundamentals (confidentiality, integrity, availability) and OWASP Top 10.
  • Understanding of HTTP, TLS, DNS and TCP/IP fundamentals.
  • Knowledge of authentication/authorization patterns (OAuth 2.0, JWT).
  • Familiarity with Linux command line and POSIX environments.
  • Ability to read technical material and explain it clearly in writing.
  • Experience with Git and standard development workflows.

Responsibilities

  • Triage findings from SAST/DAST/SCAs and dependency scanners across repos.
  • Reproduce and document vulnerabilities; write remediation tickets for teams.
  • Contribute to secure code reviews on selected merge requests.
  • Participate in threat modelling and write-ups for new features.
  • Run scoped assessments in staging with senior sign-off.
  • Maintain security tooling and dashboards; triage false positives.
  • Assist with security checks during release cycles.
  • Contribute to DevSecOps, CI/CD gates, and container image scanning.
  • Engage in incident response exercises with senior engineers.
  • Collaborate with SOC for logging and alert triage.

Skills

InfoSec fundamentals
Networking basics
OAuth 2.0 / JWT
Linux command line
Reading technical material
Git workflows
English communication
Python or Go (Strong plus)
CTF participation
Burp Suite / ZAP
Vulnerability scanners / SAST/SCA
Mobile app security basics
Container security basics
Bug bounty experience
DevSecOps tooling
SIEM / SOC exposure
SQL basics
Cryptography fundamentals

Tools

Burp Suite
OWASP ZAP
Nessus
OpenVAS
Trivy
Grype
Semgrep
CodeQL
Snyk
Docker security
Kubernetes security

Job description

About the company

Tabby builds financial products used by millions of users across the GCC. We work on high-load, security-critical systems with strict regulatory requirements. The Information Security function protects Tabby across mobile apps, backend services, payment integrations and cloud infrastructure.

Department

InfoSec GRC

Location

KSA (office‑first in Riyadh; candidates may be based outside KSA)

Key Responsibilities
On the VAPT track
  • Triage findings from SAST, DAST, SCA and dependency scanners across mobile and backend repositories.
  • Reproduce and document vulnerabilities; write clear remediation tickets for product teams.
  • Contribute to secure code reviews on selected merge requests (auth, input validation, data handling).
  • Participate in threat‑modelling sessions for new features and produce write‑ups.
  • Run scoped assessments against staging environments under senior sign‑off.
  • Help maintain security tooling: scanner configs, baseline rules, dashboards and false‑positive triage queues.
  • Assist with security checks during release cycles.
  • Contribute to DevSecOps – security gates in CI/CD pipelines, dependency and container image scanning.
  • Exposure to logging, monitoring and alert triage workflows alongside the SOC.
  • Participate in incident response exercises and post‑mortems alongside senior engineers.
On the GRC track
  • Support compliance programs against frameworks such as PCI DSS, ISO 27001 and SAMA – evidence collection, control mapping and gap analysis.
  • Help maintain security policies, standards and procedures across domains – access control, cryptography, asset management, change management, third‑party security, vulnerability management, awareness and training; track owners and review cycles.
  • Contribute to risk assessments – risk registers, control testing and treatment plans.
  • Support vendor and third‑party security assessments.
  • Help prepare for internal and external audits – workpapers, evidence packages and response coordination.
  • Contribute to security awareness content, training rollouts and metrics tracking.
  • Work alongside engineering teams to translate policy requirements into concrete technical controls.
Both tracks
  • Work with risk and platform engineers on PII handling, secrets management and encryption reviews.
  • Contribute to the internal security knowledge base – runbooks, playbooks and awareness content.
Skills, Knowledge & Expertise
Required
  • Solid understanding of information security fundamentals: confidentiality, integrity, availability and common attack categories (OWASP Top 10) as well as common control categories.
  • Understanding of HTTP, TLS, DNS and TCP/IP fundamentals.
  • Understanding of authentication and authorization patterns (sessions, cookies, OAuth 2.0, JWT).
  • Familiarity with Linux command line and POSIX‑like environments.
  • Ability to read technical material and explain it clearly in writing.
  • Experience with Git and standard development workflows.
  • Strong ethical mindset and discretion – security findings and compliance evidence are sensitive by default; non‑disclosure outside the team is non‑negotiable.
  • Open to constructive feedback.
  • English sufficient for documentation and team communication.
Strong plus
  • Working knowledge of a programming language (Python or Go preferred).
  • CTF participation (Hack The Box, TryHackMe, picoCTF, SAFCSP CTFs) with documented solves or write‑ups.
  • Hands‑on experience with Burp Suite Community, OWASP ZAP or similar interception proxies.
  • Familiarity with vulnerability scanners (Nessus, OpenVAS, Trivy, Grype) or SAST/SCA tools (Semgrep, CodeQL, Snyk).
  • Familiarity with mobile app security basics (iOS and Android – certificate pinning, secure storage, deep‑link risks).
  • Exposure to container and orchestration security (Docker, Kubernetes – image scanning, RBAC).
  • Bug bounty submissions on any public program (HackerOne, Bugcrowd, Intigriti).
  • Familiarity with DevSecOps tooling – CI/CD security gates, IaC scanning and container image scanning.
  • Exposure to SIEM or SOC tooling – log analysis and alert triage.
  • Basic knowledge of SQL and how queries can be abused.
  • Familiarity with cryptography fundamentals (symmetric vs asymmetric, hashing, signing – conceptual).
What we do not expect
  • Prior professional information security experience.
  • Mastery of all listed tools and frameworks.
  • Ability to perform independent penetration tests on production systems.
  • Deep cryptography, reverse‑engineering or compliance‑framework expertise.
  • Existing certifications (OSCP, CEH, Security+, CISA, CISM, CRISC) – welcome but not required.
Eligibility
  • Saudi nationals only.
  • Self‑funded internship by Tabby.
  • We welcome both current students and fresh graduates.
  • Full‑time level of engagement throughout the internship – interns should contribute at a full working‑day pace. Flexibility for classes or exams can be aligned with the mentor in advance, but overall performance, ownership and context involvement are expected at a full‑time level.
Internship Format
  • Paid internship.
  • Full integration into the Information Security team.
  • Distributed engineering team across multiple countries.
  • Office‑first in Riyadh where possible.
  • Clear path to a junior Information Security engineer role based on performance.
  • Internship designed for fast professional growth in regulated fintech.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Intern KSA
Information Security Intern KSA

تابي • Riyadh

Hybrid
FinTech InfoSec Intern: VAPT, DevSecOps & Compliance
FinTech InfoSec Intern: VAPT, DevSecOps & Compliance

Tabby | تابي • Riyadh

On-site
Paid internship
Office-based in Riyadh
Mentorship and growth
DevOps Intern
DevOps Intern

Tabby | تابي • Riyadh

Hybrid
Intern QA Engineer
Intern QA Engineer

tabby • Saudi Arabia

On-site
Intern Backend (Go) Engineer KSA
Intern Backend (Go) Engineer KSA

تابي • Riyadh

Hybrid
Paid internship
Office-first in Riyadh (on-site when 1
Global distributed team
DBA Intern KSA
DBA Intern KSA

تابي • Saudi Arabia

On-site
Paid internship
Information Security Intern — VAPT/GRC Track
Information Security Intern — VAPT/GRC Track

تابي • Riyadh

Hybrid
Intern Backend (Go) Engineer
Intern Backend (Go) Engineer

Tabby | تابي • Riyadh

Hybrid
Paid internship
Office first in Riyadh (Saudi Arabia)
DBA Intern
DBA Intern

Tabby | تابي • Riyadh

Hybrid
Paid internship
Intern QA Engineer
Intern QA Engineer

Tabby | تابي • Riyadh

On-site
Paid internship
Full integration into an engineering团队
Distributed engineering team across多国
+2