25 дней назад
Lead, Information Security (Defensive) (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Lead, Information Security (Defensive) (Fintech): Leading defensive security architecture, cloud security, and DevSecOps initiatives for a financial technology platform with an accent on GCP, AWS, vulnerability management, and secure software development. Focus on managing security engineers and analysts, designing detection and incident response capabilities, and strengthening security across infrastructure, endpoints, and products.
Location: Onsite in Riyadh, KSA
Company
is a fintech platform that provides flexible payment solutions for shoppers and businesses across the GCC region.
What you will do
- Lead security architecture and design reviews across IT, cloud, and product initiatives.
- Drive cloud security across GCP and AWS, including IAM, security posture, and infrastructure security.
- Own the Secure SDLC and DevSecOps program, covering SAST, DAST, SCA, and container security.
- Lead vulnerability management, penetration testing, red team engagements, detection engineering, threat intelligence, and complex incident response.
- Oversee endpoint, infrastructure, and firewall security.
- Manage and mentor cybersecurity engineers and analysts while partnering with Engineering, IT, and Compliance.
Requirements
- 5+ years of cybersecurity experience, including technical leadership or senior-level responsibilities.
- Strong experience in security architecture, cloud security, AppSec/DevSecOps, and vulnerability management.
- Hands-on knowledge of offensive and defensive security, penetration testing, red/purple teaming, and incident response.
- Experience with SIEM, EDR/XDR, CSPM, DLP, vulnerability management platforms, Terraform, Kubernetes, and CI/CD security.
- Knowledge of SAMA CSF, NCA ECC, PCI-DSS, and ISO 27001.
- CISSP/CISM and OSCP or equivalent certifications are required.
Culture & Benefits
- Full-time employment in the Information Security Monitoring department.
- Onsite collaboration in Riyadh, KSA.
- Work alongside Engineering, IT, Compliance, and other functions on organization-wide security initiatives.
Hiring process
- Application review followed by an HR call.
- Technical interview with .
- Final interview with .
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →