Back to jobs
Tabby

Analyst, Information Security (SOC)

Riyadh, Saudi Arabia, KSA

Employment
Full-timeemployment source
Employment type Full Time
Read the full posting

What you’ll work on

Full posting
  • Maintain SIEM configuration documentation — recording index patterns, log source integration specifications, agent deployment standards, and platform architecture notes.

  • Ensure detection coverage aligns with relevant frameworks — reviewing use case libraries against MITRE ATT&CK, SAMA CSF controls, and NCA ECC requirements.

  • Maintain Tabby's incident register — ensuring the master incident log is accurate, current, and audit-ready in line with SAMA CSF and internal governance requirements.

From the employer’s posting
Support SIEM tuning activities under senior guidance — adjusting field mappings, resolving ingest pipeline issues, and validating that log data is correctly normalised and queryable by the managed SOC team. Maintain SIEM configuration documentation — recording index patterns, log source integration specifications, agent deployment standards, and platform architecture notes. Detection Engineering & Use Case Governance
Assist in developing Tabby-specific detection requirements for Fintech threats — translating business and regulatory risks (ATO, payment fraud, API abuse, credential stuffing) into detection use case specifications. Ensure detection coverage aligns with relevant frameworks — reviewing use case libraries against MITRE ATT&CK, SAMA CSF controls, and NCA ECC requirements. Cyber Threat Intelligence & Brand Protection (Cyble)
Track managed SOC SLA performance — monitoring key metrics including escalation quality, threat hunting deliverable timeliness, and use case update frequency; flagging deviations to the SOC Lead. Maintain Tabby's incident register — ensuring the master incident log is accurate, current, and audit-ready in line with SAMA CSF and internal governance requirements. Participate in post-incident reviews — reviewing vendor post-incident reports, validating root cause analysis findings, and tracking agreed corrective actions to completion.

See how this role fits your experience

Add your resume to compare the role’s scope, tools and requirements with your experience.

Pay and work setup unconfirmed

Not confirmed in this saved copy: pay, work setup. Check the full posting

Tools in this posting

  • kibana
Source — Tool mentions in context
- No mandatory professional experience required. Any internship, academic project, or personal lab experience related to security operations, log analysis, SIEM platforms, or threat intelligence is a strong advantage. Hands-on exposure to Elastic Stack, even in a self-study context, is a distinct advantage - Foundational understanding of SIEM platforms — ability to navigate Elastic Stack (Kibana dashboards, KQL/Lucene queries, ES|QL) consoles to review alerts, investigate events, and query log data across multiple sources. - Basic understanding of network security fundamentals — TCP/IP protocols, DNS, HTTP/S, common attack traffic patterns (port scans, brute force, C2 beaconing), and how they manifest in SIEM log sources.

Find answers in the posting

AI
How answers work

AI selects complete passages from this posting. Check them for conditions and exceptions.

Uses this posting and your question. No profile needed.

Already applied? Track this application

About applying

Apply opens the employer’s site in a new tab. Add your outcome here after you submit.

Source details & eligibility

Before you apply

Source excerpts

Selected passages from the saved posting. Check the full description for conditions and exceptions.

Pay

No pay amount identified in the saved description.

Location & working pattern

Riyadh, Saudi Arabia, KSA

Working pattern and location restrictions need checking in the full posting.

Work authorization

No clear work-authorization passage found. Eligibility is unconfirmed.

Posting history
Status in our records
Active
First seen by us
Sep 10, 2026
Recorded sightings
1

These dates show when we found the listing. Check the employer’s website to confirm it is still accepting applications.

Report an error

Job description

Tabby creates financial freedom in the way people shop, earn and save by reshaping their relationship with money. Over 17 million users choose Tabby to stay in control of their spending and make the most out of their money.

The company’s flagship offering allows shoppers to split their payments online and in-store with no interest or fees. Over 40,000 global brands and small businesses, including Amazon, Noon, IKEA, and SHEIN use Tabby to accelerate growth and gain loyal customers by offering easy and flexible payments online and in stores.

Tabby generates over $10 billion in annual transaction volume for its partner brands and is the highest-rated, most-reviewed, largest, and fastest-growing FinTech in the GCC region.
Tabby launched in 2019 and has since raised +$1 billion in equity and debt funding from global and regional investors, and is now valued at $4.5 billion.

The Cyber Security Analyst (SOC/CTI) is an internal Tabby role responsible for owning and administering Tabby's security operations platform and cyber threat intelligence capability. With 24x7 security monitoring and alert triage delivered by Tabby's managed SOC service provider, the internal SOC/CTI Analyst focuses on the functions Tabby retains in-house: administering Elastic SIEM, managing the Cyble CTI and brand protection platform, governing detection engineering and use case quality, overseeing managed SOC service performance, and serving as the internal authority for incident validation and closure. Working under the guidance of senior SOC engineers and the SOC/CTI Lead, the role ensures Tabby maintains full operational visibility, controls the quality of the managed service, and progressively builds internal SOC and detection engineering expertise aligned to Tabby's Fintech threat landscape.

Key Responsibilities

SIEM Administration & Log Source Management
  • Administer Tabby's Elastic SIEM deployment — monitoring platform health, index lifecycle management, cluster performance, and log ingestion rates to maintain continuous operational visibility across all connected log sources.
  • Own the log source onboarding process — coordinating with IT, Cloud, DevOps, and application teams to integrate new assets into Elastic SIEM via syslog, API connectors, Beats agents, or custom parsers.
  • Maintain and continuously improve Tabby's asset and log source inventory — tracking onboarding status, ingestion volumes, and coverage gaps, and escalating visibility deficiencies to the SOC Lead for prioritisation.
  • Perform routine SIEM housekeeping — reviewing index health, managing retention policies, verifying that critical detection rules are active and firing correctly, and resolving parsing errors or dropped log sources promptly.
  • Support SIEM tuning activities under senior guidance — adjusting field mappings, resolving ingest pipeline issues, and validating that log data is correctly normalised and queryable by the managed SOC team.
  • Maintain SIEM configuration documentation — recording index patterns, log source integration specifications, agent deployment standards, and platform architecture notes.

Detection Engineering & Use Case Governance
  • Serve as Tabby's internal point of contact for detection engineering — reviewing, testing, and formally approving correlation rules and use cases submitted by the managed SOC provider before production deployment.
  • Validate detection logic submitted by the vendor — testing use cases against sample log data in a staging environment to confirm accuracy, alignment with Tabby's threat model, and false positive risk before go-live.
  • Maintain Tabby's use case library — tracking all active, pending, and retired detection rules with their logic, use case ID, last review date, trigger frequency, and approval status.
  • Monitor weekly use case performance reports from the managed SOC — flagging rules with high false positive rates, untriggered rules, or detection gaps for remediation with the vendor.
  • Assist in developing Tabby-specific detection requirements for Fintech threats — translating business and regulatory risks (ATO, payment fraud, API abuse, credential stuffing) into detection use case specifications.
  • Ensure detection coverage aligns with relevant frameworks — reviewing use case libraries against MITRE ATT&CK, SAMA CSF controls, and NCA ECC requirements.

Cyber Threat Intelligence & Brand Protection (Cyble)
  • Administer and manage Tabby's Cyble CTI platform — maintaining platform configuration, user access, feed integrations, and API connectivity between Cyble and the Elastic SIEM environment.
  • Monitor Cyble for emerging threat intelligence relevant to Tabby — tracking new threat actor TTPs, CVE disclosures targeting Tabby's technology stack, and Fintech-specific threats including ATO campaigns, payment fraud schemes, and mobile app threats.
  • Manage Tabby's IOC registry — collecting, categorising, and maintaining accurate IOC entries (IP addresses, domains, file hashes, URLs) from Cyble and other feeds, with context, confidence levels, and expiry dates correctly recorded.
  • Oversee IOC operationalisation — coordinating with the managed SOC team to ensure confirmed IOCs are ingested into Elastic SIEM detection rules within agreed timeframes, and tracking coverage confirmation.
  • Monitor brand protection alerts via Cyble — reviewing findings for domain spoofing, counterfeit mobile applications, fake social media profiles, dark web data exposure, and leaked credentials; escalating confirmed threats per defined procedures.
  • Prepare and distribute periodic CTI briefings — compiling notable intelligence findings, brand protection status, active IOC feeds, and sector-relevant threat trends for the SOC Lead and relevant stakeholders.

Managed SOC Oversight & Incident Closure
  • Act as Tabby's primary internal liaison with the managed SOC service provider — reviewing daily alert summaries, weekly threat hunting reports, and monthly management reports submitted by the vendor.
  • Validate vendor escalations — reviewing incidents escalated by the managed SOC to confirm sufficient investigation evidence, accurate severity classification, and completeness of remediation recommendations before internal action.
  • Own Tabby's incident closure process — reviewing vendor-recommended closures, confirming remediation actions have been completed, ensuring evidence is properly documented, and formally closing incidents in the incident management system.
  • Track managed SOC SLA performance — monitoring key metrics including escalation quality, threat hunting deliverable timeliness, and use case update frequency; flagging deviations to the SOC Lead.
  • Maintain Tabby's incident register — ensuring the master incident log is accurate, current, and audit-ready in line with SAMA CSF and internal governance requirements.
  • Participate in post-incident reviews — reviewing vendor post-incident reports, validating root cause analysis findings, and tracking agreed corrective actions to completion.

SOC Reporting & Continuous Improvement
  • Maintain SOC operational documentation — escalation records, tool status trackers, runbook libraries, and detection playbooks — ensuring records are accurate, current, and audit-ready.
  • Support the preparation of SOC performance reports and metrics dashboards — compiling MTTD/MTTR statistics, SLA adherence data, IOC registry accuracy, and use case coverage metrics.
  • Contribute to SOC process improvement initiatives — identifying gaps in detection coverage, tooling, or process and raising improvement recommendations to the SOC Lead.
  • Actively invest in continuous self-development — studying SIEM administration, detection engineering, Cyble platform capabilities, and the MITRE ATT&CK framework to build independent expertise and progress toward the next grade.

Skills, Knowledge and Expertise

  • Bachelor's degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, or a related field.
  • Recent graduates and fresh university leavers are encouraged to apply — no prior professional SOC experience is required.
  • Academic projects, home labs (e.g., TryHackMe Blue Team paths, HackTheBox, Elastic Stack builds), or internship experience in security operations or monitoring are viewed favorably.
  • No mandatory professional experience required. Any internship, academic project, or personal lab experience related to security operations, log analysis, SIEM platforms, or threat intelligence is a strong advantage. Hands-on exposure to Elastic Stack, even in a self-study context, is a distinct advantage
  • Foundational understanding of SIEM platforms — ability to navigate Elastic Stack (Kibana dashboards, KQL/Lucene queries, ES|QL) consoles to review alerts, investigate events, and query log data across multiple sources.
  • Basic understanding of network security fundamentals — TCP/IP protocols, DNS, HTTP/S, common attack traffic patterns (port scans, brute force, C2 beaconing), and how they manifest in SIEM log sources.
  • Foundational awareness of endpoint security monitoring — Windows Event Log analysis (logon events, process creation, registry changes), Linux syslog, and common persistence and lateral movement indicators.

Employment type

Full Time