Level

Tabby

Information Security Engineer (SOC L2)

AI in this role

Information Security Engineer responsible for monitoring infrastructure, analyzing security events, and managing incident response.

siemids-ips
incident-responsethreat-intelligencesecurity-monitoringlog-analysis
Tabby creates financial freedom in the way people shop, earn and save by reshaping their relationship with money. Over 25 million users choose Tabby to stay in control of their spending and make the most out of their money.

The company’s flagship offering allows shoppers to split their payments online and in-store with no interest or fees. Over 70,000 global brands and small businesses, including Amazon, Noon, IKEA, and SHEIN use Tabby to accelerate growth and gain loyal customers by offering easy and flexible payments online and in stores.
Tabby generates over $18 billion in annual transaction volume for its partner brands and is the highest-rated, most-reviewed, largest, and fastest-growing FinTech in the GCC region.

Tabby launched in 2019 and has since raised +$1 billion in equity and debt funding from global and regional investors, and is now valued at $6,5 billion.

As Information Security Engineer, you’ll play a key part in monitoring and defending our infrastructure, applications, and cloud environments from cyber threats. 

You’ll lead incident response efforts, develop and tune detection rules, investigate security events, and collaborate with cross-functional teams to strengthen our security posture.

Key Responsibilities

Security Monitoring & Detection
  • Monitor and analyze logs and alerts from a wide range of sources including firewalls, intrusion detection/prevention systems (IDS/IPS), endpoints, servers, and cloud platforms.
  • Perform correlation of events from multiple sources to identify advanced threats and unusual patterns of behavior.
  • Fine-tune alert thresholds and detection logic to reduce false positives and improve signal-to-noise ratio.
  • Maintain dashboards and reporting to provide real-time visibility into security posture.

Incident Response & Investigation
  • Serve as a frontline responder for security incidents, managing incidents through their lifecycle – detection, containment, eradication, recovery, and lessons learned.
  • Coordinate with internal stakeholders and external vendors during high-severity incidents or data breaches.
  • Perform root cause analysis and forensic investigations using endpoint and network-based artifacts.
  • Maintain detailed incident documentation and contribute to post-mortem analysis and reports.

Threat Intelligence & Detection Rule Development
  • Research emerging threats and trends. 
  • Contribute to the creation and tuning of detection rules, threat-hunting queries, and use cases across multiple platforms including cloud environments.
  • Maintaining CTI Platform along with the integration of the CTI feeds with the security controls to have active CTI driven detections.

Collaboration and Communication
  • Communicate effectively with cross-functional teams including IT, DevOps, Risk, and Compliance during incidents and investigations.
  • Provide concise and clear updates during incident handling to stakeholders and management.
  • Mentor junior analysts and assist in training efforts within the SOC team.

Skills, Knowledge and Expertise

  • 2–3 years of experience in a SOC or cybersecurity operations role, ideally in a fast-paced fintech or enterprise environment.
  • Strong knowledge of security best practices, including incident handling, alert triage, log analysis, and threat modeling.
  • Understanding of online technologies, REST APIs, microservices, and modern application architectures.
  • Experience working in a culturally diverse and collaborative environment.
  • Familiarity with DLP, AV, and anti-malware systems from an operational monitoring perspective.
  • Experience with phishing detection, user behavior analytics, and security awareness campaigns.
  • Security certifications such as Security+, CySA+, eCIR, eCTHPv2, GCIA, or GMON (preferred but not required).
  • Strong communication skills, especially for coordinating incident response and writing clear incident reports.
  • Experience with SIEM platforms, SOAR tools, EDR/XDR, and Threat Intelligence platforms.
  • Familiarity with cloud environments and cloud-native logging and monitoring tools.
  • Scripting experience (e.g., Python) to automate tasks and improve SOC efficiency.

How we rate this

Information Security Engineer (SOC L2) at Tabby rates 0 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.

Classification

Little AI. AI is not part of the work.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Prepare for this job

A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.

Skills and AI tools this role asks for

Incident ResponseThreat IntelligenceSecurity MonitoringLog AnalysisSiemIds Ips

Questions you could be asked

  1. Tell me about a project where incident response was part of your work. What did you do?
  2. Tell me about a project where threat intelligence was part of your work. What did you do?
  3. Tell me about a project where security monitoring was part of your work. What did you do?
  4. Tell me about a project where log analysis was part of your work. What did you do?
  5. Walk me through how you've used Siem in your day-to-day work.

Adapt your resume

  • List these exact terms on your resume: Incident Response, Threat Intelligence, Security Monitoring, Log Analysis, and Siem. An applicant tracking system matches the wording, not the idea.
  • Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.

Want an expert to read your CV for this job?

Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.

Get a free CV review

Get new cybersecurity jobs by email

One email a week with the new cybersecurity jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Security roles that involve little AI, at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at Tabby

More cybersecurity jobs

Related searches

Same AI level