Information Security Intern
On-siteRiyadh, Riyadh Region, Saudi Arabia or Ksa, Far North Region, Republic of Cameroon
Job Summary
Triage findings from SAST, DAST, SCA, and dependency scanners across mobile and backend repos, then reproduce and document vulnerabilities while writing remediation tickets for product teams. Contribute to secure code reviews on merge requests, participate in threat-modelling sessions, and run scoped assessments against staging environments under senior sign-off. Help maintain security tooling, including scanner configs and baseline rules, and contribute to DevSecOps by implementing security gates in CI/CD pipelines. Support compliance programs against frameworks like PCI DSS, ISO 27001, and SAMA through evidence collection, control mapping, and gap analysis. Assist with risk assessments, vendor security reviews, and audit preparation by organizing workpapers and evidence packages. Work alongside engineering teams on PII handling, secrets management, and encryption reviews while contributing to internal security knowledge bases.
Required Qualifications
- Solid understanding of information security fundamentals: confidentiality, integrity, availability; common attack categories (OWASP Top 10) and common control categories
- Understanding of HTTP, TLS, DNS, and TCP/IP fundamentals
- Understanding of authentication and authorization patterns (sessions, cookies, OAuth 2.0, JWT)
- Familiarity with Linux command line and POSIX-like environments
- Ability to read technical material and explain it clearly in writing
- Experience with Git and standard development workflows
- Strong ethical mindset and discretion — security findings and compliance evidence are sensitive by default, non-disclosure outside the team is non-negotiable
- Open to constructive feedback
- English sufficient for documentation and team communication
- Saudi nationals only
- Saudi passport required
- Self-funded internship by Tabby
- We welcome both current students and fresh grads
- We expect a full-time level of engagement throughout the internship
- interns should be ready to contribute at a full working-day pace
- overall performance, ownership, and context involvement are expected at a full-time level
- Paid internship
- Full integration into the Information Security team
- Open to Saudi nationals (Saudi passport required); location flexible — candidates may be based outside KSA
- Office-first in Riyadh where possible
- Clear path to a junior Information Security engineer role based on performance
Desired Qualifications
- Working knowledge of a programming language (Python or Go preferred)
- CTF participation (Hack The Box, TryHackMe, picoCTF, SAFCSP CTFs) with documented solves or write-ups
- Hands-on experience with Burp Suite Community, OWASP ZAP, or similar interception proxies
- Familiarity with vulnerability scanners (Nessus, OpenVAS, Trivy, Grype) or SAST/SCA tools (Semgrep, CodeQL, Snyk)
- Familiarity with mobile app security basics (iOS / Android — certificate pinning, secure storage, deep-link risks)
- Exposure to container and orchestration security (Docker, Kubernetes — image scanning, RBAC)
- Bug bounty submissions on any public program (HackerOne, Bugcrowd, Intigriti)
- Familiarity with DevSecOps tooling — CI/CD security gates, IaC scanning, container image scanning
- Exposure to SIEM or SOC tooling — log analysis, alert triage
- Basic knowledge of SQL and how queries can be abused
- Familiarity with cryptography fundamentals (symmetric vs asymmetric, hashing, signing — conceptual)
- Exposure to security frameworks: PCI DSS, ISO 27001, NIST CSF, or SAMA CSF
- Awareness of risk management concepts — likelihood, impact, residual risk, control effectiveness
- Comfort with structured documentation: writing clear policies, procedures, evidence narratives
- Familiarity with audit basics — sampling, control testing, evidence collection
- Awareness of GDPR or other privacy regulations
- Exposure to GRC tooling (Vanta, Drata, OneTrust, or similar)
- Understanding of cloud security basics on GCP (IAM, VPC isolation, secrets, KMS)
- Interest in security automation and security platform engineering
- Existing certifications (OSCP, CEH, Security+, CISA, CISM, CRISC) — welcome but not required
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.