Tabby, founded in 2019 and headquartered in Riyadh, operates one of the Middle East's largest Buy Now, Pay Later platforms. With over 20 million users and more than 40,000 merchant partners across Saudi Arabia, UAE, and Kuwait, the company processes over $10 billion in annual transaction volume. Its $4.5 billion valuation came during a secondary share sale.
The security posture for a fintech at this scale is nontrivial. Tabby's stack sits at the intersection of payment processing, financial technology, and e-commerce platforms - each surface carrying distinct threat models. Real-time transaction authorization, merchant integrations, user account security, and regulatory compliance across multiple Gulf markets all demand rigorous engineering. The attack surface spans card-not-present fraud, account takeover vectors, API abuse targeting merchant endpoints, and the kind of data exfiltration risks that come with holding financial records for tens of millions of users.
Engineers here are working against a live, high-throughput payment system where downtime means lost revenue for 40,000+ businesses and millions of consumers unable to complete purchases. The infrastructure must handle fraud detection, secure payment orchestration, and installment scheduling at scale while maintaining compliance with regional financial regulations. It's the kind of environment where security isn't a bolt-on - it's load-bearing infrastructure.




