What Jobs are available for Cybersecurity Engineer in South Africa?
Showing 111 Cybersecurity Engineer jobs in South Africa
Cybersecurity Engineer
Posted today
Job Viewed
Job Description
Company Description
Aspen TESS is Aspen's technology enabled shared services business, established to be a partner in unlocking business value through digital innovation and process efficiency. Aspen TESS will eliminate repetitive effort and use technology to optimize standardized processes, by delivering cost-effective services and innovative solutions to Aspen business units globally.
OBJECTIVE
The Cybersecurity Engineer plays a crucial role in protecting Aspen's infrastructure by implementing, maintaining, and enhancing security technologies and processes. This role works closely with the SOC, IT, and Compliance teams to ensure systems and data remain secure and threats are identified and mitigated.
Below is a general description of the key responsibilities, qualifications, and skills needed for this role:
Key Responsibilities
Incident Response and Escalation
- Act as a Tier 2/3 escalation point for complex security incidents raised by the SOC or IT teams.
- Lead and support incident response activities, including forensic analysis and root cause investigation.
- Support red/blue team exercises to test and improve detection, response, and defense capabilities.
Security Platform Management
- Manage configurations and policies for the Cyber Security platforms, ensuring optimal performance and alignment with security standards.
Vulnerability Management
- Analyze vulnerability scan reports to identify and assess security weaknesses.
- Coordinate remediation efforts with relevant teams and ensure timely closure of vulnerabilities
Secure Systems and Network Configuration
- Collaborate with IT teams to implement secure system and network configurations, following industry best practices and compliance requirements.
Training and Mentorship
- Provide training and mentorship to junior analysts, fostering their professional development and enhancing team capabilities.
Project Involvement
- Participate in cross-functional IT and business projects to ensure security requirements are identified, integrated, and enforced throughout the project lifecycle
SKILLS AND COMPETENCIES:
- Hands-on experience with Cisco Umbrella, Defender for Endpoint, Identity, Office, and Sentinel.
- Working knowledge of SIEM, SOAR, EDR, vulnerability and data protection tools.
- Scripting skills (e.g., PowerShell, Python, KQL) for automation and threat hunting.
- Strong understanding of networking, authentication, certificates and cloud security principles.
- Familiarity with MITRE ATT&CK, NIST CSF, and other industry frameworks.
- Strong analytical and problem-solving skills.
- Clear and concise communication for incident handling and documentation.
- Collaborative mindset with the ability to work independently when required.
- Effective multitasking under pressure.
Qualifications & Experience
- Bachelor's degree in Computer Science, Information Technology, or related field (or equivalent experience).
- Preferred certifications:
Microsoft Certified: Security Operations Analyst Associate
Microsoft Security, Compliance, and Identity Fundamentals
Cisco Certified CyberOps Associate or CCNP Security
CompTIA Security+, CySA+, or similar
NBIs this job a match or a miss?
Cybersecurity Engineer
Posted 25 days ago
Job Viewed
Job Description
Company Description
Aspen TESS is Aspen's technology enabled shared services business, established to be a partner in unlocking business value through digital innovation and process efficiency. Aspen TESS will eliminate repetitive effort and use technology to optimize standardized processes, by delivering cost-effective services and innovative solutions to Aspen business units globally.
OBJECTIVE
The Cybersecurity Engineer plays a crucial role in protecting Aspen’s infrastructure by implementing, maintaining, and enhancing security technologies and processes. This role works closely with the SOC, IT, and Compliance teams to ensure systems and data remain secure and threats are identified and mitigated.
Below is a general description of the key responsibilities, qualifications, and skills needed for this role:
KEY RESPONSIBILITIES
Incident Response and Escalation
- Act as a Tier 2/3 escalation point for complex security incidents raised by the SOC or IT teams.
- Lead and support incident response activities, including forensic analysis and root cause investigation.
- Support red/blue team exercises to test and improve detection, response, and defense capabilities.
Security Platform Management
- Manage configurations and policies for the Cyber Security platforms, ensuring optimal performance and alignment with security standards.
Vulnerability Management
- Analyze vulnerability scan reports to identify and assess security weaknesses.
- Coordinate remediation efforts with relevant teams and ensure timely closure of vulnerabilities
Secure Systems and Network Configuration
- Collaborate with IT teams to implement secure system and network configurations, following industry best practices and compliance requirements.
Training and Mentorship
- Provide training and mentorship to junior analysts, fostering their professional development and enhancing team capabilities.
Project Involvement
- Participate in cross-functional IT and business projects to ensure security requirements are identified, integrated, and enforced throughout the project lifecycle
SKILLS AND COMPETENCIES:
- Hands-on experience with Cisco Umbrella, Defender for Endpoint, Identity, Office, and Sentinel.
- Working knowledge of SIEM, SOAR, EDR, vulnerability and data protection tools.
- Scripting skills (e.g., PowerShell, Python, KQL) for automation and threat hunting.
- Strong understanding of networking, authentication, certificates and cloud security principles.
- Familiarity with MITRE ATT&CK, NIST CSF, and other industry frameworks.
- Strong analytical and problem-solving skills.
- Clear and concise communication for incident handling and documentation.
- Collaborative mindset with the ability to work independently when required.
- Effective multitasking under pressure.
QUALIFICATIONS & EXPERIENCE
- Bachelor’s degree in Computer Science, Information Technology, or related field (or equivalent experience).
- Preferred certifications:
Microsoft Certified: Security Operations Analyst Associate
Microsoft Security, Compliance, and Identity Fundamentals
Cisco Certified CyberOps Associate or CCNP Security
CompTIA Security+, CySA+, or similar
Is this job a match or a miss?
Senior Cybersecurity Engineer
Posted today
Job Viewed
Job Description
Key Responsibilities
JOB DESCRIPTION
- Lead network security advisory efforts, including LAN/WAN segmentation, firewall posture reviews, and NAC deployments.
- Provide assurance on secure network configurations and collaborate on optimization of core protocols (TCP/IP, DNS, DHCP).
- Guide secure systems design across Windows, Linux, and hybrid cloud environments, ensuring alignment with security standards.
- Advise on infrastructure changes, identity platforms, and PKI environments to reduce risk and improve resilience.
- Support vulnerability remediation, configuration reviews, and automation strategies for compliance and hardening.
- Engage with stakeholders to align infrastructure initiatives with cybersecurity strategy and mentor teams on secure practices.
Qualifications And Experience
- 8+ years in enterprise cybersecurity, with a strong emphasis on network engineering and infrastructure security.
- Proven expertise in network architecture, including secure design of LAN/WAN, wireless (802.1X, WPA3), and segmentation strategies.
- Hands-on experience with firewall platforms (Fortinet, Cisco, Palo Alto) and Network Access Control (NAC) solutions (FortiNAC, Cisco ISE, Aruba ClearPass).
- Deep understanding of network protocols and services: TCP/IP, DNS, DHCP, VLANs, routing, switching, VPN, and remote access.
- Strong advisory capability across Microsoft environments (Windows Server, Active Directory, Exchange, PKI) and Linux systems (RHEL/Ubuntu).
- Familiarity with cloud platforms (Azure, AWS, GCP), especially hybrid identity and infrastructure deployments.
- Experience with automation and compliance tooling (PowerShell, Ansible, Terraform) for system hardening and monitoring.
- Solid grasp of Data Loss Prevention (DLP) principles and implementation strategies.
Skills
- Advanced knowledge of network security architecture, including segmentation, NAC, and firewall policy design.
- Strong command of network protocols and diagnostics: TCP/IP, DNS, DHCP, VLANs, routing, and switching.
- Proficient in security automation and scripting (PowerShell, Ansible, Terraform) for configuration and compliance.
- Skilled in secure systems design across Windows, Linux, and hybrid cloud environments.
- Experienced in threat modeling, vulnerability assessment, and technical risk analysis.
- Effective communicator with the ability to translate technical risk into business impact.
- Adept at collaborating across IT and security teams, with a proactive and detail-oriented mindset.
Behaviours
- Action Oriented - readily takes on new challenges and opportunities with a sense of urgency and eagerness
- Communicates Effectively - conveys information and communicates ideas in a clear, concise and impactful manner
- Courage - confronts and tackles challenging situations with courage
- Decision Quality - consistently makes timely, well-rounded and informed decisions
- Ensures Accountability - takes accountability and ensures others are held to account on agreed upon performance targets
- Manages Complexity - interprets and simplifies complex and contradictory information when resolving organisational problems
- Plans and Aligns - develops plans and prioritises initiatives that align to the organisational goals and objectives
- Tech Savvy - leverages new technology to enhance productivity, improve problem solving, and support business growth
Preference will be given, but not limited to, candidates from designated groups in terms of the Employment Equity Act.
About Us
Who we are is because of our people. They are our greatest asset. TFG is an internationally diversified retail portfolio of 34 speciality lifestyle and apparel brands that
Inspire our Customers to live their Best Lives
and are woven into the lives of millions. Our vision is to create the most remarkable omnichannel experiences for our customers. TFG is more than a workplace, it's a launchpad for your growth. Join us and explore endless growth opportunities across our diverse brands. We're a purpose-led business, and on this team, you'll share the pride of making an impact across a whole industry.
We're the designers, the makers, the shakers and the teams behind the scenes.
Are you with us?
About The Team
At TFG, technology is the silent engine behind fashion, financial services, and our factory floors. Our Infotec team builds the platforms that power over 3,600 stores and millions of customer moments. From cloud-native retail applications to AI/ML deployments, we solve real-world retail problems at scale. Whether you love engineering, data, architecture, or innovation at the edge—we have room for your kind of talent. Let's build something enduring together.
Is this job a match or a miss?
Manager Information Security Architecture
Posted today
Job Viewed
Job Description
The Manager Information Security Architecture is responsible for delivering technical security solution designs, reference architecture designs and technical standards for Information Systems within the MTN Group in accordance with the enterprise security designs
Security is entering a new phase where the architecture and systems between IT and the Mobile Network are now using shared platforms or infrastructures. There is an increased focus in the security of these networks and across all areas of the business. The introduction of cloud has blurred the lines between a traditional IT security professional and a Mobile Network Security function. The candidate is further responsible for vetting and advising all OPCO's in the MTN portfolio on Core network, Digital and IT security related projects, including software developed in house by S2 COE. The candidate is also responsible to support Fintech and Infraco security colleague in designing robust and secure architecture for the platform business The incumbent must therefore ensure the successful delivery in context of:
An expertise-based multicultural federated organisation
A dynamic and evolving field of information security
Revolutionary workforce practices which are bringing together global labour markets
Evolving industry sector constantly presenting new challenges, opportunities and threats to the core businesses
Dynamic legal and regulatory environment (with specific focus on data sovereignty and privacy/data protection)
Agile ways of working
Hybrid networks (cloud and on-premises)
Values (Our Culture)
We at MTN are a purpose and value-led organization. At MTN, we believe that understanding our people's needs and aspirations is key to creating experiences that delight you at work, everyday. We are committed to fostering an environment where every member of our Y'ello Family is heard, understood and empowered to live an inspired life.
Our values keep us grounded and moving in the right direction. Most importantly, they keep us honest. It is not something we claim to be. It is in our DNA.
As an organisation, we consider it our mission to create an exciting and rewarding place to work, where our people can be themselves, thrive in positivity and ignite their full potential. A workplace that boosts creativity and innovation, improves productivity, and ultimately drives meaningful results. A workplace that is built on relationships and achieving a purpose that is bigger than us,
Our commitments go beyond an organisational promise. It is in our leadership and managerial ethos to meaningfully partner with our employees, customers and stakeholders with a vision to realise our shared goals.
Live Y'ello
• Lead with Care
• Can-do with Integrity
• Collaborate with Agility
• Serve with Respect
• Act with Inclusion
- Key Performance Areas: Core, essential responsibilities / outputs of the position (KPA's)
The Manager Information Security Architecture is responsible for the following deliverables
Develop information security solution architectures (e.g., people, processes, technology);
Develop information security reference architecture (IT & telecoms) to manage threats, monitor implementation & compliance; support the design of security reference architecture for both Fintech and Infraco
Assist with the refinement of MTN Information Security reference architecture and test the architecture against pilot implementations and ongoing OPCO implementations
Obtain inputs and validate the MTN information security reference architecture with key MTN partners;
Responsible for design of information security solution architectures for group wide risk mitigation of key risk areas including standardised security architecture, security monitoring, and vulnerability management;
Develop reference architectures for specific technical security solutions
Assist OPCOs and platforms with technical security solution designs
Determine a holistic view of security requirements by evaluating current security operations and requirements; researching information security standards; studying architecture/platform; identifying integration issues and preparing cost estimates;
Assist in the evaluation of outsourced / third-party technologies and hosting environments to ensure they provide adequate protection for the processing, transmission, and storage of MTN's information;
Ensure the development of security architectural and development standards for all components of key application stacks (OS, DB, Middleware, Web etc.) and cloud environment (in collaboration with CCOE);
Maintain a 3 - 5 years security architecture road map with budget requirements to prevent future cybersecurity attacks. Articulate the solution to senior management to receive executive buy-in
Support the activity of the Architecture Working Committee (AWC) and support the periodic request of the architecture principles related to information security
Support AI working group and the definition of "security guardrails" as part of the Responsible AI initiatives
Support the network standardization activities of the GSMA Fraud and Security Group (FASG)
Assist with management of divisional budgets in line with business objectives and facilitate forecasting;
Manage project initiative budgets in line with business objectives; and
Drive initiatives that will ensure that the "cost of operations" are reduced, in line with a least cost operating strategy stemming from the business drivers
Work with the Senior Manager: Information Systems in order to implement the overall information security architecture requirements and framework, overarched by the business risk strategy;
Responsible for the implementation of the information security architecture roll-out definition and actualization via third parties;
Roadmap definitions for security systems by monitoring security environment; identifying security gaps; evaluating and implementing enhancements
Job Requirements (Education, Experience and Competencies)
Education:
4/6-year Information Technology/ Information Systems/ Engineering (or related) Degree
Master's in business administration is advantageous
CISSP/CISM/CEH/CSSP (one of)
SABSA and/or TOGAF qualification will be an advantage
Cloud certifications (Azure, GCP, AWS) will be an advantage
DevSecOps certifications will be an advantage
IA and responsible AI certifications will be an advantageOther Architectural qualifications (ITIL, TMF, COBIT) will be an advantage
Experience:
3-5 years of relevant work experience in Information Technology (specifically security)
Experience in designing and implementing organisation wide information security systems architecture
Experience in managing and implementing large scale information security projects
Experience working in Africa and Middle East and have a grasp of political, social, infrastructure and integrity challenges
Good understanding of the information technology environment of a telecom company
Functional Knowledge:
Knowledge of technical security disciplines, specifically around security architecture, engineering, and solution delivery
Knowledge and experience across security products, tools, and industry trends: e.g. Mobile Network Security, Hardware Configuration, Network Protocols, Networking Standards, Windows, Linux and Unix operating systems, Application Security, Data Security, generative and analytical AI models and safeguards, Application integration and Infrastructure Security, Security Frameworks (ISO27001, COBIT, NIST etc.), security attacks pathologies, wired and wireless security, and cyber laws and ethics
Security protocols, communication protocols, cryptography, authentication and authorisation across mobile networks and systems
Implementation of multi-factor authentication, single sign-on, identity management or related technologies
Working knowledge of current security risks, risk management and assessments
Deep understanding of the MTN business and technology strategy
Skills
Strong Analytics/data interpretation and presentation skills
Learning, self-development and continuous improvement
Detail orientation and high standards on work performed
Negotiation skills, Interpersonal skills, conflict management and problem solving
Stress Management and Emotional Intelligence
Behavioural Qualities
Analytical, organised and methodical
Operationally astute, proactive, detail-oriented
Results drive team player
Is this job a match or a miss?
Ops Spec: Cybersecurity Engineer
Posted today
Job Viewed
Job Description
Job description:
Core Description
Responsible for ensuring that quality standards are met through evaluating, implementing firewall requests and incidents for larger complex networks and communication systems that are in alignment with BCX's standards, as well as supervising direct reports.
Key Deliverables / Primary Functions
- Liaising with and advising the Client IT Manager or ISO on operational security matters.
- Managing mitigating actions associated with vulnerability assessments and/or audits.
- Implementation of a security control framework
- Act as a primary contact for security operations for a customer.
- Facilitate basic security investigations
- Guidance on global information security threat trends, new technology solutions and management responses
- Provide security risk assessment and advisory services to the customer and BCX
Core Functional Skills & Capabilities
Data Governance Communication Information Security Risk Management
Core Behavioural Competencies
Job Match Creating & Innovating Analysing Adhering to principles and values Deciding & Initiating Action
Minimum Qualifications
NQF 6: 3 year Degree/ Diploma/ National Diploma OR NQF 4: Grade 12
Additional Education -Preferred /Advantage
Experience
3 years' experience
OR
Grade 12 & 5 years' experience
Certifications
(ISC)² Certified in Cybersecurity (CC) CompTIA Cybersecurity Analyst (CySA+) EC-Council Certified Ethical Hacker (CEH) Cisco Certified CyberOps Associate GIAC Security Essentials (GSEC)
Professional Memberships in Relevant Industry
Level of Engagement & Span of Control
Span of Control : 0
Level of Engagement : Interacting with clients as well as relevant stakeholders within BCX.
Special Requirements / Employment Condition
Drivers Licence and Reliable Vehicle - both required Ability to work extended /long hours as and when required BCX is an equal opportunity employer, and appointments will be made in line with our employment equity plan and talent requirements. We seek to promote the employment and advancement of designated groups, inclusive of people with disabilities, while building an inclusive workforce that embraces diversity.
Profile description:
The Cybersecurity Engineer is responsible for safeguarding complex customer network and communication environments by evaluating, implementing, and managing firewall requests and incidents in line with BCX standards. This role ensures compliance with security frameworks, mitigates risks identified during vulnerability assessments or audits, and provides expert advisory services to both clients and internal stakeholders.
Key responsibilities include acting as the primary contact for customer security operations, facilitating security investigations, advising on global cybersecurity threats, and implementing appropriate control measures. The role also requires strong engagement with client IT managers, information security officers, and internal teams to align security operations with business objectives.
Core skills and capabilities include information security, data governance, risk management, and effective communication. The position requires relevant certifications (Cisco, Huawei, Checkpoint) and proven experience in network and security operations.
This role suits a detail-oriented professional with strong analytical skills, a proactive approach to mitigating risks, and the ability to provide practical security solutions in a dynamic cloud platform environment.
Is this job a match or a miss?
Cyber Security Architecture and Engineering Manager
Posted today
Job Viewed
Job Description
We are seeking a hands on, skilled and detail-oriented Security Leader to spear head our Architect and Engineering department with expertise in Microsoft technologies to join a rapidly expanding global team of security experts that provides services to protect our business. This role will report into the Head of Information Security and will work closely across all IT Teams and business units.
In this role, you will be responsible for leading, designing, implementing, managing, and optimizing security solutions to protect our IT infrastructure, technology assets, cloud environments, and applications. The ideal candidate will have hands-on experience with Microsoft security tools and technologies, such as Azure, Microsoft 365, Microsoft Purview and Microsoft Defender, and will play a critical role in safeguarding our digital assets.
Requirements
Leadership and Team Management
- Lead and mentor a team of Security Engineers and Architects focused on, designing and implementing secure controls across Microsoft technologies, such as Microsoft 365, Microsoft Defender, Azure Security Centre, and Microsoft Sentinel.
- Establish team goals, manage performance, and provide regular feedback to ensure the success of security operations.
- Foster a culture of continuous improvement and professional development within the team.
Cloud Security Strategy
- Responsible for the cloud security strategy for our Azure-based solutions, leveraging Azure Security Centre, Azure Active Directory, and other Azure-native security tools to secure infrastructure and applications.
- Design security controls in Azure to protect resources, networks, data, and identities.
- Oversee the integration of security practices in cloud migration strategies and help guide the secure adoption of cloud technologies.
Security Solution Implementation
- Implement, configure, and manage security solutions in Microsoft environments, including Azure, Microsoft 365, Microsoft Defender, Microsoft Purview and other Microsoft security tools.
- Ensure the secure deployment and configuration of Microsoft cloud resources, applications, and services, adhering to security best practices and company policies.
- Set up and maintain security controls such as firewalls including WAFs, VPNs, and endpoint protection across all environments.
Identity and Access Management (IAM)
- Responsible for Architecting and implementing advanced identity and access management (IAM) solutions using Microsoft technologies such as Azure Active Directory/EntraID, Azure AD B2B/B2C, and Microsoft Identity Platform.
- Design and enforce least privilege access principles, multi-factor authentication (MFA), conditional access policies, and role-based access control (RBAC) across all Microsoft service.
Vulnerability Management and Risk Assessment
- Responsible for security assessments and risk analysis for new Microsoft technologies, AI, cloud services and digital products.
- Regularly assess and monitor Microsoft systems and services for vulnerabilities and security gaps, using tools like Microsoft Defender for Endpoint and Azure Security Centre.
Security Automation and Optimisation
- Responsible for an Automation Strategy for security processes and tasks using PowerShell, Azure CLI, and other tools to improve efficiency and response times.
- Optimise security configurations across Microsoft environments to ensure best practices and consistent application of security controls.
- Continuously review and improve existing security processes, tools, and policies.
Compliance and Reporting
- Ensure Microsoft-based systems meet regulatory requirements (e.g., GDPR), internal security standards (ISO 27001/2, SOC) and policies.
- Assist in security audits and assessments, providing the necessary documentation and evidence to support compliance initiatives.
- Generate regular security reports, dashboards, project status and metrics using Microsoft security tools.
Collaboration and Effective Communication
- Work closely with IT, system administrators, and other security teams to coordinate incident response efforts, identify vulnerabilities, and implement mitigation strategies across the Microsoft technology stack.
- Communicate and conduct regularly presentations at a senior leadership level.
- Ensure that the IT Security documentation is maintained and updated regularly as required
- Provide guidance and support to internal teams regarding Microsoft security best practices, threat mitigation and security by design
- Participate in security projects, including cloud migration efforts, that involve Microsoft technologies, ensuring security is a top priority
- Provide input to the monthly IT Security report.
Who You Are:
Essential
- 5+ years of experience in a security engineering/architecture or cybersecurity leadership role, with a strong focus on Microsoft environments such as Microsoft 365, Azure, Microsoft Purview, and related Microsoft security products.
- Proven track record in leading security engineering/architecture teams, managing risk, design and build security principles for products (e.g. Microsoft 365, Microsoft Azure, CoPilot, Microsoft Defender, Microsoft Sentinel).
- Experience of working in a diverse Global Company;
- Understanding of key network and infrastructure security solutions such as firewalls, SD-WAN, WAF, DDoS protection IPS, Web Proxy, etc.
- Excellent knowledge of security solutions and technologies including Network Firewalls, proxy technologies, EDR, SIEM (Sentinel);
- Understanding of SASE solutions and cloud-based service delivery of traditional security controls (e.g. content filtering, firewall)
- Knowledge of Intrusion detection/prevention systems (IDS/IPS/WAF) and vulnerability assessment tools );
- Excellent knowledge of different threat scenarios, incident response and remediation techniques;
- Hands on experience of applying security by design across a Microsoft eco system.
- Knowledge of security technologies (encryption, data protection, permissions, privilege access etc.);
- Knowledge of applying CIS benchmark policies in Azure & O365;
- Experience with Security frameworks, ISO 27001, Cyber Essentials, NIST, PCI;
- Good working knowledge of Active Directory services, including reporting and auditing of Active Directory objects;
- Skilled in using scripting tools (PowerShell, MS CLI & VBS).
- Understand Incident Response, Cyber Kill Chain, Threat Modelling and pertinent Attack Vectors;
- Desirable qualifications, Microsoft Certified: Azure Security Engineer or Architect Associate, Microsoft Certified: Security, Compliance, and Identity Fundamentals, Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), CompTIA Security+, Certified Cloud Security Professional (CCSP) or other similar security certifications or demonstratable experience.
- Good communication (English Writing, Reading and Speaking) skills and ability to articulate subjects clearly.
- Proven analytical and problem-solving skills;
- Strong documentation skills;
- Organised, methodical and self-motivated;
- Keeping abreast of industry trends and security technologies.
- Takes the initiative to proactively resolve issues within own remit and recognises when escalation is required;
- Uses own knowledge and experience to make sounds judgements or assist others with sound judgements;
- Considers the regional and global implications of what we do in our own areas of responsibility;
- Identifies and builds relationships across team and region;
- Understands need to work within project scope, including price;
- Shows understanding of others in order to influence as appropriate.
Is this job a match or a miss?
Cyber Security Architecture and Engineering Manager
Posted today
Job Viewed
Job Description
Description
- We are seeking a hands on, skilled and detail-oriented Security Leader to spear head our Architect and Engineering department with expertise in Microsoft technologies to join a rapidly expanding global team of security experts that provides services to protect our business. This role will report into the Head of Information Security and will work closely across all IT Teams and business units.
- In this role, you will be responsible for leading, designing, implementing, managing, and optimizing security solutions to protect our IT infrastructure, technology assets, cloud environments, and applications. The ideal candidate will have hands-on experience with Microsoft security tools and technologies, such as Azure, Microsoft 365, Microsoft Purview and Microsoft Defender, and will play a critical role in safeguarding our digital assets.
Requirements
- Leadership and Team Management
- Lead and mentor a team of Security Engineers and Architects focused on, designing and implementing secure controls across Microsoft technologies, such as Microsoft 365, Microsoft Defender, Azure Security Centre, and Microsoft Sentinel.
- Establish team goals, manage performance, and provide regular feedback to ensure the success of security operations.
- Foster a culture of continuous improvement and professional development within the team.
- Cloud Security Strategy
- Responsible for the cloud security strategy for our Azure-based solutions, leveraging Azure Security Centre, Azure Active Directory, and other Azure-native security tools to secure infrastructure and applications.
- Design security controls in Azure to protect resources, networks, data, and identities.
- Oversee the integration of security practices in cloud migration strategies and help guide the secure adoption of cloud technologies.
- Security Solution Implementation
- Implement, configure, and manage security solutions in Microsoft environments, including Azure, Microsoft 365, Microsoft Defender, Microsoft Purview and other Microsoft security tools.
- Ensure the secure deployment and configuration of Microsoft cloud resources, applications, and services, adhering to security best practices and company policies.
- Set up and maintain security controls such as firewalls including WAFs, VPNs, and endpoint protection across all environments.
- Identity and Access Management (IAM)
- Responsible for Architecting and implementing advanced identity and access management (IAM) solutions using Microsoft technologies such as Azure Active Directory/EntraID, Azure AD B2B/B2C, and Microsoft Identity Platform.
- Design and enforce least privilege access principles, multi-factor authentication (MFA), conditional access policies, and role-based access control (RBAC) across all Microsoft service.
- Vulnerability Management and Risk Assessment
- Responsible for security assessments and risk analysis for new Microsoft technologies, AI, cloud services and digital products.
- Regularly assess and monitor Microsoft systems and services for vulnerabilities and security gaps, using tools like Microsoft Defender for Endpoint and Azure Security Centre.
- Security Automation and Optimization
- Responsible for an Automation Strategy for security processes and tasks using PowerShell, Azure CLI, and other tools to improve efficiency and response times.
- Optimize security configurations across Microsoft environments to ensure best practices and consistent application of security controls.
- Continuously review and improve existing security processes, tools, and policies.
- Compliance and Reporting
- Ensure Microsoft-based systems meet regulatory requirements (e.g., GDPR), internal security standards (ISO 27001/2, SOC) and policies.
- Assist in security audits and assessments, providing the necessary documentation and evidence to support compliance initiatives.
- Generate regular security reports, dashboards, project status and metrics using Microsoft security tools.
- Collaboration and Effective Communication
- Work closely with IT, system administrators, and other security teams to coordinate incident response efforts, identify vulnerabilities, and implement mitigation strategies across the Microsoft technology stack.
- Communicate and conduct regularly presentations at a senior leadership level.
- Ensure that the IT Security documentation is maintained and updated regularly as required
- Provide guidance and support to internal teams regarding Microsoft security best practices, threat mitigation and security by design
- Participate in security projects, including cloud migration efforts, that involve Microsoft technologies, ensuring security is a top priority
- Provide input to the monthly IT Security report.
Who You Are:
Essential
- 5+ years of experience in a security engineering/architecture or cybersecurity leadership role, with a strong focus on Microsoft environments such as Microsoft 365, Azure, Microsoft Purview, and related Microsoft security products.
- Proven track record in leading security engineering/architecture teams, managing risk, design and build security principles for products (e.g. Microsoft 365, Microsoft Azure, Copilot, Microsoft Defender, Microsoft Sentinel).
- Experience of working in a diverse Global Company;
- Understanding of key network and infrastructure security solutions such as firewalls, SD-WAN, WAF, DDoS protection IPS, Web Proxy, etc.
- Excellent knowledge of security solutions and technologies including Network Firewalls, proxy technologies, EDR, SIEM (Sentinel);
- Understanding of SASE solutions and cloud-based service delivery of traditional security controls (e.g. content filtering, firewall)
- Knowledge of Intrusion detection/prevention systems (IDS/IPS/WAF) and vulnerability assessment tools (Nessus/Tenable.io/Qualys);
- Excellent knowledge of different threat scenarios, incident response and remediation techniques;
- Hands on experience of applying security by design across a Microsoft eco system.
- Knowledge of security technologies (encryption, data protection, permissions, privilege access etc.);
- Knowledge of applying CIS benchmark policies in Azure & O365;
- Experience with Security frameworks, ISO 27001, Cyber Essentials, NIST, PCI;
- Good working knowledge of Active Directory services, including reporting and auditing of Active Directory objects;
- Skilled in using scripting tools (PowerShell, MS CLI & VBS).
- Understand Incident Response, Cyber Kill Chain, Threat Modelling and pertinent Attack Vectors;
- Desirable qualifications, Microsoft Certified: Azure Security Engineer or Architect Associate, Microsoft Certified: Security, Compliance, and Identity Fundamentals, Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), CompTIA Security+, Certified Cloud Security Professional (CCSP) or other similar security certifications or demonstratable experience.
- Good communication (English Writing, Reading and Speaking) skills and ability to articulate subjects clearly.
- Proven analytical and problem-solving skills;
- Strong documentation skills;
- Organized, methodical and self-motivated;
- Keeping abreast of industry trends and security technologies.
- Takes the initiative to proactively resolve issues within own remit and recognizes when escalation is required;
- Uses own knowledge and experience to make sounds judgements or assist others with sound judgements;
- Considers the regional and global implications of what we do in our own areas of responsibility;
- Identifies and builds relationships across team and region;
- Understands need to work within project scope, including price;
- Shows understanding of others in order to influence as appropriate.
- ICT jobs
Is this job a match or a miss?
Be The First To Know
About the latest Cybersecurity engineer Jobs in South Africa !
Senior SIEM Engineer (Cybersecurity Analyst)
Posted today
Job Viewed
Job Description
Job Purpose
- We are seeking a highly skilled and experienced Senior SIEM Engineer to lead and enhance our Security Information and Event Management (SIEM) capabilities. The ideal candidate will have deep expertise in Elastic and/or Splunk, strong Linux and scripting skills, and a solid understanding of Windows systems, firewalls, IPS, and EDR technologies. Experience in the financial sector, particularly banking, is highly desirable.
Job Responsibilities
- Design, implement, and maintain SIEM solutions (Elastic/Splunk) across enterprise environments.
- Develop and optimize detection rules, dashboards, and alerts for threat monitoring.
- Integrate diverse log sources including Windows, Linux, firewalls, IPS, and EDRs.
- Automate tasks using scripting languages (Bash, Python).
- Collaborate with incident response and threat intelligence teams to improve detection and response capabilities.
- Conduct regular health checks, performance tuning, and upgrades of SIEM infrastructure.
- Support compliance and audit requirements through log retention and reporting.
- Mentor junior engineers and contribute to capability development within the department.
- Write and maintain technical documentation for SIEM configurations, processes, and playbooks.
- Apply an automation-first mindset to streamline operations and reduce manual effort.
- Demonstrate strong attention to detail in rule creation, log analysis, and incident handling.
Essential Qualifications - NQF Level
- Diploma
- Advanced Diplomas/National 1st Degrees
Preferred Qualification
- Certifications such as GCIA, GCIH, Splunk Certified Architect, Elastic Certified Engineer, or similar.
- Exposure to regulatory frameworks (e.g., SARB, POPIA, PCI-DSS)
Preferred Certifications
- Relevant Information Security Certification
Required Skills & Experience
- 5+ years in cybersecurity operations or engineering roles.
- Proven experience with Sentinel, Elastic Stack (ELK) and/or Splunk Enterprise Security.
- Proficient in Linux administration and scripting (Bash, Python).
- Familiarity with Windows event logging, firewalls, IPS/IDS, and EDR platforms.
- Familiarity with different Cloud platforms.
- Experience in log ingestion, parsing, and normalization.
- Understanding of MITRE ATT&CK, threat detection frameworks, and incident response workflows is highly advantageous.
- Excellent problem-solving and communication skills.
- Experience with alert lifecycle management, data indexing, and case management is highly advantageous.
Technical / Professional Knowledge
- Administrative procedures and systems
- Data analysis
- Governance, Risk and Controls
- Principles of project management
- Relevant regulatory knowledge
- Relevant software and systems knowledge
- Cluster Specific Operational Knowledge
- System Development Life cycle(SDLC)
- TCP/IP
- Information Security terms and definitions
- Relevant Operating System
- Information Security policies and procedures
- Vendor Management Principles
Behavioural Competencies
- Applied Learning
- Communication
- Collaborating
- Customer Focus
- Initiating Action
- Managing Work
- Technical/Professional Knowledge and Skills
- ICT jobs
Is this job a match or a miss?
Information Security Manager
Posted today
Job Viewed
Job Description
- Who we're looking for: An experienced Information Security Manager to lead the implementation and ongoing maturity of our Information Security Management System (ISMS), ensure alignment with ISO 27001:2022, and manage risk across the business.
- The challenge: To own the ISMS documentation and audit programme, coordinate internal and external audits, oversee the risk register, and support internal teams on policy compliance and security awareness.
- Where you'll work: This role will be based in Cape Town, you'll be part of our global team, collaborating with colleagues and serving customers across the UK, USA, Australia, South Africa, and beyond. Our hybrid approach offers flexibility with regular team connection in our Cape Town office.
The Tillo Difference
We're in the business of rewards and incentives, so we know a thing or two about the importance of giving back. We can't grow as a business without growing as individuals, so we are committed to providing a workplace where passionate, driven individuals can thrive. We value collaboration, trust, positivity, and a willingness to learn - only by working as a team will we reach our goals.
We're the market leader in the UK and are active in a number of other markets including USA, Europe, Australia and India.
This role will be responsible for:
ISMS Ownership & Audit Readiness
Maintain and evolve the ISMS documentation and controls in line with ISO 27001:2022.
- Coordinate and lead internal audits (quarterly for TZ) and external certification audits.
- Write up audit findings and risk reports for SLT and the Board.
- Monitor ISMS KPIs and compliance metrics .
Risk Management
Own the company-wide risk register and associated documentation (excluding the risk framework itself).
- Support teams in identifying, assessing, and documenting risks.
- Track and ensure timely implementation of Risk Treatment Plans.
- Monitor and report on key risk metrics.
Incident & Corrective Action Management
Maintain the incident log, ensuring proper documentation, root cause analysis and closure.
- Drive corrective actions and improvements from internal/external audits and incidents.
Security Policy & Training
Maintain and develop ISO 27001-compliant security policies (non-Engineering).
- Coordinate business-wide security awareness training (e.g., KnowBe4).
- Champion InfoSec awareness and lead monthly security meetings.
Client & Vendor Security Assurance
Complete InfoSec and risk sections of client due diligence questionnaires.
- Support the development of a Trust Centre to streamline security responses.
What we're looking for
- 3+ years in an Information Security or Risk Management role with experience in ISO 27001 implementation and audits.
- A strong understanding of risk frameworks, internal controls, and compliance management.
- Experience with audit coordination and ISMS documentation.
- The ability to translate technical and regulatory language into business-friendly advice.
- Working knowledge of privacy, AML, and business continuity requirements.
- Familiarity with InfoSec tooling (e.g., Drata, Vanta, KnowBe4).
- Exceptional communication, reporting and organisational skills.
Benefits
We offer all our employees trust and empower our team to work with flexibility and autonomy. We're a close-knit team and love working collaboratively, with our hybrid model, our team can come together at our fantastic offices, but also focus in their own space. The Tillo team are a motivated bunch and we all work hard to push Tillo forwards, always innovating. We completely understand the importance of work/life balance and offer a supportive and collaborative working environment with the following benefits:
- 21 days holiday per annum
- Retirement Fund (5%)
- Health insurance contribution
- Employee Incentive Scheme
- Hybrid Working
- Top spec equipment including laptop, mouse, keyboard, monitor
- Anniversary gifts
- Monthly breakfasts, drinks, snacks and events
- Team Learning & Development budget
Tillo makes gift cards, rewards, and incentives simple, efficient, and profitable. Operating in over 37 markets and 25 currencies, Tillo processes billions in gift card transactions through a single, plug-and-go API, powering rewards and incentives for the world's leading businesses.
Backed by Tenzing, Tillo is setting the global standard for digital gift card infrastructure.
Diversity, Equity, and Inclusion Statement
We are committed to fostering a diverse and inclusive workplace where everyone feels valued and respected. We welcome applications from individuals of all backgrounds, regardless of age, disability, gender identity, marital status, race, ethnicity, religion or belief, sex, or sexual orientation.
If you require any reasonable adjustments during the recruitment process, please let us know, and we will be happy to accommodate your needs.
Is this job a match or a miss?
Information Security Specialist
Posted today
Job Viewed
Job Description
We're Hiring: Information Security Specialist
Company Description
Welcome to JNS Cloud Solutions, where innovation meets excellence in web design and development, SharePoint services, and ICT resourcing. Our comprehensive suite of services is designed to elevate businesses through managed IT services, strategic professional insights, and dedicated quality assurance. We also offer Office 365 solutions, data strategy consulting, application migration & development, and AI-powered transformation to stay ahead in the digital landscape.
Role Description
We are looking for an Information Security Specialist for a contract role in the Johannesburg Metropolitan Area with some work from home flexibility. The Information Security Specialist will be responsible for ensuring the security of applications, managing cybersecurity protocols, and overseeing information security management operations. The role also involves maintaining data privacy and network security within the organization.
Qualifications
- Proficiency in Application Security
- Experience in Cybersecurity and Information Security Management
- Knowledge in Data Privacy practices
- Skills in Network Security management
- Strong analytical and problem-solving abilities
- Excellent written and verbal communication skills
- Ability to work independently and as part of a team
- Relevant industry certifications (e.g., CISSP, CISM) are a plus
Are you passionate about securing enterprise data during high-impact migrations?
Join our team to: Ensure
data encryption
during migration (in transit & at rest)
Perform
risk assessments
for SharePoint Online migration
Guarantee
compliance with security standards
Requirements
:
- Proven experience in
data security and compliance - Strong understanding of
ISO 27001
or equivalent standards - Experience with
SharePoint and Microsoft 365 environments
is a plus
Contract Duration: 30 months
Submit your
CV and project examples
to (Insert application email or link)
Be part of a team modernising one of South Africa's largest digital ecosystems.
CyberSecurity #InformationSecurity #SharePointMigration #Hiring #TenderOpportunity #JNSGroup #Eskom #DataProtection #InfosecJobsIs this job a match or a miss?