461 Information Security jobs in South Africa
Information Security Consultant Cape Town
Posted today
Job Viewed
Job Description
Our client, a leading financial services company, is seeking an Information Security Consultant to join their team on a permanent basis.
Responsibilities- Security Auditing
- Responsible for Security tools monitoring
- Network experience (TCP/IP, Firewalls, IPS, NAC)
- Operating System management and Hardening
- Anti-Virus System management and Configuration
- Logical Access Management
- Vulnerability Management
- Matric and an Information Technology diploma or degree qualification
- 4+ years experience
Salary Market Related
#J-18808-LjbffrArmed Response Security - Durban
Posted today
Job Viewed
Job Description
Icebolethu Group is an Authorised Financial Service Provider FSP45714 and a Level 1 BBBEE Contributor is South Africa's second largest Funeral Assurance Group. Winner of the Standard Bank KZN - Top Brand award for 2022 provides a centre of excellence and a leading provider of dignified burial solutions.
Icebolethu Security is currently in search of suitable candidate s to fill the position of a n Armed Response Security guard located in Durban . The position is available on a permanent basis within the Security company , a Division of Icebolethu Group .
JOB SUMMARYIcebolethu Group is looking for a competent Armed Response Security Guard to monitor , safe guard and undertake the surveillance of our premises and protection of our staff and visitors, resources and equipment. You will be responsible for detecting any suspicious behaviour and preventing vandalism, thefts or other criminal activities.
A n armed response security guard must be well-trained in surveillance and dealing with perpetrators. The ideal candidate will inspire respect and authority as well as possess a high level of observation. The ideal candidate will help the company in maintaining excellent working conditions by keeping our facilities safe and problem-free.
Minimum Qualifications:
• Matric • PSIRA registered • Fire-arm Competency / license in handgun , Shotgun or Rifle • Valid Driver’s License • Diploma in Security Management or equivalent (advantageous) • Computer literacy (Microsoft Office)Experience and Competencies required:
• 2 years minimum experience as a n Armed Response security guard or Security Officer • Knowledge of legal guidelines for area security and public safety • Report writing skills • Advanced / Defensive driving skills • Fire-arm Competency for handgun , Shotgun or Rifle • Physical health and fitness • Strong Communication Skills • Tech-savvy with experience in surveillance systems and Communication Equipment. • Trained in First Aid/BLS • Trained in self- defenseKey Performance Areas
• Patrol premises regularly to maintain order and establish presence • Monitor and authorize entrance of vehicles or people in the property • Secure all exits, doors and windows after end of operations • Check surveillance cameras periodically to identify disruptions or unlawful acts • Investigate people for suspicious activity or possessions • Respond to alarms by investigating and assessing the situation • Provide assistance to people in need • Apprehend and detain perpetrators according to legal protocol before arrival of authorities • Submit reports of daily surveillance activity and important occurrences • Remove wrongdoers or trespassers from the area #J-18808-LjbffrInformation Security Customer Engagement Specialist
Posted today
Job Viewed
Job Description
About the Business
LexisNexis Legal & Professional provides legal, regulatory, and business information and analytics that help customers increase their productivity, improve decision-making, achieve better outcomes, and advance the rule of law around the world. As a digital pioneer, the company was the first to bring legal and business information online with its Lexis and Nexis services.
About our Team
LexisNexis Legal & Professional, which serves customers in more than 150 countries with 11,800 employees worldwide, is part of RELX ( a global provider of information-based analytics and decision tools for professional and business customers. Our company has been a long-time leader in deploying AI and advanced technologies to the legal market to improve productivity and transform the overall business and practice of law, deploying ethical and powerful generative AI solutions with a flexible, multi-model approach that prioritizes using the best model from today’s top model creators for each individual legal use case. The company employs over 2,000 technologists, data scientists, and experts to develop, test, and validate solutions in line with RELX Responsible AI Principles (
About the Role
We are thrilled to announce an exciting opportunity to join our Information Security Customer Engagement team! Our team is dedicated to helping customers gain the confidence they need to buy and utilize our products. In this entry-level role, you will collaborate with senior security specialists to respond to security questionnaires and maintain our public Trust Center content.
Responsibilities
- As an Information Security Customer Engagement Specialist, you will:
- Respond to customer security questionnaires using a blend of knowledgebases, generative AI, and subject matter expertise.
- Create and maintain documentation for our public Trust Center, empowering customers to self-serve.
- Drive improvements to our knowledgebase through collaboration with product and technology colleagues.
- Provide regular metrics and reports to management, demonstrating overall trends and performance.
Qualifications
We are looking for candidates who:
- Have a basic understanding of information security principles, frameworks, and regulatory requirements.
- Are passionate about delivering positive customer experiences and outcomes.
- Can manage multiple workloads simultaneously while waiting for input from others.
- Possess excellent verbal and written communication skills to effectively interact with customers and internal stakeholders, fostering transparency and trust.
- Have a growth mindset and eagerness to learn various information security topics and processes.
We welcome candidates from all backgrounds to apply and join our inclusive and diverse team. We value different perspectives and believe they contribute to our success.
Work in a way that works for you
We promote a healthy work/life balance across the organisation. We offer an appealing working prospect for our people. With numerous wellbeing initiatives, shared parental leave, study assistance and sabbaticals, we will help you meet your immediate responsibilities and your long-term goals.
Working Pattern
Working flexible hours - flexing the times when you work in the day to help you fit everything in and work when you are the most productive
We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact .
Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here .
Please read our Candidate Privacy Policy .
We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.
USA Job Seekers:
#J-18808-LjbffrSenior Network Security Engineer
Posted today
Job Viewed
Job Description
The purpose of this position is to plan, implement, monitor, and maintain robust network security measures that protect the integrity, confidentiality, and availability of CPUT’s information systems and infrastructure, while ensuring compliance with institutional policies and regulatory standards.
Job Knowledge, Skills and Experience
- A BTech in Information Technology or equivalent qualification
- At least 3-5 years’ experience in network security (firewalls, DNS layer security, MFA) Deployment, Configuration and Support / in CCNA / HCIA (International certified)
Key Performance Areas / Principal Accountabilities
- Network Security Architecture and Design
- Cybersecurity Monitoring and Incident Response
- Firewall and Perimeter Defense Management
- Vulnerability Management and Threat Mitigation
- Policy, Compliance, and Audit Support
- Security Awareness and Capacity Building
- Project Involvement and Strategic Input
To apply please use the link below: CPUT Talent Management - Senior Network Security Engineer
Closing date: 12 October
Penetration Tester (Security Analyst)
Posted today
Job Viewed
Job Description
ENVIRONMENT
A leading cybersecurity company based in Johannesburg is seeking a skilled and detail-oriented Red Team Penetration Tester /Security Analyst to join their dynamic team. The ideal candidate will have 2-5 years of hands-on experience in Penetration Testing, with a strong background in identifying and mitigating security vulnerabilities across various environments. This role involves conducting comprehensive security assessments, including but not limited to network, mobile, web, thick-client, wireless, social engineering, and physical penetration testing. The successful candidate will be responsible for analysing security risks, providing actionable recommendations, and collaborating with clients and internal teams to enhance overall cybersecurity posture. If you are passionate about ethical hacking, threat analysis, and proactive security measures, this is an excellent opportunity to grow your career in a fast-paced and innovative environment.
DUTIES Penetration Testing Duties- Work as part of a vulnerability assessment and /or penetration testing team, taking direction from line managers and executing directives in a thorough and timely fashion
- Conduct vulnerability assessments on a wide variety of technologies and implementations utilising both automated tools and manual techniques
- Conduct network penetration tests
- Conduct application penetration tests (web and thick client)
- Conduct wireless and mobile security assessments
- Conduct social engineering assessments
- Conduct physical security assessments
- Effectively communicate successes and obstacles with fellow team members and line managers
- Interface with client contact(s) and staff in a constructive and professional manner
- Develop subject matter expertise in topics to include network, database, wireless and application security assessments and adversarial network operations
- Utilise common vulnerability assessment and penetration testing tools
- Working as part of a Red Team and assisting with the following duties (but not limited to):
- Initial reconnaissance – open-source intelligence (OSINT) for collecting information on the targets
- Initial compromise – gaining a foothold into the target environment through targeting weaknesses in people, process and / or technology.
- Deploy command-and-control servers (C&C or C2) and custom payloads to establish communication / persistence in the target’s network.
- Develop tools, techniques and procedures to evade detection by blue team (including the development of custom payloads)
- Escalate privileges and maintain persistence
- Exfiltrate and / or complete objectives
- Research new vulnerabilities with a focus on high-profile products
- Understand the terminology and tactics employed by threat actors Research new attack methods
- Minimum 2-5 years of Penetration Testing experience required Including conducting different types of assessments, such as network, mobile, web, thick, wireless, social engineering, physical, etc.
- Previous Red Team experience required
Cyber Security Specialist
Posted today
Job Viewed
Job Description
Join to apply for the Cyber Security Specialist role at ExecutivePlacements.com - The JOB Portal
1 week ago Be among the first 25 applicants
Join to apply for the Cyber Security Specialist role at ExecutivePlacements.com - The JOB Portal
Get AI-powered advice on this job and more exclusive features.
SUMMARY:
Psybergate is an IT company that builds bespoke software solutions and provides highly skilled resources to its clients.
Cyber Security Specialist
Recruiter:
Penny The Recruiter
Job Ref:
PR /RN
Date posted:
Tuesday, June 24, 2025
Location:
Midrand, South Africa
Salary:
Monthly
SUMMARY:
Psybergate is an IT company that builds bespoke software solutions and provides highly skilled resources to its clients.
We are looking for a Cybersecurity Engineer to join our client based in JHB North.
An established AWS-driven technology solutions company is looking for a Cybersecurity Engineer who thrives in both technical execution and client-facing engagement. If you’re passionate about cloud security and enjoy designing and deploying secure environments for real clients, this role is for you. This is a 6-month Contract with the view to go perm.
POSITION INFO:
What you will be doing:
- Collaborate with the sales team as the technical security expert during pre-sales engagements.
- Conduct client workshops, requirements gathering, and security assessments.
- Design, present, and implement cloud-based security architectures on AWS.
- Configure and deploy AWS security services.
- Stay updated with AWS security trends and contribute to continuous improvement of offerings.
Technical Expertise
- 6+ years in IT security, with recent experience in cloud (AWS) security.
- Strong experience with AWS-native tools
- Familiarity with security benchmarks and frameworks (CIS, NIST, ISO 27001, etc.).
- Prior experience supporting pre-sales or working in a client-facing tech role.
- Excellent ability to explain technical solutions to both technical and non-technical audiences.
- Skilled in preparing diagrams, proposals, or solution documentation.
- AWS Security Specialty certification is a strong advantage.
- Other relevant certs like Security+, CEH, CISSP, etc. will be considered.
Seniority level
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Engineering and Information Technology
- Industries Advertising Services
Referrals increase your chances of interviewing at ExecutivePlacements.com - The JOB Portal by 2x
Sign in to set job alerts for “Cyber Security Specialist” roles.Johannesburg, Gauteng, South Africa 1 week ago
Johannesburg Metropolitan Area 2 days ago
Talent Pool: Information Security AdministratorJohannesburg Metropolitan Area 2 days ago
Johannesburg, Gauteng, South Africa 8 hours ago
Johannesburg, Gauteng, South Africa 3 days ago
Illovo, Gauteng, South Africa 1 month ago
Johannesburg, Gauteng, South Africa 1 week ago
Johannesburg Metropolitan Area 5 days ago
Johannesburg Metropolitan Area 1 week ago
Johannesburg, Gauteng, South Africa 2 months ago
IT, Network and Cybersecurity Support TechnicianJohannesburg, Gauteng, South Africa 1 week ago
Johannesburg, Gauteng, South Africa 1 week ago
Woodmead, Gauteng, South Africa 1 week ago
Johannesburg, Gauteng, South Africa 1 month ago
Messaging Security Analyst I (Threat Protection)Johannesburg, Gauteng, South Africa 5 days ago
Johannesburg, Gauteng, South Africa 7 months ago
Johannesburg, Gauteng, South Africa 4 days ago
Associate Messaging Security Analyst - Threat ProtectionJohannesburg, Gauteng, South Africa 5 days ago
Johannesburg, Gauteng, South Africa 1 week ago
Customer Success Engineer - Cyber Security Security Analyst - Penetration Testing & Red TeamingJohannesburg, Gauteng, South Africa 1 week ago
Johannesburg, Gauteng, South Africa 1 week ago
Randburg, Gauteng, South Africa 8 hours ago
Randburg, Gauteng, South Africa 8 hours ago
Illovo, Gauteng, South Africa 8 months ago
Associate Messaging Security Analyst - Threat ProtectionJohannesburg, Gauteng, South Africa 1 week ago
Johannesburg, Gauteng, South Africa 1 week ago
Johannesburg, Gauteng, South Africa 1 week ago
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrSenior Application Security Engineer
Posted today
Job Viewed
Job Description
Who we are
We're a leading, global security authority that's disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world's largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to the little things like surgically embedded pacemakers. We help companies put trust - an abstract idea - to work. That's digital trust for the real world.
Job summary
As a Senior Application Security Engineer specializing in application security and DevSecOps within our cybersecurity team, you will play a crucial role in safeguarding our company's web applications by integrating security practices into the Software Development Life Cycle (SDLC). You will be responsible for the proactive identification, assessment, and mitigation of security vulnerabilities, developing and driving the adoption of DevSecOps practices, and ensuring that security is embedded in all phases of software development.
This is a remote position.
What you will do
- Lead the integration of security measures into the SDLC, ensuring that all aspects of web application development are secure by design.
- Conduct thorough security assessments and penetration testing for web applications to identify vulnerabilities and security gaps.
- Play an advisory role with software engineering teams in the architectural design of new applications, emphasizing secure architectural patterns and best practices.
- Perform and coordinate manual and automated code reviews.
- Lead threat modeling exercises across engineering teams.
- Collaborate with software development teams to implement DevSecOps practices, providing guidance on secure coding, automated security testing, and continuous monitoring.
- Contribute to internal security tooling development or integration.
- Develop and maintain a secure framework for code deployment, automating security processes where possible to streamline the development workflow.
- Work cross-functionally with various teams, including IT, engineering, operations, and business units, to communicate security policies and procedures effectively.
- Establish and maintain strong relationships with stakeholders, presenting complex security concepts in an accessible manner.
- Stay abreast of the latest security threats, trends, and technologies in web application security and incorporate this knowledge into company practices.
- Assist in the development and enforcement of security policies and procedures, ensuring compliance with industry standards and regulations.
- Assist with managing bug bounty program.
- Develop program documentation to promote operational stability and scalability.
- Support Leadership in defining and executing the roadmap for DevSecOps maturity and secure SDLC initiatives.
- Support governance and compliance teams on secure engineering practices for aligning security policies related to SDLC
- Drive and support security identified remediation efforts.
- Foster and promote a security-forward culture.
- Mentor junior team members.
- Other duties and responsibilities, as assigned.
What you will have
- Bachelor’s or master’s degree in computer science, cybersecurity, or a related field.
- Professional security certifications such as CISSP, OSCP, CEH, or equivalent are highly desirable.
- 5+ years of experience in cybersecurity, with a focus on web application security and secure SDLC.
- Experience with red team implementation and methodologies.
- Proven track record of working with DevSecOps tools (such as SAST/DAST/SCA) and methodologies.
- Strong understanding of security protocols, cryptography, authentication, authorization, and security vulnerabilities.
- Proficiency with programming/scripting languages such as JavaScript, Python, Java, Bash, PowerShell
- Excellent communication skills with the ability to engage technical and non-technical stakeholders.
- Strong analytical and problem-solving abilities, with a meticulous attention to detail.
- Advanced level of knowledge of Information Security design concepts and principles
Nice to have
- Master's degree in a technical discipline
- Experience working in highly regulated environments.
- Advanced level of knowledge of IT frameworks and standards (NIST, OWASP Top Ten, COBIT, ITIL, ISO, PCI-PIN, GDPR, WebTrust, FedRAMP)
- Certified Information Systems Auditor (CISA)
- AWS Solutions Architect
Benefits
- Provident Fund
- Medical Aid + Gap Cover
- Employee Assistance Program
- Gym Reimbursement
- Life Insurance
- Disability Insurance
- Sabbatical
#LI-GA1
__PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT
__PRESENT __PRESENT
#J-18808-LjbffrBe The First To Know
About the latest Information security Jobs in South Africa !
Senior Application Security Engineer
Posted today
Job Viewed
Job Description
Who we are
We're a leading, global security authority that's disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world's largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to the little things like surgically embedded pacemakers. We help companies put trust - an abstract idea - to work. That's digital trust for the real world.
Job summary
As a Senior Application Security Engineer specializing in application security and DevSecOps within our cybersecurity team, you will play a crucial role in safeguarding our company's web applications by integrating security practices into the Software Development Life Cycle (SDLC). You will be responsible for the proactive identification, assessment, and mitigation of security vulnerabilities, developing and driving the adoption of DevSecOps practices, and ensuring that security is embedded in all phases of software development.
This is a remote position.
What you will do
- Lead the integration of security measures into the SDLC, ensuring that all aspects of web application development are secure by design.
- Conduct thorough security assessments and penetration testing for web applications to identify vulnerabilities and security gaps.
- Play an advisory role with software engineering teams in the architectural design of new applications, emphasizing secure architectural patterns and best practices.
- Perform and coordinate manual and automated code reviews.
- Lead threat modeling exercises across engineering teams.
- Collaborate with software development teams to implement DevSecOps practices, providing guidance on secure coding, automated security testing, and continuous monitoring.
- Contribute to internal security tooling development or integration.
- Develop and maintain a secure framework for code deployment, automating security processes where possible to streamline the development workflow.
- Work cross-functionally with various teams, including IT, engineering, operations, and business units, to communicate security policies and procedures effectively.
- Establish and maintain strong relationships with stakeholders, presenting complex security concepts in an accessible manner.
- Stay abreast of the latest security threats, trends, and technologies in web application security and incorporate this knowledge into company practices.
- Assist in the development and enforcement of security policies and procedures, ensuring compliance with industry standards and regulations.
- Assist with managing bug bounty program.
- Develop program documentation to promote operational stability and scalability.
- Support Leadership in defining and executing the roadmap for DevSecOps maturity and secure SDLC initiatives.
- Support governance and compliance teams on secure engineering practices for aligning security policies related to SDLC
- Drive and support security identified remediation efforts.
- Foster and promote a security-forward culture.
- Mentor junior team members.
- Other duties and responsibilities, as assigned.
What you will have
- Bachelor’s or master’s degree in computer science, cybersecurity, or a related field.
- Professional security certifications such as CISSP, OSCP, CEH, or equivalent are highly desirable.
- 5+ years of experience in cybersecurity, with a focus on web application security and secure SDLC.
- Experience with red team implementation and methodologies.
- Proven track record of working with DevSecOps tools (such as SAST/DAST/SCA) and methodologies.
- Strong understanding of security protocols, cryptography, authentication, authorization, and security vulnerabilities.
- Proficiency with programming/scripting languages such as JavaScript, Python, Java, Bash, PowerShell
- Excellent communication skills with the ability to engage technical and non-technical stakeholders.
- Strong analytical and problem-solving abilities, with a meticulous attention to detail.
- Advanced level of knowledge of Information Security design concepts and principles
Nice to have
- Master's degree in a technical discipline
- Experience working in highly regulated environments.
- Advanced level of knowledge of IT frameworks and standards (NIST, OWASP Top Ten, COBIT, ITIL, ISO, PCI-PIN, GDPR, WebTrust, FedRAMP)
- Certified Information Systems Auditor (CISA)
- AWS Solutions Architect
Benefits
- Provident Fund
- Medical Aid + Gap Cover
- Employee Assistance Program
- Gym Reimbursement
- Life Insurance
- Disability Insurance
- Sabbatical
#LI-GA1
__PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT
__PRESENT __PRESENT
#J-18808-LjbffrSenior Application Security Engineer
Posted today
Job Viewed
Job Description
Who we are
We're a leading, global security authority that's disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world's largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to the little things like surgically embedded pacemakers. We help companies put trust - an abstract idea - to work. That's digital trust for the real world.
Job summary
As a Senior Application Security Engineer specializing in application security and DevSecOps within our cybersecurity team, you will play a crucial role in safeguarding our company's web applications by integrating security practices into the Software Development Life Cycle (SDLC). You will be responsible for the proactive identification, assessment, and mitigation of security vulnerabilities, developing and driving the adoption of DevSecOps practices, and ensuring that security is embedded in all phases of software development.
This is a remote position.
What you will do
- Lead the integration of security measures into the SDLC, ensuring that all aspects of web application development are secure by design.
- Conduct thorough security assessments and penetration testing for web applications to identify vulnerabilities and security gaps.
- Play an advisory role with software engineering teams in the architectural design of new applications, emphasizing secure architectural patterns and best practices.
- Perform and coordinate manual and automated code reviews.
- Lead threat modeling exercises across engineering teams.
- Collaborate with software development teams to implement DevSecOps practices, providing guidance on secure coding, automated security testing, and continuous monitoring.
- Contribute to internal security tooling development or integration.
- Develop and maintain a secure framework for code deployment, automating security processes where possible to streamline the development workflow.
- Work cross-functionally with various teams, including IT, engineering, operations, and business units, to communicate security policies and procedures effectively.
- Establish and maintain strong relationships with stakeholders, presenting complex security concepts in an accessible manner.
- Stay abreast of the latest security threats, trends, and technologies in web application security and incorporate this knowledge into company practices.
- Assist in the development and enforcement of security policies and procedures, ensuring compliance with industry standards and regulations.
- Assist with managing bug bounty program.
- Develop program documentation to promote operational stability and scalability.
- Support Leadership in defining and executing the roadmap for DevSecOps maturity and secure SDLC initiatives.
- Support governance and compliance teams on secure engineering practices for aligning security policies related to SDLC
- Drive and support security identified remediation efforts.
- Foster and promote a security-forward culture.
- Mentor junior team members.
- Other duties and responsibilities, as assigned.
What you will have
- Bachelor’s or master’s degree in computer science, cybersecurity, or a related field.
- Professional security certifications such as CISSP, OSCP, CEH, or equivalent are highly desirable.
- 5+ years of experience in cybersecurity, with a focus on web application security and secure SDLC.
- Experience with red team implementation and methodologies.
- Proven track record of working with DevSecOps tools (such as SAST/DAST/SCA) and methodologies.
- Strong understanding of security protocols, cryptography, authentication, authorization, and security vulnerabilities.
- Proficiency with programming/scripting languages such as JavaScript, Python, Java, Bash, PowerShell
- Excellent communication skills with the ability to engage technical and non-technical stakeholders.
- Strong analytical and problem-solving abilities, with a meticulous attention to detail.
- Advanced level of knowledge of Information Security design concepts and principles
Nice to have
- Master's degree in a technical discipline
- Experience working in highly regulated environments.
- Advanced level of knowledge of IT frameworks and standards (NIST, OWASP Top Ten, COBIT, ITIL, ISO, PCI-PIN, GDPR, WebTrust, FedRAMP)
- Certified Information Systems Auditor (CISA)
- AWS Solutions Architect
Benefits
- Provident Fund
- Medical Aid + Gap Cover
- Employee Assistance Program
- Gym Reimbursement
- Life Insurance
- Disability Insurance
- Sabbatical
#LI-GA1
__PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT
__PRESENT __PRESENT
#J-18808-LjbffrSenior Application Security Engineer
Posted today
Job Viewed
Job Description
Who we are
We're a leading, global security authority that's disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world's largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to the little things like surgically embedded pacemakers. We help companies put trust - an abstract idea - to work. That's digital trust for the real world.
Job summary
As a Senior Application Security Engineer specializing in application security and DevSecOps within our cybersecurity team, you will play a crucial role in safeguarding our company's web applications by integrating security practices into the Software Development Life Cycle (SDLC). You will be responsible for the proactive identification, assessment, and mitigation of security vulnerabilities, developing and driving the adoption of DevSecOps practices, and ensuring that security is embedded in all phases of software development.
This is a remote position.
What you will do
- Lead the integration of security measures into the SDLC, ensuring that all aspects of web application development are secure by design.
- Conduct thorough security assessments and penetration testing for web applications to identify vulnerabilities and security gaps.
- Play an advisory role with software engineering teams in the architectural design of new applications, emphasizing secure architectural patterns and best practices.
- Perform and coordinate manual and automated code reviews.
- Lead threat modeling exercises across engineering teams.
- Collaborate with software development teams to implement DevSecOps practices, providing guidance on secure coding, automated security testing, and continuous monitoring.
- Contribute to internal security tooling development or integration.
- Develop and maintain a secure framework for code deployment, automating security processes where possible to streamline the development workflow.
- Work cross-functionally with various teams, including IT, engineering, operations, and business units, to communicate security policies and procedures effectively.
- Establish and maintain strong relationships with stakeholders, presenting complex security concepts in an accessible manner.
- Stay abreast of the latest security threats, trends, and technologies in web application security and incorporate this knowledge into company practices.
- Assist in the development and enforcement of security policies and procedures, ensuring compliance with industry standards and regulations.
- Assist with managing bug bounty program.
- Develop program documentation to promote operational stability and scalability.
- Support Leadership in defining and executing the roadmap for DevSecOps maturity and secure SDLC initiatives.
- Support governance and compliance teams on secure engineering practices for aligning security policies related to SDLC
- Drive and support security identified remediation efforts.
- Foster and promote a security-forward culture.
- Mentor junior team members.
- Other duties and responsibilities, as assigned.
What you will have
- Bachelor’s or master’s degree in computer science, cybersecurity, or a related field.
- Professional security certifications such as CISSP, OSCP, CEH, or equivalent are highly desirable.
- 5+ years of experience in cybersecurity, with a focus on web application security and secure SDLC.
- Experience with red team implementation and methodologies.
- Proven track record of working with DevSecOps tools (such as SAST/DAST/SCA) and methodologies.
- Strong understanding of security protocols, cryptography, authentication, authorization, and security vulnerabilities.
- Proficiency with programming/scripting languages such as JavaScript, Python, Java, Bash, PowerShell
- Excellent communication skills with the ability to engage technical and non-technical stakeholders.
- Strong analytical and problem-solving abilities, with a meticulous attention to detail.
- Advanced level of knowledge of Information Security design concepts and principles
Nice to have
- Master's degree in a technical discipline
- Experience working in highly regulated environments.
- Advanced level of knowledge of IT frameworks and standards (NIST, OWASP Top Ten, COBIT, ITIL, ISO, PCI-PIN, GDPR, WebTrust, FedRAMP)
- Certified Information Systems Auditor (CISA)
- AWS Solutions Architect
Benefits
- Provident Fund
- Medical Aid + Gap Cover
- Employee Assistance Program
- Gym Reimbursement
- Life Insurance
- Disability Insurance
- Sabbatical
#LI-GA1
__PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT
__PRESENT __PRESENT
#J-18808-Ljbffr