461 Information Security jobs in South Africa

Information Security Consultant Cape Town

Cape Town, Western Cape iLaunch (Pty) Ltd

Posted today

Job Viewed

Tap Again To Close

Job Description

Job Description

Our client, a leading financial services company, is seeking an Information Security Consultant to join their team on a permanent basis.

Responsibilities
  • Security Auditing
  • Responsible for Security tools monitoring
  • Network experience (TCP/IP, Firewalls, IPS, NAC)
  • Operating System management and Hardening
  • Anti-Virus System management and Configuration
  • Logical Access Management
  • Vulnerability Management
Minimum Requirements
  • Matric and an Information Technology diploma or degree qualification
  • 4+ years experience
Package & Remuneration

Salary Market Related

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Armed Response Security - Durban

Durban, KwaZulu Natal Icebolethu

Posted today

Job Viewed

Tap Again To Close

Job Description

Icebolethu Group is an Authorised Financial Service Provider FSP45714 and a Level 1 BBBEE Contributor is South Africa's second largest Funeral Assurance Group. Winner of the Standard Bank KZN - Top Brand award for 2022 provides a centre of excellence and a leading provider of dignified burial solutions.

Icebolethu Security is currently in search of suitable candidate s to fill the position of a n Armed Response Security guard located in Durban . The position is available on a permanent basis within the Security company , a Division of Icebolethu Group .

JOB SUMMARY

Icebolethu Group is looking for a competent Armed Response Security Guard to monitor , safe guard and undertake the surveillance of our premises and protection of our staff and visitors, resources and equipment. You will be responsible for detecting any suspicious behaviour and preventing vandalism, thefts or other criminal activities.

A n armed response security guard must be well-trained in surveillance and dealing with perpetrators. The ideal candidate will inspire respect and authority as well as possess a high level of observation. The ideal candidate will help the company in maintaining excellent working conditions by keeping our facilities safe and problem-free.

Minimum Qualifications:

• Matric • PSIRA registered • Fire-arm Competency / license in handgun , Shotgun or Rifle • Valid Driver’s License • Diploma in Security Management or equivalent (advantageous) • Computer literacy (Microsoft Office)

Experience and Competencies required:

• 2 years minimum experience as a n Armed Response security guard or Security Officer • Knowledge of legal guidelines for area security and public safety • Report writing skills • Advanced / Defensive driving skills • Fire-arm Competency for handgun , Shotgun or Rifle • Physical health and fitness • Strong Communication Skills • Tech-savvy with experience in surveillance systems and Communication Equipment. • Trained in First Aid/BLS • Trained in self- defense

Key Performance Areas

• Patrol premises regularly to maintain order and establish presence • Monitor and authorize entrance of vehicles or people in the property • Secure all exits, doors and windows after end of operations • Check surveillance cameras periodically to identify disruptions or unlawful acts • Investigate people for suspicious activity or possessions • Respond to alarms by investigating and assessing the situation • Provide assistance to people in need • Apprehend and detain perpetrators according to legal protocol before arrival of authorities • Submit reports of daily surveillance activity and important occurrences • Remove wrongdoers or trespassers from the area #J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Information Security Customer Engagement Specialist

Western Cape, Western Cape RELX

Posted today

Job Viewed

Tap Again To Close

Job Description

workfromhome

About the Business

LexisNexis Legal & Professional provides legal, regulatory, and business information and analytics that help customers increase their productivity, improve decision-making, achieve better outcomes, and advance the rule of law around the world. As a digital pioneer, the company was the first to bring legal and business information online with its Lexis and Nexis services.

About our Team

LexisNexis Legal & Professional, which serves customers in more than 150 countries with 11,800 employees worldwide, is part of RELX ( a global provider of information-based analytics and decision tools for professional and business customers. Our company has been a long-time leader in deploying AI and advanced technologies to the legal market to improve productivity and transform the overall business and practice of law, deploying ethical and powerful generative AI solutions with a flexible, multi-model approach that prioritizes using the best model from today’s top model creators for each individual legal use case. The company employs over 2,000 technologists, data scientists, and experts to develop, test, and validate solutions in line with RELX Responsible AI Principles (

About the Role

We are thrilled to announce an exciting opportunity to join our Information Security Customer Engagement team! Our team is dedicated to helping customers gain the confidence they need to buy and utilize our products. In this entry-level role, you will collaborate with senior security specialists to respond to security questionnaires and maintain our public Trust Center content.

Responsibilities

  • As an Information Security Customer Engagement Specialist, you will:
  • Respond to customer security questionnaires using a blend of knowledgebases, generative AI, and subject matter expertise.
  • Create and maintain documentation for our public Trust Center, empowering customers to self-serve.
  • Drive improvements to our knowledgebase through collaboration with product and technology colleagues.
  • Provide regular metrics and reports to management, demonstrating overall trends and performance.

Qualifications

We are looking for candidates who:

  • Have a basic understanding of information security principles, frameworks, and regulatory requirements.
  • Are passionate about delivering positive customer experiences and outcomes.
  • Can manage multiple workloads simultaneously while waiting for input from others.
  • Possess excellent verbal and written communication skills to effectively interact with customers and internal stakeholders, fostering transparency and trust.
  • Have a growth mindset and eagerness to learn various information security topics and processes.

We welcome candidates from all backgrounds to apply and join our inclusive and diverse team. We value different perspectives and believe they contribute to our success.

Work in a way that works for you

We promote a healthy work/life balance across the organisation. We offer an appealing working prospect for our people. With numerous wellbeing initiatives, shared parental leave, study assistance and sabbaticals, we will help you meet your immediate responsibilities and your long-term goals.

Working Pattern

Working flexible hours - flexing the times when you work in the day to help you fit everything in and work when you are the most productive

We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact .

Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here .

Please read our Candidate Privacy Policy .

We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.

USA Job Seekers:

EEO Know Your Rights .

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Senior Network Security Engineer

Cape Peninsula University of Technology

Posted today

Job Viewed

Tap Again To Close

Job Description

The purpose of this position is to plan, implement, monitor, and maintain robust network security measures that protect the integrity, confidentiality, and availability of CPUT’s information systems and infrastructure, while ensuring compliance with institutional policies and regulatory standards.

Job Knowledge, Skills and Experience

  • A BTech in Information Technology or equivalent qualification
  • At least 3-5 years’ experience in network security (firewalls, DNS layer security, MFA) Deployment, Configuration and Support / in CCNA / HCIA (International certified)

Key Performance Areas / Principal Accountabilities

  • Network Security Architecture and Design
  • Cybersecurity Monitoring and Incident Response
  • Firewall and Perimeter Defense Management
  • Vulnerability Management and Threat Mitigation
  • Policy, Compliance, and Audit Support
  • Security Awareness and Capacity Building
  • Project Involvement and Strategic Input
please contact Mr Odwa Siza, (Human Capital Department) email:

To apply please use the link below: CPUT Talent Management - Senior Network Security Engineer

Closing date: 12 October

#J-18808-Ljbffr

This advertiser has chosen not to accept applicants from your region.

Penetration Tester (Security Analyst)

Johannesburg, Gauteng DataFin

Posted today

Job Viewed

Tap Again To Close

Job Description

ENVIRONMENT

A leading cybersecurity company based in Johannesburg is seeking a skilled and detail-oriented Red Team Penetration Tester /Security Analyst to join their dynamic team. The ideal candidate will have 2-5 years of hands-on experience in Penetration Testing, with a strong background in identifying and mitigating security vulnerabilities across various environments. This role involves conducting comprehensive security assessments, including but not limited to network, mobile, web, thick-client, wireless, social engineering, and physical penetration testing. The successful candidate will be responsible for analysing security risks, providing actionable recommendations, and collaborating with clients and internal teams to enhance overall cybersecurity posture. If you are passionate about ethical hacking, threat analysis, and proactive security measures, this is an excellent opportunity to grow your career in a fast-paced and innovative environment.

DUTIES Penetration Testing Duties
  • Work as part of a vulnerability assessment and /or penetration testing team, taking direction from line managers and executing directives in a thorough and timely fashion
  • Conduct vulnerability assessments on a wide variety of technologies and implementations utilising both automated tools and manual techniques
  • Conduct network penetration tests
  • Conduct application penetration tests (web and thick client)
  • Conduct wireless and mobile security assessments
  • Conduct social engineering assessments
  • Conduct physical security assessments
  • Effectively communicate successes and obstacles with fellow team members and line managers
  • Interface with client contact(s) and staff in a constructive and professional manner
  • Develop subject matter expertise in topics to include network, database, wireless and application security assessments and adversarial network operations
  • Utilise common vulnerability assessment and penetration testing tools
Red Teaming Duties
  • Working as part of a Red Team and assisting with the following duties (but not limited to):
  • Initial reconnaissance – open-source intelligence (OSINT) for collecting information on the targets
  • Initial compromise – gaining a foothold into the target environment through targeting weaknesses in people, process and / or technology.
  • Deploy command-and-control servers (C&C or C2) and custom payloads to establish communication / persistence in the target’s network.
  • Develop tools, techniques and procedures to evade detection by blue team (including the development of custom payloads)
  • Escalate privileges and maintain persistence
  • Exfiltrate and / or complete objectives
Research and Development Duties
  • Research new vulnerabilities with a focus on high-profile products
  • Understand the terminology and tactics employed by threat actors Research new attack methods
REQUIREMENTS
  • Minimum 2-5 years of Penetration Testing experience required Including conducting different types of assessments, such as network, mobile, web, thick, wireless, social engineering, physical, etc.
  • Previous Red Team experience required

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Cyber Security Specialist

Midrand, Gauteng ExecutivePlacements.com - The JOB Portal

Posted today

Job Viewed

Tap Again To Close

Job Description

Join to apply for the Cyber Security Specialist role at ExecutivePlacements.com - The JOB Portal

1 week ago Be among the first 25 applicants

Join to apply for the Cyber Security Specialist role at ExecutivePlacements.com - The JOB Portal

Get AI-powered advice on this job and more exclusive features.

SUMMARY:

Psybergate is an IT company that builds bespoke software solutions and provides highly skilled resources to its clients.

Cyber Security Specialist

Recruiter:

Penny The Recruiter

Job Ref:

PR /RN

Date posted:

Tuesday, June 24, 2025

Location:

Midrand, South Africa

Salary:

Monthly

SUMMARY:

Psybergate is an IT company that builds bespoke software solutions and provides highly skilled resources to its clients.

We are looking for a Cybersecurity Engineer to join our client based in JHB North.

An established AWS-driven technology solutions company is looking for a Cybersecurity Engineer who thrives in both technical execution and client-facing engagement. If you’re passionate about cloud security and enjoy designing and deploying secure environments for real clients, this role is for you. This is a 6-month Contract with the view to go perm.

POSITION INFO:

What you will be doing:

  • Collaborate with the sales team as the technical security expert during pre-sales engagements.
  • Conduct client workshops, requirements gathering, and security assessments.
  • Design, present, and implement cloud-based security architectures on AWS.
  • Configure and deploy AWS security services.
  • Stay updated with AWS security trends and contribute to continuous improvement of offerings.

What we are looking for :

Technical Expertise

  • 6+ years in IT security, with recent experience in cloud (AWS) security.
  • Strong experience with AWS-native tools
  • Familiarity with security benchmarks and frameworks (CIS, NIST, ISO 27001, etc.).

Consulting/Pre-Sales Skills

  • Prior experience supporting pre-sales or working in a client-facing tech role.
  • Excellent ability to explain technical solutions to both technical and non-technical audiences.
  • Skilled in preparing diagrams, proposals, or solution documentation.

Certifications

  • AWS Security Specialty certification is a strong advantage.
  • Other relevant certs like Security+, CEH, CISSP, etc. will be considered.

Please note that if you do not hear from us within 3 weeks, consider your application unsuccessful.



Seniority level
  • Seniority level Mid-Senior level
Employment type
  • Employment type Full-time
Job function
  • Job function Engineering and Information Technology
  • Industries Advertising Services

Referrals increase your chances of interviewing at ExecutivePlacements.com - The JOB Portal by 2x

Sign in to set job alerts for “Cyber Security Specialist” roles.

Johannesburg, Gauteng, South Africa 1 week ago

Johannesburg Metropolitan Area 2 days ago

Talent Pool: Information Security Administrator

Johannesburg Metropolitan Area 2 days ago

Johannesburg, Gauteng, South Africa 8 hours ago

Johannesburg, Gauteng, South Africa 3 days ago

Illovo, Gauteng, South Africa 1 month ago

Johannesburg, Gauteng, South Africa 1 week ago

Johannesburg Metropolitan Area 5 days ago

Johannesburg Metropolitan Area 1 week ago

Johannesburg, Gauteng, South Africa 2 months ago

IT, Network and Cybersecurity Support Technician

Johannesburg, Gauteng, South Africa 1 week ago

Johannesburg, Gauteng, South Africa 1 week ago

Woodmead, Gauteng, South Africa 1 week ago

Johannesburg, Gauteng, South Africa 1 month ago

Messaging Security Analyst I (Threat Protection)

Johannesburg, Gauteng, South Africa 5 days ago

Johannesburg, Gauteng, South Africa 7 months ago

Johannesburg, Gauteng, South Africa 4 days ago

Associate Messaging Security Analyst - Threat Protection

Johannesburg, Gauteng, South Africa 5 days ago

Johannesburg, Gauteng, South Africa 1 week ago

Customer Success Engineer - Cyber Security Security Analyst - Penetration Testing & Red Teaming

Johannesburg, Gauteng, South Africa 1 week ago

Johannesburg, Gauteng, South Africa 1 week ago

Randburg, Gauteng, South Africa 8 hours ago

Randburg, Gauteng, South Africa 8 hours ago

Illovo, Gauteng, South Africa 8 months ago

Associate Messaging Security Analyst - Threat Protection

Johannesburg, Gauteng, South Africa 1 week ago

Johannesburg, Gauteng, South Africa 1 week ago

Johannesburg, Gauteng, South Africa 1 week ago

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Senior Application Security Engineer

DigiCert

Posted today

Job Viewed

Tap Again To Close

Job Description

workfromhome

Who we are

We're a leading, global security authority that's disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world's largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to the little things like surgically embedded pacemakers. We help companies put trust - an abstract idea - to work. That's digital trust for the real world.

Job summary

As a Senior Application Security Engineer specializing in application security and DevSecOps within our cybersecurity team, you will play a crucial role in safeguarding our company's web applications by integrating security practices into the Software Development Life Cycle (SDLC). You will be responsible for the proactive identification, assessment, and mitigation of security vulnerabilities, developing and driving the adoption of DevSecOps practices, and ensuring that security is embedded in all phases of software development.

This is a remote position.

What you will do

  • Lead the integration of security measures into the SDLC, ensuring that all aspects of web application development are secure by design.
  • Conduct thorough security assessments and penetration testing for web applications to identify vulnerabilities and security gaps.
  • Play an advisory role with software engineering teams in the architectural design of new applications, emphasizing secure architectural patterns and best practices.
  • Perform and coordinate manual and automated code reviews.
  • Lead threat modeling exercises across engineering teams.
  • Collaborate with software development teams to implement DevSecOps practices, providing guidance on secure coding, automated security testing, and continuous monitoring.
  • Contribute to internal security tooling development or integration.
  • Develop and maintain a secure framework for code deployment, automating security processes where possible to streamline the development workflow.
  • Work cross-functionally with various teams, including IT, engineering, operations, and business units, to communicate security policies and procedures effectively.
  • Establish and maintain strong relationships with stakeholders, presenting complex security concepts in an accessible manner.
  • Stay abreast of the latest security threats, trends, and technologies in web application security and incorporate this knowledge into company practices.
  • Assist in the development and enforcement of security policies and procedures, ensuring compliance with industry standards and regulations.
  • Assist with managing bug bounty program.
  • Develop program documentation to promote operational stability and scalability.
  • Support Leadership in defining and executing the roadmap for DevSecOps maturity and secure SDLC initiatives.
  • Support governance and compliance teams on secure engineering practices for aligning security policies related to SDLC
  • Drive and support security identified remediation efforts.
  • Foster and promote a security-forward culture.
  • Mentor junior team members.
  • Other duties and responsibilities, as assigned.

What you will have

  • Bachelor’s or master’s degree in computer science, cybersecurity, or a related field.
  • Professional security certifications such as CISSP, OSCP, CEH, or equivalent are highly desirable.
  • 5+ years of experience in cybersecurity, with a focus on web application security and secure SDLC.
  • Experience with red team implementation and methodologies.
  • Proven track record of working with DevSecOps tools (such as SAST/DAST/SCA) and methodologies.
  • Strong understanding of security protocols, cryptography, authentication, authorization, and security vulnerabilities.
  • Proficiency with programming/scripting languages such as JavaScript, Python, Java, Bash, PowerShell
  • Excellent communication skills with the ability to engage technical and non-technical stakeholders.
  • Strong analytical and problem-solving abilities, with a meticulous attention to detail.
  • Advanced level of knowledge of Information Security design concepts and principles

Nice to have

  • Master's degree in a technical discipline
  • Experience working in highly regulated environments.
  • Advanced level of knowledge of IT frameworks and standards (NIST, OWASP Top Ten, COBIT, ITIL, ISO, PCI-PIN, GDPR, WebTrust, FedRAMP)
  • Certified Information Systems Auditor (CISA)
  • AWS Solutions Architect

Benefits

  • Provident Fund
  • Medical Aid + Gap Cover
  • Employee Assistance Program
  • Gym Reimbursement
  • Life Insurance
  • Disability Insurance
  • Sabbatical

#LI-GA1

__PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT

__PRESENT __PRESENT

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.
Be The First To Know

About the latest Information security Jobs in South Africa !

Senior Application Security Engineer

DigiCert

Posted today

Job Viewed

Tap Again To Close

Job Description

workfromhome

Who we are

We're a leading, global security authority that's disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world's largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to the little things like surgically embedded pacemakers. We help companies put trust - an abstract idea - to work. That's digital trust for the real world.

Job summary

As a Senior Application Security Engineer specializing in application security and DevSecOps within our cybersecurity team, you will play a crucial role in safeguarding our company's web applications by integrating security practices into the Software Development Life Cycle (SDLC). You will be responsible for the proactive identification, assessment, and mitigation of security vulnerabilities, developing and driving the adoption of DevSecOps practices, and ensuring that security is embedded in all phases of software development.

This is a remote position.

What you will do

  • Lead the integration of security measures into the SDLC, ensuring that all aspects of web application development are secure by design.
  • Conduct thorough security assessments and penetration testing for web applications to identify vulnerabilities and security gaps.
  • Play an advisory role with software engineering teams in the architectural design of new applications, emphasizing secure architectural patterns and best practices.
  • Perform and coordinate manual and automated code reviews.
  • Lead threat modeling exercises across engineering teams.
  • Collaborate with software development teams to implement DevSecOps practices, providing guidance on secure coding, automated security testing, and continuous monitoring.
  • Contribute to internal security tooling development or integration.
  • Develop and maintain a secure framework for code deployment, automating security processes where possible to streamline the development workflow.
  • Work cross-functionally with various teams, including IT, engineering, operations, and business units, to communicate security policies and procedures effectively.
  • Establish and maintain strong relationships with stakeholders, presenting complex security concepts in an accessible manner.
  • Stay abreast of the latest security threats, trends, and technologies in web application security and incorporate this knowledge into company practices.
  • Assist in the development and enforcement of security policies and procedures, ensuring compliance with industry standards and regulations.
  • Assist with managing bug bounty program.
  • Develop program documentation to promote operational stability and scalability.
  • Support Leadership in defining and executing the roadmap for DevSecOps maturity and secure SDLC initiatives.
  • Support governance and compliance teams on secure engineering practices for aligning security policies related to SDLC
  • Drive and support security identified remediation efforts.
  • Foster and promote a security-forward culture.
  • Mentor junior team members.
  • Other duties and responsibilities, as assigned.

What you will have

  • Bachelor’s or master’s degree in computer science, cybersecurity, or a related field.
  • Professional security certifications such as CISSP, OSCP, CEH, or equivalent are highly desirable.
  • 5+ years of experience in cybersecurity, with a focus on web application security and secure SDLC.
  • Experience with red team implementation and methodologies.
  • Proven track record of working with DevSecOps tools (such as SAST/DAST/SCA) and methodologies.
  • Strong understanding of security protocols, cryptography, authentication, authorization, and security vulnerabilities.
  • Proficiency with programming/scripting languages such as JavaScript, Python, Java, Bash, PowerShell
  • Excellent communication skills with the ability to engage technical and non-technical stakeholders.
  • Strong analytical and problem-solving abilities, with a meticulous attention to detail.
  • Advanced level of knowledge of Information Security design concepts and principles

Nice to have

  • Master's degree in a technical discipline
  • Experience working in highly regulated environments.
  • Advanced level of knowledge of IT frameworks and standards (NIST, OWASP Top Ten, COBIT, ITIL, ISO, PCI-PIN, GDPR, WebTrust, FedRAMP)
  • Certified Information Systems Auditor (CISA)
  • AWS Solutions Architect

Benefits

  • Provident Fund
  • Medical Aid + Gap Cover
  • Employee Assistance Program
  • Gym Reimbursement
  • Life Insurance
  • Disability Insurance
  • Sabbatical

#LI-GA1

__PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT

__PRESENT __PRESENT

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Senior Application Security Engineer

DigiCert

Posted today

Job Viewed

Tap Again To Close

Job Description

workfromhome

Who we are

We're a leading, global security authority that's disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world's largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to the little things like surgically embedded pacemakers. We help companies put trust - an abstract idea - to work. That's digital trust for the real world.

Job summary

As a Senior Application Security Engineer specializing in application security and DevSecOps within our cybersecurity team, you will play a crucial role in safeguarding our company's web applications by integrating security practices into the Software Development Life Cycle (SDLC). You will be responsible for the proactive identification, assessment, and mitigation of security vulnerabilities, developing and driving the adoption of DevSecOps practices, and ensuring that security is embedded in all phases of software development.

This is a remote position.

What you will do

  • Lead the integration of security measures into the SDLC, ensuring that all aspects of web application development are secure by design.
  • Conduct thorough security assessments and penetration testing for web applications to identify vulnerabilities and security gaps.
  • Play an advisory role with software engineering teams in the architectural design of new applications, emphasizing secure architectural patterns and best practices.
  • Perform and coordinate manual and automated code reviews.
  • Lead threat modeling exercises across engineering teams.
  • Collaborate with software development teams to implement DevSecOps practices, providing guidance on secure coding, automated security testing, and continuous monitoring.
  • Contribute to internal security tooling development or integration.
  • Develop and maintain a secure framework for code deployment, automating security processes where possible to streamline the development workflow.
  • Work cross-functionally with various teams, including IT, engineering, operations, and business units, to communicate security policies and procedures effectively.
  • Establish and maintain strong relationships with stakeholders, presenting complex security concepts in an accessible manner.
  • Stay abreast of the latest security threats, trends, and technologies in web application security and incorporate this knowledge into company practices.
  • Assist in the development and enforcement of security policies and procedures, ensuring compliance with industry standards and regulations.
  • Assist with managing bug bounty program.
  • Develop program documentation to promote operational stability and scalability.
  • Support Leadership in defining and executing the roadmap for DevSecOps maturity and secure SDLC initiatives.
  • Support governance and compliance teams on secure engineering practices for aligning security policies related to SDLC
  • Drive and support security identified remediation efforts.
  • Foster and promote a security-forward culture.
  • Mentor junior team members.
  • Other duties and responsibilities, as assigned.

What you will have

  • Bachelor’s or master’s degree in computer science, cybersecurity, or a related field.
  • Professional security certifications such as CISSP, OSCP, CEH, or equivalent are highly desirable.
  • 5+ years of experience in cybersecurity, with a focus on web application security and secure SDLC.
  • Experience with red team implementation and methodologies.
  • Proven track record of working with DevSecOps tools (such as SAST/DAST/SCA) and methodologies.
  • Strong understanding of security protocols, cryptography, authentication, authorization, and security vulnerabilities.
  • Proficiency with programming/scripting languages such as JavaScript, Python, Java, Bash, PowerShell
  • Excellent communication skills with the ability to engage technical and non-technical stakeholders.
  • Strong analytical and problem-solving abilities, with a meticulous attention to detail.
  • Advanced level of knowledge of Information Security design concepts and principles

Nice to have

  • Master's degree in a technical discipline
  • Experience working in highly regulated environments.
  • Advanced level of knowledge of IT frameworks and standards (NIST, OWASP Top Ten, COBIT, ITIL, ISO, PCI-PIN, GDPR, WebTrust, FedRAMP)
  • Certified Information Systems Auditor (CISA)
  • AWS Solutions Architect

Benefits

  • Provident Fund
  • Medical Aid + Gap Cover
  • Employee Assistance Program
  • Gym Reimbursement
  • Life Insurance
  • Disability Insurance
  • Sabbatical

#LI-GA1

__PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT

__PRESENT __PRESENT

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Senior Application Security Engineer

Gauteng, Gauteng DigiCert

Posted today

Job Viewed

Tap Again To Close

Job Description

workfromhome

Who we are

We're a leading, global security authority that's disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world's largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to the little things like surgically embedded pacemakers. We help companies put trust - an abstract idea - to work. That's digital trust for the real world.

Job summary

As a Senior Application Security Engineer specializing in application security and DevSecOps within our cybersecurity team, you will play a crucial role in safeguarding our company's web applications by integrating security practices into the Software Development Life Cycle (SDLC). You will be responsible for the proactive identification, assessment, and mitigation of security vulnerabilities, developing and driving the adoption of DevSecOps practices, and ensuring that security is embedded in all phases of software development.

This is a remote position.

What you will do

  • Lead the integration of security measures into the SDLC, ensuring that all aspects of web application development are secure by design.
  • Conduct thorough security assessments and penetration testing for web applications to identify vulnerabilities and security gaps.
  • Play an advisory role with software engineering teams in the architectural design of new applications, emphasizing secure architectural patterns and best practices.
  • Perform and coordinate manual and automated code reviews.
  • Lead threat modeling exercises across engineering teams.
  • Collaborate with software development teams to implement DevSecOps practices, providing guidance on secure coding, automated security testing, and continuous monitoring.
  • Contribute to internal security tooling development or integration.
  • Develop and maintain a secure framework for code deployment, automating security processes where possible to streamline the development workflow.
  • Work cross-functionally with various teams, including IT, engineering, operations, and business units, to communicate security policies and procedures effectively.
  • Establish and maintain strong relationships with stakeholders, presenting complex security concepts in an accessible manner.
  • Stay abreast of the latest security threats, trends, and technologies in web application security and incorporate this knowledge into company practices.
  • Assist in the development and enforcement of security policies and procedures, ensuring compliance with industry standards and regulations.
  • Assist with managing bug bounty program.
  • Develop program documentation to promote operational stability and scalability.
  • Support Leadership in defining and executing the roadmap for DevSecOps maturity and secure SDLC initiatives.
  • Support governance and compliance teams on secure engineering practices for aligning security policies related to SDLC
  • Drive and support security identified remediation efforts.
  • Foster and promote a security-forward culture.
  • Mentor junior team members.
  • Other duties and responsibilities, as assigned.

What you will have

  • Bachelor’s or master’s degree in computer science, cybersecurity, or a related field.
  • Professional security certifications such as CISSP, OSCP, CEH, or equivalent are highly desirable.
  • 5+ years of experience in cybersecurity, with a focus on web application security and secure SDLC.
  • Experience with red team implementation and methodologies.
  • Proven track record of working with DevSecOps tools (such as SAST/DAST/SCA) and methodologies.
  • Strong understanding of security protocols, cryptography, authentication, authorization, and security vulnerabilities.
  • Proficiency with programming/scripting languages such as JavaScript, Python, Java, Bash, PowerShell
  • Excellent communication skills with the ability to engage technical and non-technical stakeholders.
  • Strong analytical and problem-solving abilities, with a meticulous attention to detail.
  • Advanced level of knowledge of Information Security design concepts and principles

Nice to have

  • Master's degree in a technical discipline
  • Experience working in highly regulated environments.
  • Advanced level of knowledge of IT frameworks and standards (NIST, OWASP Top Ten, COBIT, ITIL, ISO, PCI-PIN, GDPR, WebTrust, FedRAMP)
  • Certified Information Systems Auditor (CISA)
  • AWS Solutions Architect

Benefits

  • Provident Fund
  • Medical Aid + Gap Cover
  • Employee Assistance Program
  • Gym Reimbursement
  • Life Insurance
  • Disability Insurance
  • Sabbatical

#LI-GA1

__PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT

__PRESENT __PRESENT

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.
 

Nearby Locations

Other Jobs Near Me

Industry

  1. request_quote Accounting
  2. work Administrative
  3. eco Agriculture Forestry
  4. smart_toy AI & Emerging Technologies
  5. school Apprenticeships & Trainee
  6. apartment Architecture
  7. palette Arts & Entertainment
  8. directions_car Automotive
  9. flight_takeoff Aviation
  10. account_balance Banking & Finance
  11. local_florist Beauty & Wellness
  12. restaurant Catering
  13. volunteer_activism Charity & Voluntary
  14. science Chemical Engineering
  15. child_friendly Childcare
  16. foundation Civil Engineering
  17. clean_hands Cleaning & Sanitation
  18. diversity_3 Community & Social Care
  19. construction Construction
  20. brush Creative & Digital
  21. currency_bitcoin Crypto & Blockchain
  22. support_agent Customer Service & Helpdesk
  23. medical_services Dental
  24. medical_services Driving & Transport
  25. medical_services E Commerce & Social Media
  26. school Education & Teaching
  27. electrical_services Electrical Engineering
  28. bolt Energy
  29. local_mall Fmcg
  30. gavel Government & Non Profit
  31. emoji_events Graduate
  32. health_and_safety Healthcare
  33. beach_access Hospitality & Tourism
  34. groups Human Resources
  35. precision_manufacturing Industrial Engineering
  36. security Information Security
  37. handyman Installation & Maintenance
  38. policy Insurance
  39. code IT & Software
  40. gavel Legal
  41. sports_soccer Leisure & Sports
  42. inventory_2 Logistics & Warehousing
  43. supervisor_account Management
  44. supervisor_account Management Consultancy
  45. supervisor_account Manufacturing & Production
  46. campaign Marketing
  47. build Mechanical Engineering
  48. perm_media Media & PR
  49. local_hospital Medical
  50. local_hospital Military & Public Safety
  51. local_hospital Mining
  52. medical_services Nursing
  53. local_gas_station Oil & Gas
  54. biotech Pharmaceutical
  55. checklist_rtl Project Management
  56. shopping_bag Purchasing
  57. home_work Real Estate
  58. person_search Recruitment Consultancy
  59. store Retail
  60. point_of_sale Sales
  61. science Scientific Research & Development
  62. wifi Telecoms
  63. psychology Therapy
  64. pets Veterinary
View All Information Security Jobs