Talent.com
Shoprite Group of Companies
Security Engineer IShoprite Group of Companies • Cape Town, ZA
Search for other jobs
Security Engineer I

Security Engineer I

Shoprite Group of Companies • Cape Town, ZA
12 days ago
Job description

About the role

  • The purpose of the Cyber Security Engineer I in the Red Team is to support the planning, execution and reporting of red team engagements that simulate real-world attacks against the Group's networks, applications, cloud environments, endpoints and people.
  • The role participates in reconnaissance, vulnerability identification, exploitation support and adversary emulation activities under the guidance of senior red team members and takes ownership of the human risk management workstream - including social engineering simulations and human risk reporting - as part of a broader offensive security remit.
  • The Cyber Security Engineer I in the Red Team supports the execution of low to fairly complex offensive security initiatives and requires a developing professional who is comfortable working through varied, sometimes ambiguous problem-solving challenges, operates effectively and ethically in a fast-paced environment, and demonstrates a clear passion for offensive security and adversarial thinking.

What you'll do

  • Support the planning, scoping and execution of red team engagements across network, application, cloud, endpoint and physical environments, working to defined rules of engagement.
  • Conduct reconnaissance and open-source intelligence (OSINT) gathering to map an organisation's attack surface, including infrastructure, applications and people.
  • Assist with the identification, validation and exploitation of vulnerabilities across networks, applications, cloud platforms and endpoints, under senior guidance.
  • Support post-exploitation activities such as privilege escalation, lateral movement and persistence testing within approved scope, using recognised red team tooling and frameworks.
  • Contribute to adversary emulation exercises aligned to recognised frameworks such as MITRE ATT&CK, simulating the tactics, techniques and procedures used by real-world threat actors.
  • Plan, build and run phishing, vishing and other social engineering simulations as part of the red team's human risk workstream, testing employee resilience to real-world attack tactics.
  • Assist with the measurement, tracking and reporting of human cyber risk indicators, such as phishing click and report rates, repeat-offender trends and awareness training completion, to inform the Group's overall risk posture.
  • Support the development and delivery of security awareness content and culture-building initiatives that reduce employee susceptibility to social engineering, alongside technical remediation recommendations.
  • Document findings from red team and social engineering exercises, including root cause, business impact, evidence and practical, prioritised recommendations for remediation.
  • Collaborate with blue team and security operations stakeholders on purple-team style exercises to validate detection and response capability.
  • Support the development and maintenance of red team playbooks, attack scenarios and rules of engagement, ensuring all activity - technical and human-focused - remains within approved legal and ethical boundaries.
  • Stay abreast of emerging attack tactics, techniques and procedures, both technical and human-focused, to keep engagements realistic and relevant.
  • Maintain strict confidentiality, discretion and professionalism given the sensitive nature of red team and human risk testing.

What you bring

  • A Qualification in Computer Science, Cybersecurity, Information Technology, Information Systems or a related field - (essential).
  • A recognised industry certifications relevant to offensive security, such as CompTIA Security+, CompTIA PenTest+, or a practical junior penetration testing certification (e.g. PJPT, eJPT) - (beneficial).
  • Demonstrable online portfolio evidencing hands-on practical ability, such as an active GitHub profile, CTF (Capture the Flag) participation, or completed rooms and rankings on TryHackMe, HackTheBox or similar platforms - (beneficial)
  • 1-2 years of experience in cybersecurity, with exposure to penetration testing, red teaming, vulnerability assessment or offensive security tooling - (essential).
  • Knowledge of common attack techniques across networks, web applications, cloud platforms and endpoints, including exposure to social engineering tactics and the psychology of manipulation - (essential).
  • Demonstrable understanding and exposure to information security standards, cybersecurity architecture, risk management practices and security models - (essential).
  • Practical exposure to offensive security tooling for web applications, network and host exploitation frameworks. - (desired).
  • Exposure to phishing simulation and security awareness platforms, and breach and attack simulation (BAS) - (desired).
  • Understanding of the cyber kill chain and MITRE ATT&CK across both technical and human-focused techniques - (desired).
  • Knowledge of automation, scripting and basic programming to support red team tooling and reporting - (desired).

Closing Date

  • 2026/09/20
Create a job alert for this search

Security Engineer I • Cape Town, ZA