Talent.com
Security Engineer

Security Engineer

wePlacePretoria, South Africa
30+ days ago
Job description

Job Purpose :

Responsible for company-wide cybersecurity and related documents, process and record management to ensure that systems and products are safe and effective. Ensures data integrity, and that information is kept accurate and consistent unless authorized changes are made (and documented), and that confidentiality is upheld by protecting information from unauthorized access. Responsible for cybersecurity compliance and training throughout the Company.

As the IT Security Engineer, you'll support the company by taking the lead on cybersecurity and working with the team to perform ongoing operations, administration, and development of security systems, as well as implementing fixes that would protect their systems. You will continuously work towards high confidence and high accuracy detection rules leveraging abnormal or suspicious events.

Minimum education (essential) :

Engineering degree (Computer, Software, Mechanical or Electronic

Minimum education (desirable) :

  • OSCP (Offensive Security Certified Professional)
  • PNPT (Practical Network Penetration Tester)
  • CISSP (Certified Information Systems Security Professional)
  • CCSP (Certified Cloud Security Practitioner)

Minimum applicable experience (years) :

AWS' ecosystem :

  • AWS Well Architected Framework
  • Trusted Advisor
  • GuardDuty / SCP / SSM / IAM / WAF
  • Container services such as ECS / EKS
  • Incident detection and response management.
  • Performing penetration tests and vulnerability scans against networks and infrastructure, applications and AWS environments.
  • Drafting and implementing security policies, security procedures, security design and implementation.
  • The following would be advantageous :

  • ISO 14971 (risk management) compliance
  • ISO 27032 (cybersecurity) compliance
  • SOC2 Type 2 (with HiTrust attestation) or HiTrust experience (or equivalent)
  • Skills and Knowledge (essential) :

  • Deep understanding of automation, quality engineering, architectural methodologies, principles, and solution design.
  • Familiarity with operational observability, including log aggregation, application performance monitoring, etc.
  • Understanding of the following : Linux / Windows server and application administration and configuration, networking, scripting and automation, large scale distributed computing architecture.
  • Solid knowledge of IT security (firewalls, EDR, IDS / IPS, SOAR, vulnerability scanning forensic and Threat Hunting).
  • Understanding of AWS ECS & Kubernetes and Containerisation (Docker / Podman / Containerd) with implementation, support, and design.
  • Knowledge in security classification frameworks like MITRE or the cyber-attack kill chain.
  • Good knowledge and understanding of industry standards, memberships, and frameworks such as CIS and SOC 2.
  • Cybersecurity Management 40%

  • Drive development standards and processes related to cybersecurity compliance.
  • Monitor all cybersecurity processes, operations and infrastructure, monitoring internal and external policy and regulatory compliance.
  • Review and evaluate development designs (for existing products and during design phase for new products) to identify gaps in cybersecurity controls, and drive updates to any cybersecurity or compliance documentation.
  • Liaise with internal and external stakeholders to prepare for SOC2 Type 2 and HiTrust).
  • Drive cybersecurity audit strategy and readiness from a dev, security and devops perspective.
  • Identify, implement and maintain all security tools and technology.
  • Schedule (and ideally automate) internal vulnerability scans, remediating findings and ensuring accurate & timely reporting to satisfy PCI DSS requirements.
  • Schedule annual Penetration Tests with external supplier(s) and ensure implementation of items identified in remediation plans.
  • Complete required cybersecurity applications and records for large customers and audits, including reporting as required.
  • Infrastructure Management 30%

  • Drive and action where required the planning, installation, monitoring and maintenance of IT systems and infrastructure focused on cyber security including any penetration testing that is required.
  • Design and execute short- and long-term initiatives to detect and prevent any security vulnerabilities in the IT infrastructure (cloud, security and devops) to meet current and future needs.
  • Develop, execute and oversee procedures, policies and related training plans for cybersecurity project management and infrastructure administration.
  • Conduct research and recommend changes in services, products, protocols, and standards to support development efforts and infrastructure procurement.
  • Define software and hardware security standards in collaboration with stakeholders and owners for the provisioning of the development and IT infrastructure.
  • Ensure appropriate security levels on network, infrastructure and servers are maintained, ensuring that the IT team follows the requirements set in line with cybersecurity standards.
  • Implement cybersecurity continuous improvement programs.
  • Crisis management - keeping stakeholders informed and actively working with teams to return service in the shortest possible time frame. This would include documenting all disaster recovery procedures.
  • Effective management and optimisation of vendors (where applicable) as well as collaborating with the dev and IT teams as necessary.
  • Risk Management and Compliance 20%

  • Collaborate with divisional the RAQA team and Senior ManagersManagerst to define and centralize risks and put mitigation measures in place for new and existing products and services, from a cybersecurity and privacy perspective.
  • Improve the automation of security controls.
  • Work closely with the dev team on defining industry-standard processes and system requirements, identifying and proposing fixes to shortcomings in the development lifecycle, code reviews and scanning as well as infrastructure provisioning.
  • Work with the dev team to ensure that security standards and policies are being set up and configured correctly, ensuring adherence to certifications and best-practice.
  • Assist with remediations on risk items identified from security and preventative detection reviews to ensure compliance and ensure the security posture of the IT landscape is ensured at all times.
  • Remediate audit items by putting measures in place to prevent the recurrence of findings. For example, by making sure that audit findings are resolved by the relevant personnel and that the resolutions are such that they prevent the item from reoccurring in the future.
  • Manage internal and external audits as required with relation to cybersecurity.
  • Maintain documentation for cybersecurity-related risks, processes and findings.
  • QMS and Documentation 10%

  • Manage annual cybersecurity roadmap, IT audit (internal and external) plan and calendar.
  • Work closely with the Compliance team to gather and submit evidence for all security and IT audits.
  • Proactively keep stakeholders updated on status, progress, risks and problems.
  • Review and approve documented outcomes of Penetration Tests, Remediation Plans and required activities.
  • Review and approve documented outcomes of Vulnerability Scans, Remediation Plans and required activities.
  • Maintain cybersecurity documents and records in line with certification requirements.
  • Maintain document bank and matrix for the cybersecurity setup and external customer-audit matrix requests. For example, ensuring that all cybersecurity related information, such as architectural diagrams, asset lists, asset control lists and vulnerabilities, can be referenced from a single central source from which to direct the readers to the appropriate resources.
  • 2 days work-from-home in line with Company Policy (only applicable after probation is successfully passed).

    Should you not receive a response from us within one week of your application, your application has unfortunately not been successful.

    Create a job alert for this search

    Security Engineer • Pretoria, South Africa

    Related jobs
    • Promoted
    Security Engineer Centurion

    Security Engineer Centurion

    Alinta Tech SolutionsCenturion, Gauteng, South Africa
    The Security Engineer is tasked with the vital responsibility of implementing and maintaining robust security protocols to safeguard the organization's data and infrastructure.This hands-on positio...Show moreLast updated: 30+ days ago
    • Promoted
    Network Security Engineer

    Network Security Engineer

    Polish ManagementPretoria, Gauteng, South Africa
    We are seeking a skilled Network Security Engineer to design, implement, and maintain secure network infrastructures.The role involves safeguarding systems, data, and networks from cyber threats, e...Show moreLast updated: 4 days ago
    • Promoted
    Software Engineer (Cryptography and Network Securi

    Software Engineer (Cryptography and Network Securi

    E and D RecruitersPretoria, Gauteng, South Africa
    International Company - Software Engineer (Cryptography and Network Security).This exciting career opportunity is for a person with skills in Cryptography and computer & network security.We require...Show moreLast updated: 30+ days ago
    • Promoted
    It Security Engineer

    It Security Engineer

    CodeConnect Staffing (Pty) LtdPretoria, Gauteng, South Africa
    Work Model : 2 days remote per week (post-probation).A well-established medical devices company is seeking a skilled IT Security Engineer to lead company-wide cybersecurity operations.This role will...Show moreLast updated: 13 days ago
    • Promoted
    Team Lead Security Engineer

    Team Lead Security Engineer

    Hire ResolveRandburg, Gauteng, South Africa
    A leading provider in vehicle tracking telematics and security technology is seeking a highly skilled Team Lead Security Engineer to head up a dedicated security engineering team.The position calls...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer : Enterprise and Cloud Infrastracture

    Security Engineer : Enterprise and Cloud Infrastracture

    Alinta Tech SolutionsCenturion, Gauteng, South Africa
    The Security Engineer is tasked with the vital responsibility of implementing and maintaining robust security protocols to safeguard the organization's data and infrastructure.This hands-on positio...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer

    Security Engineer

    Air ChefsPretoria, Gauteng, South Africa
    We're looking for an experienced Security Engineer to support our cybersecurity and compliance efforts across product, operations, and infrastructure. Cybersecurity Management (40%).Develop and main...Show moreLast updated: 14 days ago
    • Promoted
    Security Software Developer

    Security Software Developer

    E&D RecruitersPretoria, South Africa
    Electronic Engineering) or BEng / BSc (Computer Engineering) or Computer Science.Experience writing software in C and C++ for embedded platforms. Experience or knowledge in communications security and...Show moreLast updated: 13 days ago
    • Promoted
    Security Engineer

    Security Engineer

    AiRPretoria, Gauteng, South Africa
    Cybersecurity Management (40%).Develop and maintain security standards and processes to support compliance requirements.Oversee cybersecurity operations and ensure alignment with internal policies ...Show moreLast updated: 16 days ago
    • Promoted
    Engineer, Cyber Security (Linux Engineer)

    Engineer, Cyber Security (Linux Engineer)

    Standard Bank GroupRosebank, Gauteng, South Africa
    To provide expertise, professional knowledge, and technical skills to automate building, testing and operating data ingestion systems. To operate and monitor the group's cyber security operational c...Show moreLast updated: 26 days ago
    • Promoted
    Senior Security Technical Architect

    Senior Security Technical Architect

    NTT DATA, Inc.WorkFromHome, Gauteng, South Africa
    Senior Security Technical Architect.Join a company that is pushing the boundaries of what is possible.We are renowned for our technical excellence and leading innovations, and for making a differen...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer

    Security Engineer

    Network RecruitmentPretoria, Gauteng, South Africa
    Be the reason our systems stay safe, compliant, and unbreakable.Establish and maintain cybersecurity standards, controls and compliance frameworks (SOC2, HiTrust, PCI DSS).Monitor security operatio...Show moreLast updated: 16 days ago
    • Promoted
    Team Lead : Security Engineer

    Team Lead : Security Engineer

    Tracker South AfricaRandburg, Gauteng, South Africa
    Network Administration and Security.Tracker is seeking an individual to lead the design, implementation, and continuous improvement of a secure, scalable, and high-performing network infrastructure...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Data Management Security Engineer

    Senior Data Management Security Engineer

    NTT LimitedWorkFromHome, Gauteng, South Africa
    Senior Data Management Security Engineer page is loaded.Senior Data Management Security Engineer.Apply remote type Hybrid Working locations Johannesburg, South Africa Cape Town, South Africa time t...Show moreLast updated: 30+ days ago
    • Promoted
    Network Security Engineer

    Network Security Engineer

    Interfront SOCWorkFromHome, Gauteng, South Africa
    Design implement and maintain robust network security infrastructure to protect Customers digital environment.Manage and optimize security platforms including firewalls, intrusion prevention system...Show moreLast updated: 4 days ago
    • Promoted
    Fire Detection Engineer – OTN Systems South-Africa

    Fire Detection Engineer – OTN Systems South-Africa

    HopecompassMidrand, Gauteng, South Africa
    If you are ready to take your technical knowledge further, join our team of distributing fire alarm equipment.Our company provides a wide range of services, including state-of-the-art fire detectio...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer

    Security Engineer

    The Hiring HousePretoria, South Africa
    Risk Management and Compliance.Engineering degree (Computer, Software, Mechanical or Electronic).Minimum education (desirable) : . OSCP (Offensive Security Certified Professional).PNPT (Practical Netw...Show moreLast updated: 30+ days ago
    • Promoted
    SOC Engineer L3 Cyber Security Specialist

    SOC Engineer L3 Cyber Security Specialist

    60 DegreesCenturion, Gauteng, South Africa
    Are you obsessed with uncovering digital threats fine-tuning detection strategies and architecting bulletproof incident response plans Then stop scrolling this is the opportunity you’ve been huntin...Show moreLast updated: 24 days ago