Antimalware Specialist

Sasso Consulting

Centurion

Presencial

ZAR 700.000 - 900.000

Jornada completa

hace 38 horas
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Una candidatura hecha a medida para este puesto de trabajo — un currículum y una carta de presentación adaptados que responden directamente a la oferta.

Supera los filtros ATS

Descripción de la vacante

Sasso Consulting is seeking an experienced Antimalware Specialist to implement, administer and optimise enterprise antimalware and endpoint protection across our clients' environments. You will protect endpoints, servers and critical infrastructure by deploying, configuring and monitoring security platforms, and by tuning policies and detection rules.

The role emphasizes hands-on administration, threat prevention and incident response, with focus on Windows and Linux server environments, cloud

Formación

  • Relevant diploma or degree in Information Technology, Computer Science, Cybersecurity, Information Security, Network Engineering or a related discipline.
  • Typically 3–5 years of relevant hands-on experience in enterprise antimalware administration, endpoint protection engineering or related technical specialisation.
  • Proven practical experience deploying, configuring and administering enterprise antimalware or endpoint protection platforms.
  • Strong knowledge of malware prevention, antivirus technologies and endpoint security controls.
  • Experience managing centralised endpoint security platforms across enterprise environments.

Responsabilidades

  • Implement, configure, administer and maintain enterprise antimalware and antivirus security platforms.
  • Deploy and manage endpoint protection technologies across workstations, laptops, servers and other devices.
  • Configure and maintain antimalware policies, scanning schedules, exclusions and security settings.
  • Investigate malware detections and endpoint security incidents in collaboration with SOC teams.
  • Maintain consistent endpoint protection across on‑premises and cloud-managed devices.

Conocimientos

Enterprise antimalware administration
Endpoint protection engineering
Threat investigation
Security policy configuration
Malware detection

Educación

Relevant diploma or degree in IT/Cybersecurity

Herramientas

Microsoft Defender Antivirus
Microsoft Defender for Endpoint
EDR/XDR platforms
SIEM integration
Windows Server/Linux security

Descripción del empleo

Antimalware Specialist

Location: Centurion, Gauteng (provisional – to be confirmed)
Positions Available: 5
Salary: Market-related
Employment Type: To be confirmed

Job Overview

We are seeking experienced and technically proficient Antimalware Specialists to implement, administer, maintain and optimise enterprise antimalware, antivirus and endpoint protection technologies within complex IT environments.

The successful candidates will be responsible for protecting enterprise endpoints, servers and critical infrastructure against malware, ransomware, viruses, trojans, spyware and other malicious software through the effective deployment, configuration, monitoring and management of enterprise security solutions.

This role requires strong hands‑on expertise in enterprise antimalware administration, endpoint security management, malware detection, threat prevention, security policy configuration, malware incident investigation and endpoint protection platform optimisation.

The ideal candidates will have proven experience managing enterprise endpoint protection environments, investigating malware‑related security events, implementing effective antimalware controls and ensuring that endpoint security technologies remain operational, appropriately configured and continuously updated.

This is a specialist technical role requiring practical experience with enterprise antimalware and endpoint protection platforms rather than general desktop support or basic antivirus software installation.

Key Responsibilities

Enterprise Antimalware Administration

  • Implement, configure, administer and maintain enterprise antimalware and antivirus security platforms.
  • Deploy and manage endpoint protection technologies across workstations, laptops, servers and other supported enterprise devices.
  • Configure and maintain antimalware policies, scanning schedules, exclusions and security settings.
  • Monitor endpoint protection platform health, availability and effectiveness.
  • Ensure endpoint protection agents are installed, operational and communicating with central management systems.
  • Manage antimalware signature updates, detection engine updates and platform upgrades.
  • Investigate and resolve endpoint protection deployment and configuration issues.
  • Maintain consistent antimalware security policies across enterprise environments.
  • Identify endpoints with outdated, disabled or malfunctioning security protection.
  • Recommend improvements to enterprise antimalware architecture and administration.

Malware Detection and Threat Prevention

  • Monitor and investigate malware detections and endpoint security alerts.
  • Identify and analyse viruses, trojans, ransomware, spyware, worms and other malicious software.
  • Investigate suspicious files, processes and potentially malicious endpoint activity.
  • Analyse malware‑related security events to determine severity and potential business impact.
  • Implement preventive security controls to reduce malware exposure.
  • Identify recurring malware threats and recommend corrective actions.
  • Monitor emerging malware campaigns and relevant cybersecurity threats.
  • Support the identification of malicious attachments, scripts and executable files.
  • Investigate suspicious endpoint behaviour that may indicate malware infection.
  • Collaborate with SOC analysts and threat hunters to identify and respond to malware threats.

Endpoint Protection and Security Policy Management

  • Develop, implement and maintain enterprise endpoint protection policies.
  • Configure real‑time protection, behavioural monitoring and malware prevention settings.
  • Manage antivirus scanning configurations and automated remediation actions.
  • Implement and maintain appropriate endpoint security exclusions.
  • Review exclusions to ensure they do not introduce unnecessary security risks.
  • Configure endpoint security controls according to organisational security standards.
  • Manage tamper protection and other safeguards against unauthorised security configuration changes.
  • Support application control and attack surface reduction capabilities where supported.
  • Maintain consistent endpoint protection across on‑premises and cloud‑managed devices.
  • Review endpoint protection effectiveness and recommend policy improvements.

Malware Incident Investigation and Response

  • Investigate suspected and confirmed malware infections.
  • Determine the affected systems, potential infection methods and scope of compromise.
  • Analyse malware alerts, endpoint logs and security telemetry.
  • Support containment and isolation of compromised endpoints.
  • Coordinate malware quarantine, removal and remediation activities.
  • Work with incident response teams to investigate ransomware and other significant malware incidents.
  • Assist with identifying potential malware persistence mechanisms.
  • Validate that affected endpoints have been successfully remediated.
  • Support recovery and restoration activities following malware incidents.
  • Document investigation findings, remediation actions and lessons learned.

Enterprise Endpoint Security Platform Management

  • Administer centralised endpoint security management consoles.
  • Configure endpoint groups, policies, administrative access and security reporting.
  • Manage endpoint protection agent deployment and lifecycle activities.
  • Monitor security agent compliance and endpoint protection coverage.
  • Troubleshoot endpoint security connectivity and communication failures.
  • Support integration between endpoint protection platforms and SIEM, EDR or XDR technologies.
  • Manage platform updates, maintenance and configuration changes.
  • Develop security dashboards and endpoint protection reports.
  • Monitor security platform licensing, capacity and operational requirements.
  • Support endpoint security technology migrations and upgrades.

EDR and Advanced Endpoint Security

  • Support endpoint detection and response capabilities where integrated with antimalware solutions.
  • Investigate suspicious endpoint processes and behavioural security detections.
  • Analyse endpoint telemetry to identify malware execution and persistence.
  • Support endpoint isolation and automated response actions.
  • Configure relevant endpoint security detection and prevention policies.
  • Collaborate with security operations teams on advanced malware investigations.
  • Assist with detection tuning and false‑positive reduction.
  • Support threat intelligence integration with endpoint protection technologies.
  • Recommend improvements to endpoint visibility and malware detection capabilities.

Server and Infrastructure Protection

  • Implement and manage antimalware protection for supported enterprise server environments.
  • Configure appropriate endpoint protection settings for Windows and Linux servers.
  • Work with infrastructure teams to manage application‑specific scanning requirements.
  • Review antimalware exclusions for databases, enterprise applications and critical services.
  • Ensure security controls do not unnecessarily disrupt critical business operations.
  • Monitor malware protection coverage across virtualised and hybrid infrastructure.
  • Support antimalware deployment and maintenance within cloud‑hosted workloads.
  • Investigate malware‑related incidents affecting enterprise servers and infrastructure.
  • Maintain appropriate documentation of server protection configurations.

Security Monitoring, Reporting and Compliance

  • Monitor enterprise antimalware compliance and endpoint security posture.
  • Generate reports on malware detections, protection coverage and remediation activities.
  • Identify endpoints that do not comply with organisational security standards.
  • Support security audits and endpoint protection assessments.
  • Maintain documentation of security policies, configurations and operational procedures.
  • Track malware trends and recurring security weaknesses.
  • Recommend improvements to malware prevention and endpoint security controls.
  • Support alignment with relevant cybersecurity frameworks and organisational policies.
  • Collaborate with cybersecurity governance, infrastructure and operational teams.
Minimum Requirements
  • Relevant diploma or degree in Information Technology, Computer Science, Cybersecurity, Information Security, Network Engineering or a related discipline.
  • Typically 3–5 years of relevant hands‑on experience in enterprise antimalware administration, endpoint protection engineering, endpoint security management or a closely related technical specialisation.
  • Proven practical experience deploying, configuring and administering enterprise antimalware or endpoint protection platforms.
  • Strong knowledge of malware prevention, antivirus technologies and endpoint security controls.
  • Experience managing centralised endpoint security platforms across enterprise environments.
  • Practical experience configuring endpoint security policies, exclusions, scanning and protection settings.
  • Experience investigating malware detections and endpoint security incidents.
  • Strong understanding of Windows operating systems and Windows Server environments.
  • Familiarity with Linux endpoint or server security would be advantageous.
  • Experience deploying and troubleshooting endpoint protection agents.
  • Knowledge of malware infection methods, ransomware and common malicious software behaviours.
  • Understanding of endpoint security monitoring and incident response processes.
  • Experience managing endpoint security updates and protection compliance.
  • Familiarity with EDR, XDR and SIEM integration would be advantageous.
  • Good understanding of Active Directory, enterprise networking and endpoint management technologies.
  • Strong technical troubleshooting, analytical and problem‑solving skills.
Technical Skills and Competencies

Enterprise Antimalware and Endpoint Protection Platforms

Practical experience with one or more of the following technologies:

  • Microsoft Defender Antivirus
  • Microsoft Defender for Endpoint
  • Microsoft Defender XDR
  • Trellix Endpoint Security
  • McAfee ePolicy Orchestrator (ePO)
  • Broadcom Symantec Endpoint Security
  • Trend Micro Apex One
  • Trend Micro Vision One
  • Sophos Intercept X
  • Sophos Central
  • CrowdStrike Falcon
  • SentinelOne Singularity
  • ESET PROTECT
  • Bitdefender GravityZone
  • Other enterprise antimalware and endpoint protection platforms

Antimalware Administration

  • Enterprise antivirus deployment
  • Endpoint protection agent management
  • Centralised security console administration
  • Malware signature and engine updates
  • Real‑time protection configuration
  • Scheduled and on‑demand scanning
  • Antivirus policy management
  • Endpoint security exclusions
  • Tamper protection
  • Malware quarantine and remediation
  • Security agent health monitoring
  • Endpoint protection troubleshooting
  • Security platform upgrades and migrations

Malware Detection and Prevention

  • Malware identification
  • Ransomware detection and prevention
  • Trojan and spyware detection
  • Suspicious process investigation
  • Malicious script identification
  • Behaviour‑based malware detection
  • File reputation analysis
  • Indicators of Compromise (IOCs)
  • Malware infection investigation
  • Malware persistence mechanisms
  • Threat intelligence integration
  • Malware containment and remediation

Endpoint Detection and Response

  • Endpoint Detection and Response (EDR)
  • Extended Detection and Response (XDR)
  • Endpoint telemetry analysis
  • Endpoint isolation
  • Behavioural detection
  • Attack surface reduction
  • Security alert investigation
  • Endpoint threat investigation
  • Detection rule tuning
  • False‑positive analysis
  • Automated endpoint response
  • Endpoint security reporting

Enterprise Infrastructure and Operating Systems

  • Windows 10 and Windows 11
  • Windows Server
  • Linux fundamentals
  • Microsoft Active Directory
  • Microsoft Entra ID
  • Group Policy
  • Microsoft Intune
  • Microsoft Configuration Manager
  • Enterprise endpoint management
  • Virtualised server environments
  • Hybrid infrastructure
  • Enterprise networking fundamentals

Cloud and Hybrid Endpoint Protection

  • Microsoft Defender for Endpoint
  • Microsoft Defender for Cloud
  • Microsoft Intune
  • Microsoft Azure
  • Cloud‑managed endpoint security
  • Hybrid endpoint protection
  • Cloud workload protection fundamentals
  • Endpoint security compliance monitoring
  • Centralised cloud security administration

Security Monitoring and Integration

  • SIEM integration
  • Microsoft Sentinel
  • Splunk
  • IBM QRadar
  • Security event logs
  • Endpoint security telemetry
  • Security alert monitoring
  • Endpoint compliance reporting
  • Security dashboards
  • Threat intelligence feeds
  • Incident escalation workflows

Scripting and Automation

  • PowerShell
  • Python fundamentals
  • Windows command‑line tools
  • Endpoint deployment scripting
  • Security administration automation
  • API integration
  • Automated endpoint reporting
  • Security policy deployment automation

Cybersecurity Frameworks and Standards

  • NIST Cybersecurity Framework
  • ISO/IEC 27001
  • CIS Critical Security Controls
  • MITRE ATT&CK
  • Endpoint security best practices
  • Malware incident response procedures
  • Enterprise security configuration standards
  • Security logging and monitoring requirements
Relevant Certifications (Advantageous)

One or more of the following certifications would be beneficial:

  • Microsoft Certified: Security Operations Analyst Associate (SC‑200)
  • Microsoft Certified: Endpoint Administrator Associate (MD‑102)
  • Microsoft Certified: Azure Security Engineer Associate
  • CompTIA Security+
  • CompTIA CySA+
  • GIAC Security Essentials (GSEC)
  • GIAC Certified Incident Handler (GCIH)
  • Certified Information Systems Security Professional (CISSP)
  • Relevant Microsoft Defender certifications or training
  • Trellix or McAfee endpoint security certifications
  • Trend Micro endpoint security certifications
  • Sophos endpoint security certifications
  • CrowdStrike or SentinelOne certifications
  • Other recognised enterprise endpoint protection and antimalware certifications
Key Personal Attributes
  • Strong technical troubleshooting and problem‑solving abilities.
  • Excellent attention to detail and security configuration accuracy.
  • Analytical approach to investigating malware and endpoint security incidents.
  • Ability to manage enterprise‑wide endpoint protection technologies.
  • Proactive approach to identifying security weaknesses and improving protection coverage.
  • Strong understanding of endpoint security risks and malware prevention.
  • Excellent communication and technical documentation skills.
  • Ability to collaborate effectively with cybersecurity, infrastructure and desktop engineering teams.
  • Strong organisational and time‑management skills.
  • Ability to work effectively under pressure during malware incidents.
  • High levels of confidentiality, accountability and professional integrity.
Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Antimalware Specialist
Antimalware Specialist

Sasso Consulting (Pty) Ltd • Johannesburg

Presencial
ZAR 700.000 - 950.000
IT Security Administrator
IT Security Administrator

Sasso Consulting • Centurion

Presencial
ZAR 350.000 - 650.000
Threat and Vulnerability Management Specialist
Threat and Vulnerability Management Specialist

Sasso Consulting (Pty) Ltd • Johannesburg

Presencial
ZAR 700.000 - 1.000.000
IT Security Administrator
IT Security Administrator

Sasso Consulting (Pty) Ltd • Johannesburg

Presencial
ZAR 420.000 - 640.000
Cyber Security SOC Engineer
Cyber Security SOC Engineer

Sasso Consulting (Pty) Ltd • Johannesburg

Presencial
ZAR 520.000 - 780.000
Senior Cybersecurity Engineer-Oct
Senior Cybersecurity Engineer-Oct

Moladira Skills • Sandton

Presencial
ZAR 1.000.000 - 1.600.000
Senior Cybersecurity Engineer-Oct
Senior Cybersecurity Engineer-Oct

Moladira Skills • Gauteng

Presencial
ZAR 900.000 - 1.300.000
CyberArk Specialist
CyberArk Specialist

Sasso Consulting (Pty) Ltd • Johannesburg

Presencial
ZAR 600.000 - 1.000.000
Cyber Security Incident Responder
Cyber Security Incident Responder

Sasso Consulting (Pty) Ltd • Johannesburg

Presencial
ZAR 650.000 - 950.000
DLP Specialist (Data Loss Prevention)
DLP Specialist (Data Loss Prevention)

Sasso Consulting • Centurion

Presencial
ZAR 800.000 - 1.000.000