Application and Data Security Specialist
Location: Centurion, Gauteng (provisional – to be confirmed)
Positions Available: 5
Salary: Market-related
Employment Type: To be confirmed
Job Overview
We are seeking experienced and technically proficient Application and Data Security Specialists to support the protection of enterprise applications, sensitive information and critical business systems.
The successful candidates will be responsible for identifying and mitigating application security risks, implementing data protection controls, assessing vulnerabilities and ensuring that applications and data environments comply with recognised cybersecurity standards and best practices.
This role requires strong technical expertise in application security, data protection, vulnerability management and secure software development practices.
Key Responsibilities
- Conduct application security assessments, vulnerability assessments and security reviews across enterprise applications.
- Identify, analyse and remediate application-level security vulnerabilities and data protection risks.
- Implement and maintain application security controls aligned with organisational security policies and industry standards.
- Perform static application security testing (SAST), dynamic application security testing (DAST) and software composition analysis (SCA).
- Support secure software development lifecycle (SSDLC) processes and DevSecOps practices.
- Assess and strengthen security controls for web applications, APIs, databases and cloud-based applications.
- Implement appropriate data encryption, masking, tokenisation and access control mechanisms.
- Collaborate with development, infrastructure, architecture and cybersecurity teams to address security weaknesses.
- Conduct security risk assessments and recommend practical remediation strategies.
- Support data classification, information protection and data loss prevention initiatives.
- Review application authentication, authorisation and session management controls.
- Monitor emerging application security threats, vulnerabilities and attack techniques.
- Assist with security incident investigations involving applications or sensitive data.
- Maintain security documentation, assessment reports and remediation recommendations.
- Support compliance with relevant data protection regulations and information security frameworks.
Minimum Requirements
- Relevant diploma or degree in Information Technology, Computer Science, Cybersecurity, Information Security or a related discipline.
- Typically 3–5 years of relevant experience in application security, data security or a closely related cybersecurity specialisation.
- Demonstrable hands‑on experience identifying and remediating application security vulnerabilities.
- Strong understanding of OWASP Top 10 vulnerabilities and secure coding principles.
- Practical knowledge of application security testing methodologies and tools.
- Experience securing web applications, APIs, databases and enterprise application environments.
- Understanding of encryption, authentication, authorisation and identity and access management principles.
- Familiarity with vulnerability management and security risk assessment processes.
- Knowledge of information security frameworks such as ISO 27001 and NIST.
- Understanding of data protection requirements, including POPIA and applicable privacy regulations.
- Ability to analyse technical security findings and communicate remediation recommendations effectively.
Technical Skills and Competencies
- Application Security: OWASP Top 10, secure coding, application vulnerability assessments, API security and penetration testing fundamentals.
- Security Testing: SAST, DAST, SCA, Burp Suite, OWASP ZAP, Checkmarx, Fortify or equivalent tools.
- Data Security: Data encryption, data masking, tokenisation, data classification and database access controls.
- Cloud Security: Familiarity with application and data security controls in Microsoft Azure, AWS or equivalent cloud environments.
- DevSecOps: Secure CI/CD pipelines, automated security testing and integration of security controls into development processes.
- Identity and Access Security: Authentication, authorisation, role‑based access control, OAuth 2.0 and OpenID Connect.
- Security Frameworks: ISO 27001, NIST Cybersecurity Framework, OWASP and relevant regulatory requirements.
- Vulnerability Management: Risk identification, vulnerability prioritisation, remediation tracking and security reporting.
Relevant Certifications (Advantageous)
One or more of the following certifications would be beneficial:
- Certified Information Systems Security Professional (CISSP)
- Certified Information Systems Security Manager (CISM)
- Certified Ethical Hacker (CEH)
- Certified Application Security Engineer (CASE)
- GIAC Web Application Penetration Tester (GWAPT)
- CompTIA Security+
- Microsoft Certified: Azure Security Engineer Associate
- Relevant application security, cloud security or DevSecOps certifications
Key Personal Attributes
- Strong analytical and technical problem-solving abilities.
- High attention to detail and commitment to information security.
- Ability to identify risks and recommend practical security improvements.
- Excellent communication and technical documentation skills.
- Ability to collaborate effectively with technical and non-technical stakeholders.
- Proactive approach to cybersecurity threats and emerging vulnerabilities.
- Ability to manage multiple security assessments and remediation activities.
- Strong professional ethics and commitment to confidentiality.