Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
RedHerd is seeking a Security Engineer to own the Microsoft security stack across Entra ID, Defender, Sentinel, Intune and Purview. You will design CA policies, automate detections, and drive endpoint security for Windows and macOS in a hybrid Johannesburg environment.
The role emphasizes hands-on engineering over governance, with a requirement for 2–5 years of Microsoft security experience, PowerShell proficiency, and the ability to operate live incidents end-to-end.
Location: Johannesburg, hybrid. Minimum of three days a week in the Johannesburg office. This role is not remote.
Employment type: Permanent, full-time.
Seniority: Individual contributor. Not a management seat.
Experience: 2 to 5 years hands-on in a Microsoft environment.
Have your matric certificate and academic transcripts ready before you apply. The client asks for both at submission, before they meet you, not at offer stage.
RedHerd is a specialist cybersecurity recruitment and advisory firm. We work with consultancies, product companies, vendors and enterprise security teams across South Africa, the UK, Europe and the United States. We are deliberately low volume. We scope roles deeply, read the market honestly, and curate shortlists rather than flood them. Clients come to us when a role is niche, senior, sensitive or business-critical. We are recruiting this position exclusively on behalf of our client. We share their identity with you during qualification, before submitting anything. We never introduce your profile without your knowledge and consent.
A global technology and services business, founded in South Africa and operating from more than thirty offices worldwide.
That work means holding other organisations' financial data at scale. Security here is not an internal IT concern. It is a contractual requirement. The posture is mature, not aspirational. The business holds ISO 27001:2022, ISO 22301:2019 and Cloud Security Alliance STAR certification, is independently SOC 2 Type II audited, and already runs SIEM, SOAR, DLP, intrusion detection, endpoint management, single sign-on and multi-factor authentication.
You take hands-on ownership of the Microsoft security estate: hybrid Active Directory and Entra, Windows and macOS devices, Defender and Sentinel for detection and response, and Purview for data protection.
The controls already exist and are audited every year. What it does need is engineering. The existing internal security function is weighted toward governance and compliance, and it does that well. This role fills the technical gap beside it. You design the Conditional Access policy rather than evidencing that one exists, write the detection rather than reporting on the alert, and automate the task rather than documenting it.
Identity
Detection and response
Endpoint
Cloud, data and automation
Certifications are welcome, but practical capability carries considerably more weight here.
Come ready to talk about specifics rather than tooling.
The team is explicit that full coverage is not expected, so an honest account of your gaps reads better here than a claim to all of it.If your work is confidential and you cannot describe it in detail, describe your own contribution and the shape of the problem without naming customers or disclosing sensitive information. We would rather read that than a thin CV.
Applications are considered against the skills, experience, location and verification requirements of the role. RedHerd and our clients are committed to a fair and respectful process and do not discriminate on the basis of any protected characteristic.