Security Engineer - Microsoft Security Stack

Redherd.Io

Johannesburg

Hybrid

ZAR 720,000 - 950,000

Full time

11 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Training and certification supported
Hybrid work arrangement
Office in Johannesburg

Job summary

RedHerd is seeking a Security Engineer to own the Microsoft security stack across Entra ID, Defender, Sentinel, Intune and Purview. You will design CA policies, automate detections, and drive endpoint security for Windows and macOS in a hybrid Johannesburg environment.

The role emphasizes hands-on engineering over governance, with a requirement for 2–5 years of Microsoft security experience, PowerShell proficiency, and the ability to operate live incidents end-to-end.

Qualifications

  • 2–5 years hands-on security in a Microsoft environment.
  • You own the tooling: configured, engineered, investigated, contained or automated.
  • Practical Entra ID depth with CA design, not just administration.
  • Sentinel and Defender experience, including crafting KQL queries.
  • Experience running a live security incident end-to-end.
  • PowerShell proficiency and scripting.
  • Based in Johannesburg with in-office three days a week; not remote.
  • Credible depth in three of four areas: identity; detection and response; endpoint; cloud/data protection.

Responsibilities

  • Identity: design Entra ID CA, PIM, and identity protection; manage hybrid identity estate via Entra Connect.
  • Detection and response: investigate incidents across Defender for Endpoint, Identity, Office 365; write analytics rules; automate responses; hunt with KQL.
  • Endpoint: build/maintain Intune policies; manage macOS and Windows; enforce security baselines and BitLocker.
  • Cloud, data and automation: harden Azure with RBAC and Key Vault; configure Purview DLP and retention; automate tasks with PowerShell/Graph API.

Skills

Entra ID
Defender
Sentinel
Intune
Purview
PowerShell
KQL

Education

Matric certificate

Tools

Entra Connect
Microsoft Graph API
Azure
Office 365

Job description

Security Engineer - Microsoft Security Stack

Location: Johannesburg, hybrid. Minimum of three days a week in the Johannesburg office. This role is not remote.
Employment type: Permanent, full-time.
Seniority: Individual contributor. Not a management seat.
Experience: 2 to 5 years hands-on in a Microsoft environment.

At a glance
  • You own the Microsoft security estate hands-on: Entra ID and Conditional Access, Defender and Sentinel, Intune across Windows and macOS, Purview for data protection.
  • The controls exist and are audited annually. You run and improve them rather than building from nothing.
  • You are not expected to cover everything on this list. Credible depth in roughly three of the four areas is enough.

Have your matric certificate and academic transcripts ready before you apply. The client asks for both at submission, before they meet you, not at offer stage.

About RedHerd

RedHerd is a specialist cybersecurity recruitment and advisory firm. We work with consultancies, product companies, vendors and enterprise security teams across South Africa, the UK, Europe and the United States. We are deliberately low volume. We scope roles deeply, read the market honestly, and curate shortlists rather than flood them. Clients come to us when a role is niche, senior, sensitive or business-critical. We are recruiting this position exclusively on behalf of our client. We share their identity with you during qualification, before submitting anything. We never introduce your profile without your knowledge and consent.

About the client

A global technology and services business, founded in South Africa and operating from more than thirty offices worldwide.

That work means holding other organisations' financial data at scale. Security here is not an internal IT concern. It is a contractual requirement. The posture is mature, not aspirational. The business holds ISO 27001:2022, ISO 22301:2019 and Cloud Security Alliance STAR certification, is independently SOC 2 Type II audited, and already runs SIEM, SOAR, DLP, intrusion detection, endpoint management, single sign-on and multi-factor authentication.

The role

You take hands-on ownership of the Microsoft security estate: hybrid Active Directory and Entra, Windows and macOS devices, Defender and Sentinel for detection and response, and Purview for data protection.

The controls already exist and are audited every year. What it does need is engineering. The existing internal security function is weighted toward governance and compliance, and it does that well. This role fills the technical gap beside it. You design the Conditional Access policy rather than evidencing that one exists, write the detection rather than reporting on the alert, and automate the task rather than documenting it.

What you will do

Identity

  • Own Entra ID: Conditional Access design, Privileged Identity Management, and Identity Protection risk policies.
  • Manage the hybrid identity estate through Entra Connect.
  • Govern application identity: app registrations, service principals and OAuth consent grants.
  • Diagnose authentication failures across Kerberos, NTLM, SAML, OIDC and OAuth2.

Detection and response

  • Investigate and contain incidents across Defender for Endpoint, Identity, Office 365 and Cloud Apps, from first alert through device isolation, session revocation and token invalidation.
  • Write and tune Sentinel analytics rules, build workbooks, and automate response through Logic Apps playbooks.
  • Hunt across the estate in KQL.

Endpoint

  • Build and maintain Intune: compliance policies, configuration profiles, Autopilot, update rings and proactive remediations.
  • Manage macOS to the same standard as Windows, including Apple Business Manager enrolment and custom configuration payloads.
  • Apply and enforce Microsoft security baselines, attack surface reduction rules, BitLocker and FileVault.

Cloud, data and automation

  • Harden the Azure estate through role-based access control, managed identities, Key Vault and Defender for Cloud.
  • Configure Purview data loss prevention, sensitivity labels and retention, and run audit log searches and eDiscovery when the business needs it.
  • Replace manual security work with automation in PowerShell and the Microsoft Graph API, and keep that work in version control.
What you must bring
  • 2 to 5 years of hands-on security experience in a Microsoft environment, at individual contributor level.
  • Genuine ownership of the tooling, not familiarity with it. You have configured, engineered, investigated, contained or automated. Not coordinated or advised.
  • Practical Entra ID depth. You have designed Conditional Access, not only administered it.
  • Working Sentinel and Defender experience, including writing your own KQL without a reference.
  • You have run a live security incident end-to-end, from first alert to containment.
  • PowerShell as a tool you utilise.
  • The ability to explain a security decision clearly to a technically strong audience that is not security specialists.
  • Based in Johannesburg. You can be in the Johannesburg office three days a week. This role is not remote. Cape Town will only be considered if the Johannesburg market does not produce the right person.
  • Credible depth in roughly three of these four areas: Microsoft identity; detection and response; endpoint security; cloud, data protection and automation. Full coverage of every technology named above is not expected.
Useful extras

Certifications are welcome, but practical capability carries considerably more weight here.

  • Microsoft Graph API and Git.
  • Infrastructure as code through Terraform or ARM.
  • Active Directory Certificate Services and public key infrastructure.
  • Windows or macOS internals.
  • Microsoft security certifications.
Work arrangement
  • Johannesburg, hybrid. Minimum three days a week in the office, two days out.
  • The team is in the office most days, and the client is explicit that this is how the team gels.
  • Cape Town will only be considered if the Johannesburg market does not produce the right person.
Package and development
  • We will discuss the package during the Clearing Call with RedHerd.
  • Training and certification supported.

Come ready to talk about specifics rather than tooling.
The team is explicit that full coverage is not expected, so an honest account of your gaps reads better here than a claim to all of it.If your work is confidential and you cannot describe it in detail, describe your own contribution and the shape of the problem without naming customers or disclosing sensitive information. We would rather read that than a thin CV.

Why this role
  • Full technical ownership of a mature Microsoft security estate rather than one corner of one.
  • Security is commercially material here, because the business is trusted with other organisations' secure data.
  • A team with long tenure, under a manager who is well regarded internally.
  • You engineer the controls rather than audit them.
  • A short two-stage process. The technical stage is with the people you would actually work alongside.
  • Training and certification supported.
Equal opportunity

Applications are considered against the skills, experience, location and verification requirements of the role. RedHerd and our clients are committed to a fair and respectful process and do not discriminate on the basis of any protected characteristic.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Microsoft Security Specialist
Senior Microsoft Security Specialist

Boardroom Appointments • Johannesburg

Hybrid
ZAR 1,339,000 - 2,009,000
Senior Security Analyst - Hybrid
Senior Security Analyst - Hybrid

Recruit-It • Somerset West

On-site
ZAR 900,000 - 1,200,000
Junior Specialist: Identity & Access Management (Azure / Entra ID) & Security
Junior Specialist: Identity & Access Management (Azure / Entra ID) & Security

homechoice • Wes-Kaap

On-site
ZAR 300,000 - 460,000
L2 Soc Analyst
L2 Soc Analyst

Redherd.Io • Johannesburg

Hybrid
ZAR 420,000 - 540,000
Medical aid
Gap cover
Provident fund
+1
Senior Soc Analyst (Soc L4)
Senior Soc Analyst (Soc L4)

Redherd.Io • Johannesburg

Hybrid
ZAR 900,000 - 1,200,000
Medical aid
Gap cover
Provident fund
+4
Senior Security Analyst
Senior Security Analyst

Interfront SOC • Somerset West

Hybrid
ZAR 900,000 - 1,300,000
Hybrid working conditions
Open to people with disabilities
Senior Security Analyst
Senior Security Analyst

Sabenza IT & Recruitment • Cape Town

On-site
ZAR 700,000 - 1,100,000
Security Operations Engineer
Security Operations Engineer

Parvana • South Africa

Hybrid
ZAR 700,000 - 900,000
Hybrid work model
Career development
Security Operations Engineer
Security Operations Engineer

Parvana • Cape Town

Hybrid
ZAR 600,000 - 900,000
Head of Security
Head of Security

Chosen Online Pty Ltd • Cape Town

On-site
ZAR 1,421,784 - 1,703,016
Continuous learning budget
Competitive salary + benefits
Opportunity to pioneer AI-driven security