Senior Cybersecurity Engineer-Oct

Moladira Skills

Gauteng

On-site

ZAR 900,000 - 1,300,000

Full time

9 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Moladira Skills seeks a Senior Cybersecurity Engineer to protect the organization’s information assets and digital infrastructure. The role blends hands-on defense with governance, leading incident response, vulnerability remediation, and secure development practices across endpoints, cloud, and data security.

You will drive secure SDLC, IAM, DLP compliance, and threat intelligence translation into practical defenses while mentoring junior security staff in a dynamic Gauteng environment.

Qualifications

  • Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or an equivalent technical qualification.
  • 7+ years of progressive hands-on information security experience across enterprise security operations, threat detection, DevSecOps, and incident response in complex environments.
  • Demonstrated track record reviewing technical architectures, collaborating with senior stakeholders, and managing external cybersecurity service providers.

Responsibilities

  • Oversee enterprise SIEM/SOC operations, manage EDR/XDR deployments, and lead end-to-end incident handling (triage, containment, root-cause analysis, forensic investigation, and post-incident reporting).
  • Enforce identity governance, MFA, SSO, and PAM; configure and govern data security frameworks, information classification, and DLP policies.
  • Establish and govern Secure SDLC standards—SAST, DAST, SCA, secrets management, and CI/CD security controls; enforce API security architectures aligned to OWASP Top 10; manage WAF and DDoS protections.
  • Monitor and secure cloud environments, containerized workloads, and Kubernetes clusters using CSPM/CNAPP tools; oversee PKI, encryption, and email authentication (SPF, DKIM, DMARC).
  • Coordinate vulnerability identification/remediation, track pen-test actions, analyze attacker TTPs, and operationalize threat intel into defense.
  • Map technical controls to ISO 27001, NIST CSF, CIS Controls, POPIA; provide audit assurance.
  • Act as SME across engineering teams, drive security awareness and mentor interns/junior analysts.

Skills

EDR/XDR
SIEM/SOC
IAM
DLP
WAF
DevSecOps
Threat intel

Education

Bachelor's degree in Cybersecurity/Info Security/CS/IT
Postgraduate qualifications advantageous

Tools

KQL
PowerShell
Python
Terraform

Job description

The Senior Cybersecurity Engineer serves as a senior technical authority responsible for protecting the organization's information assets, systems, and digital infrastructure. Operating as a lead individual contributor within the Information Technology team, this role oversees core defensive security capabilities across endpoint, SIEM/SOC, identity, data loss prevention, web, and email security.

The position blends deep hands-on technical execution with operational risk governance,leading incident response workflows, driving vulnerability remediation, enforcing application and API security standards across development lifecycles, translating threat intelligence into actionable defenses, and mentoring junior security personnel.

Key Responsibilities & Functional Scope
  • Security Operations & Incident Response:

    Oversee enterprise SIEM/SOC operations, manage EDR/XDR deployments, and lead end-to-end incident handling (triage, containment, root-cause analysis, forensic investigation, and post-incident reporting).

  • Identity, Access & Data Protection:

    Enforce identity governance, Multi-Factor Authentication (MFA), Single Sign-On (SSO), and Privileged Access Management (PAM). Configure and govern data security frameworks, information classification, and Data Loss Prevention (DLP) policies.

  • Application, Web & API Security (DevSecOps):

    Establish and govern secure software development lifecycle (Secure SDLC) standards—including SAST, DAST, SCA, secrets management, and CI/CD security controls. Define and enforce API security architectures aligned to OWASP Top 10 standards (OAuth 2.0, OIDC, JWT, rate limiting, gateway policies). Manage Web Application Firewalls (WAF) to defend against DDoS, botnets, and application-layer threats.

  • Cloud, Container & Infrastructure Defense:

    Monitor and secure cloud environments, containerized workloads, and Kubernetes clusters using CSPM/CNAPP tools and container scanning. Oversee network boundary controls, PKI/certificate lifecycle management, encryption standards, and email authentication mechanisms (SPF, DKIM, DMARC).

  • Vulnerability Management & Threat Intelligence:

    Coordinate continuous vulnerability identification and remediation workflows, track penetration testing action items, analyze attacker TTPs, and operationalize external threat intelligence into active defensive postures.

  • Governance, Risk & Compliance Support:

    Map technical controls and provide audit assurance against recognized industry frameworks and regulatory mandates (including ISO 27001, NIST CSF, CIS Controls, and POPIA).

  • Leadership & Security Culture:

    Act as a subject-matter expert across cross-functional engineering teams, drive enterprise security awareness and simulated phishing campaigns, and mentor cybersecurity interns and junior analysts.

Technical Competency
  • Endpoint & Threat Hunting (EDR/XDR) Enterprise endpoint prevention, investigation, rapid containment, and host isolation.
  • Monitoring & Operations (SIEM/SOC) Centralized logging, correlation rule development, alerting triage, and SOC oversight.
  • Identity & Access Management (IAM) Principle of least privilege, Privileged Identity Management (PIM), identity lifecycles, and access governance.
  • Information Protection Classification labelling, Microsoft Purview / enterprise DLP, and sensitive asset protection.
  • Application & API Security OWASP Top 10 / API Top 10, gateway architecture, code review oversight, CI/CD pipeline scanning, token-based authentication.
  • Cloud & Container Security CSPM/CNAPP, infrastructure as code (IaC) verification, container image scanning, and Kubernetes security.
  • Perimeter & Email Defense WAF rule configuration, anti-DDoS, mail filtering, business email compromise (BEC) investigation, SPF/DKIM/DMARC.
  • Cryptography & PKI Certificate authorities, key management systems, and enterprise TLS configurations.
  • Automation & Scripting Automation of repetitive analytical tasks and custom reporting (e.g., Python, PowerShell, KQL).
Candidate Profile & Qualifications
Education & Experience
  • Education: Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or an equivalent technical qualification. Relevant postgraduate qualifications are advantageous.

  • Experience: 7+ years of progressive hands-on information security experience, demonstrating senior-level competence across enterprise security operations, threat detection, DevSecOps, and incident response in complex environments.

  • Demonstrated Track Record: Proven background reviewing technical architectures, collaborating with senior business and engineering stakeholders, and managing external cybersecurity service providers.

Professional Certifications (Advantageous)
  • General Security Management: CISSP, CISM

  • Threat Detection & Offensive Operations: GIAC (GCIH, GCFA, etc.), CEH

  • Platform & Cloud Credentials: Microsoft Certified: Cybersecurity Architect / Security Operations Analyst, EDR/XDR specialist accreditations, or recognized enterprise cloud/WAF security certifications.

Professional & Behavioral Attributes
  • Strong analytical, root-cause investigation, and structured problem-solving skills.

  • Calm, decisive execution under pressure during active cyber incidents.

  • Clear verbal and technical communication skills, with the ability to convey complex cyber risk to non-technical executive stakeholders.

  • Uncompromising professional integrity, confidentiality, and sound risk-based technical judgement.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Engineer-Oct
Senior Cybersecurity Engineer-Oct

Moladira Skills • Sandton

On-site
ZAR 1,000,000 - 1,600,000
Threat and Vulnerability Management Specialist
Threat and Vulnerability Management Specialist

Sasso Consulting (Pty) Ltd • Johannesburg

On-site
ZAR 700,000 - 1,000,000
Cyber Security SOC Engineer
Cyber Security SOC Engineer

Sasso Consulting (Pty) Ltd • Johannesburg

On-site
ZAR 520,000 - 780,000
Senior Cybersecurity Engineer - Compliance & Technology
Senior Cybersecurity Engineer - Compliance & Technology

ATS Client • Sandton

On-site
ZAR 900,000 - 1,600,000
Cyber Security Consultant
Cyber Security Consultant

Network Finance • Randburg

On-site
ZAR 900,000 - 1,500,000
Cybersecurity Specialist
Cybersecurity Specialist

SavageOne Pty Ltd • Johannesburg

On-site
ZAR 600,000 - 1,000,000
Information Security Officer
Information Security Officer

Old Mutual Limited • Johannesburg

On-site
ZAR 1,200,000 - 1,800,000
Security Engineer
Security Engineer

Gxa • South Africa

On-site
ZAR 650,000 - 950,000
Cyber Safety Engineer
Cyber Safety Engineer

Boardroom Appointments • Johannesburg

On-site
ZAR 600,000 - 900,000
Cyber Security Incident Responder
Cyber Security Incident Responder

Sasso Consulting (Pty) Ltd • Johannesburg

On-site
ZAR 650,000 - 950,000