An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Moladira Skills is seeking a Senior Cybersecurity Engineer to act as a technical authority protecting information assets. You will lead SIEM/SOC operations, enforce IAM and data protection, and champion Secure SDLC across cloud-native environments.
You will coordinate vulnerability remediation, threat intelligence, and regulatory compliance while mentoring junior analysts. You will bridge hands-on security engineering with risk governance, ensuring robust defenses and incident response readiness
The Senior Cybersecurity Engineer serves as a senior technical authority responsible for protecting the organization's information assets, systems, and digital infrastructure. Operating as a lead individual contributor within the Information Technology team, this role oversees core defensive security capabilities across endpoint, SIEM/SOC, identity, data loss prevention, web, and email security.
The position blends deep hands-on technical execution with operational risk governance,leading incident response workflows, driving vulnerability remediation, enforcing application and API security standards across development lifecycles, translating threat intelligence into actionable defenses, and mentoring junior security personnel.
Security Operations & Incident Response:
Oversee enterprise SIEM/SOC operations, manage EDR/XDR deployments, and lead end-to-end incident handling (triage, containment, root-cause analysis, forensic investigation, and post-incident reporting).
Identity, Access & Data Protection:
Enforce identity governance, Multi-Factor Authentication (MFA), Single Sign-On (SSO), and Privileged Access Management (PAM). Configure and govern data security frameworks, information classification, and Data Loss Prevention (DLP) policies.
Application, Web & API Security (DevSecOps):
Establish and govern secure software development lifecycle (Secure SDLC) standards—including SAST, DAST, SCA, secrets management, and CI/CD security controls. Define and enforce API security architectures aligned to OWASP Top 10 standards (OAuth 2.0, OIDC, JWT, rate limiting, gateway policies). Manage Web Application Firewalls (WAF) to defend against DDoS, botnets, and application-layer threats.
Cloud, Container & Infrastructure Defense:
Monitor and secure cloud environments, containerized workloads, and Kubernetes clusters using CSPM/CNAPP tools and container scanning. Oversee network boundary controls, PKI/certificate lifecycle management, encryption standards, and email authentication mechanisms (SPF, DKIM, DMARC).
Vulnerability Management & Threat Intelligence:
Coordinate continuous vulnerability identification and remediation workflows, track penetration testing action items, analyze attacker TTPs, and operationalize external threat intelligence into active defensive postures.
Governance, Risk & Compliance Support:
Map technical controls and provide audit assurance against recognized industry frameworks and regulatory mandates (including ISO 27001, NIST CSF, CIS Controls, and POPIA).
Leadership & Security Culture:
Act as a subject-matter expert across cross-functional engineering teams, drive enterprise security awareness and simulated phishing campaigns, and mentor cybersecurity interns and junior analysts.
Education: Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or an equivalent technical qualification. Relevant postgraduate qualifications are advantageous.
Experience: 7+ years of progressive hands-on information security experience, demonstrating senior-level competence across enterprise security operations, threat detection, DevSecOps, and incident response in complex environments.
Demonstrated Track Record: Proven background reviewing technical architectures, collaborating with senior business and engineering stakeholders, and managing external cybersecurity service providers.
General Security Management: CISSP, CISM
Threat Detection & Offensive Operations: GIAC (GCIH, GCFA, etc.), CEH
Platform & Cloud Credentials: Microsoft Certified: Cybersecurity Architect / Security Operations Analyst, EDR/XDR specialist accreditations, or recognized enterprise cloud/WAF security certifications.
Strong analytical, root-cause investigation, and structured problem-solving skills.
Calm, decisive execution under pressure during active cyber incidents.
Clear verbal and technical communication skills, with the ability to convey complex cyber risk to non-technical executive stakeholders.
Uncompromising professional integrity, confidentiality, and sound risk-based technical judgement.