Offensive + Defensive Security Engineer
Watershed Consulting · Johannesburg
Posted 29 July 2026
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Job Title: Offensive + Defensive Security Engineer
Duration: 6 to 12 months (renewal possible) Location: Johannesburg Subcon budget: Share profiles including your margins
Description
We are seeking a versatile Offensive + Defensive Security Engineer to join a lean, high-impact team focused on vulnerability discovery, attack simulation, and remediation enablement. This role requires developer-led profiles with a cybersecurity mindset capable of operating across both offensive and defensive domains. The successful candidate will contribute to both offensive engagements and defensive improvements, enabling the organisation to identify, validate, and remediate security issues effectively.
Duties & Responsibilities
Responsibilities
- Perform penetration testing, ethical hacking, and red teaming engagements to discover vulnerabilities and simulate realistic attacker techniques.
- Plan and execute adversary simulation exercises to test detection and response capabilities.
- Identify, validate, and prioritise vulnerabilities across applications, networks, cloud, containers, and endpoints.
- Develop proof-of-concept exploits and demonstrate impact where appropriate to drive remediation.
- Conduct secure code reviews and support SAST and DAST activities with development teams.
- Provide clear remediation guidance and work closely with engineering teams to enable fixes and secure-by-design practices.
- Support incident response, threat hunting, and security monitoring efforts to strengthen defensive posture.
- Automate testing and reporting tasks to scale offensive and defensive activities, and contribute to DevSecOps tooling.
- Document findings and present technical reports and risk assessments to technical and non-technical stakeholders.
Skills
Candidates should be prepared to demonstrate applied experience with the following skills and provide relevant profiles and margins as part of the subcon submission.
Desired Experience & Qualification
Qualifications
- Proven experience in penetration testing, red teaming, or ethical hacking with demonstrable deliverables.
- Strong application security background and practical secure coding experience.
- Experience with vulnerability assessment, exploit development, and adversary simulation techniques.
- Familiarity with incident response, threat hunting, and security operations practices.
- Experience collaborating with development teams to enable remediation and implement secure fixes.
- Relevant certifications preferred (e.g., OSCP, OSCE, CREST, CISSP, GIAC) but not mandatory.
- Excellent written and verbal communication skills and ability to produce concise, actionable reports.
Team Composition
The engagement will include a mix of highly skilled senior specialists and mid-level support resources responsible for testing, analysis, and support activities. Developer-led profiles with a cybersecurity mindset are strongly preferred.