Senior Identity Security Specialist (Enterprise Access & Governance) (Contract) (CPT Hybrid)
Datafin IT Recruitment · Cape Town · Market related
Posted 5 August 2026
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →DataFin was established in 1999. We pride ourselves on the fact that we have established relationships with industry leaders and a vast majority of our business is repeat business.
Duties & Responsibilities
ENVIRONMENT: A growing provider of cutting-edge Custom Cloud Solutions seeks an experienced Senior Identity Security Specialist to join its InfoSec team on a long-term contract basis. This role is designed for an InfoSec practitioner who views Identity as the primary security perimeter. You will bridge the gap between traditional infrastructure / AD environments and modern Microsoft Entra ID cloud security. Rather than functioning as a pure technical sysadmin, you will own the identity threat surface—proactively identifying security risks, designing architectural controls, and driving governance across complex, enterprise-scale environments. DUTIES: Identity Architecture & Tiering Governance –
- Drive the evolution and enforcement of identity privilege models, moving legacy environments from traditional AD Tiering (Tier 0/1/2), Red Forest / Bastion models, and Delegation of Control Frameworks toward Microsoft’s modern Enterprise Access Model (EAM).
Entra ID & Hybrid Identity Security –
- Lead security strategy and enforcement across Microsoft Entra ID (Azure AD) and on-premises Active Directory.
- Oversee Enterprise Application registrations, service principal permissions, consent frameworks, and tenant-wide security boundaries.
Modern Authentication & Passwordless Adoption –
- Architect, refine, and enforce passwordless authentication paths, including Windows Hello for Business (WHfB), Passkeys (FIDO2), and robust Conditional Access/MFA policies.
Access Delegation & Control –
- Audit, redesign, and maintain strict delegation models across hybrid environments to eliminate privilege creep, lateral movement paths, and over-provisioned administrative accounts.
Autonomous Security Ownership –
- Independently scan the environment for identity security gaps, misconfigurations, and governance blind spots. Define solutions and execute remediations with minimal oversight.
Cross-Team Collaboration –
- Act as an authoritative InfoSec lead, advising internal Infrastructure, Operations, and Application teams on identity best practices, compliance, and risk reduction.
REQUIREMENTS: Senior-Level Experience: Demonstrated background in Information Security / InfoSec with a heavy focus on Identity Architecture, IAM, and Identity Access Governance (IAG). Deep Microsoft Identity Expertise: Extensive hands-on and architectural knowledge of Microsoft Entra ID and Active Directory Domain Services (AD DS). Privileged Access Architecture: Practical knowledge of Microsoft Privilege/Separation models (Enterprise Access Model, AD Tiering, Red/Bastion Forest legacy concepts, and Delegation of Control Wizard/ACL management). Enterprise App Governance: Strong grasp of Entra ID Enterprise Application Registrations, OAuth/OIDC permissions, App Roles, and API consent models. Strong Authentication Standards: Deep experience implementing modern auth controls—MFA, FIDO2/Passkeys, and Windows Hello for Business. InfoSec & Governance Focus: Ability to analyse identity posture through a threat, compliance, and risk lens rather than purely operational task execution. Advantageous (Nice to Have) -
- Experience with Privileged Access Management (PAM) solutions (e.g., CyberArk, Delinea, Entra PIM).
- Core understanding of Public Key Infrastructure (PKI), digital certificates, and Smart Card/Certificate-Based Authentication (CBA).
ATTRIBUTES: Autonomous & Self-Directed: Thrives on vague or high-level direction; capable of identifying complex problems independently, defining the scope, and driving solutions to completion. Exceptional Communication: Strong verbal and written communication skills; comfortable presenting identity risk and security strategy to corporate stakeholders and executive leadership. Corporate Professionalism: Accustomed to operating within strict enterprise/banking environments, maintaining a polished and professional standard at all times.
Desired Experience & Qualification
Senior, Identity, Security, Active, Directory, Entra, ID, PAM, CyberArk, or, similar, CPT, Hybrid, Package & Remuneration
Negotiable