Senior Identity Security Specialist (Enterprise Access & Governance) (Contract) (CPT Hybrid)
Datafin Recruitment · Cape Town, Western Cape
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →ENVIRONMENT
- A growing provider of cutting-edge Custom Cloud Solutions seeks an experienced Senior Identity Security Specialist to join its InfoSec team on a long-term contract basis.
- This role is designed for an InfoSec practitioner who views Identity as the primary security perimeter. You will bridge the gap between traditional infrastructure / AD environments and modern Microsoft Entra ID cloud security. Rather than functioning as a pure technical sysadmin, you will own the identity threat surface—proactively identifying security risks, designing architectural controls, and driving governance across complex, enterprise-scale environments.
DUTIES
Identity Architecture & Tiering Governance –
Drive the evolution and enforcement of identity privilege models, moving legacy environments from traditional AD Tiering Tier 0/1/2, Red Forest / Bastion models, and Delegation of Control Frameworks toward Microsoft's modern Enterprise Access Model EAM.
Entra ID & Hybrid Identity Security –
- Lead security strategy and enforcement across Microsoft Entra ID Azure AD and on-premises Active Directory.
- Oversee Enterprise Application registrations, service principal permissions, consent frameworks, and tenant-wide security boundaries.
Modern Authentication & Passwordless Adoption –
Architect, refine, and enforce passwordless authentication paths, including Windows Hello for Business WHfB, Passkeys FIDO2, and robust Conditional Access/MFA policies.
Access Delegation & Control –
Audit, redesign, and maintain strict delegation models across hybrid environments to eliminate privilege creep, lateral movement paths, and over-provisioned administrative accounts.
Autonomous Security Ownership –
Independently scan the environment for identity security gaps, misconfigurations, and governance blind spots. Define solutions and execute remediations with minimal oversight.
Cross-Team Collaboration –
Act as an authoritative InfoSec lead, advising internal Infrastructure, Operations, and Application teams on identity best practices, compliance, and risk reduction.
REQUIREMENTS
- Senior-Level Experience: Demonstrated background in Information Security / InfoSec with a heavy focus on Identity Architecture, IAM, and Identity Access Governance IAG.
- Deep Microsoft Identity Expertise: Extensive hands-on and architectural knowledge of Microsoft Entra ID and Active Directory Domain Services AD DS.
- Privileged Access Architecture: Practical knowledge of Microsoft Privilege/Separation models Enterprise Access Model, AD Tiering, Red/Bastion Forest legacy concepts, and Delegation of Control Wizard/ACL management.
- Enterprise App Governance: Strong grasp of Entra ID Enterprise Application Registrations, OAuth/OIDC permissions, App Roles, and API consent models.
- Strong Authentication Standards: Deep experience implementing modern auth controls—MFA, FIDO2/Passkeys, and Windows Hello for Business.
- InfoSec & Governance Focus: Ability to analyse identity posture through a threat, compliance, and risk lens rather than purely operational task execution.
Advantageous Nice to Have –
- Experience with Privileged Access Management PAM solutions e.g., CyberArk, Delinea, Entra PIM.
- Core understanding of Public Key Infrastructure PKI, digital certificates, and Smart Card/Certificate-Based Authentication CBA.
ATTRIBUTES
- Autonomous & Self-Directed: Thrives on vague or high-level direction; capable of identifying complex problems independently, defining the scope, and driving solutions to completion.
- Exceptional Communication: Strong verbal and written communication skills; comfortable presenting identity risk and security strategy to corporate stakeholders and executive leadership.
- Corporate Professionalism: Accustomed to operating within strict enterprise/banking environments, maintaining a polished and professional standard at all times.