Senior Information Security Engineer
Talent Match Consulting · Midrand
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Introduction
A leading Investment firm in johannesburg is searching for a Senior Information Security Architect.
The Senior Information Security Engineer is a strategic technical leader responsible for designing, implementing, and optimizing advanced security architectures across hybrid infrastructure, applications, and cloud environments. This role drives security engineering initiatives, mentors junior engineers, leads complex incident response efforts, and ensures compliance with global standards and regulatory requirements. The senior engineer collaborates with IT leadership, risk, and compliance teams to strengthen the company security posture and influence enterprise security strategy. You will be supporting both on-premises and cloud-based environments
Duties & Responsibilities
Key Responsibilities
1. Security Architecture & Engineering
- Lead the design and implementation of advanced security controls across on-prem, cloud, and SaaS environments (Azure, Microsoft 365).
- Define security architecture standards and review new technology integrations for compliance.
- Champion secure development lifecycle practices and perform advanced application security assessments.
- Configure and maintain enterprise firewalls to ensure optimal security and performance.
- Implement and manage Web Application Firewall (WAF) solutions to protect against application-layer attacks.
2. Security Operations Leadership
- Oversee, configure and optimize security tools (Firewalls, Webservers, SIEM, EDR, DLP, vulnerability management platforms).
- Develop automation strategies for threat detection and response, integrating with ITSM platforms
- Establish operational playbooks and mentor team members on best practices.
- Collaborate with outsourced SOC teams to ensure effective monitoring and incident escalation.
- Integrate SOC services into the company security operations framework for seamless threat detection and response.
- Manage SLAs and performance metrics for outsourced SOC providers.
3. Incident Response & Threat Management
- Lead major incident investigations, forensic analysis, and root cause determination.
- Act as escalation point for critical security events and coordinate cross-functional response.
- Drive proactive threat hunting and advanced analytics initiatives.
4. Vulnerability & Patch Management
- Define vulnerability management strategy and ensure timely remediation of critical risks.
- Provide executive-level reporting on risk exposure and remediation progress.
5. Identity & Access Management
- Architect and enforce enterprise-level identity governance using Microsoft Entra ID (Azure AD).
- Implement advanced privileged access management and zero-trust principles.
6. Information Security Awareness
- Develop and deliver security awareness programs to educate employees on cybersecurity best practices.
- Create engaging content and campaigns to promote a culture of security across the organization.
- Measure effectiveness of awareness initiatives and report improvements to leadership.
7. Compliance & Risk Advisory
- Ensure alignment with ISO 27001, NIST CSF, CIS benchmarks, and regulatory requirements (POPIA, GDPR, FSCA).
- Lead technical audits, penetrations tests, red/blue team exercises and provide authoritative guidance on risk mitigation strategies.
8. Operational & Executive Reporting
- Deliver strategic security metrics, risk dashboards, and board-level presentations.
- Recommend improvements to security posture based on threat intelligence and trend analysis.
- Implement security posture improvements and report on progress
- Produce detailed reports on firewall and WAF configurations, changes, and performance metrics.
Desired Experience & Qualification
Qualifications & Experience
o Diploma or Bachelor’s degree in IT, Computer Science, or related field.
o CISSP, CISM, or equivalent senior-level certifications.
o Microsoft Certified: Cybersecurity Architect Expert or SC-series certifications.
Experience
o 7+ years in cybersecurity or security engineering roles, with at least 3 years in a senior or lead capacity.
o Expert-level knowledge of SIEM, EDR, firewalls, DLP, and vulnerability management platforms.
o Hands-on experience in firewall configuration, WAF deployment, and generating detailed security reports.
o Experience in designing and implementing information security awareness programs.
o Advanced understanding of identity governance, zero-trust architecture, and cloud security (Azure, Microsoft 365).
o Strong experience with scripting and automation (PowerShell, Python).
o Proven track record in leading incident response and security architecture projects.
- Preferred: Experience with Hillstone security technologies, NGINX, Microsoft InTune, Microsoft Purview, and various SIEM solutions
Should you not receive a response within 7 days, please consider your application as unsuccessful