Senior Security Analyst
Ozow · Cape Town, Western Cape
Posted 25 September 2026
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Meet Ozow
Ozow is a leading fintech company that’s redefining digital payments in South Africa and beyond, making payments more accessible, secure, and convenient for businesses and consumers alike. As a fast-growing player in the sector, we foster a culture of innovation, diversity, and inclusivity.
More about this Ozow fantastic position
The Senior Security Analyst is the most senior hands-on security specialist at Ozow, accountable for the strength of our security posture and for protecting the integrity, availability, and confidentiality of our systems and data. Reporting into the Infrastructure Manager, this role owns and evolves the security programme rather than only executing it.
This is a deeply technical role for someone who enjoys both breaking and securing systems, and who is ready to set direction. You will set the standards, lift security capability across the business, and translate technical risk into decisions that leadership, auditors, banks, and merchants can act on.
Your role and responsibilities
Security direction and technical leadership
- Own and evolve the security roadmap with the Infrastructure Manager, sequenced by risk and business impact.
- Define security standards, baselines, and testing methodology, and hold teams to them.
- Mentor engineers and infrastructure specialists, and set the testing strategy: what is tested, how often, and to what depth.
- Report security posture, risk, and progress to senior leadership in terms the business can act on.
Offensive security and assurance
- Lead hands-on penetration testing across infrastructure, cloud workloads, applications, APIs, and endpoints.
- Design and run adversary simulations and red team exercises to validate real-world defensive capability.
- Validate remediation through retesting, and drive a purple-team approach with Engineering.
Security operations and incident response
- Own the selection, implementation, and tuning of security tooling (SIEM, EDR, scanners, WAFs, IDS/IPS).
- Set the detection and monitoring strategy, and define escalation paths and response playbooks.
- Act as technical lead during incidents, coordinating Infrastructure, Engineering, and Risk through to closure.
- Run post-incident reviews and turn findings into permanent control improvements.
Vulnerability management and hardening
- Own vulnerability management end to end across cloud infrastructure, applications, CI/CD pipelines, and endpoints.
- Define risk-based prioritisation and remediation SLAs, and drive closure across teams.
- Act as design authority on secure architecture, least privilege, segmentation, and encryption.
- Define and enforce secure configuration baselines, aligned to CIS Benchmarks where applicable.
Automation and enablement
- Automate repeatable security work: triage, reporting, evidence collection, and remediation tracking, and own external penetration testing engagements end to end.
- Define safe, controlled GenAI use cases for security, including the guardrails around them.
- Embed security into engineering practice, pipelines, and workflows (DevSecOps).
Compliance, governance, and stakeholders
- Lead the technical workstream for audits across PCI DSS, ISO 27001, POPIA, and relevant SARB directives.
- Own internal security policies and standards, and advise Risk on where risk acceptance is appropriate.
- Lead technical responses for merchant and bank due diligence and security questionnaires.
You are an ideal candidate if you have
- Bachelor’s degree in computer science, Information Security, or a related field, or equivalent experience.
- 8+ years in cybersecurity, offensive security, security engineering, or security operations, including clear ownership of a security programme or domain.
- Deep hands-on penetration testing and adversary simulation experience, and experience leading incidents through to root cause and closure.
- A track record in vulnerability management at scale, including setting SLAs and driving remediation across teams you do not manage.
- Deep working knowledge of ISO 27001, NIST, PCI DSS, CIS Benchmarks, and OWASP, and how to evidence them under audit.
- Experience selecting and implementing security tooling, not only operating it, strong AWS security expertise or another major cloud, and scripting ability.
- Advantageous : OSCP, OSCE, CRTO, CREST, CISSP, or AWS Security Specialty, and regulated-environment experience.
- Able to influence without authority, and to take a technical risk to an executive, an auditor, or a merchant and be understood.
- Self-directed and pragmatic, focused on practical risk reduction over perfect security.