Principal Application Security Architect

2 weeks ago


South Africa Sanlam Limited Full time
Press Tab to Move to Skip to Content Link
Select how often (in days) to receive an alert: Create Alert
Principal Application Security ArchitectDate: 23 May 2024

Location:
Bellville, Western Cape, South Africa

Santam BITS has a career opportunity for a senior role of Principal Application Security Architect in the Business Information and Technology Services (BITS) department which is based in the Western Cape or Gauteng.

KEY RESPONSIBILITIESDriving a comprehensive application security strategy.
Threat mitigation and risk management.
Secure architecture and design.
Vulnerability management and code reviews.
Securing the development lifecycle.
Collaboration and communication with development teams and other stakeholders.
Understanding regional requirements.
Lead the development and execution of application security assessments.
Ensure applications comply with all relevant security standards and regulations.
Champion a "security by design" culture.
Develop and maintain application security documentation.
Develop and manage risk mitigation strategies.
Work with other security teams (e.g., security operations, etc.)Stay up-to-date on the latest application security threats and vulnerabilities.
Application Security Incident Response and Cyber Crisis Management.
Participate in Group Information Security Programme (GISP) initiatives.
Application Security (including cloud security), Infrastructure Security, and Cybersecurity Education, Training and Awareness.
Provide regular feedback to Santam Manco on Group-wide application security issues.
Clear and timely communication to management and users regarding application security matters.
Application Security Risk assessment that identifies a requirement for additional awareness or targeted education, training, and awareness interventions.
Review and respond to all application security-related audit findings.
Produce required application security reports.
Ensure that security 'gates' are a formal part of the SDLC/ Agile/ relevant solution development methodology.
Active participation in Sanlam-sanctioned industry bodies (e.g. ISF Live, ISACA, FS-ISAC)Timeous escalation of new, high or escalating cybersecurity risks.

Engage with application owners and the Group Cyber Security Centre (GCSC) Operations Team to ensure that system vulnerabilities identified during penetration tests, Red Team exercises, or vulnerability scans are addressed.

Ensure that the Group CIO is aware of risks and actions required.
Find & provide root cause analysis and implement permanent and/or long-term fixes for application security-related incidents.
Strong understanding of integration between Workstations and Network/Servers

QUALIFICATIONS AND EXPERIENCEA bachelor's Degree or Diploma in Cybersecurity, Computer Science, Information Systems, or a related field, or equivalent work experience.

A Recognised Cyber Security Certification(s) (e.g., Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Ethical Hacker (CEH), or similar certification will be an advantage.

With 15+ years of experience in software engineering, a significant portion of that in an architectural position focusing on cybersecurity within complex organisations, preferably in the financial services sector.

The incumbent must have a solid technical software engineering background with a deep understanding of cybersecurity concepts, threats, and vulnerabilities.

COMPETENCIESHigh Stress Tolerance.
Building and maintaining relationships.
Teamwork and ability to function independently.
Facilitation Skills.
Planning and organising.
Ability to work independently.
Interpersonal savvy.
Plans and aligns.
Optimises work processes.
Cultivates innovation.
Drives results.
Sensitivity to RiskBalances StakeholdersReporting and Administration

ADDITIONAL COMPETENCIES AND SKILLS

Mobile Development:
Security expertise in Android, iOS, and cross-platform frameworks like Flutter helps secure sensitive data on user devices

Cloud Security:
A deep grasp of cloud platforms like AWS, Azure, and GCP and their security implications is vital for secure cloud deployments

API Security:
Understanding API security best practices is critical to prevent unauthorized access and data breaches

Vulnerability Understanding:
In-depth knowledge of common and obscure vulnerabilities in various technologies allows for accurate identification and exploitation for testing and mitigation purposes

Secure Coding Practices:
Expertise in secure coding principles and best practices for different languages and frameworks empowers proactive vulnerability prevention

Threat Modelling:

The ability to analyse application architecture and functionality to anticipate potential attack vectors and proactively address them is crucial.


Security Scanners and Code Analysis Tools:
It is vital to understand how to use these tools to identify vulnerabilities in code and recommend remediation strategies

Penetration Testing Tools:
Familiarity with these allows for thorough vulnerability assessment and simulating real-world attack scenarios

Security Incident Response Tools:
Knowledge of incident response tools and methodologies helps them effectively handle security breaches and minimize damage

Cryptography and Encryption:
Understanding encryption algorithms and their application in securing data is essential.

ADDITIONAL COMPETENCIES AND SKILLSABOUT THE COMPANYSantam is the leading short-term insurer in South Africa. Along with its subsidiaries, the business transacts all classes of short-term insurance. Santam is a large, diversified, and transforming company and our success is rooted in our passion for our clients. Everything we do is centered on our delivery of Insurance Good and Proper.
Please note this appointment will be made in line with the Divisional Employment Equity targets. People with disabilities are welcome to apply

#J-18808-Ljbffr

  • South Africa Sanlam Limited Full time

    Press Tab to Move to Skip to Content Link Select how often (in days) to receive an alert: Create Alert Location: Bellville, Western Cape, South Africa A great career opportunity exists in Santam's Business Information Technology Services team (BITS) in the Western Cape or Gauteng for an Enterprise Cloud Architect.JOB DESCRIPTIONThe purpose of an enterprise...


  • South Africa Fcs Security Services, Inc. Full time

    Job Summary:WHO ARE WE?Live Nation Entertainment is the world's leading live entertainment company, comprised ofglobal market leaders: Ticketmaster, Live Nation Concerts, and Live Nation Media & Sponsorship.Ticketmaster is the global leader in event ticketing with over 500 million tickets sold annually andmore than 12,000 clients worldwide. Live Nation...


  • South Africa Calibre Search Ltd Full time

    With the appointment of a new Lead Bridge Engineer a multi-disciplinary international consultancy are looking for a Chartered Principal engineer to Technically lead the Bridge Design team and assist the Bridge Lead in delivering projects across Rail and Highways.As a Principal Bridge Engineer you will need to show previous experience of holding a design lead...

  • Project Architect

    2 weeks ago


    South Africa Rarecruit Full time

    MINIMUM REQUIREMENTS FOR APPLICANTS:Registered as a Professional Architect or Professional ArchitecturalTechnologist with SACAPMinimum 10 years post graduate experience fulfilling the role of project architect, performing both architectural and managerial duties, to lead and execute any scale or complexity of project from start to finishHands-on lead,...


  • South Africa Calibre Search Ltd Full time

    A Principal/Associate Health and Safety Consultant opportunity has come available for an award winning international multi disciplinary consultancy to work directly with the EU lead in all aspects of project delivery, strategic planning, internal and external growth. As a Principal/Associate Health and Safety Consultant, you will be working at the forefront...


  • Durban South, South Africa Dimension Data Full time

    FunctieomschrijvingAre you looking to take your career to the next level? Are you searching for a culture where being successful means more than just sitting at your desk all day long? We are looking forward to receiving your application!The Senior Solution Architect is an industry respected pre-sales, technology and solution-focused specialist who creates...


  • South Africa First Recruitment Group Full time

    In a rush? Simply drop off your CV by clicking on the button to your right, and we'll get in contact if we have a suitable vacancy.Our client is looking to recruit a Principal Civil Structural Engineer on a contract basis.Principal Civil Structural Engineer Remote Working – Occasional Visits to Manchester Description:Working in a multi-disciplinary team,...

  • Security Supervisor

    2 weeks ago


    Johannesburg South, South Africa dia intelligence security cc Full time

    Looking to hire a supervisor who has experience in a security enviroment.Must be able to work shifts as needed.Salary: R7, R8,000.00 per monthAbility to commute/relocate: Johannesburg South, Gauteng: Reliably commute or planning to relocate before starting work (required)Application Deadline: 2023/07/03

  • Microsoft Security

    2 weeks ago


    South Africa Fempower Full time

    A well established company within the IT space is seeking the expertise of a Microsoft Security & Firewalls Specialist to join their company based in Brits. This will be a permanent requirement. The Key Responsibilities for this Role IncludeEnsure Security and Integrity of the IT InfrastructureConfigure and Manage Sophos FirewallsNetwork SecurityIncident...

  • Microsoft Security

    2 weeks ago


    South Africa Fempower Full time

    A well established company within the IT space is seeking the expertise of a Microsoft Security & Firewalls Specialist to join their company based in Brits. This will be a permanent requirement. The Key Responsibilities for this Role Include Ensure Security and Integrity of the IT InfrastructureConfigure and Manage Sophos FirewallsNetwork SecurityIncident...

  • Application Developer

    2 weeks ago


    South Africa Execustaff South Africa (Pty) Ltd Full time

    Job Duties:Writing medium to complex systems and applications using best software development practices.Investigating issues and requests received from Clients.Assisting with data manipulation, database changes and database design.Collaborating with cross-functional teams to build new features.Fixing bugs and improving application performance.Maintain...

  • Application Developer

    2 weeks ago


    South Africa University Of Fort Hare Full time

    Application Developer - On-Site position available in South Africa - Eastern Cape, Nelson Mandela Bay (Port Elizabeth / Uitenhage) Application Developer - On-Site Permanent PE000701 Information Technology / Telecommunications South Africa - Eastern Cape , Nelson Mandela Bay (Port Elizabeth / Uitenhage) 17, ,000 Monthly (Market related, Negotiable) Our client...


  • South Africa Fempower Full time

    A well established company within the IT space is seeking the expertise of a Cloud Solutions Specialist with a focus on Azure and Microsoft 365 to join their company based in Brits. This will be a permanent requirement. The Key Responsibilities for this Role IncludeDesign, implement, maintain secure cloud solutions for Azure and Microsoft 365...


  • South Africa Fempower Full time

    A well established company within the IT space is seeking the expertise of a Cloud Solutions Specialist with a focus on Azure and Microsoft 365 to join their company based in Brits. This will be a permanent requirement. The Key Responsibilities for this Role Include Design, implement, maintain secure cloud solutions for Azure and Microsoft 365...

  • Security Manager

    2 weeks ago


    South Africa Fidelity Services Group Full time

    The overall purpose of this position is to manage several Operations Managers in covering the following key areas, client liaison, HR /IR matters, fleet management, expenses control, Investigations and to ensure the posting of Security officers, that all site security requirements are adhered to and that the Client's needs are efficiently and professionally...


  • South Africa Sanlam Limited Full time

    Press Tab to Move to Skip to Content Link Select how often (in days) to receive an alert: Create Alert Cyber Security Vulnerability & Tech Compliance Manager JG6Location: Bellville, Western Cape, South Africa Santam BITS has a career opportunity for a senior role as Cyber Security Vulnerability and Technical Compliance Manager in the Business Information...


  • Sandton, City of Johannesburg Metropolitan Municipality, Gauteng, , South Africa Aim Personnel Full time

    Database Architect – Sandton Bachelor's degree in Computer Science/ Information Systems/Business Management. 10 years extensive exp in data migration, integration, and ETL processes. Exp with SQL, NoSQL data storage, Snowflake, Databricks, Apache Spark. Exp with cloud-based data platforms (AWS, GCP, Azure). Data architecture, governance, quality, security...


  • South Africa HR Genie Full time

    Our client is seeking an eloquent Senior DevOps Engineer - a hands-on individual who has great Development & DevOps experience. They will be required to install, configure, monitor and maintain installations with the core team, working in partnership with developers and support staff.Requirements: Configuring the applications to meet the requirements of...

  • Principal

    3 weeks ago


    Johannesburg South, South Africa Phakathi Holdings (Pty)Ltd Full time

    **Minimum Requirements** - Minimum 10 years’ experience in a Principal role - Previous ECD teaching experience - Bachelor's degree in foundation phase or ECD. - SACE registered **Duties and Responsibilities** - Oversee the overall running of the school. - Strong people management and team work skills. - Observe staff and evaluate their performance. -...


  • South Africa Sanlam Limited Full time

    Press Tab to Move to Skip to Content Link Select how often (in days) to receive an alert: Create Alert Select how often (in days) to receive an alert: Location: Bellville, Western Cape, South Africa Who are we? Sanlam Group Technology is responsible for the provision of a digitally enabled technology service as a group COE, drive business and...