CYBER SECURITY SPECIALIST: DevSecOps, IT CYBER SECURITY

6 days ago


Cape Town, Western Cape, South Africa Boardroom Appointments Full time R1 200 000 - R2 400 000 per year


Job Description

  • Secure the development of products - integrate security practices as early as possible in the lifecycle of software development under the guiding principles of shift left and security by default.
  • Prescribe, maintain and enhance cool toolsets manage the relevant tools required for mature product security that include pen testing, secure coding, and source code analysis. Investigate new approaches, technology, and automation to challenge traditional thinking and raise the level of security.
  • Verify the security of internally and externally developed applications and services during and after development and deployment. Actively participate in the SDLC though guidance, education, input, and facilitation.
  • Perform threat modelling enhance and optimize infrastructure, platform, application, and mobile security by identifying threats, vulnerabilities, and associated countermeasures.
  • Provide AppSec training and raise the awareness banner high create and manage learning and reference materials and exercises.
  • Define and implement documentation and standards on application security processes, tooling, and other resources to assist collaboration with the various stakeholder across company.
  • Provide expert guidance on, and where relevant maintain and enhance the toolsets required for mature application security covering secure coding, source code analysis and vulnerability management.
  • Investigate new approaches, technologies, and automation to mature AppSec.

Additional Responsibilities:

  • Collaborate with the broader SecOps Team to drive and support various operational and strategic initiatives.
  • Champion or co-champion internal security solutions and/or processes.

Minimum Requirements

Mandatory

  • 3-year IT or NQF aligned Qualification
  • 5 years relevant experience in cyber security, with at least 3 years in a DevOps / DevSecOps capacity.
  • Hands on practical experience in DevOps / DevSecOps and the ability to integrate security into the CI/CD processes
  • Hands on practical experience in application security testing.
  • Extensive knowledge of DevSecOps principles, practices, and tools, including containerization, orchestration, and automation.
  • Experience in securing CI/CD pipelines on Cloud platforms, specifically AWS and Azure.
  • Experience with infrastructure-as-code tools (e.g., Terraform).
  • Basic scripting experience and skills. Python and JavaScript are preferred.
  • Solid experience in Secure Code Development practices and tools, e.g., SonarCube.
  • Good understanding of common security libraries, frameworks, and tools.
  • Ability to explain the common security flaws as well as potential ways to address them.
  • Deep technical skills and ability to automate manual processes.
  • Bloodhound approach to security.
  • Relentless pursuit of threat identification and remediation.
  • Relevant research and translation into defence.
  • Very good people skills to engage with the various stakeholders across the business, while ensuring that professionalism is maintained.
  • Ability to engage with and contribute to the Information Security community.

Additional Criteria

  • Software development experience.
  • Relevant qualifications and certifications such as SANS (SEC 540 or SEC 534), GIAC GCSA or the AWS Developer Associate certification is highly advantageous.
  • Practical experience with the MITRE ATT&CK framework is advantageous.
  • May be required to assist outside of working hours.
  • Knowledge of company IT and cyber security landscape, including systemic understanding of key business linkages and dependencies
  • Is aware of and responsive to internal and external events and influences on the technical landscape
  • Ability to research technology-related concepts, trends, and best practices, and apply findings
  • Appropriately derives and organises the essence of information to draw solid conclusions
  • Looks beyond symptoms to uncover root causes of problems to be solved
  • Synthesises data from different sources to identify trends
  • Presents problem analysis and a recommended solution rather than just identifying and describing the problem itself
  • Proactively approaches others to obtain missing information
  • Demonstrates a results-oriented mindset in planning and implementing activities/projects
  • Clearly defines objectives and translates them into workable activities
  • Monitors and tracks progress to ensure delivery of all planned commitments, and keeps the appropriate people informed
  • Prepares written reports and briefs and communicates ideas clearly
  • Speaks fluently in team meetings when presenting information
  • Manages existing partnerships within established agreements or contracts; negotiates adjustments when mutually beneficial to do so
  • Genuinely cultivates personal bonds with colleagues to enhance performance throughout the organisation
  • Adjusts to work effectively within new work structures, processes, requirements, or cultures
  • Demonstrates resourcefulness in acquiring necessary knowledge, skills, and competencies to adapt to change



  • Cape Town, Western Cape, South Africa Ultima Full time R250 000 - R450 000 per year

    Cyber Security Specialist (Vuln Mgmt Focused)Department:Managed Services – Cyber SecurityWork Location: -RemoteShift Pattern:Daytime working only, working a shift pattern of either 7am - 3:30pm, 9-5:30 or 10:30am – 7pm UK working hours37.5 Hour week (7.5 hour days plus Lunch)Job PurposeThis role is for someone to come into the Cyber Security Operations...


  • Cape Town, Western Cape, South Africa Redherd Full time R900 000 - R1 200 000 per year

    ​​​​​​​Cyber Security Specialist: EngineeringAbout RedherdRedherd is a specialist technical cybersecurity recruitment firm supporting organisations that are building or maturing high-performance cyber functions. We partner with companies undergoing significant digital transformation who need deeply skilled security professionals capable of...


  • Cape Town, Western Cape, South Africa Boardroom Appointments Full time R600 000 - R1 200 000 per year

    Key purpose:The Cybersecurity Engineer is responsible for designing, implementing and managing a highly secure network solution that protects against potential cyber attacks and hacking threats by maintaining the cybersecurity environment on prem and in the cloud.The candidate must display an excellent understanding of technology infrastructures using...

  • Cyber Risk

    2 weeks ago


    Cape Town, Western Cape, South Africa Integrity360 Full time R1 200 000 - R2 400 000 per year

    About UsIntegrity360 is the largest independent cyber security provider in Europe, with a growing international presence spanning the UK, Ireland, mainland Europe, Africa and the Caribbean. With over 700 employees, across 12 locations, and six Security Operations Centres (SOCs)—including locations in Dublin, Sofia, Stockholm, Madrid, Rome and Cape...

  • Cyber Risk

    2 weeks ago


    Cape Town, Western Cape, South Africa Integrity360 Full time R120 000 - R180 000 per year

    About UsIntegrity360 is the largest independent cyber security provider in Europe, with a growing international presence spanning the UK, Ireland, mainland Europe, Africa and the Caribbean. With over 700 employees, across 12 locations, and six Security Operations Centres (SOCs)—including locations in Dublin, Sofia, Stockholm, Madrid, Rome and Cape...


  • Cape Town, Western Cape, South Africa Global One Full time R900 000 - R1 200 000 per year

    Job briefA Cyber Security Specialists responsibilities include using their skills to detect insecure features and malicious activities within our networks and infrastructure. They will implement customized application security assessments for client-based asset risk, corporate policy compliance as well as conduct vulnerability assessment. They should have an...


  • Cape Town, Western Cape, South Africa Boardroom Appointments Full time R1 200 000 - R2 400 000 per year

    Cyber Security Engineer - 6 Month ContractMinimum Requirements:7+ years experience in Infrastructure, Software Development, DevOps or Security4+ years of design and implementation of highly available, enterprise-scale public Cloud infrastructure.3+ years in AWS with a focus on Data, Security & IAMintroducing cloud security technology (start-up) in an...


  • Cape Town, Western Cape, South Africa Redherd Full time R120 000 - R180 000 per year

    Senior Cyber Security Specialist – ArchitectureLocation: Cape Town (Hybrid, 3 days in office)Type: Full-time, permanentRecruiter: Redherd (on behalf of a major South African enterprise)Role OverviewWe are hiring a Senior Cyber Security Specialist to join a small, highly technical architecture and engineering team within a mature cyber security function....


  • Cape Town, Western Cape, South Africa Boardroom Appointments Full time R1 000 000 - R3 000 000 per year

    Key purpose:As an ICT Security Specialist, you will be responsible for implementing and maintaining the security of company assets in accordance with industry standards. You will also ensure that all internal processes are in line with regulations and best practice guidelines. Your responsibilities include reviewing vulnerabilities to identify potential...


  • Cape Town, Western Cape, South Africa Boardroom Appointments Full time

    Key purpose:As a Security Sales Specialist, you'll be responsible for developing new business opportunities and managing existing accounts. You will use your sales skills to build long-term relationships with customers by providing them with the best possible service and advice on their security needs. You must have a passion for selling Cyber Security...