Principal Application Security Architect

6 months ago


Cape Town, South Africa Sanlam Full time

CAREER OPPORTUNITY

Santam BITS has a career opportunity for a senior role of Principal Application Security Architect in the Business Information and Technology Services (BITS) department which is based in the Western Cape or Gauteng.

KEY RESPONSIBILITIES

Driving a comprehensive application security strategy. Threat mitigation and risk management. Secure architecture and design. Vulnerability management and code reviews. Securing the development lifecycle. Collaboration and communication with development teams and other stakeholders. Protecting global assets. Understanding regional requirements. Lead the development and execution of application security assessments. Ensure applications comply with all relevant security standards and regulations. Champion a "security by design" culture. Develop and maintain application security documentation. Develop and manage risk mitigation strategies. Work with other security teams (., security operations, Stay up-to-date on the latest application security threats and vulnerabilities. Application Security Incident Response and Cyber Crisis Management. Participate in Group Information Security Programme (GISP) initiatives. Application Security (including cloud security), Infrastructure Security, and Cybersecurity Education, Training and Awareness. Provide regular feedback to Santam Manco on Group-wide application security issues. Clear and timely communication to management and users regarding application security matters. Application Security Risk assessment that identifies a requirement for additional awareness or targeted education, training, and awareness interventions. Review and respond to all application security-related audit findings. Produce required application security reports. Ensure that security 'gates' are a formal part of the SDLC/ Agile/ relevant solution development methodology. Active participation in Sanlam-sanctioned industry bodies (. ISF Live, ISACA, FS-ISAC) Timeous escalation of new, high or escalating cybersecurity risks. Engage with application owners and the Group Cyber Security Centre (GCSC) Operations Team to ensure that system vulnerabilities identified during penetration tests, Red Team exercises, or vulnerability scans are addressed. Ensure that the Group CIO is aware of risks and actions required. Find & provide root cause analysis and implement permanent and/or long-term fixes for application security-related incidents. Strong understanding of integration between Workstations and Network/Servers

QUALIFICATIONS AND EXPERIENCE

A bachelor’s Degree or Diploma in Cybersecurity, Computer Science, Information Systems, or a related field, or equivalent work experience. A Recognised Cyber Security Certification(s) (., Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Ethical Hacker (CEH), or similar certification will be an advantage. With 15+ years of experience in software engineering, a significant portion of that in an architectural position focusing on cybersecurity within complex organisations, preferably in the financial services sector. The incumbent must have a solid technical software engineering background with a deep understanding of cybersecurity concepts, threats, and vulnerabilities.

COMPETENCIES

High Stress Tolerance. Building and maintaining relationships. Teamwork and ability to function independently. Facilitation Skills. Adaptability. Attention to detail. Planning and organising. Ability to work independently. Interpersonal savvy. Decision quality. Plans and aligns. Optimises work processes. Being resilient. Collaborates. Cultivates innovation. Customer focus. Drives results. Sensitivity to Risk Balances Stakeholders Reporting and Administration

ADDITIONAL COMPETENCIES AND SKILLS

Programming Languages: It is crucial to understand the security considerations of languages like Java, Python, C#, JavaScript and emerging ones like Kotlin. Web Technologies: Familiarity with HTML, CSS, JavaScript frameworks like React and Angular, and web application security concepts is essential. Mobile Development: Security expertise in Android, iOS, and cross-platform frameworks like Flutter helps secure sensitive data on user devices. Cloud Security: A deep grasp of cloud platforms like AWS, Azure, and GCP and their security implications is vital for secure cloud deployments. API Security: Understanding API security best practices is critical to prevent unauthorized access and data breaches. Vulnerability Understanding: In-depth knowledge of common and obscure vulnerabilities in various technologies allows for accurate identification and exploitation for testing and mitigation purposes. Secure Coding Practices: Expertise in secure coding principles and best practices for different languages and frameworks empowers proactive vulnerability prevention. Threat Modelling: The ability to analyse application architecture and functionality to anticipate potential attack vectors and proactively address them is crucial. Security Scanners and Code Analysis Tools: It is vital to understand how to use these tools to identify vulnerabilities in code and recommend remediation strategies. Penetration Testing Tools: Familiarity with these allows for thorough vulnerability assessment and simulating real-world attack scenarios. Security Incident Response Tools: Knowledge of incident response tools and methodologies helps them effectively handle security breaches and minimize damage. Cryptography and Encryption: Understanding encryption algorithms and their application in securing data is essential.

ADDITIONAL COMPETENCIES AND SKILLS

ABOUT THE COMPANY

Santam is the leading short-term insurer in South Africa. Along with its subsidiaries, the business transacts all classes of short-term insurance. Santam is a large, diversified, and transforming company and our success is rooted in our passion for our clients. Everything we do is centered on our delivery of Insurance Good and Proper. 

Please note this appointment will be made in line with the Divisional Employment Equity targets. People with disabilities are welcome to apply



  • Cape Town, Western Cape, South Africa Santam Full time

    Career OpportunityA senior role for a Principal Application Security Architect in the Business Information and Technology Services (BITS) department at Santam in South Africa.


  • Cape Town, South Africa DigiCert, Inc. Full time

    at DigiCert Cape Town **ABOUT DIGICERT** We’re a leading, global security authority that’s disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world’s largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to little things like surgically embedded...


  • Cape Town, South Africa DigiCert Full time

    **ABOUT DIGICERT** We're a leading, global security authority that's disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world's largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to little things like surgically embedded pacemakers. We help companies...


  • Cape Town, Western Cape, South Africa Neptune Full time

    Job Description for Principal Network Architect at NeptuneThe Principal Network Architect will play a crucial role in designing, implementing, and maintaining Neptune's computer infrastructure and networks. This highly skilled individual will have experience in managing complex systems, troubleshooting system-related issues, and ensuring system security and...


  • Cape Town, Western Cape, South Africa South African Radio Astronomy Observatory Full time

    Job Title: Principal Systems ArchitectWe are seeking an experienced and skilled Principal Systems Architect to join our team at the South African Radio Astronomy Observatory.About the RoleThis is a senior position that requires strong technical expertise, leadership skills, and excellent communication abilities. As a Principal Systems Architect, you will be...


  • Cape Town, Western Cape, South Africa Principal Class Placements Full time

    Role Summary:Principal Architectural Technologist is a key position at Principal Class Placements, requiring a skilled and experienced Architectural Technologist to manage multiple projects from proposal through to construction.Key Responsibilities:Measurement & Scoping: Accurately measure and scope buildings to create detailed drawings that adhere to...

  • Security Architect

    6 months ago


    Cape Town, South Africa ABC Worldwide (Pty) Ltd Full time

    **Security Architect** **Key Responsibilities** - Providing security advice, requirements and guidance to the business when delivering new systems or updates to existing, to ensure Security by design. - Performing security-focused risk assessment on new systems/services and changes to existing to ensure they are within risk tolerance. - Working with the...

  • Security Architect

    6 months ago


    Cape Town, South Africa ABC Worldwide (Pty) Ltd Full time

    **Security Architect** **Key Responsibilities** - Providing security advice, requirements and guidance to the business when delivering new systems or updates to existing, to ensure Security by design. - Performing security-focused risk assessment on new systems/services and changes to existing to ensure they are within risk tolerance. - Working with the...

  • Application Architect

    6 months ago


    Cape Town, South Africa iLaunch Full time

    Convert logical architecture into physical architecture in AWS Experience leading the architecture and design Tertiary Qualification 5+ years in a Lead or Architect role **Proven track record using technologies such as**: C#.NET, SQL Server,AWS (In-depth knowledge of AWS services, Lambda, security, and compliance) Must have strong problem solving...

  • Security Architect

    8 months ago


    Cape Town, South Africa DAV Full time

    **RESPONSIBILITIES** - Security risk assessments on new systems and services - Working with businesses and various stakeholders to review designs and they are in line with existing security principles - Define, document, and implements ore security patterns - Reviewing current security processes - Working with the wider Security Architecture teams to ensure...


  • Cape Town, Western Cape, South Africa Principal Class Placements Full time

    We are seeking a skilled Professional Architectural Technologist to join our fast-growing development team at Principal Class Placements. This role offers the opportunity to manage multiple projects from proposal through to construction, making a significant impact on design and development process.Key Responsibilities:Measurement & Scoping: Accurately...


  • Cape Town, Western Cape, South Africa BET Software Full time

    Unlock Your Potential in a Thriving Tech HubAbout the RoleWe are seeking a highly skilled Principal Software Architect to join our dynamic team at BET Software in Cape Town. As a key member of our development team, you will play a pivotal role in designing, coding, and refining complex software solutions that shape the future of innovation.This is an...


  • Cape Town, Western Cape, South Africa Dimension Data Full time

    About the RoleAs a highly skilled Application Solution Architect at Dimension Data, you'll be responsible for designing and developing software solutions that meet our clients' needs. Your day-to-day tasks will involve working closely with a team of developers to build new features and create software applications using Microsoft technologies.Key...


  • Cape Town, Western Cape, South Africa Communicate Recruitment Full time

    Company OverviewWe are a leading recruitment agency, Communicate Recruitment, dedicated to connecting talented professionals with exciting opportunities in the tech industry.SalaryThe estimated salary for this position is $120,000 per annum, commensurate with experience and qualifications.Job DescriptionWe are seeking a highly skilled Principal Software...


  • Cape Town, South Africa Redherd Full time

    Our client is a South African based security vendor with a global reach and customers in the highest spheres of technology and innovation. They provide real-time reporting on adversaries interacting with your networks or snooping around your infrastructure, allowing you to identify and defend against attacks. They are extremely vested in the global security...


  • Cape Town, Western Cape, South Africa SBV Services Ltd. Full time

    Job Title: Chief Information Security ArchitectAbout the Role:We are seeking an experienced Chief Information Security Architect to join our team at SBV Services Ltd. This is a unique opportunity to drive the development and implementation of our information security strategy, ensuring the confidentiality, integrity, and availability of our systems and...


  • Cape Town, South Africa Electrum Payments Full time

    As a Principal Solutions Architect at Electrum, you will play a pivotal role in driving our technical solutions to align seamlessly with client needs and market trends. You will be a source of technical guidance and expertise, support our clients in achieving their strategic objectives and drive our continued growth. **Responsibilities** - Client Pre-sales...


  • Cape Town, Western Cape, South Africa Datafin IT Recruitment Full time

    **Job Overview**Datafin IT Recruitment is seeking an experienced Cyber Security Specialist - Systems Architect to join a dynamic Healthcare Service Provider. This role requires a strong passion for Information Governance and Cyber Security, with technical expertise in optimization, monitoring, and support of internal and client-facing Security &...


  • Cape Town, Western Cape, South Africa Parvana Full time

    About Our Client: Parvana is a renowned international software development house specialising in telecommunications and payment gateways. With a proven track record of remarkable growth, they offer an exceptional training and mentorship program. What You Will Be Doing: As a Cyber Security Architect, you will be responsible for developing and maintaining...

  • Mobile Architect

    4 weeks ago


    Cape Town, South Africa RealmDigital Full time

    Overview Our client a leading financial institution dedicated to innovation and customer satisfaction is on the look out for a Mobile Architect who can drive their native i OS and Android platforms to new heights, ensuring that our mobile banking experience is top-notch, reliable, and secure for our users. Purpose As the Native Mobile Architect for i OS &...