The Senior Cybersecurity Engineer serves as a senior technical authority responsible for protecting the organization's information assets, systems, and digital infrastructure. Operating as a lead individual contributor within the Information Technology team, this role oversees core defensive security capabilities across endpoint, SIEM/SOC, identity, data loss prevention, web, and email security.
The position blends deep hands-on technical execution with operational risk governance,leading incident response workflows, driving vulnerability remediation, enforcing application and API security standards across development lifecycles, translating threat intelligence into actionable defenses, and mentoring junior security personnel.
Security Operations & Incident Response:
Oversee enterprise SIEM/SOC operations, manage EDR/XDR deployments, and lead end-to-end incident handling (triage, containment, root-cause analysis, forensic investigation, and post-incident reporting).
Identity, Access & Data Protection:
Enforce identity governance, Multi-Factor Authentication (MFA), Single Sign-On (SSO), and Privileged Access Management (PAM). Configure and govern data security frameworks, information classification, and Data Loss Prevention (DLP) policies.
Application, Web & API Security (DevSecOps):
Establish and govern secure software development lifecycle (Secure SDLC) standards—including SAST, DAST, SCA, secrets management, and CI/CD security controls. Define and enforce API security architectures aligned to OWASP Top 10 standards (OAuth 2.0, OIDC, JWT, rate limiting, gateway policies). Manage Web Application Firewalls (WAF) to defend against DDoS, botnets, and application-layer threats.
Cloud, Container & Infrastructure Defense:
Monitor and secure cloud environments, containerized workloads, and Kubernetes clusters using CSPM/CNAPP tools and container scanning. Oversee network boundary controls, PKI/certificate lifecycle management, encryption standards, and email authentication mechanisms (SPF, DKIM, DMARC).
Vulnerability Management & Threat Intelligence:
Coordinate continuous vulnerability identification and remediation workflows, track penetration testing action items, analyze attacker TTPs, and operationalize external threat intelligence into active defensive postures.
Governance, Risk & Compliance Support:
Map technical controls and provide audit assurance against recognized industry frameworks and regulatory mandates (including ISO 27001, NIST CSF, CIS Controls, and POPIA).
Leadership & Security Culture:
Act as a subject-matter expert across cross-functional engineering teams, drive enterprise security awareness and simulated phishing campaigns, and mentor cybersecurity interns and junior analysts.
| Domain | Core Focus Areas |
| Endpoint & Threat Hunting (EDR/XDR) | Enterprise endpoint prevention, investigation, rapid containment, and host isolation. |
| Monitoring & Operations (SIEM/SOC) | Centralized logging, correlation rule development, alerting triage, and SOC oversight. |
| Identity & Access Management (IAM) | Principle of least privilege, Privileged Identity Management (PIM), identity lifecycles, and access governance. |
| Information Protection | Classification labelling, Microsoft Purview / enterprise DLP, and sensitive asset protection. |
| Application & API Security | OWASP Top 10 / API Top 10, gateway architecture, code review oversight, CI/CD pipeline scanning, token-based authentication. |
| Cloud & Container Security | CSPM/CNAPP, infrastructure as code (IaC) verification, container image scanning, and Kubernetes security. |
| Perimeter & Email Defense | WAF rule configuration, anti-DDoS, mail filtering, business email compromise (BEC) investigation, SPF/DKIM/DMARC. |
| Cryptography & PKI | Certificate authorities, key management systems, and enterprise TLS configurations. |
| Automation & Scripting | Automation of repetitive analytical tasks and custom reporting (e.g., Python, PowerShell, KQL). |
Education: Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or an equivalent technical qualification. Relevant postgraduate qualifications are advantageous.
Experience: 7+ years of progressive hands-on information security experience, demonstrating senior-level competence across enterprise security operations, threat detection, DevSecOps, and incident response in complex environments.
Demonstrated Track Record: Proven background reviewing technical architectures, collaborating with senior business and engineering stakeholders, and managing external cybersecurity service providers.
General Security Management: CISSP, CISM
Threat Detection & Offensive Operations: GIAC (GCIH, GCFA, etc.), CEH
Platform & Cloud Credentials: Microsoft Certified: Cybersecurity Architect / Security Operations Analyst, EDR/XDR specialist accreditations, or recognized enterprise cloud/WAF security certifications.
Strong analytical, root-cause investigation, and structured problem-solving skills.
Calm, decisive execution under pressure during active cyber incidents.
Clear verbal and technical communication skills, with the ability to convey complex cyber risk to non-technical executive stakeholders.
Uncompromising professional integrity, confidentiality, and sound risk-based technical judgement.
You'll apply on Moladira Skills's own site before 1 November 2026. Put your most relevant experience at the top of your CV first.
Apply NowReal employers never ask you to pay to apply. How to spot a job scam