Cloud Security Engineer (L2)
Cape Town - South Africa
Job Summary
Stellenbosch Cape Town South Africa Predominantly Onsite Intermediate
Job Purpose
We are seeking a Cloud Security Engineer to join the Security Operations and Engineering team. The successful candidate will be responsible for the operational security governance monitoring and ongoing management of Azure cloud environments.
The role will focus on maintaining secure cloud infrastructure enforcing security controls ensuring compliance responding to security incidents and driving continuous improvement of cloud security capabilities.
The successful candidate will work closely with Security Operations Infrastructure Identity Management and Cloud Engineering teams.
Key Responsibilities
Azure Cloud Security Management
- Administer and maintain Azure security controls and configurations.
- Manage and monitor Azure security posture through Microsoft Defender and Azure-native security tooling.
- Ensure compliance of:
- Privileged Identity Management (PIM)
- Role Based Access Control (RBAC)
- Service Principals
- Managed Identities
- Break Glass Accounts
- Maintain cloud security baselines and standards.
- Monitor cloud infrastructure for threats security events and vulnerabilities.
- Investigate security alerts and recommend remediation activities.
- Support threat detection monitoring and logging activities.
- Assist with cloud incident response and remediation.
- Ensure compliance with governance and risk management frameworks.
- Support cloud security hardening initiatives.
Identity & Access Security
- Maintain Azure AD / Entra security controls.
- Monitor privileged access activities.
- Support identity governance reviews.
- Conduct access reviews and permissions audits.
- Ensure compliance with Zero Trust principles.
Vulnerability Management
- Work with system owners to remediate identified vulnerabilities.
- Perform vulnerability reviews and risk assessments.
- Assist with security compliance reviews.
Security Operations
- Investigate security incidents and alerts.
- Collaborate with SOC teams during incident response activities.
- Support remediation and lessons learned exercises.
- Assist with security reporting and compliance documentation.
Automation & Continuous Improvement
- Support automation initiatives using PowerShell Logic Apps Sentinel Automation Rules and Playbooks.
- Identify opportunities for operational improvement.
- Assist with developing security operational runbooks and documentation.
Minimum Requirements
Education
- Degree in Information Security Computer Science Information Technology or related discipline preferred.
- Relevant Microsoft certifications advantageous.
Experience
- 35 years experience in IT Security or Cloud Security.
- Hands-on Azure administration and cloud security experience.
- Experience working with Microsoft security technologies.
- Experience with vulnerability management and security monitoring.
Technical Skills
- Microsoft Azure
- Microsoft Defender Suite
- Microsoft Entra ID
- Azure Security Centre / Defender for Cloud
- Microsoft Sentinel
- PIM
- RBAC
- KQL
- Security monitoring and incident response
- Vulnerability management
Certifications Advantageous
- AZ-500
- SC-200
- SC-300
- AZ-104