
Security Engineer - Cloud & Infrastructure
- Cape Town, Western Cape
- Permanent
- Full-time
- Deploy, configure, and manage security solutions across cloud (AWS, Azure, OCI) and on-premises infrastructure.
- Implement and maintain controls for network security, IAM, endpoint protection, and cloud governance.
- Support the secure design and integration of hybrid and multi-cloud environments.
- Conduct security assessments, vulnerability analysis, and remediation of cloud and infrastructure assets.
- Collaborate with platform, infrastructure, and application teams to embed security into solutions from design to operation.
- Monitor for and respond to security incidents affecting cloud and infrastructure services.
- Maintain documentation including architecture diagrams, security control mappings, and operational procedures.
- Research and recommend new technologies, tools, and practices to enhance security posture.
- Ensure compliance with relevant frameworks and internal security standards (e.g., NIST, ISO 27001, CSA CCM).
- Deploy, configure, and manage security controls for AWS, Azure, and OCI environments.
- Implement cloud-native security controls including Security Groups, IAM policies, KMS, and encryption.
- Integrate and manage CSPM and CWPP tools to monitor and enforce cloud security posture.
- Enforce least privilege and Zero Trust principles across cloud accounts and subscriptions.
- Secure cloud and infrastructure environments supporting mergers and acquisitions.
- Implement and manage Microsoft 365 security baselines, Conditional Access, and Intune compliance.
- Harden operating systems, containers, and virtual machines following best practices.
- Design and maintain secure network architectures for hybrid and multi-cloud connectivity.
- Configure firewalls, WAFs, VPN gateways, and implement network segmentation.
- Deploy intrusion prevention/detection (IPS/IDS) and network monitoring solutions.
- Support DDoS protection strategies and integrate with cloud provider capabilities.
- Conduct patching, vulnerability scanning, and secure configuration audits.
- Manage identity federation, SSO, MFA, and enforce strong authentication policies.
- Investigate and respond to incidents affecting cloud workloads, networks, or infrastructure.
- Map cloud and infrastructure security controls to frameworks such as NIST CSF, ISO 27001, and CSA CCM.
- Maintain asset inventory and ensure continuous compliance with corporate security standards.
- Research and recommend new security tools, services, and best practices to strengthen defenses.
- 5–8 years of experience in cybersecurity, cloud, or infrastructure roles, with a focus on security engineering.
- Proven hands-on experience with AWS, Azure
- Strong knowledge of network security, IAM, endpoint protection, and vulnerability management.
- Familiarity with Kubernetes, CI/CD security, and cloud automation (Terraform, Ansible, etc.).
- Understanding of security frameworks (NIST, ISO 27001, CSA CCM, MITRE ATT&CK).
- Ability to troubleshoot and resolve security incidents in complex environments.
- Strong communication skills to work effectively with both technical and non-technical stakeholders.
- Relevant certifications such as CCSP, CISSP, AWS/Azure Security Engineer, or equivalent are advantageous.
- Opportunity to work with senior security professionals across multiple global teams.
- Exposure to cutting-edge cloud and infrastructure technologies.
- Flexible work options and a strong focus on collaboration and growth.
- A role where you can directly influence Apex’s global security posture.