Security Engineer - Cloud & Infrastructure

Apex Group

  • Cape Town, Western Cape
  • Permanent
  • Full-time
  • 1 month ago
The Apex Group was established in Bermuda in 2003 and is now one of the world’s largest fund administration and middle office solutions providers.Our business is unique in its ability to reach globally, service locally and provide cross-jurisdictional services. With our clients at the heart of everything we do, our hard-working team has successfully delivered on an unprecedented growth and transformation journey, and we are now represented by over circa 13,000 employees across 112 offices worldwide.Your career with us should reflect your energy and passion.That’s why, at Apex Group, we will do more than simply ‘empower’ you. We will work to supercharge your unique skills and experience.Take the lead and we’ll give you the support you need to be at the top of your game. And we offer you the freedom to be a positive disrupter and turn big ideas into bold, industry-changing realities.For our business, for clients, and for youThe RoleAs a Cloud and Infrastructure Security Engineer, you’ll work across multiple security domains, with emphasis on building, maintaining, and improving security controls that protect Apex’s global technology environmentKey Responsibilities
  • Deploy, configure, and manage security solutions across cloud (AWS, Azure, OCI) and on-premises infrastructure.
  • Implement and maintain controls for network security, IAM, endpoint protection, and cloud governance.
  • Support the secure design and integration of hybrid and multi-cloud environments.
  • Conduct security assessments, vulnerability analysis, and remediation of cloud and infrastructure assets.
  • Collaborate with platform, infrastructure, and application teams to embed security into solutions from design to operation.
  • Monitor for and respond to security incidents affecting cloud and infrastructure services.
  • Maintain documentation including architecture diagrams, security control mappings, and operational procedures.
  • Research and recommend new technologies, tools, and practices to enhance security posture.
  • Ensure compliance with relevant frameworks and internal security standards (e.g., NIST, ISO 27001, CSA CCM).
Areas of Focus
  • Deploy, configure, and manage security controls for AWS, Azure, and OCI environments.
  • Implement cloud-native security controls including Security Groups, IAM policies, KMS, and encryption.
  • Integrate and manage CSPM and CWPP tools to monitor and enforce cloud security posture.
  • Enforce least privilege and Zero Trust principles across cloud accounts and subscriptions.
  • Secure cloud and infrastructure environments supporting mergers and acquisitions.
  • Implement and manage Microsoft 365 security baselines, Conditional Access, and Intune compliance.
  • Harden operating systems, containers, and virtual machines following best practices.
  • Design and maintain secure network architectures for hybrid and multi-cloud connectivity.
  • Configure firewalls, WAFs, VPN gateways, and implement network segmentation.
  • Deploy intrusion prevention/detection (IPS/IDS) and network monitoring solutions.
  • Support DDoS protection strategies and integrate with cloud provider capabilities.
  • Conduct patching, vulnerability scanning, and secure configuration audits.
  • Manage identity federation, SSO, MFA, and enforce strong authentication policies.
  • Investigate and respond to incidents affecting cloud workloads, networks, or infrastructure.
  • Map cloud and infrastructure security controls to frameworks such as NIST CSF, ISO 27001, and CSA CCM.
  • Maintain asset inventory and ensure continuous compliance with corporate security standards.
  • Research and recommend new security tools, services, and best practices to strengthen defenses.
Required Experience & Skills
  • 5–8 years of experience in cybersecurity, cloud, or infrastructure roles, with a focus on security engineering.
  • Proven hands-on experience with AWS, Azure
  • Strong knowledge of network security, IAM, endpoint protection, and vulnerability management.
  • Familiarity with Kubernetes, CI/CD security, and cloud automation (Terraform, Ansible, etc.).
  • Understanding of security frameworks (NIST, ISO 27001, CSA CCM, MITRE ATT&CK).
  • Ability to troubleshoot and resolve security incidents in complex environments.
  • Strong communication skills to work effectively with both technical and non-technical stakeholders.
  • Relevant certifications such as CCSP, CISSP, AWS/Azure Security Engineer, or equivalent are advantageous.
What will you get in return:
  • Opportunity to work with senior security professionals across multiple global teams.
  • Exposure to cutting-edge cloud and infrastructure technologies.
  • Flexible work options and a strong focus on collaboration and growth.
  • A role where you can directly influence Apex’s global security posture.
Additional information:We are an equal opportunity employer and ensure that no applicant is subject to less favourable treatment on the grounds of gender, gender identity, marital status, race, colour, nationality, ethnicity, age, sexual orientation, socio-economic, responsibilities for dependents, physical or mental disability. Any hiring decision are made on the basis of skills, qualifications and experiences. We measure our success as a business, not only by delivering great products and services and continually increasing our assets under administration and market share, but also by how we positively impact people, society and the planet. For more information on our commitment to Corporate Social Responsibility (CSR) please visit . If you are looking to take that next step in your career and are ready to work for a high performing organization, alongside talented people who take pride in delivering great results, please submit your application (with your CV, cover letter and salary’s expectations).Disclaimer: Unsolicited CVs sent to Apex (Talent Acquisition Team or Hiring Managers) by recruitment agencies will not be accepted for this position. Apex operates a direct sourcing model and where agency assistance is required, the Talent Acquisition team will engage directly with our exclusive recruitment partners.

Apex Group