Senior Security Operations Engineer

Lula

  • Cape Town, Western Cape
  • Permanent
  • Full-time
  • 9 days ago
Job title: Senior Security Operations EngineerReporting to: Engineering Team LeadLocation: Cape TownALL STAFF APPOINTMENTS WILL BE MADE WITH DUE CONSIDERATION OF THE COMPANY'S EE TARGETSWHAT WE DOLula is an innovative and human-focused FinTech company on a mission to help small businesses optimise their cash flow. Our purpose is to help SMEs manage their businesses better, faster, and more simply, so they can spend more time doing what they love.If you're looking for a new place to call ‘home' that believes in the potential of the broader SME landscape in South Africa and a place where you'll work with awesome people - then Lula's the place for you!We're making business banking fast, human, Lula!CULTURE CODEWe embrace CuriosityWe win as OneWe're Driven by PurposeWe Execute with AmbitionOVERALL PURPOSEWe are looking for a Senior Security Operations Engineer to join our team. The successful candidate will be responsible for securing, monitoring, and maintaining the overall security posture of our Azure platform and infrastructure, as well as our on-site networks and systems. You will work closely with all departments and teams to implement and provide guidance on security best practices and regulatory compliance. As a Senior Security Operations Engineer, you will also be responsible for identifying and responding to security incidents and conducting security assessments, audits and simulations.Responsibilities will include:
  • Infrastructure Security
  • Partner with our DevSecOps team to design, implement and manage security controls and policies for our Microsoft Azure Infrastructure
  • Partner with our Engineering teams to ensure that code deployed on Lula's infrastructure is done securely
  • Conduct regular security assessments and audits of Azure and internal infrastructure and platforms, including vulnerability scanning and penetration testing
  • Identity Security
  • Manage and regularly audit our privileged accounts to ensure access remains relevant and required
  • Design, implement and manage policies and controls to secure Lula's accounts and access to our resources using Microsoft Entra ID toolsets
  • Provide security awareness training to the business to improve our security posture
  • Perform security incident/phishing simulations to ensure our processes and training are robust and effective
  • On-Premise Security
  • Monitor and manage Lula's access control and camera systems
  • Provide guidance and support to internal departments on handling of confidential information
  • Partner with our Technical Support team to ensure Lula's network and endpoints are configured securely and monitored for threats
  • Regulatory Compliance and Governance
  • Be a critical part of Lula's PCI DSS annual re-certification process
  • Develop and maintain security documentation including policies, procedures and technical standards that adhere to compliance requirements
  • Collaborate with external auditors and partners to ensure compliance with various regulatory requirements and industry standards
  • Security Incident Management
  • Be the key point of contact for security incident and alert investigations
  • Develop remediation plans, conduct Root Cause Analysis' and provide corrective and preventative measures during Post Incident Reviews
  • Participate in on-call rotation to provide 24/7 support for Security Incidents
THE SKILLS AND EXPERIENCE WE'RE LOOKING FOR
  • Tertiary qualification in Computer Science, Information Security, or equivalent experience
  • 5+ years of experience in a SecOps field, preferably using Microsoft technologies, with a focus on Azure
  • Expert knowledge of Cloud focussed security features, including Azure Defender for Cloud, Azure Sentinel, Entra ID, Front Door, Privileged Identity Management, Intune and Defender for Endpoint
  • Experience with security assessments and audits, including vulnerability scanning, penetration testing and incident simulations
  • Hands-on Kali experience would be beneficial
  • Exposure to configuring SAST tools, like SonarCloud
  • Familiarity with industry standards and regulatory requirements, such as POPIA, PCI DSS and ISO 27001
  • Familiarity with security related network technologies such as firewalls & VPNs
  • Azure or Cyber Security certifications, such as Azure Security Engineer Associate, Azure Solutions Architect Expert or CISSP are a plus
  • Knowledge of securing coding practices, like OWASP
  • Knowledge of secure API implementation technologies, OAuth and OIDC
Please note that all appointments are subject to our background checking process, which may include Credit, Criminal and any other job inherent checks.

Lula

Similar Jobs

  • Senior Data Engineer

    Network Recruitment

    • Cape Town, Western Cape
    Key Responsibilities: Design, build, and maintain scalable data pipelines and ETL processes. Develop and optimize data models, ensuring data quality, accuracy, and accessibilit…
    • 17 hours ago
  • Cyber Security Engineer

    Pure Placements

    • Cape Town, Western Cape
    Location: Cape Town (Century City), On-Site Salary: R 840,000 - R 1,080,000 Annual CTC Benefits: Medical Aid Contribution Travel: Occasional international travel required The …
    • 17 hours ago
  • Intermediate Data Engineer

    Network Recruitment

    • Cape Town, Western Cape
    Key Responsibilities: Design, develop, and maintain efficient data pipelines and ETL processes. Build and optimize data models to ensure accuracy, accessibility, and performanc…
    • 17 hours ago