Live opening · Posted 3 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Meet Ozow
Ozow is a leading fintech company that’s redefining digital payments in South Africa and beyond, making payments more accessible, secure, and convenient for businesses and consumers alike. As a fast-growing player in the sector, we foster a culture of innovation, diversity, and inclusivity.
More about this Ozow fantastic position
The Senior Security Analyst is the most senior hands-on security specialist at Ozow, accountable for the strength of our security posture and for protecting the integrity, availability, and confidentiality of our systems and data. Reporting into the Infrastructure Manager, this role owns and evolves the security programme rather than only executing it.
This is a deeply technical role for someone who enjoys both breaking and securing systems, and who is ready to set direction. You will set the standards, lift security capability across the business, and translate technical risk into decisions that leadership, auditors, banks, and merchants can act on.
Your role and responsibilities
Security direction and technical leadership
Own and evolve the security roadmap with the Infrastructure Manager, sequenced by risk and business impact.
Define security standards, baselines, and testing methodology, and hold teams to them.
Mentor engineers and infrastructure specialists, and set the testing strategy: what is tested, how often, and to what depth.
Report security posture, risk, and progress to senior leadership in terms the business can act on.
Offensive security and assurance
Lead hands-on penetration testing across infrastructure, cloud workloads, applications, APIs, and endpoints.
Design and run adversary simulations and red team exercises to validate real-world defensive capability.
Validate remediation through retesting, and drive a purple-team approach with Engineering.
Security operations and incident response
Own the selection, implementation, and tuning of security tooling (SIEM, EDR, scanners, WAFs, IDS/IPS).
Set the detection and monitoring strategy, and define escalation paths and response playbooks.
Act as technical lead during incidents, coordinating Infrastructure, Engineering, and Risk through to closure.
Run post-incident reviews and turn findings into permanent control improvements.
Vulnerability management and hardening
Own vulnerability management end to end across cloud infrastructure, applications, CI/CD pipelines, and endpoints.
Define risk-based prioritisation and remediation SLAs, and drive closure across teams.
Act as design authority on secure architecture, least privilege, segmentation, and encryption.
Define and enforce secure configuration baselines, aligned to CIS Benchmarks where applicable.
Automation and enablement
Automate repeatable security work: triage, reporting, evidence collection, and remediation tracking, and own external penetration testing engagements end to end.
Define safe, controlled GenAI use cases for security, including the guardrails around them.
Embed security into engineering practice, pipelines, and workflows (DevSecOps).
Compliance, governance, and stakeholders
Lead the technical workstream for audits across PCI DSS, ISO 27001, POPIA, and relevant SARB directives.
Own internal security policies and standards, and advise Risk on where risk acceptance is appropriate.
Lead technical responses for merchant and bank due diligence and security questionnaires.
You are an ideal candidate if you have
Bachelor’s degree in computer science, Information Security, or a related field, or equivalent experience.
More openings worth a look
Recently tracked roles with full details and direct application links.