Senior Security Analyst
- Location
- Cape Town, Western Cape
- Minimum qualification
- Bachelor's degree
- Closing date
- Not stated — check the original listing
First listed . Last checked at source .
In brief
**Overview** Ozow is a leading fintech company in South Africa that is redefining digital payments, aiming to make payments more accessible, secure, and convenient for both businesses and consumers. As a fast-growing player in the sector, Ozow fosters a culture of innovation, diversity, and inclusivity. The Senior Security Analyst position is the most senior hands-on security specialist role at Ozow. This individual will be accountable for the strength of the company's security posture and for protecting the integrity, availability, and confidentiality of its systems and data. Reporting to the Infrastructure Manager, the role involves owning and evolving the security programme, rather than merely executing it. This is a deeply technical position for someone who enjoys both breaking and securing systems, and who is ready to set direction, lift security capability across the business, and translate technical risk into actionable decisions for leadership, auditors, banks, and merchants. **What you will do** Key responsibilities for this role include: * **Security direction and technical leadership:** Owning and evolving the security roadmap, defining security standards, baselines, and testing methodology, mentoring engineers and infrastructure specialists, and reporting security posture, risk, and progress to senior leadership. * **Offensive security and assurance:** Leading hands-on penetration testing across infrastructure, cloud workloads, applications, APIs, and endpoints; designing and running adversary simulations and red team exercises; validating remediation through retesting; and driving a purple-team approach with Engineering. * **Security operations and incident response:** Owning the selection, implementation, and tuning of security tooling (SIEM, EDR, scanners, WAFs, IDS/IPS); setting the detection and monitoring strategy, and defining escalation paths and response playbooks; acting as technical lead during incidents; and running post-incident reviews to implement permanent control improvements. * **Vulnerability management and hardening:** Owning end-to-end vulnerability management across cloud infrastructure, applications, CI/CD pipelines, and endpoints; defining risk-based prioritisation and remediation SLAs; acting as design authority on secure architecture, least privilege, segmentation, and encryption; and defining and enforcing secure configuration baselines aligned to CIS Benchmarks where applicable. * **Automation and enablement:** Automating repeatable security work such as triage, reporting, evidence collection, and remediation tracking; owning external penetration testing engagements; defining safe, controlled GenAI use cases for security, including guardrails; and embedding security into engineering practice, pipelines, and workflows (DevSecOps). * **Compliance, governance, and stakeholders:** Leading the technical workstream for audits across PCI DSS, ISO 27001, POPIA, and relevant SARB directives; owning internal security policies and standards, and advising Risk on where risk acceptance is appropriate; and leading technical responses for merchant and bank due diligence and security questionnaires. **Requirements (from the original advert)** * Bachelor’s degree in computer science, Information Security, or a related field, or equivalent experience. * 8+ years in cybersecurity, offensive security, security engineering, or security operations, including clear ownership of a security programme or domain. * Deep hands-on penetration testing and adversary simulation experience, and experience leading incidents through to root cause and closure. * A track record in vulnerability management at scale, including setting SLAs and driving remediation across teams you do not manage. * Deep working knowledge of ISO 27001, NIST, PCI DSS, CIS Benchmarks, and OWASP, and how to evidence them under audit. * Experience selecting and implementing security tooling, not only operating it. * Strong AWS security expertise or another major cloud. * Scripting ability. * Able to influence without authority, and to take a technical risk to an executive, an auditor, or a merchant and be understood. * Self-directed and pragmatic, focused on practical risk reduction over perfect security. * **Advantageous skills/experience:** OSCP, OSCE, CRTO, CREST, CISSP, or AWS Security Specialty certifications, and regulated-environment experience. **Who should apply** The ideal candidate is someone who: * Is able to influence without authority and effectively communicate technical risk to diverse audiences including executives, auditors, and merchants. * Is self-directed, pragmatic, and focused on practical risk reduction over theoretical perfection. * Eagerly embraces change, absorbs cross-functional skills, and connects ideas across disciplines to drive fresh thinking and innovation. * Possesses the ability to initiate, develop, maintain, and leverage outstanding relationships to influence a wide network, both inside and outside the company. * Is a trailblazer who steps up, takes charge, and creates meaningful impact, driven by performance and purpose to lead from the front. * Thrives in collaboration, embraces inclusion, and brings a genuine curiosity for global cultures, valuing collective success over individual credit. * Demonstrates strategic foresight, sound judgement, and the ability to make confident decisions under uncertainty, always working toward the best possible outcomes. * Challenges norms, champions innovation, and constantly seeks growth for themselves, their team, and the solutions they build. * Is a decisive doer who takes initiative, follows through with confidence, and ensures results through courageous, hands-on leadership. * Values optimism, agility, and the strength to persevere under pressure, balancing performance with positivity. * Is driven, proactive, takes ownership, faces challenges with grit, and consistently pushes for excellence. * Demonstrates a high level of integrity and trustworthiness, professionalism, accountability, and a commitment to ethical conduct in line with financial regulations and industry standards. **Deadline** Not specified **Reference** Original posting: https://job-boards.greenhouse.io/ozow/jobs/8000434003 Source: greenhouse
Summary drafted with AI assistance from the original advert. The advert itself is the authority — how we use AI.
At a glance
- AWS
Extracted automatically from the advert; confirm requirements on the original listing.
Job description
Before you apply
- Confirm the requirements and closing date on the original listing (greenhouse). SPANi lists vacancies from other sites and may not reflect last-minute changes.
- Legitimate employers do not charge application, registration or training fees.
- Don't send your ID or bank details before you have confirmed the employer is real.
Before you apply
- Read the full advert and confirm you meet the minimum requirements before applying.
- Tailor your CV headline and most recent experience to the job title and key skills.
- Note the closing date and reference number, and keep a copy of what you submit.
- Apply only through the employer or job board link — never pay to apply.