JobVault never charges job seekers. Learn how to stay safe →
Back to all jobs
Finance
full time

Senior Security Analyst

OzowCape Town

Salary

Not disclosed

Job Type

full time

Posted

about 3 hours ago

Closing date

25 Nov 2026

Share:WhatsAppLinkedIn

Job Description

Ozow, a prominent South African fintech innovator, is seeking a highly skilled and experienced Senior Security Analyst to bolster its cybersecurity defences. This pivotal role is entrusted with safeguarding the integrity, availability, and confidentiality of Ozow's critical systems and sensitive data as the company continues its rapid expansion in the digital payments landscape. This is not merely an execution-focused position; it demands a strategic thinker capable of owning and advancing the organisation's entire security programme.

About the Role

Reporting directly to the Infrastructure Manager, the Senior Security Analyst will be the most senior, hands-on security specialist within the company. The core mandate of this role is to proactively shape and continuously improve Ozow's security posture. This involves not only identifying potential threats but also designing and implementing robust defence mechanisms. The successful candidate will be instrumental in charting the course for the security programme, ensuring it remains aligned with evolving risks and critical business objectives. A significant aspect of the role involves translating complex security issues and progress into clear, actionable insights for senior leadership, enabling informed decision-making.

Key Responsibilities

The Senior Security Analyst will undertake a wide array of responsibilities critical to maintaining a strong security framework. Key duties include:

  • **Strategic Security Planning:** Collaborating with the Infrastructure Manager to develop and refine the security roadmap, prioritising initiatives based on risk assessment and business impact.
  • **Defining Security Standards:** Establishing comprehensive security standards, baselines, and testing methodologies, and ensuring adherence across relevant teams.
  • **Mentorship and Strategy:** Providing guidance and mentorship to engineering and infrastructure specialists, and defining the organisation's testing strategy, encompassing scope, frequency, and depth.
  • **Hands-on Security Testing:** Leading in-depth penetration testing across various environments, including infrastructure, cloud platforms, applications, APIs, and endpoints.
  • **Adversary Simulation:** Designing and executing sophisticated adversary simulation and red team exercises to rigorously validate the effectiveness of existing defensive capabilities in real-world scenarios.
  • **Remediation and Collaboration:** Validating the effectiveness of security fixes through retesting and fostering a collaborative "purple-team" approach with the Engineering department to enhance mutual understanding and defence.
  • **Security Tooling Management:** Overseeing the selection, implementation, configuration, and ongoing optimisation of essential security tools such as SIEM, EDR, vulnerability scanners, WAFs, and IDS/IPS.
  • **Detection and Response:** Defining the strategy for security detection and monitoring, establishing clear escalation paths, and developing comprehensive response playbooks.
  • **Incident Leadership:** Acting as the technical lead during security incidents, coordinating efforts across Infrastructure, Engineering, and Risk teams until resolution. Conducting post-incident reviews to identify root causes and implement permanent control improvements.
  • **Vulnerability Management:** Owning the end-to-end vulnerability management lifecycle across cloud infrastructure, applications, CI/CD pipelines, and endpoints, including defining risk-based prioritisation, SLAs, and driving remediation efforts.
  • **Secure Architecture Design:** Serving as the design authority for secure architectural principles, including least privilege, network segmentation, and encryption strategies.
  • **Configuration Management:** Defining and enforcing secure configuration baselines, leveraging established frameworks like CIS Benchmarks where appropriate.
  • **Automation and Efficiency:** Automating repetitive security tasks such as triage, reporting, evidence collection, and remediation tracking.
  • **External Engagements:** Managing external penetration testing engagements from initiation to completion.
  • **Generative AI Security:** Defining secure and controlled use cases for Generative AI within security operations, including establishing necessary guardrails.
  • **DevSecOps Integration:** Embedding security practices into engineering workflows and pipelines to foster a DevSecOps culture.
  • **Audit and Compliance:** Leading the technical workstreams for audits related to PCI DSS, ISO 27001, POPIA, and relevant SARB directives.
  • **Policy Development:** Owning internal security policies and standards, and advising the Risk department on appropriate risk acceptance strategies.
  • **Due Diligence:** Handling technical responses for merchant and bank due diligence requests and security questionnaires.

What They're Looking For

Ozow is seeking a candidate with a robust foundation in cybersecurity, demonstrated through extensive experience and specific qualifications. Ideal candidates will possess:

  • A Bachelor's degree in Computer Science, Information Security, or a related discipline, or equivalent practical experience.
  • A minimum of 8 years of experience in cybersecurity, offensive security, security engineering, or security operations. A proven track record of directly owning and evolving a security programme or a significant security domain is essential.
  • Deep, hands-on expertise in penetration testing and adversary simulation, coupled with demonstrable experience leading security incidents from detection through to root cause analysis and resolution.
  • A strong history of managing vulnerability programmes at scale, including the ability to establish remediation SLAs and effectively drive closure across teams that the individual does not directly manage.
  • In-depth working knowledge of key security frameworks and standards such as ISO 27001, NIST, PCI DSS, CIS Benchmarks, and OWASP, with the ability to demonstrate compliance during audits.
  • Substantial experience in selecting and implementing security tooling, beyond mere operational use. Proficiency in AWS security or another major cloud provider, along with scripting capabilities, is required.
  • Certifications such as OSCP, OSCE, CRTO, CREST, CISSP, or AWS Security Specialty, and experience operating within regulated environments, would be advantageous.
  • The ability to influence stakeholders effectively without direct authority, and to communicate technical risks clearly and understandably to executives, auditors, and business partners.
  • A self-directed, pragmatic approach focused on delivering practical risk reduction rather than striving for unattainable "perfect" security.

This role offers a significant opportunity to shape the security future of a dynamic fintech company in South Africa. It requires a blend of technical acumen, strategic thinking, and strong interpersonal skills to navigate the complexities of modern cybersecurity threats.

Requirements

  • Bachelor’s degree in computer science, Information Security, or a related field, or equivalent experience.
  • 8+ years in cybersecurity, offensive security, security engineering, or security operations, including clear ownership of a security programme or domain.
  • Deep hands-on penetration testing and adversary simulation experience, and experience leading incidents through to root cause and closure.
  • A track record in vulnerability management at scale, including setting SLAs and driving remediation across teams you do not manage.
  • Deep working knowledge of ISO 27001, NIST, PCI DSS, CIS Benchmarks, and OWASP, and how to evidence them under audit.
  • Experience selecting and implementing security tooling, not only operating it, strong AWS security expertise or another major cloud, and scripting ability.
  • Advantageous: OSCP, OSCE, CRTO, CREST, CISSP, or AWS Security Specialty, and regulated-environment experience.
  • Able to influence without authority, and to take a technical risk to an executive, an auditor, or a merchant and be understood.
  • Self-directed and pragmatic, focused on practical risk reduction over perfect security.

About the employer

O

Ozow

Ozow is a hiring organisation operating in Cape Town within the finance sector. They are currently recruiting for the Senior Security Analyst role advertised on this page. Visit the official application link for more about the company, its culture and the team you would be joining.

Interested in this role at Ozow?

JobVault never charges job seekers to apply.

Apply Now

More Finance jobs

See all →

Get ready for your application

Free career guides written for South African job seekers.

Browse all career resources →