Security Operations Manager – SecOps
Skye Business Solutions
Stellenbosch, Western Cape
Security is one of SA's largest employers. With a PSIRA grade, security officer and guard roles are widely available across malls, estates, sites and events nationwide.
This listing does not state a salary. As a guide, security roles in South Africa typically pay R5 000 to R11 000 a month (indicative).
Job description
About this position
Stellenbosch, Western Cape | Hybrid – one day per week working from home | R Neg | Permanent
Standby requirement: Participation in a weekly rotating Security Operations and Incident Response standby roster.
Join our client’s Security Operations Team
Our leading MSSP client is seeking an experienced, hands-on Security Operations Manager to lead and manage critical security operations across endpoint, identity, email, network and Azure cloud environments.
This is a broad, technically demanding role requiring someone who can combine operational leadership with strong practical expertise. You will take ownership of security platforms, policies, controls, compliance, incident response and continuous improvement, while coordinating effectively with the SOC, infrastructure teams, system owners and wider business stakeholders.
The successful candidate will be based in Stellenbosch and work on a hybrid basis.
Key Responsibilities
Security Operations Leadership
- Lead the day-to-day management and continuous improvement of security operations.
- Take ownership of security tooling, operational controls, policies, processes and reporting.
- Coordinate security activities across the SOC, infrastructure teams, system owners and business units.
- Ensure security incidents, vulnerabilities and compliance issues are addressed within agreed corporate service levels.
- Drive consistent operational standards, effective governance and continuous security hardening.
- Identify opportunities to automate repetitive security processes and improve operational efficiency.
- Produce clear security, risk, vulnerability, compliance and operational reports for relevant stakeholders.
Endpoint Security – Microsoft Defender for Endpoint
- Ensure appropriate endpoint coverage, onboarding and compliance.
- Manage endpoint security configurations, policies and security baselines.
- Manage Attack Surface Reduction rules and controls.
- Oversee endpoint firewall and network protection settings.
- Manage endpoint vulnerabilities, configuration weaknesses and security baselines.
- Monitor threat detections, alerts and incidents, ensuring appropriate investigation and response.
- Manage platform updates, patching, sensor health and overall service performance.
- Review and manage exclusions and exceptions.
- Maintain policy compliance and configuration governance.
- Manage integrations between the EDR platform and the broader security ecosystem.
- Oversee platform lifecycle management, continuous improvement and reporting.
Vulnerability Management – Nessus
- Ensure vulnerability scanning coverage across all relevant servers and infrastructure.
- Manage authenticated vulnerability scans.
- Oversee internal and external Nessus scanners.
- Manage scanner updates, patching, health and performance.
- Review and manage scan exclusions and exceptions.
- Maintain vulnerability management policies and compliance controls.
- Manage the vulnerability platform lifecycle.
- Analyse findings and coordinate remediation activities with system and application owners.
- Track outstanding vulnerabilities and escalate overdue or high-risk remediation items.
- Produce vulnerability, remediation and compliance reports.
Microsoft Defender for Identity
- Ensure appropriate sensor coverage, health and compliance.
- Monitor high-value identity activity and potential identity-based threats.
- Manage and maintain identity protection policies and governance controls.
- Oversee identity-related threat intelligence, alerts and investigations.
- Support identity exposure management and continuous risk reduction.
- Manage platform integrations, logging and data availability.
- Oversee configuration management and performance monitoring.
- Support identity governance and compliance reporting.
- Drive lifecycle management and continuous hardening of identity security controls.
Microsoft Defender for Office 365
- Manage domain authentication controls.
- Maintain anti-spoofing, anti-malware, anti-phishing and anti-spam policies.
- Manage mailbox intelligence capabilities.
- Oversee Safe Attachments and Safe Links policies.
- Monitor email-related threat detections and security alerts.
- Investigate and respond to email security incidents.
- Manage protection for relevant Microsoft 365 collaboration applications.
- Drive configuration management, security hardening and policy optimisation.
- Oversee ongoing platform operations, maintenance and reporting.
Network Security – Vectra
- Manage Vectra platform configurations.
- Oversee platform maintenance, health, updates and performance.
- Monitor, investigate and triage network security alerts.
- Fine-tune detection rules and appropriately manage false positives and whitelisting.
- Coordinate alert remediation with the relevant technical teams.
- Maintain effective integration between Vectra and the SOC environment.
- Ensure network detections are correlated with endpoint, identity, cloud and other security events.
Azure Cloud Security
- Ensure security and compliance across Azure identity and access controls, including:
- Privileged Identity Management
- Role-Based Access Control
- Service principals and managed identities
- Break-glass accounts
- Manage, maintain and monitor compliance across:
- Azure network security controls
- Host and workload protection
- Data protection and storage security
- Platform security and configuration management
- Threat detection, monitoring and logging
- Identity and access logging and auditability
- Governance, compliance and risk management
- Identity-centric controls and Zero Trust principles
- Secure DevOps and CI/CD pipeline security
- Incident response and recovery
- Security automation and remediation
- Lifecycle management
- Produce regular cloud security, risk and compliance reporting.
Identity and Access Management – Security
- Monitor identity lifecycle compliance.
- Ensure appropriate governance of privileged and service accounts.
- Monitor compliance with IAM policies and standards.
- Review the security and compliance of groups and roles.
- Oversee identity security monitoring and threat detection.
- Support identity protection and remediation activities.
- Coordinate access reviews for privileged users and third parties.
- Maintain identity security policies and baselines.
- Produce identity security and compliance reports.
Compliance and Security Reviews
- Conduct security compliance reviews against corporate policies.
- Review the configuration and effectiveness of implemented security solutions.
- Identify control gaps, configuration weaknesses and areas of non-compliance.
- Coordinate corrective actions with control owners.
- Track remediation through to completion.
- Produce clear findings, recommendations and compliance reports.
Security Incident Response
- Respond to, investigate and remediate security incidents.
- Coordinate security incident response activities across multiple technical and business teams.
- Collaborate with the SOC, infrastructure teams, system owners and business units.
- Ensure incidents are correctly prioritised, documented, escalated and resolved.
- Ensure security incidents are addressed within defined corporate service levels.
- Support post-incident reviews and identify opportunities to strengthen controls.
- Maintain incident response processes, playbooks and supporting documentation.
SecOps Automation
- Identify opportunities to automate security operational processes.
- Develop and maintain automated security workflows.
- Create playbooks for repeatable investigation, response and remediation activities.
- Improve the speed, accuracy and consistency of security operations.
- Work with technical teams to integrate automation across the security toolset.
What We Are Looking For
- Substantial experience in Security Operations, Cybersecurity Operations or
Good to know
What does this security job pay?
This listing does not state a salary. As a guide, security roles in South Africa typically pay R5 000 to R11 000 a month (indicative).
Do I need experience for security jobs in Stellenbosch?
Many security roles in Stellenbosch are open to candidates with little or no experience. Read the listing for its exact requirements.
How do I apply for this job?
Tap "Apply on Indeed" to open the original listing, where you can read the full description and apply directly. JobsZA never charges you to apply, and you should never pay money to get a job.
Found on Indeed · Posted Yesterday
More security and similar jobs in Stellenbosch
Kendrick Recruitment
R11K - R13K/mo
Kendrick Recruitment
R8K - R8.5K/mo
Kendrick Recruitment
R20K - R25K/mo
Kendrick Recruitment
R6.2K - R6.2K/mo