This is a remote position.
IgniteByte Digital is seeking an experienced Cybersecurity Specialist to support the security of our client's website redevelopment project.
We are looking for a hands-on cybersecurity professional who understands that security needs to be embedded throughout the development lifecycle rather than treated as a final-stage audit.
The ideal candidate will be comfortable working directly with developers and DevOps teams, identifying risks early, implementing security controls and helping deliver secure, production-ready digital platforms.
The role will focus on application security, cloud security, DevSecOps, threat monitoring and secure development practices, ensuring the new digital platform is secure, resilient and aligned with modern cybersecurity standards.
The successful candidate will work closely with developers, DevOps, QA and project stakeholders throughout the development lifecycle and post-Go-Live support period.
Key Responsibilities
- Define and implement secure coding practices across the software development lifecycle
- Perform application security reviews and identify potential vulnerabilities
- Apply OWASP Top 10 and OWASP ASVS principles to web applications
- Configure and validate HTTPS/TLS security
- Support implementation and configuration of Web Application Firewall (WAF) controls
- Support DDoS protection and cloud security controls
- Configure and monitor security controls within the cloud environment
- Work with Microsoft Defender for Cloud to identify and remediate security risks
- Support continuous security monitoring using Microsoft Sentinel / SIEM or equivalent
- Integrate security controls into CI/CD pipelines
- Implement and support SAST and DAST security testing
- Work with tools such as SonarQube, Snyk and OWASP ZAP
- Support vulnerability assessment and remediation activities
- Support third-party penetration testing and remediation of findings
- Participate in security incident response activities
- Support security patching and vulnerability remediation after Go-Live
- Assist with security documentation, risk assessments and technical recommendations
- Support POPIA and privacy-by-design requirements
- Work closely with development and DevOps teams to embed security into the delivery process
Requirements
Essential Requirements
- Diploma or Degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field.
- Demonstrable experience securing cloud-hosted web applications
- Strong understanding of web application security
- Practical knowledge of OWASP Top 10 and OWASP ASVS
- Experience with secure coding practices and application security
- Working knowledge of WAF, DDoS protection and HTTPS/TLS
- Hands-on experience with Microsoft Defender for Cloud
- Experience with Microsoft Sentinel or equivalent SIEM
- Practical DevSecOps experience
- Experience integrating security testing into CI/CD pipelines
- Knowledge of SAST and DAST tools
- Experience with vulnerability assessment and remediation
- Understanding of penetration testing methodologies and findings
- Working knowledge of POPIA and data-protection-by-design
- Strong understanding of identity, authentication and access control
- Strong analytical and problem-solving skills
- Ability to work closely with developers, DevOps and technical teams
Security Tools & Technologies
Experience with one or more of the following is advantageous:
- Microsoft Defender for Cloud
- Microsoft Sentinel
- Azure WAF
- SonarQube
- Snyk
- OWASP ZAP
- GitHub Advanced Security
- GitHub / Azure DevOps
- SAST / DAST platforms
- SIEM platforms
- Vulnerability management tools
Advantageous Qualifications & Certifications
- Azure Security Engineer Associate – AZ-500
- CISSP
- CompTIA Security+
- Other recognised cybersecurity certification
- Diploma or Degree in Cybersecurity, Information Technology, Computer Science or related field
Advantageous Experience
- Government or regulated-sector digital platforms
- Enterprise website security
- Cloud security architecture
- Digital transformation projects
- Experience supporting third-party penetration testing
- Security automation and scripting
- AI-assisted security tooling such as GitHub Advanced Security or Copilot for security reviews