Cloud Security Specialist
Location: Centurion, Gauteng (provisional – to be confirmed)
Positions Available: 5
Salary: Market-related
Employment Type: To be confirmed
Job Overview
We are seeking experienced and technically proficient Cloud Security Specialists to design, implement, manage and continuously improve security controls across enterprise cloud computing environments.
The successful candidates will be responsible for protecting cloud infrastructure, applications, networks, identities and sensitive business information against cybersecurity threats, vulnerabilities and unauthorised access.
This role requires strong hands-on expertise in cloud security architecture, cloud infrastructure protection, identity and access management, security monitoring, vulnerability management and regulatory compliance.
The ideal candidates will have proven experience securing cloud environments across platforms such as Microsoft Azure, Amazon Web Services (AWS) and Google Cloud Platform (GCP), with the ability to implement effective security controls within complex enterprise and hybrid cloud infrastructures.
Key Responsibilities
Cloud Security Architecture and Implementation
- Design, implement, configure and maintain security controls across enterprise cloud environments.
- Assess cloud infrastructure, applications and workloads to identify security risks and vulnerabilities.
- Develop and implement secure cloud configurations, policies and architecture standards.
- Apply cloud security best practices across Infrastructure as a Service (IaaS), Platform as a Service (PaaS) and Software as a Service (SaaS) environments.
- Support secure cloud infrastructure deployments, migrations and modernisation initiatives.
- Implement security controls aligned with Zero Trust principles and cloud security frameworks.
- Conduct cloud security architecture reviews and configuration assessments.
- Identify and remediate cloud misconfigurations, excessive permissions and infrastructure vulnerabilities.
- Collaborate with cloud architects, infrastructure engineers and cybersecurity teams to strengthen cloud security posture.
Cloud Identity and Access Security
- Implement and maintain identity and access management controls across cloud platforms.
- Configure role-based access control (RBAC), least-privilege permissions and secure access policies.
- Implement multi-factor authentication (MFA), privileged access controls and conditional access mechanisms.
- Secure cloud service accounts, managed identities, API credentials and administrative access.
- Monitor and investigate suspicious authentication activity and unauthorised access attempts.
- Support identity federation and secure integration between cloud and on-premises environments.
- Conduct periodic access reviews and privileged access assessments.
- Implement secure authentication and authorisation practices across cloud services.
Cloud Network and Infrastructure Security
- Configure and maintain cloud firewalls, security groups and network access controls.
- Implement network segmentation, private connectivity and secure cloud networking architectures.
- Secure virtual networks, subnets, gateways and cloud-based infrastructure.
- Configure Web Application Firewalls (WAF), DDoS protection and network threat prevention controls.
- Monitor cloud network traffic and investigate suspicious activity.
- Implement secure connectivity between cloud environments and on-premises infrastructure.
- Support security hardening of virtual machines, containers and cloud workloads.
- Identify and remediate network security vulnerabilities and misconfigurations.
Cloud Threat Detection and Security Monitoring
- Implement and maintain cloud security monitoring and threat detection solutions.
- Configure Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) capabilities.
- Monitor cloud security alerts, audit logs and threat intelligence.
- Investigate cloud security incidents and coordinate appropriate response activities.
- Support integration with Security Information and Event Management (SIEM) and Security Orchestration, Automation and Response (SOAR) platforms.
- Conduct cloud vulnerability assessments and coordinate remediation activities.
- Analyse suspicious cloud activities, privilege escalation attempts and potential data exposure.
- Develop cloud security dashboards, reports and risk metrics.
- Support continuous monitoring and improvement of enterprise cloud security posture.
Cloud Data Protection and Compliance
- Implement encryption and data protection controls across cloud environments.
- Configure and maintain cloud key management, secrets management and certificate services.
- Secure cloud storage, databases, backups and sensitive information.
- Implement data access controls, retention policies and information protection mechanisms.
- Support data classification and data loss prevention initiatives.
- Ensure cloud security configurations align with organisational policies and recognised security standards.
- Support cloud security audits, compliance assessments and remediation activities.
- Maintain security documentation, risk assessments and compliance evidence.
DevSecOps and Cloud Security Automation
- Integrate security controls into cloud deployment and DevOps processes.
- Support secure CI/CD pipelines and automated security testing.
- Implement infrastructure-as-code security controls and configuration validation.
- Develop scripts and automation workflows to improve cloud security operations.
- Support container and Kubernetes security assessments.
- Identify security vulnerabilities within cloud-native applications and deployment configurations.
- Collaborate with DevOps and development teams to implement secure cloud engineering practices.
- Recommend continuous improvements to cloud security automation, governance and operational efficiency.
Minimum Requirements
- Relevant diploma or degree in Information Technology, Computer Science, Cybersecurity, Cloud Computing, Information Systems or a related discipline.
- Typically 3–5 years of relevant experience in cloud security, cybersecurity engineering, cloud infrastructure security or a related technical security discipline.
- Proven hands-on experience implementing and managing security controls within enterprise cloud environments.
- Strong working knowledge of at least one major cloud platform, such as Microsoft Azure, AWS or GCP.
- Experience implementing cloud identity and access management controls.
- Practical knowledge of cloud networking, firewalls, security groups and network segmentation.
- Experience with cloud security posture management, vulnerability assessments and security remediation.
- Understanding of cloud workload protection and secure infrastructure configuration.
- Experience monitoring cloud security events and investigating potential security incidents.
- Knowledge of encryption, key management and cloud data protection mechanisms.
- Familiarity with cloud security governance, risk management and compliance requirements.
- Understanding of Zero Trust architecture and the shared responsibility model.
- Experience with cloud automation, scripting or infrastructure-as-code technologies.
- Knowledge of recognised security frameworks such as ISO 27001, NIST and CIS Controls.
- Strong technical troubleshooting, analytical and documentation skills.
Technical Skills and Competencies
Cloud Platforms and Infrastructure
Practical experience with one or more of the following:
- Microsoft Azure
- Amazon Web Services (AWS)
- Google Cloud Platform (GCP)
- Hybrid cloud environments
- Enterprise cloud infrastructure
- IaaS, PaaS and SaaS security
Cloud Security Technologies
Experience with relevant security technologies, such as:
- Microsoft Defender for Cloud
- AWS Security Hub
- Amazon GuardDuty
- AWS Inspector
- Google Security Command Center
- Cloud Security Posture Management (CSPM)
- Cloud Workload Protection Platforms (CWPP)
- Cloud-Native Application Protection Platforms (CNAPP)
- Cloud Infrastructure Entitlement Management (CIEM)
- Wiz, Prisma Cloud, Orca Security or equivalent platforms
Identity and Access Management
- Cloud Identity and Access Management (IAM)
- Microsoft Entra ID
- AWS IAM
- Google Cloud IAM
- Role-Based Access Control (RBAC)
- Multi-Factor Authentication (MFA)
- Privileged access management
- Identity federation
- Service account security
- Least-privilege access controls
- Zero Trust identity principles
Cloud Network Security
- Cloud firewalls
- Virtual networks and virtual private clouds
- Network Security Groups
- AWS Security Groups
- Network access control lists
- Web Application Firewalls (WAF)
- DDoS protection
- Network segmentation
- Private endpoints and secure connectivity
- VPN and hybrid cloud connectivity
Cloud Data Protection
- Encryption at rest and in transit
- Cloud Key Management Services (KMS)
- Azure Key Vault
- AWS KMS
- Google Cloud KMS
- Secrets management
- Certificate management
- Secure cloud storage
- Database security
- Data classification and protection
Security Monitoring and Incident Response
- Microsoft Sentinel
- Microsoft Defender XDR
- AWS CloudTrail
- Amazon CloudWatch
- Google Cloud Logging
- SIEM and SOAR integration
- Cloud security event monitoring
- Threat detection and investigation
- Vulnerability management
- Cloud incident response
- Security reporting and dashboards
DevSecOps and Automation
- Terraform
- Bicep
- ARM templates
- AWS CloudFormation
- PowerShell
- Python
- Bash
- Azure CLI
- AWS CLI
- CI/CD pipeline security
- Infrastructure-as-code security scanning
- Container security
- Kubernetes security fundamentals
- Automated security policy enforcement
Security Frameworks and Standards
- ISO/IEC 27001
- NIST Cybersecurity Framework
- NIST SP 800-53
- CIS Benchmarks
- Cloud Security Alliance Cloud Controls Matrix
- Zero Trust security architecture
- Cloud shared responsibility model
- POPIA and applicable data protection requirements
Relevant Certifications (Advantageous)
One or more of the following certifications would be beneficial:
- Certified Cloud Security Professional (CCSP)
- Certificate of Cloud Security Knowledge (CCSK)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
- AWS Certified Security – Specialty
- Google Cloud Professional Cloud Security Engineer
- Certified Information Systems Security Professional (CISSP)
- CompTIA Security+
- GIAC Cloud Security Automation (GCSA)
- GIAC Public Cloud Security (GPCS)
- Relevant cloud platform, DevSecOps or cybersecurity certifications
Key Personal Attributes
- Strong analytical and technical problem-solving abilities.
- Excellent attention to detail and cybersecurity awareness.
- Ability to identify and remediate complex cloud security vulnerabilities.
- Strong understanding of enterprise cloud infrastructure and security architecture.
- Proactive approach to security monitoring and threat prevention.
- Excellent communication and stakeholder engagement skills.
- Ability to collaborate effectively with cloud engineering, DevOps, infrastructure and cybersecurity teams.
- Strong organisational and technical documentation skills.
- Ability to manage multiple cloud security priorities and technical projects.
- High levels of confidentiality, accountability and professional integrity.
Application Requirements
Interested candidates should submit an updated CV clearly detailing their practical cloud security implementation, administration and engineering experience, together with copies of relevant academic qualifications and professional certifications.
Candidates should specifically highlight:
- Cloud platforms they have secured, implemented or supported, including Azure, AWS or GCP.
- Cloud security tools and technologies they have configured and administered.
- Experience with cloud security posture management, workload protection and vulnerability remediation.
- Cloud IAM, privileged access management and identity security experience.
- Cloud networking, firewall configuration and infrastructure security expertise.
- Experience with encryption, key management and cloud data protection.
- Cloud security monitoring, threat detection and incident response experience.
- Terraform, PowerShell, Python or other security automation capabilities.
- DevSecOps, container security and Kubernetes security experience, where applicable.
- Cloud security implementation, migration, remediation or architecture projects.
- The size and complexity of cloud environments they have supported.
- Relevant cloud security certifications and specialised technical training.
Important: This is a specialist Cloud Security opportunity requiring demonstrable hands-on experience securing enterprise cloud environments. General cloud administration, infrastructure support or cloud migration experience without substantial cloud security expertise will not be sufficient.
Please note: Specific project requirements, remuneration, employment arrangements and working conditions will be confirmed during the recruitment process.