IT Security Administrator
Location: Centurion, Gauteng (provisional – to be confirmed)
Positions Available: 5
Salary: Market-related
Employment Type: To be confirmed
Job Overview
We are seeking experienced and technically proficient IT Security Administrators to implement, administer, maintain and support enterprise information security technologies, systems and operational security controls within complex IT environments.
The successful candidates will be responsible for the day-to-day administration of cybersecurity platforms, security configurations, access controls, endpoint protection technologies, firewalls and other enterprise security infrastructure.
This role requires strong hands-on expertise in IT security administration, enterprise security technologies, system hardening, access management, security monitoring, vulnerability remediation and operational cybersecurity support.
The ideal candidates will have proven experience administering security technologies across Windows, Linux, network and cloud environments, ensuring that security controls remain operational, appropriately configured and aligned with organisational security policies.
The role involves working closely with cybersecurity engineers, SOC teams, infrastructure administrators and IT support teams to maintain a secure, stable and compliant enterprise technology environment.
This is a specialist operational cybersecurity role requiring practical experience administering enterprise security systems rather than general IT support or theoretical information security knowledge.
Key Responsibilities
Enterprise IT Security Administration
- Administer, maintain and support enterprise IT security technologies and infrastructure.
- Configure and manage security controls across servers, endpoints, networks and cloud environments.
- Perform day-to-day security administration activities.
- Monitor the operational health and effectiveness of security technologies.
- Implement approved security configurations and technical controls.
- Investigate and resolve security platform configuration and operational issues.
- Support security technology upgrades, patching and maintenance.
- Maintain appropriate access controls for security administration platforms.
- Identify security configuration weaknesses and recommend corrective actions.
- Ensure security administration activities follow organisational policies and change management procedures.
Identity and Access Security Administration
- Administer user accounts, groups, permissions and access controls.
- Support identity lifecycle processes, including user provisioning, modification and deprovisioning.
- Configure and maintain access security policies.
- Administer security controls within Microsoft Active Directory and Microsoft Entra ID environments.
- Support Multi-Factor Authentication (MFA) implementation and administration.
- Assist with privileged access management and privileged account security.
- Investigate access-related security incidents and configuration issues.
- Support periodic user access reviews and permission assessments.
- Identify excessive privileges and inappropriate access configurations.
- Maintain accurate access administration records and documentation.
Endpoint Security Administration
- Deploy, configure and maintain enterprise endpoint security technologies.
- Administer antivirus, antimalware, EDR and XDR platforms.
- Manage endpoint security policies and protection settings.
- Monitor endpoint security compliance and protection coverage.
- Investigate endpoint security alerts and operational issues.
- Support endpoint security agent deployment and troubleshooting.
- Implement approved endpoint hardening and protection configurations.
- Maintain endpoint security updates and platform health.
- Support endpoint isolation and remediation activities during security incidents.
- Collaborate with endpoint engineering and SOC teams to improve security controls.
Network and Firewall Security Administration
- Administer and support enterprise firewall and network security technologies.
- Implement approved firewall rules and security policy changes.
- Review firewall configurations and access control rules.
- Support VPN security administration and secure remote access.
- Monitor network security events and investigate configuration issues.
- Assist with network segmentation and access restriction controls.
- Support intrusion detection and prevention technologies.
- Maintain documentation of network security configurations.
- Collaborate with network engineering teams to address security weaknesses.
- Ensure network security changes follow approved operational procedures.
Security Monitoring and Incident Support
- Monitor security dashboards, logs and operational security alerts.
- Investigate routine security events and suspicious activities.
- Escalate potential security incidents to SOC analysts and incident response teams.
- Support incident investigation and containment activities.
- Maintain security event records and operational documentation.
- Assist with collecting relevant security logs and technical evidence.
- Investigate security tool failures and monitoring gaps.
- Support integration of security platforms with SIEM solutions.
- Assist with implementing remediation measures following security incidents.
- Contribute to improvements in operational security monitoring.
Vulnerability Management and System Hardening
- Support enterprise vulnerability scanning and remediation activities.
- Review vulnerability assessment findings affecting supported systems.
- Coordinate security patching with infrastructure and application teams.
- Implement approved security configuration changes.
- Apply system hardening standards to servers, endpoints and supported platforms.
- Identify outdated software, insecure configurations and unsupported technologies.
- Support vulnerability remediation tracking and verification.
- Assist with security baseline assessments.
- Maintain technical records of security remediation activities.
- Recommend improvements to enterprise system security.
Cloud and Microsoft 365 Security Administration
- Administer operational security controls within Microsoft Azure or equivalent cloud environments.
- Support Microsoft Entra ID security administration.
- Configure and maintain Microsoft 365 security settings.
- Administer relevant Microsoft Defender security capabilities.
- Support conditional access and MFA configuration.
- Monitor cloud security alerts and configuration issues.
- Assist with cloud identity and access management.
- Support cloud security posture improvements.
- Investigate cloud security administration and integration issues.
- Maintain documentation of cloud security configurations.
Security Platform Maintenance and Operational Support
- Monitor security platform availability, performance and operational health.
- Perform routine security technology maintenance and configuration reviews.
- Support security tool upgrades, migrations and lifecycle management.
- Troubleshoot security platform connectivity and integration failures.
- Maintain security configuration backups where applicable.
- Support disaster recovery and operational resilience for critical security systems.
- Maintain technical procedures and administrative documentation.
- Provide technical support to cybersecurity and infrastructure teams.
- Track security administration tasks, incidents and changes.
- Support continuous improvement of enterprise security operations.
Security Governance, Compliance and Reporting
- Ensure technical security administration aligns with organisational security policies.
- Support implementation of approved cybersecurity standards and controls.
- Assist with internal and external IT security audits.
- Maintain evidence of security configurations, access controls and remediation activities.
- Support compliance with applicable information security requirements.
- Generate operational security reports and compliance summaries.
- Identify deviations from approved security configurations.
- Recommend corrective actions for operational security weaknesses.
- Maintain accurate security administration documentation.
- Support continuous improvement of organisational cybersecurity practices.
Minimum Requirements
- Relevant diploma or degree in Information Technology, Computer Science, Cybersecurity, Information Security, Network Engineering or a related discipline.
- Typically 3–5 years of relevant hands-on experience in IT security administration, cybersecurity operations, security infrastructure administration or a closely related technical specialisation.
- Proven practical experience administering enterprise IT security technologies and security controls.
- Strong knowledge of Windows Server, Windows endpoints and enterprise infrastructure.
- Experience administering Microsoft Active Directory and identity-related security controls.
- Practical experience with endpoint protection, antivirus, EDR or XDR technologies.
- Experience configuring and maintaining security policies and technical security controls.
- Understanding of firewall administration and network security fundamentals.
- Experience supporting user access management and authentication security.
- Knowledge of vulnerability management, patching and system hardening.
- Experience investigating security administration issues and routine security alerts.
- Familiarity with Microsoft 365 and Azure security administration would be advantageous.
- Understanding of security incident escalation and operational response procedures.
- Experience working within structured enterprise IT environments.
- Strong technical troubleshooting, documentation and problem-solving skills.
Technical Skills and Competencies
Enterprise IT Security Administration
- Security platform administration
- Security policy configuration
- Security control implementation
- Security configuration management
- Security technology maintenance
- Security monitoring
- Security incident escalation
- Security platform troubleshooting
- Operational security reporting
- Security administration documentation
- Enterprise security standards
- Security change management
Microsoft and Windows Security
- Windows Server
- Windows 10 and Windows 11
- Microsoft Active Directory
- Microsoft Entra ID
- Group Policy
- Microsoft Defender for Endpoint
- Microsoft Defender XDR
- Microsoft Defender for Cloud
- Microsoft Intune
- Microsoft Configuration Manager
- Microsoft 365 security
- Windows security event logs
- Windows system hardening
- PowerShell
Identity and Access Management
- User account administration
- Access provisioning and deprovisioning
- Role-Based Access Control (RBAC)
- Multi-Factor Authentication (MFA)
- Conditional Access
- Privileged account security
- Password and authentication policies
- Active Directory security groups
- Microsoft Entra ID
- Access reviews
- Identity lifecycle administration
- Privileged Access Management fundamentals
Endpoint Security Technologies
Experience with relevant technologies such as:
- Microsoft Defender for Endpoint
- Microsoft Defender XDR
- CrowdStrike Falcon
- SentinelOne
- Sophos Central
- Trend Micro
- Trellix Endpoint Security
- Symantec Endpoint Security
- Other enterprise endpoint protection platforms
Relevant competencies include:
- Endpoint security agent deployment
- Antivirus and antimalware administration
- Endpoint protection policy management
- EDR and XDR administration
- Endpoint security compliance
- Security alert investigation
- Endpoint hardening
- Endpoint protection troubleshooting
Firewall and Network Security
Experience with relevant enterprise technologies such as:
- Fortinet FortiGate
- Palo Alto Networks firewalls
- Cisco Secure Firewall
- Check Point firewalls
- Sophos Firewall
- Other enterprise firewall platforms
Relevant competencies include:
- Firewall rule administration
- Network access control
- VPN administration
- Network segmentation fundamentals
- IDS/IPS fundamentals
- TCP/IP networking
- DNS
- DHCP
- HTTP/HTTPS
- Secure remote access
- Network security monitoring
- Firewall logging
Vulnerability Management and Security Hardening
- Vulnerability scanning fundamentals
- Vulnerability remediation
- Security patch management
- Windows security baselines
- Linux security fundamentals
- CIS Benchmarks
- Security configuration assessments
- Endpoint and server hardening
- Vulnerability tracking
- Security remediation verification
- Secure configuration management
Security Monitoring and SIEM
- Microsoft Sentinel
- Splunk
- IBM QRadar
- Elastic Security
- Windows Event Viewer
- Security event logs
- SIEM monitoring fundamentals
- Security alert triage
- Security event escalation
- Endpoint security telemetry
- Firewall logs
- Authentication logs
- Security monitoring dashboards
Cloud Security Administration
- Microsoft Azure
- Microsoft Entra ID
- Microsoft 365
- Microsoft Defender for Cloud
- Microsoft Defender XDR
- Microsoft Intune
- Azure Role-Based Access Control
- Conditional Access
- Cloud identity security
- Cloud security configuration
- Hybrid infrastructure security
- AWS security administration fundamentals
Linux and Enterprise Infrastructure
- Linux administration fundamentals
- Linux security configurations
- Server administration
- Virtualisation technologies
- VMware
- Hyper-V
- Enterprise storage and infrastructure fundamentals
- Security patching
- Infrastructure monitoring
- Secure system configurations
Scripting and Automation
- PowerShell
- Python fundamentals
- Bash fundamentals
- Windows command-line tools
- Security administration scripts
- User account automation
- Security reporting automation
- API integration fundamentals
- Security configuration automation
Cybersecurity Frameworks and Standards
- ISO/IEC 27001
- ISO/IEC 27002
- NIST Cybersecurity Framework
- CIS Critical Security Controls
- CIS Benchmarks
- MITRE ATT&CK fundamentals
- Security configuration management
- IT security operational procedures
- Access control standards
- Incident management principles
- POPIA awareness
Relevant Certifications (Advantageous)
One or more of the following certifications would be beneficial:
- CompTIA Security+
- CompTIA CySA+
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Azure Security Engineer Associate
- Microsoft Certified: Endpoint Administrator Associate (MD-102)
- Microsoft Certified: Windows Server Hybrid Administrator Associate
- Cisco Certified Network Associate (CCNA)
- Fortinet Certified Professional or equivalent Fortinet security certification
- Palo Alto Networks security certifications
- Check Point security certifications
- GIAC Security Essentials (GSEC)
- Certified Information Systems Security Professional (CISSP)
- Relevant Microsoft, endpoint security, firewall or enterprise cybersecurity certifications
Key Personal Attributes
- Strong technical troubleshooting and problem-solving abilities.
- Excellent attention to detail and security configuration accuracy.
- Ability to administer and maintain enterprise security technologies.
- Proactive approach to identifying operational security weaknesses.
- Strong understanding of cybersecurity risks and technical controls.
- Good analytical and investigative abilities.
- Excellent communication and technical documentation skills.
- Ability to collaborate with cybersecurity, infrastructure and IT operations teams.
- Strong organisational and time-management skills.
- Ability to prioritise operational security issues effectively.
- Commitment to continuous technical learning.
- High levels of confidentiality, accountability and professional integrity.
Application Requirements
Interested candidates should submit an updated CV clearly detailing their practical IT security administration, enterprise security technology management and operational cybersecurity experience, together with copies of relevant academic qualifications and professional certifications.
Candidates should specifically highlight:
- Enterprise security technologies they have personally administered.
- Experience configuring and maintaining endpoint security platforms.
- Firewall and network security administration responsibilities.
- Active Directory, Microsoft Entra ID and access security experience.
- Experience with MFA, Conditional Access and privileged account controls.
- Vulnerability remediation, patch management and system hardening activities.
- Microsoft 365, Azure or cloud security administration experience.
- Security incidents and operational security issues they have investigated.
- Security platform upgrades, migrations or implementation projects completed.
- Scripting and automation used in security administration.
- The size and complexity of enterprise environments supported.
- Relevant IT security administration, Microsoft, firewall and cybersecurity certifications.
Important: This is a specialist IT Security Administrator opportunity requiring demonstrable hands-on experience administering enterprise security technologies and technical security controls. General IT support, basic user administration or theoretical cybersecurity knowledge without substantial practical security administration experience will not be sufficient.
Please note: This is a provisional recruitment specification prepared pending confirmation of the client's detailed technical requirements. The preferred security technologies, minimum experience, qualifications, certifications, remuneration, employment arrangements and working conditions will be confirmed during the recruitment process.