Overview

SecOps Manager Jobs in Stellenbosch, Western Cape, South Africa at Avatar International SA

Title: SecOps Manager

Company: Avatar International SA

Location: Stellenbosch, Western Cape, South Africa

SecOps Manager / CISO

Cape Town (hybrid) | Permanent | Full-time | R110K-160K p/m plus benefits

Are you a technically strong Security Operations professional ready to take ownership of a complex enterprise security environment?

Our client, a well-established international cybersecurity organisation, is seeking a hands-on Security Operations Manager to strengthen and continuously improve security operations across endpoint, identity, email, cloud, network and vulnerability management.

This is not a role for someone who wants to manage from a distance. You will remain close to the technology, ensuring that security platforms are correctly deployed, configured, monitored, maintained and integrated.

You will coordinate remediation, guide incident response, improve compliance and introduce automation that makes Security Operations faster, more consistent and more effective.

THE ENVIRONMENT

The security ecosystem includes:

  • Microsoft Defender for Endpoint
  • Microsoft Defender for Identity
  • Microsoft Defender for Office 365
  • Microsoft Azure Security
  • Nessus Vulnerability Management
  • Vectra Network Detection
  • Identity and Access Management
  • Security Incident Response
  • Security Compliance
  • SecOps Automation

THE ROLE

You will take ownership of the day-to-day effectiveness and maturity of the organisation’s security controls. Your responsibilities will include identifying coverage and configuration gaps, coordinating corrective action with system owners, tracking remediation through to completion and reporting on security risks, incidents, compliance and platform health.

You will operate at both technical and management levels, bringing SOC, cloud, infrastructure, identity and business teams together during investigations, remediation and incident response.

KEY RESPONSIBILITIES

Endpoint Security

  • Ensure endpoint coverage, onboarding and compliance.
  • Manage Microsoft Defender for Endpoint policies and configurations.
  • Govern Attack Surface Reduction rules, endpoint firewall and network protection.
  • Monitor threats, vulnerabilities, alerts and incidents.
  • Coordinate investigation, containment and remediation.
  • Manage platform health, updates, exclusions, integrations and reporting.

Vulnerability Management

  • Ensure scanning coverage across relevant servers and infrastructure.
  • Manage authenticated scans and internal and external Nessus scanners.
  • Maintain scanner health, configurations and updates.
  • Prioritise findings according to severity, exposure and business risk.
  • Coordinate remediation with system owners.
  • Track high-risk and overdue vulnerabilities through to closure.

Identity Security

  • Maintain Microsoft Defender for Identity sensor coverage and compliance.
  • Monitor threats involving privileged and high-value identities.
  • Manage identity protection policies, alerts, logging and integrations.
  • Oversee identity lifecycle and IAM policy compliance.
  • Review privileged accounts, service accounts, groups, roles and permissions.
  • Coordinate privileged-user and third-party access reviews.
  • Track identity risks, exceptions and remediation.

Email and Collaboration Security

  • Manage Microsoft Defender for Office 365 security controls.
  • Oversee domain authentication, anti-spoofing, anti-malware, anti-phishing and anti-spam policies.
  • Manage Mailbox Intelligence, Safe Attachments and Safe Links.
  • Coordinate investigations and remediation of email-related incidents.
  • Maintain collaboration protection and configuration hardening.

Network Security

  • Manage Vectra configuration, maintenance, health and updates.
  • Monitor, investigate and triage network security alerts.
  • Fine-tune detections and reduce false positives.
  • Manage legitimate exceptions and whitelisting requirements.
  • Coordinate remediation with relevant technical teams.
  • Maintain integration with the broader SOC ecosystem.

Microsoft Azure Cloud Security

  • Govern Privileged Identity Management and Role-Based Access Control.
  • Oversee service principals, managed identities and break-glass accounts.
  • Maintain network, host, workload, data and storage security controls.
  • Oversee cloud configuration, threat detection, monitoring and logging.
  • Ensure identity and access activity is auditable.
  • Support Zero Trust and cloud governance.
  • Support secure DevOps and CI/CD pipeline security.
  • Coordinate cloud incident response, recovery and remediation.

Compliance and Incident Response

  • Review compliance with corporate security policies and standards.
  • Assess security platform configurations and identify control gaps.
  • Agree corrective actions with accountable system owners.
  • Track findings and remediation through to completion.
  • Respond to, investigate and remediate security incidents.
  • Coordinate technical and business response activities.
  • Ensure incidents are contained and resolved within defined service levels.
  • Support post-incident reviews and validate resulting control improvements.

SecOps Automation

  • Identify repetitive security processes suitable for automation.
  • Implement automated Security Operations workflows.
  • Create and maintain incident response playbooks.
  • Improve the speed and consistency of investigations.
  • Introduce controlled automated remediation where appropriate.
  • Monitor and continuously refine automated security controls.

Standby

  • Participate in a weekly Security Operations and Incident Response rotation.
  • Support priority security incidents outside standard operating hours when required.

WHAT WE ARE LOOKING FOR

You should offer practical experience across several of the following areas:

  • Security Operations or SecOps management.
  • Microsoft Defender for Endpoint, Identity and Office 365.
  • Microsoft Azure Security and cloud governance.
  • Identity and Access Management security.
  • Nessus vulnerability management.
  • Vectra or comparable network detection technology.
  • Security incident investigation, containment and remediation.
  • Security configuration management and hardening.
  • Compliance reviews, control testing and audit evidence.
  • Security automation, orchestration and response playbooks.
  • Working across SOC, cloud, infrastructure and identity teams.
  • Operational, risk, compliance and management reporting.

You will combine technical credibility with operational leadership, remain technically involved, communicate risk clearly and drive corrective actions through to completion.

You should be calm during security incidents, effective across multiple workstreams and committed to simplifying, standardising and automating Security Operations.

Relevant Microsoft security, CISSP, CISM, GIAC, cloud security, vulnerability management, ITIL or automation certifications would be advantageous. Equivalent practical experience will also be considered.

COMPANY BENEFITS

  • 20 working days’ paid annual leave per completed 12-month leave cycle.
  • Company contribution towards a Discovery Health Medical Scheme.
  • 4% company contribution towards the provident fund.
  • Flexibility to select an additional employee provident fund contribution.
  • Eligibility for a discretionary annual performance bonus, subject to company policy, individual performance and company profitability.
  • Annual salary review process, subject to policy, performance and eligibility.
  • Paid South African public holidays.
  • Sick leave and family responsibility leave in accordance with legislation and company policy.
  • Exposure to complex enterprise cybersecurity environments and modern security platforms.

APPLY IN CONFIDENCE

If you can combine technical expertise, operational leadership, incident coordination and continuous improvement, we would like to hear from you.

The client’s identity will be disclosed to suitably qualified candidates during the recruitment process. All applications and discussions will be handled in strict confidence.

Upload your CV/resume or any other relevant file. Max. file size: 800 MB.