Senior Identity Security Specialist (Enterprise Access & Governance) (Contract) (Cpt Hybrid
Job in
Cape Town, 7561, South Africa
Listed on 2026-08-24
Listing for:
Datafin It Recruitment
Full Time, Contract
position Listed on 2026-08-24
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
ENVIRONMENT:
A growing provider of cutting-edge Custom Cloud Solutions seeks an experienced Senior Identity Security Specialist to join its Info Sec team on a long-term contract basis. This role is designed for an Info Sec practitioner who views Identity as the primary security perimeter. You will bridge the gap between traditional infrastructure / AD environments and modern Microsoft Entra security. Rather than functioning as a pure technical sysadmin, you will own the identity threat surface—proactively identifying security risks, designing architectural controls, and driving governance across complex, enterprise-scale environments.
DUTIESIdentity Architecture & Tiering Governance –
- Drive the evolution and enforcement of identity privilege models, moving legacy environments from traditional AD Tiering (Tier 0/1/2), Red Forest / Bastion models, and Delegation of Control Frameworks toward Microsoft’s modern Enterprise Access Model (EAM).
- Lead security strategy and enforcement across Microsoft Entra (Azure AD) and on-premises Active Directory.
- Oversee Enterprise Application registrations, service principal permissions, consent frameworks, and tenant-wide security boundaries.
- Architect, refine, and enforce passwordless authentication paths, including Windows Hello for Business (WHfB), Passkeys (FIDO2), and robust Conditional Access/MFA policies.
- Audit, redesign, and maintain strict delegation models across hybrid environments to eliminate privilege creep, lateral movement paths, and over-provisioned administrative accounts.
- Independently scan the environment for identity security gaps, misconfigurations, and governance blind spots. Define solutions and execute remediations with minimal oversight.
- Act as an authoritative Info Sec lead, advising internal Infrastructure, Operations, and Application teams on identity best practices, compliance, and risk reduction.
- Senior-Level
Experience:
Demonstrated background in Information Security / Info Sec with a heavy focus on Identity Architecture, IAM, and Identity Access Governance (IAG). - Deep Microsoft Identity Expertise:
Extensive hands‑on and architectural knowledge of Microsoft Entra Active Directory Domain Services (AD DS). - Privileged Access Architecture:
Practical knowledge of Microsoft Privilege/Separation models (Enterprise Access Model, AD Tiering, Red/Bastion Forest legacy concepts, and Delegation of Control Wizard/ACL management). - Enterprise App Governance:
Strong grasp of Entra Application Registrations, OAuth/OIDC permissions, App Roles, and API consent models. - Strong Authentication Standards:
Deep experience implementing modern auth controls—MFA, FIDO2/Passkeys, and Windows Hello for Business. - Info Sec & Governance Focus:
Ability to analyse identity posture through a threat, compliance, and risk lens rather than purely operational task execution.
- Experience with Privileged Access Management (PAM) solutions (e.g., Cyber Ark, Delinea, Entra PIM).
- Core understanding of Public Key Infrastructure (PKI), digital certificates, and Smart Card/Certificate-Based Authentication (CBA).
- Autonomous & Self-Directed:
Thrives on vague or high‑level direction; capable of identifying complex problems independently, defining the scope, and driving solutions to completion. - Exceptional Communication:
Strong verbal and written communication skills; comfortable presenting identity risk and security strategy to corporate stakeholders and executive leadership. - Corporate Professionalism:
Accustomed to operating within strict enterprise/banking environments, maintaining a polished and professional standard at all times.
Position Requirements
10+ Years
work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×