×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Security Engineer - Microsoft Security Stack

Job in Johannesburg, 2000, South Africa
Listing for: Redherd.Io
Full Time position
Listed on 2026-09-18
Job specializations:
  • IT/Tech
    Cybersecurity
Job Description & How to Apply Below

Security Engineer - Microsoft Security Stack

Location:

Johannesburg, hybrid. Minimum of three days a week in the Johannesburg office. This role is not remote.

Employment type:

Permanent, full-time.
Seniority:
Individual contributor. Not a management seat.

Experience:

2 to 5 years hands-on in a Microsoft environment.

At a glance
  • You own the Microsoft security estate hands-on:
    Entra  Conditional Access, Defender and Sentinel, Intune across Windows and macOS, Purview for data protection.
  • The controls exist and are audited annually. You run and improve them rather than building from nothing.
  • You are not expected to cover everything on this list. Credible depth in roughly three of the four areas is enough.

Have your matric certificate and academic transcripts ready before you apply. The client asks for both at submission, before they meet you, not at offer stage.

About Red Herd

Red Herd is a specialist cybersecurity recruitment and advisory firm. We work with consultancies, product companies, vendors and enterprise security teams across South Africa, the UK, Europe and the United States. We are deliberately low volume. We scope roles deeply, read the market honestly, and curate shortlists rather than flood them. Clients come to us when a role is niche, senior, sensitive or business-critical.

We are recruiting this position exclusively on behalf of our client. We share their identity with you during qualification, before submitting anything. We never introduce your profile without your knowledge and consent.

About the client

A global technology and services business, founded in South Africa and operating from more than thirty offices worldwide.

That work means holding other organisations' financial data urity here is not an internal IT concern. It is a contractual requirement. The posture is mature, not aspirational. The business holds ISO 27001:2022, ISO 22301:2019 and Cloud Security Alliance STAR certification, is independently SOC 2 Type II audited, and already runs SIEM, SOAR, DLP, intrusion detection, endpoint management, single sign-on and multi-factor authentication.

The

role

You take hands-on ownership of the Microsoft security estate: hybrid Active Directory and Entra, Windows and macOS devices, Defender and Sentinel for detection and response, and Purview for data protection.

The controls already exist and are audited every year. What it does need is engineering. The existing internal security function is weighted toward governance and compliance, and it does that well. This role fills the technical gap beside it. You design the Conditional Access policy rather than evidencing that one exists, write the detection rather than reporting on the alert, and automate the task rather than documenting it.

What

you will do

Identity

  • Own Entra l Access design, Privileged Identity Management, and Identity Protection risk policies.
  • Manage the hybrid identity estate through Entra Connect.
  • Govern application identity: app registrations, service principals and OAuth consent grants.
  • Diagnose authentication failures across Kerberos, NTLM, SAML, OIDC and OAuth
    2.

Detection and response

  • Investigate and contain incidents across Defender for Endpoint, Identity, Office 365 and Cloud Apps, from first alert through device isolation, session revocation and token invalidation.
  • Write and tune Sentinel analytics rules, build workbooks, and automate response through Logic Apps playbooks.
  • Hunt across the estate in KQL.

Endpoint

  • Build and maintain Intune: compliance policies, configuration profiles, Autopilot, update rings and proactive remediations.
  • Manage macOS to the same standard as Windows, including Apple Business Manager enrolment and custom configuration payloads.
  • Apply and enforce Microsoft security baselines, attack surface…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary