Cyber Security Engineer II
Hybrid · Western Cape, South Africa
Job Summary
Join Capitec as Cyber Security Engineer II to design and implement enterprise-grade security solutions in a hybrid, cloud-first environment. You’ll protect systems, data, and customers by implementing Zero Trust architectures, deploying and optimizing Zscaler (ZIA/ZPA), and integrating security platforms with Azure AD/Entra ID using SAML/OIDC. Collaborate across engineering teams to drive secure access across on-prem and cloud deployments, influence architecture, and deliver scalable security solutions that mitigate evolving threats.
Required Qualifications
- A relevant tertiary qualification in Information Technology
- 3–5 years’ experience in security engineering or a related technical role
- Proven experience designing and implementing enterprise-scale security solutions
- Exposure to multi-region or global deployments within complex environments
- Experience working in hybrid environments (on-premise and cloud)
- Hands-on experience with Zscaler technologies (ZIA and/or ZPA)
- Practical experience implementing or working within a Zero Trust security model, including VPN modernisation or migration
- Experience integrating security platforms with Azure AD / Entra ID, including SAML and OIDC authentication
- Exposure to SASE frameworks, identity-driven access and data protection (DLP)
- Ideal: Experience configuring SSO, SCIM provisioning and Conditional Access policies
- Strong networking fundamentals (DNS, TCP/IP, routing, proxies, SSL/TLS)
- Experience working with AWS and/or Azure environments
- Hands-on experience troubleshooting production issues, including log analysis and traffic debugging (e.g. Zscaler Nanolog)
- The ability to collaborate across teams and simplify complex technical concepts
- Current Cyber Security threats, trends and mitigation approaches
- Security architecture, design patterns and compliance frameworks
- Identity and Access Management (IAM) concepts and technologies
- Knowledge of Zero Trust security principles and identity-led architecture
- SASE and secure access frameworks
- Authentication and authorisation protocols (SAML, OIDC, OAuth)
- Enterprise networking and traffic flow concepts
- Zscaler architecture, logging and traffic inspection
Apply with one swipe on Sorce. We auto-fill applications and apply on your behalf — no cover letters, no 40-minute forms.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.