Job description
- Location:Sandton
- Employee Type:Permanent
- Department:Group Security
- Division:Central Services
Cloud Security Engineer (13598)
Description
The Cloud Security Engineer is responsible for designing, implementing, and maintaining security controls across Investec's Azure cloud environments. The role focuses on cloud governance, identity security, infrastructure-as-code security, and DevSecOps enablement to ensure Azure services are secure, scalable, compliant, and aligned to enterprise standards.
The role works closely with platform engineering, infrastructure, application teams, and security stakeholders to embed security into cloud platforms, CI/CD pipelines, and cloud-native delivery processes.
Key Responsibilities
1. Azure Cloud Security Engineering
• Implement and maintain Azure-native security controls across subscriptions, management groups, and cloud services.
• Configure and manage Azure Policy, security baselines, and governance controls to enforce enterprise standards.
• Support secure cloud adoption through technical guardrails and preventative controls.
• Assist teams with secure onboarding and usage of Azure services.
2. Cloud Security Posture Management (CSPM)
• Configure, maintain, and optimise CSPM tooling and associated cloud security monitoring capabilities.
• Identify cloud security risks, misconfigurations, and compliance gaps across Azure environments.
• Work with engineering teams to remediate findings and improve overall cloud security posture.
• Develop reporting and metrics for cloud security maturity and risk reduction.
3. Identity and Access Security
• Implement and maintain secure identity and access management practices across Azure and Azure DevOps.
• Review and improve RBAC models, privileged access controls, service principals, managed identities, and federated identities.
• Ensure least-privilege principles are enforced across cloud and CI/CD environments.
• Support secure authentication and secrets management practices.
4. Infrastructure as Code (IaC) and DevSecOps
• Support and secure Infrastructure as Code deployments using Terraform and associated tooling.
• Review and improve IaC security standards, reusable modules, and deployment guardrails.
• Integrate security controls and validation into CI/CD pipelines and engineering workflows.
• Work closely with engineering teams to improve automation, deployment security, and operational resilience.
5. CI/CD and Platform Security
• Secure Azure DevOps (ADO) repositories, pipelines, agents, and associated integrations.
• Review and improve permissions, branch protection strategies, pipeline authentication models, and deployment controls.
• Support implementation of secure software delivery practices within cloud engineering workflows.
• Assist with integrating security tooling into build and deployment pipelines.
6. Governance, Risk and Collaboration
• Partner with security, risk, architecture, and engineering teams to ensure compliance with internal standards and regulatory requirements.
• Contribute to cloud security standards, patterns, and operational procedures.
• Support incident response and investigation activities related to cloud security events.
• Provide technical guidance and mentorship to engineering teams on cloud security best practices.
Qualifications, Experience and Skills
• Bachelor's degree in Computer Science, Information Technology, Engineering, or related discipline (or equivalent practical experience)
Relevant Certifications (desirable)
• Microsoft Certified: Azure Security Engineer Associate (AZ-500)
• Microsoft Certified: Azure Administrator Associate
• Terraform Associate Certification
• Cloud security certifications such as CCSP, CCSK, or equivalent advantageous
Technical Skills and Experience
• Strong hands-on experience securing Microsoft Azure environments.
• Experience with Azure Policy, management groups, RBAC, Defender for Cloud, and cloud governance frameworks.
• Strong understanding of cloud identity security and privileged access management.
• Experience securing Azure DevOps (ADO), repositories, CI/CD pipelines, and deployment workflows.
• Strong Infrastructure-as-Code knowledge with Terraform.
• Understanding of CI/CD concepts, DevSecOps practices, and secure deployment patterns.
• Familiarity with cloud networking, monitoring, logging, and security operations concepts.
• Experience working with automation and scripting technologies beneficial.
Behavioural Attributes
• Pragmatic and solutions-oriented
• Strong analytical and problem-solving capability
• Collaborative and influential communicator
• Self-driven with strong ownership mindset
• Ability to balance security, operational efficiency, and engineering agility
What We Value
At Investec we seek creative, talented people with passion, energy and stamina, who
collaborate unselfishly.
Investec Culture
At Investec we look for intelligent, energetic people filled with passion, integrity and curiosity. We value individuals who in turn value our culture that is, a flexible attitude comfortable to live with ambiguity and willing to challenge the status quo. Diversity, talent and leadership are respected in pursuit of the growth of our business. People who can manage themselves and build strong relationships in order to get things done, will perform in out of the ordinary ways in our environment.
We are committed to diversity and inclusion when recruiting internally and externally.



