OM Bank - Junior Security Engineer – Identity, Endpoint & Data Protection
Old Mutual
Cape Town
Salary not specified - Full-time
Job Description
About the Role
Let's Write Africa's Story Together! Old Mutual is a firm believer in the African opportunity and our diverse talent reflects this.
Responsibilities
- Endpoint Security & Compliance:
- Data Loss Prevention & Information Protection:
- Vulnerability Management:
- Automation & Policy Deployment:
- Threat Detection Enhancement
- Compliance Reporting
- Continuous Improvement:
- ROLE REQUIREMENTS
- Manage and optimise areas such as Azure AD / Entra ID, Conditional Access, PIM, MFA, RBAC, and access package lifecycle governance.
- Administer endpoint protection tooling with compliance baselines, ensure encryption, patching, and secure configuration of all managed devices.
- Configure and maintain Microsoft Purview DLP, sensitivity labels, and information governance policies across M365 (Exchange, SharePoint, Teams, OneDrive).
- Operate Microsoft Defender Vulnerability Management (DVM); track, prioritise, and remediate vulnerabilities in coordination with system owners.
- Build and deploy automated policies using Intune, PowerShell, and Graph API to enforce consistent security posture.
- Fine-tune Defender and SIEM detections to reduce false positives and improve coverage of endpoint, identity, and DLP telemetry
- Generate dashboards and reports for device compliance, privileged access, DLP violations, and vulnerability metrics.
- Contribute to the ongoing maturity of the Endpoint and User security ecosystem and adoption of Zero Trust, “Security as Code,” and automation.
Requirements
- Bachelor’s degree in Computer Science, Information Security, or equivalent practical experience.
- Microsoft Certified: Security Operations Analyst Associate
- Microsoft Certified: Identity & Access Administrator Associate
- Microsoft Certified: Information Protection Administrator Associate
- Microsoft 365 Certified: Enterprise Administrator Expert
- CompTIA Security+ / CySA+ / AZ/MS-500, HashiCorp Certified: Terraform Associate
- 2–4 years in Microsoft 365 / Azure security engineering or equivalent enterprise security operations.
- Proven experience managing Intune, Defender for Endpoint, and Entra ID conditional access policies.
- Hands-on with Microsoft Purview DLP and sensitivity labelling across cloud services.
- Familiarity with Defender Vulnerability Management and integration into SOC workflows.
- Understanding of NIST CSF, CIS Controls, ISO 27001, and Zero Trust principles.
- Experience with Terraform, and DevOps processes on GitHub.
- Scripting languages such as Python
- Why Join Us
- Join a modern, digital-first bank where you’ll engineer and protect the identity, data, and devices that power our business. As part of the Cloud Security Operations team, you’ll shape and secure our endpoint and User environments in a fast-paced, cloud-native environment. You’ll collaborate across Cyber Defence, Risk, and Cloud Engineering functions, developing automation and intelligence that drive resilience, regulatory compliance, and customer trust.Here, you’ll be empowered to secure identity, protect data, and enable innovation at the forefront of South African digital banking.
- Action Planning, Adaptive Thinking, Computer Literacy, Data Classification, Data Compilation, Data Controls, Data Modeling, Data Recovery, Digital Literacy, Information Technology (IT) Support, Legal Practices, Numerical Aptitude, Report Review, Test Case Management
- Competencies
- Collaborates
- Communicates Effectively
- Cultivates Innovation
- Decision Quality
- Ensures Accountability
- Manages Complexity
- Nimble Learning
- Optimizes Work Processes
- Closing Date
- 24 September 2026 , 23:59
- The appointment will be made from the designated group in line with the
- The Old Mutual Story!
Preferred Qualifications
- Certifications (Preferred):
- Nice to have - Experience with Terraform, and DevOps processes on GitHub.