Hiring.Camp

Senior Security Analyst

Ozow

·

Today

Location
Cape Town
Department
Technology
Seniority
Senior
Source
Greenhouse

Description

Meet Ozow 

Ozow is a leading fintech company that’s redefining digital payments in South Africa and beyond, making payments more accessible, secure, and convenient for businesses and consumers alike. As a fast-growing player in the sector, we foster a culture of innovation, diversity, and inclusivity. 

More about this Ozow fantastic position 

The Senior Security Analyst is the most senior hands-on security specialist at Ozow, accountable for the strength of our security posture and for protecting the integrity, availability, and confidentiality of our systems and data. Reporting into the Infrastructure Manager, this role owns and evolves the security programme rather than only executing it. 

This is a deeply technical role for someone who enjoys both breaking and securing systems, and who is ready to set direction. You will set the standards, lift security capability across the business, and translate technical risk into decisions that leadership, auditors, banks, and merchants can act on. 

Your role and responsibilities 

Security direction and technical leadership 

  • Own and evolve the security roadmap with the Infrastructure Manager, sequenced by risk and business impact. 
  • Define security standards, baselines, and testing methodology, and hold teams to them. 
  • Mentor engineers and infrastructure specialists, and set the testing strategy: what is tested, how often, and to what depth. 
  • Report security posture, risk, and progress to senior leadership in terms the business can act on. 

Offensive security and assurance 

  • Lead hands-on penetration testing across infrastructure, cloud workloads, applications, APIs, and endpoints. 
  • Design and run adversary simulations and red team exercises to validate real-world defensive capability. 
  • Validate remediation through retesting, and drive a purple-team approach with Engineering. 

Security operations and incident response 

  • Own the selection, implementation, and tuning of security tooling (SIEM, EDR, scanners, WAFs, IDS/IPS). 
  • Set the detection and monitoring strategy, and define escalation paths and response playbooks. 
  • Act as technical lead during incidents, coordinating Infrastructure, Engineering, and Risk through to closure. 
  • Run post-incident reviews and turn findings into permanent control improvements. 

Vulnerability management and hardening 

  • Own vulnerability management end to end across cloud infrastructure, applications, CI/CD pipelines, and endpoints. 
  • Define risk-based prioritisation and remediation SLAs, and drive closure across teams. 
  • Act as design authority on secure architecture, least privilege, segmentation, and encryption. 
  • Define and enforce secure configuration baselines, aligned to CIS Benchmarks where applicable. 

Automation and enablement 

  • Automate repeatable security work: triage, reporting, evidence collection, and remediation tracking, and own external penetration testing engagements end to end. 
  • Define safe, controlled GenAI use cases for security, including the guardrails around them. 
  • Embed security into engineering practice, pipelines, and workflows (DevSecOps). 

Compliance, governance, and stakeholders 

  • Lead the technical workstream for audits across PCI DSS, ISO 27001, POPIA, and relevant SARB directives. 
  • Own internal security policies and standards, and advise Risk on where risk acceptance is appropriate. 
  • Lead technical responses for merchant and bank due diligence and security questionnaires. 

You are an ideal candidate if you have 

  • Bachelor’s degree in computer science, Information Security, or a related field, or equivalent experience. 
  • 8+ years in cybersecurity, offensive security, security engineering, or security operations, including clear ownership of a security programme or domain. 
  • Deep hands-on penetration testing and adversary simulation experience, and experience leading incidents through to root cause and closure. 
  • A track record in vulnerability management at scale, including setting SLAs and driving remediation across teams you do not manage. 
  • Deep working knowledge of ISO 27001, NIST, PCI DSS, CIS Benchmarks, and OWASP, and how to evidence them under audit. 
  • Experience selecting and implementing security tooling, not only operating it, strong AWS security expertise or another major cloud, and scripting ability. 
  • Advantageous: OSCP, OSCE, CRTO, CREST, CISSP, or AWS Security Specialty, and regulated-environment experience. 
  • Able to influence without authority, and to take a technical risk to an executive, an auditor, or a merchant and be understood. 
  • Self-directed and pragmatic, focused on practical risk reduction over perfect security. 

Your skills and competencies

  • You eagerly embrace change, absorb cross-functional skills, and connect ideas across disciplines to drive fresh thinking and innovation. 
  • Ability to initiate, develop, maintain and leverage outstanding relationships to influence a wide network, both inside and outside the company. 
  • A trailblazer who steps up, takes charge, and creates meaningful impact—those driven by performance and purpose to lead from the front and make a real difference every day. 
  • You thrive in collaboration, embrace inclusion, and bring a genuine curiosity for global cultures—valuing collective success over individual credit. 
  • Demonstrate strategic foresight, sound judgement, and the ability to make confident decisions under uncertainty, always working toward the best possible outcomes. 
  • You challenge norms, champion innovation, and constantly seek growth—for themselves, their team, and the solutions they build. 
  • You are a decisive doer—those who take initiative, follow through with confidence, and ensure results through courageous, hands-on leadership. 
  • We value optimism, agility, and the strength to persevere under pressure—balancing performance with positivity, even in challenging environments. 
  • You are driven, proactive individuals who take ownership, face challenges with grit, and consistently push for excellence—not just as participants, but as catalysts for success. 

Interview process 

During the interview process you will meet with the People team, the hiring manager, and relevant CSuite. Our process may include psychometric and technical assessments, giving you an opportunity to demonstrate your strengths, skills and potential beyond your CV and interview.

In office perks 

  • Healthy breakfast, lunches and snacks
  • Monthly team connects 
  • On-site Barista 

Perks for South African based employees

  • Medical aid subsidy
  • Group Risk Insurance
  • Generous paid annual leave   
  • Birthday leave
  • Learning and Development opportunities 
  • Mentorship programme
  • Quarterly team building 
  • Community initiatives 
  • Access to cutting edge technology - Ozow Tech Stack

Our Employee Value Proposition

Join Ozow and become part of an elite force that challenges the ordinary and achieves the extraordinary. If you're driven to make an impact, embrace challenges, and seek unparalleled opportunities for growth, your journey starts here.

Compliance

As a fintech company, we prioritize data security, confidentiality, regulatory and compliance. Due to the sensitive nature of our work, we require individuals with a high level of integrity and trustworthiness to ensure adherence to financial regulations and industry standards. Given the sensitive nature of our work, all employees are expected to demonstrate professionalism, accountability, and a commitment to ethical conduct in line with financial regulations and industry standards

Ready to be exceptional? Apply now! 

Keen to know more? 

Interested in joining our rocket ship?  

To find out more about life at Ozow, head over to our Careers Page here!

Skills

AWSCI/CDCybersecurityPenetration TestingSIEMComplianceBaristaISO 27001CISSP

Similar Jobs

30

Senior Security Analyst

Abby Care·San Francisco·Hybrid

2d ago

Senior Security Analyst

Draftkings·Sofia, BG +1·Remote

2d ago

Senior Security Analyst

Gulf Coast Automation Group·Bloomingdale·Onsite

3d ago

Sr. Security Analyst

Spacex·Redmond, WA +1·Remote, Hybrid, Onsite

3d ago

Senior Security Analyst

Monzo·Cardiff, London or Remote·Remote

1w ago

Senior Security Analyst

MI Technical Solutions·Chesapeake, VA

2w ago

Senior Security Analyst

Brookfield·London - One Canada Square, Level 25

3w ago

Senior Security Analyst

Bbinsurance·300 North Beach Street, FL +1·Hybrid

3w ago

Senior Security Analyst

Valon·New York +1·Remote

3w ago

Sr. Security Analyst

Bdainc·Woodinville, Washington·Remote, Onsite

1mo ago

Senior Security Analyst

Cyderes·Bengaluru, Karnataka·Hybrid

2mo ago

Senior Security Analyst

Camlin·Málaga, Spain

2mo ago

Senior Security Analyst

Successacademycharterschool·New York·Onsite

2mo ago

Senior Security Analyst

We are hiring!·Singapore

2mo ago

Senior Security Analyst

TriNet·Hyderabad, Telangana

2mo ago

Senior Security Analyst

TriNet·Hyderabad, TS

2mo ago

Senior Security Analyst

Akamai·India·Remote

3mo ago

Senior Security Analyst

UltraViolet Cyber·Hyderabad·Onsite

3mo ago

Senior Security Analyst

Appian·Tokyo, Japan +1

4mo ago

Senior Security Analyst

Logicalis·Kuala Lumpur, MY

4mo ago

Senior Security Analyst

TMHCC enables you to take·Texas - Houston, US·Hybrid

5mo ago

Senior Security Analyst

Stellus Rx

5mo ago

Senior Security Analyst

TriNet·Hyderabad, TS

6mo ago

Senior Security Analyst

LSEG·IND-BLR-Divyasree Technopolis, India·Hybrid

11mo ago

Senior Security Analyst

Alchemy·N, A +1·Remote, Hybrid

1y+ ago

Senior Security Analyst

Quess·India

1y+ ago

[IT Delivery Center] Senior Information Security Analyst

Eurofins Scientific·Ho Chi Minh City, Ho Chi Minh·Hybrid

Today

Senior Security Risk Analyst

Muon Space·Remote +1·Remote

Today

Senior Specialist, Information Security Analyst

0101022-GIA PROD US LOS ANGELES·Pittsburgh, PA

Today

Senior Security Analyst in Security Ops - London

Bank of England Job Board -·London, GB

1d ago