SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Ozow is a leading fintech company redefining digital payments in South Africa and beyond. The Senior Security Analyst is the most senior hands-on security specialist, accountable for the strength of the company's security posture and for protecting the integrity, availability, and confidentiality of systems and data. Reporting to the Infrastructure Manager, this role owns and evolves the security programme rather than only executing it.
This is a deeply technical role for someone who enjoys both breaking and securing systems and is ready to set direction. You will set security standards, lift security capability across the business, and translate technical risk into decisions that leadership, auditors, banks, and merchants can act on.
Key responsibilities include:
**Security Direction and Technical Leadership**
- Own and evolve the security roadmap with the Infrastructure Manager, sequenced by risk and business impact
- Define security standards, baselines, and testing methodology, and hold teams to them
- Mentor engineers and infrastructure specialists; set the testing strategy: what is tested, how often, and to what depth
- Report security posture, risk, and progress to senior leadership in business-actionable terms
**Offensive Security and Assurance**
- Lead hands-on penetration testing across infrastructure, cloud workloads, applications, APIs, and endpoints
- Design and run adversary simulations and red team exercises to validate real-world defensive capability
- Validate remediation through retesting and drive a purple-team approach with Engineering
**Security Operations and Incident Response**
- Own the selection, implementation, and tuning of security tooling (SIEM, EDR, scanners, WAFs, IDS/IPS)
- Set the detection and monitoring strategy; define escalation paths and response playbooks
- Act as technical lead during incidents, coordinating Infrastructure, Engineering, and Risk through to closure
- Run post-incident reviews and turn findings into permanent control improvements
**Vulnerability Management and Hardening**
- Own vulnerability management end to end across cloud infrastructure, applications, CI/CD pipelines, and endpoints
- Define risk-based prioritisation and remediation SLAs; drive closure across teams
- Act as design authority on secure architecture, least privilege, segmentation, and encryption
- Define and enforce secure configuration baselines, aligned to CIS Benchmarks where applicable
**Automation and Enablement**
- Automate repeatable security work: triage, reporting, evidence collection, and remediation tracking
- Own external penetration testing engagements end to end
- Define safe, controlled GenAI use cases for security, including guardrails
- Embed security into engineering practice, pipelines, and workflows (DevSecOps)
**Compliance, Governance, and Stakeholders**
- Lead the technical workstream for audits across PCI DSS, ISO 27001, POPIA, and relevant SARB directives
- Manage relationships with external auditors, regulators, and third-party security assessors
- Translate compliance requirements into technical controls and evidence
Ozow values courageous, hands-on leadership; optimism and agility; and the strength to persevere under pressure. The company fosters a culture of innovation, diversity, and inclusivity.
**Requirements**
The posting does not explicitly state years of experience, certifications, or formal education requirements in the provided excerpt. However, the role clearly requires deep expertise in offensive and defensive security, hands-on penetration testing, security architecture, incident response, vulnerability management, and compliance frameworks (PCI DSS, ISO 27001, POPIA, SARB). Candidates should have demonstrated experience leading security programmes, mentoring technical teams, and translating technical risk for executive and regulatory audiences.