Datafin IT Recruitment

Senior Identity Security Specialist (Enterprise Access & Governance) (Contract) (CPT Hybrid) - Datafin IT Recruitment

Cape Town, Western Cape 14 hour(s) ago Permanent
Salary - Market Related
Apply On Company Site

ENVIRONMENT:

A growing provider of cutting-edge Custom Cloud Solutions seeks an experienced Senior Identity Security Specialist to join its InfoSec team on a long-term contract basis. This role is designed for an InfoSec practitioner who views Identity as the primary security perimeter. You will bridge the gap between traditional infrastructure / AD environments and modern Microsoft Entra ID cloud security. Rather than functioning as a pure technical sysadmin, you will own the identity threat surface—proactively identifying security risks, designing architectural controls, and driving governance across complex, enterprise-scale environments.

 

DUTIES:

Identity Architecture & Tiering Governance –

  • Drive the evolution and enforcement of identity privilege models, moving legacy environments from traditional AD Tiering (Tier 0/1/2), Red Forest / Bastion models, and Delegation of Control Frameworks toward Microsoft’s modern Enterprise Access Model (EAM).

Entra ID & Hybrid Identity Security –

  • Lead security strategy and enforcement across Microsoft Entra ID (Azure AD) and on-premises Active Directory.
  • Oversee Enterprise Application registrations, service principal permissions, consent frameworks, and tenant-wide security boundaries.

Modern Authentication & Passwordless Adoption –

  • Architect, refine, and enforce passwordless authentication paths, including Windows Hello for Business (WHfB), Passkeys (FIDO2), and robust Conditional Access/MFA policies.

Access Delegation & Control –

  • Audit, redesign, and maintain strict delegation models across hybrid environments to eliminate privilege creep, lateral movement paths, and over-provisioned administrative accounts.

Autonomous Security Ownership –

  • Independently scan the environment for identity security gaps, misconfigurations, and governance blind spots. Define solutions and execute remediations with minimal oversight.

Cross-Team Collaboration –

  • Act as an authoritative InfoSec lead, advising internal Infrastructure, Operations, and Application teams on identity best practices, compliance, and risk reduction.

REQUIREMENTS:

Senior-Level Experience: Demonstrated background in Information Security / InfoSec with a heavy focus on Identity Architecture, IAM, and Identity Access Governance (IAG).

Deep Microsoft Identity Expertise: Extensive hands-on and architectural knowledge of Microsoft Entra ID and Active Directory Domain Services (AD DS).

Privileged Access Architecture: Practical knowledge of Microsoft Privilege/Separation models (Enterprise Access Model, AD Tiering, Red/Bastion Forest legacy concepts, and Delegation of Control Wizard/ACL management). 

Enterprise App Governance: Strong grasp of Entra ID Enterprise Application Registrations, OAuth/OIDC permissions, App Roles, and API consent models.

Strong Authentication Standards: Deep experience implementing modern auth controls—MFA, FIDO2/Passkeys, and Windows Hello for Business.

InfoSec & Governance Focus: Ability to analyse identity posture through a threat, compliance, and risk lens rather than purely operational task execution.

Advantageous (Nice to Have) -

  • Experience with Privileged Access Management (PAM) solutions (e.g., CyberArk, Delinea, Entra PIM).
  • Core understanding of Public Key Infrastructure (PKI), digital certificates, and Smart Card/Certificate-Based Authentication (CBA).

ATTRIBUTES:

Autonomous & Self-Directed: Thrives on vague or high-level direction; capable of identifying complex problems independently, defining the scope, and driving solutions to completion.

Exceptional Communication: Strong verbal and written communication skills; comfortable presenting identity risk and security strategy to corporate stakeholders and executive leadership.

Corporate Professionalism: Accustomed to operating within strict enterprise/banking environments, maintaining a polished and professional standard at all times.

By applying to a job using RecruitmentPartner, you are agreeing to comply with and be subject to RecruitmentPartner Terms for use of our website.