Information Technology Security Manager
Dariel
Endpoint Security Management
- Design, implement and manage Microsoft Intune security configurations across Windows, macOS, iOS and Android devices.
- Compliance Policies
- Configuration Profiles
- Endpoint Security Policies
- Security Baselines
- Device Restrictions
- App Protection Policies (MAM)
- Ensure endpoint security controls remain aligned to Microsoft security best practices, CIS benchmarks and organisational standards.
- Continuously review and optimise endpoint security configurations to reduce risk and improve user experience.
Intune & Device Management
- Administer Microsoft Intune as the primary endpoint management platform.
- Drive adoption of modern endpoint management capabilities and cloud-native device management practices.
- Support co-management strategies between Intune and SCCM/MECM.
- Lead workload transitions from on-premise management solutions to Intune where appropriate.
- Maintain device lifecycle security standards across enrolment, compliance, monitoring and decommissioning processes.
SCCM/MECM Administration
- Patch deployment
- Software distribution
- Endpoint configuration management
- Compliance reporting
- Ensure timely deployment of security updates and critical patches.
- Support patch governance and vulnerability remediation initiatives.
- Collaborate with infrastructure and EUC teams to improve endpoint management maturity.
BYOD Security Governance
- Design and implement BYOD security frameworks that balance corporate security requirements with user convenience.
- App Protection Policies (MAM)
- MAM without MDM
- Device enrolment controls
- Conditional Access device requirements
- Corporate application access controls
- Ensure corporate data remains protected on personal devices through appropriate security controls and data separation mechanisms.
- Review BYOD adoption and security posture regularly and recommend improvements where necessary.
Endpoint Protection & Hardening
- Endpoint Detection and Response (EDR)
- Antivirus
- Attack Surface Reduction (ASR)
- Threat and Vulnerability Management
- Automated Investigation and Remediation
- BitLocker
- Windows Security Baselines
- Firewall Policies
- Device Control Policies
- CIS Benchmarks
- Monitor emerging endpoint risks and recommend mitigation strategies.
Compliance Monitoring & Risk Reduction
- Monitor device health, compliance status and security posture across the endpoint estate.
- Investigate and remediate non-compliant devices in collaboration with EUC and Service Desk teams.
- Support vulnerability management and patch compliance initiatives.
- Develop reporting and dashboards to track endpoint security performance and trends.
Incident Response & Security Operations
- Provide technical support during endpoint security incidents.
- Device isolation
- Investigation support
- Forensic artefact collection
- Malware remediation
- Work closely with Security Operations Centre (SOC) teams during investigations and recovery activities.
- Assist in identifying root causes and implementing preventative measures.
Zero Trust Enablement
- Support the organisation's Zero Trust security strategy by integrating endpoint compliance with identity and access controls.
- Collaborate with IAM and security engineering teams to align Conditional Access policies with device trust signals.
- Ensure device compliance data is effectively leveraged to strengthen access control decisions.
- Contribute to broader cloud and modern workplace security initiatives.
Decision-Making Authority
The successful candidate will:
- Implement and manage endpoint security configurations within delegated authority.
- Recommend security baselines, compliance controls and BYOD security requirements.
- Escalate high-risk devices, unresolved security issues and persistent non-compliance concerns to cyber leadership.
- Influence endpoint security standards and best practices across the organisation.
Essential Skills & Experience
Technical Experience
- Minimum 5-8 years' experience in endpoint security, endpoint management or modern workplace security engineering.
- Strong hands-on experience administering Microsoft Intune in enterprise environments.
- Experience managing SCCM/MECM and co-managed endpoint environments.
- Extensive experience implementing Microsoft Defender for Endpoint security controls.
- Proven experience managing BYOD and mobile device security frameworks.
- Experience with Windows, macOS, iOS and Android device management and security.
- Strong understanding of endpoint hardening, patch management and vulnerability remediation.
Security & Governance Knowledge
- Zero Trust security principles
- CIS Benchmarks
- Microsoft Security Baselines
- Device compliance frameworks
- Endpoint risk management
- Data protection controls
- Understanding of Conditional Access, identity-driven security and device trust concepts.
- Experience supporting audits, compliance reviews and security assessments.
Professional Skills
- Strong troubleshooting and problem-solving capabilities.
- Excellent stakeholder engagement and communication skills.
- Ability to work effectively with EUC, Service Desk and Security Operations teams.
- Strong attention to detail and commitment to security best practice.
- Ability to prioritise work effectively within a fast-paced environment.
Preferred Qualifications
- Microsoft Certified: Endpoint Administrator Associate (MD-102)
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Azure Administrator Associate (AZ-104)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- CompTIA Security+
- CISSP, CISM or equivalent security certification advantageous
Core Technologies
Endpoint Management
- Microsoft Intune
- Endpoint Security Policies
- Compliance Policies
- Configuration Profiles
- App Protection Policies (MAM)
Endpoint Protection
- Microsoft Defender for Endpoint
- Endpoint Detection and Response (EDR)
- Antivirus
- Attack Surface Reduction (ASR)
- Threat & Vulnerability Management
Legacy & Co-Management Platforms
- SCCM / MECM
- Software Deployment
- Patch Management
- Co-Management
Device Hardening & Compliance
- BitLocker
- Windows Security Baselines
- CIS Benchmarks
- Device Compliance Policies
- Firewall Management
BYOD Security
- Mobile Application Management (MAM)
- MAM without MDM
- BYOD Conditional Access
- Corporate Data Protection Controls
Identity Integration
- Microsoft Entra ID
- Device Registration
- Hybrid Azure AD Join
- Conditional Access Integration
Why Join Us?
This is an exciting opportunity to play a key role in securing a modern workplace environment through best-in-class endpoint and BYOD security practices. You will work with leading Microsoft technologies, contribute to critical Zero Trust initiatives, and help shape the future of endpoint security across the organisation.
For employers only
Is this your company's job post? Verify ownership to manage this listing and receive applications directly.
Claim this listingLooking to apply for this job? Use the Apply button above.
See more jobs in Roodepoort, Gauteng