Microservices Security Specialist.
About this role
Microservices Security Specialist
Location: Centurion, Gauteng (provisional – to be confirmed)
Positions Available: 5
Salary: Market-related
Employment Type: To be confirmed
Job Overview
We are seeking experienced and technically proficient Microservices Security Specialists to design, implement, manage and continuously improve security controls across enterprise microservices architectures, containerised applications and cloud-native environments.
The successful candidates will be responsible for securing distributed applications, APIs, containers, Kubernetes environments and service-to-service communications against cybersecurity threats, vulnerabilities and unauthorised access.
This role requires strong hands-on expertise in microservices security, API protection, container security, DevSecOps, secure application architecture and cloud-native security technologies.
The ideal candidates will have proven experience implementing security controls within enterprise microservices environments, with a strong understanding of secure software development, application security testing, identity management and Zero Trust security principles.
Key Responsibilities
Microservices Security Architecture and Implementation
- Design, implement and maintain security controls across enterprise microservices architectures.
- Conduct security assessments of distributed applications and microservices environments.
- Identify and remediate security vulnerabilities within microservices, APIs and supporting infrastructure.
- Implement secure communication mechanisms between microservices and distributed applications.
- Apply Zero Trust principles to service-to-service authentication and authorisation.
- Support the development of secure microservices architecture standards and security design patterns.
- Conduct threat modelling and security architecture reviews for cloud-native applications.
- Collaborate with software architects and development teams to implement security-by-design principles.
- Ensure microservices security controls align with organisational security policies and recognised industry standards.
API Security and Service-to-Service Protection
- Implement and maintain security controls for RESTful APIs, GraphQL APIs and microservices endpoints.
- Configure secure API authentication and authorisation mechanisms.
- Implement OAuth 2.0, OpenID Connect, JSON Web Tokens (JWT) and mutual TLS (mTLS).
- Secure API gateways and manage API access policies.
- Identify and mitigate common API vulnerabilities, including those outlined in the OWASP API Security Top 10.
- Implement API rate limiting, request validation and traffic protection mechanisms.
- Secure service-to-service communications within distributed environments.
- Monitor API security events and investigate suspicious access patterns.
- Support API security testing and vulnerability remediation.
Container and Kubernetes Security
- Implement security controls across Docker and Kubernetes environments.
- Conduct container image vulnerability assessments and security configuration reviews.
- Secure container registries, runtime environments and orchestration platforms.
- Configure Kubernetes Role-Based Access Control (RBAC), network policies and workload security controls.
- Implement secure secrets management and container authentication mechanisms.
- Monitor container and Kubernetes security events.
- Identify and remediate misconfigurations within containerised environments.
- Apply security hardening standards to Kubernetes clusters and workloads.
- Support container runtime protection and cloud-native threat detection.
- Collaborate with infrastructure and DevOps teams to maintain secure container platforms.
DevSecOps and Secure Software Development
- Integrate security controls into software development and CI/CD pipelines.
- Implement automated application security testing within development workflows.
- Support Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST) and Software Composition Analysis (SCA).
- Identify vulnerabilities in application code, third-party dependencies and container images.
- Implement secure coding standards and software supply chain security controls.
- Support Infrastructure as Code (IaC) security scanning and configuration validation.
- Collaborate with development teams to remediate security findings.
- Promote secure software development lifecycle (SSDLC) practices.
- Support continuous security monitoring and automated compliance checks.
Cloud-Native Security and Infrastructure Protection
- Implement security controls for microservices deployed across Microsoft Azure, AWS or Google Cloud environments.
- Secure cloud-native application platforms and managed Kubernetes services.
- Configure network segmentation and secure connectivity between microservices.
- Implement cloud identity and access management controls.
- Secure application secrets, cryptographic keys and sensitive configuration information.
- Support service mesh security implementations.
- Implement workload identity and secure service authentication.
- Assess cloud-native infrastructure for vulnerabilities and security misconfigurations.
- Support security monitoring, logging and incident response within distributed application environments.
Security Monitoring, Risk Management and Compliance
- Monitor microservices and API security events using relevant security monitoring tools.
- Investigate application security incidents and coordinate remediation activities.
- Conduct vulnerability assessments and security risk reviews.
- Maintain security documentation, assessment reports and remediation records.
- Support security audits and compliance assessments involving cloud-native applications.
- Implement security controls aligned with ISO 27001, NIST and OWASP guidance.
- Monitor emerging microservices, container and API security threats.
- Recommend improvements to application security architecture and operational processes.
- Provide technical guidance to development, DevOps and infrastructure teams.
Minimum Requirements
- Relevant diploma or degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, Information Security or a related discipline.
- Typically 3–5 years of relevant experience in application security, DevSecOps, cloud-native security or microservices security.
- Proven hands-on experience implementing security controls within microservices or distributed application environments.
- Strong understanding of microservices architecture and secure application design principles.
- Practical experience securing REST APIs and service-to-service communications.
- Strong knowledge of OAuth 2.0, OpenID Connect, JWT and TLS/mTLS.
- Experience implementing or assessing security controls within Docker and Kubernetes environments.
- Understanding of Kubernetes RBAC, network policies, secrets management and container security.
- Experience with application security testing tools and methodologies.
- Knowledge of OWASP Top 10 and OWASP API Security Top 10.
- Experience integrating security controls into CI/CD pipelines.
- Familiarity with cloud-native platforms such as Microsoft Azure, AWS or Google Cloud.
- Understanding of secure software development lifecycle and DevSecOps principles.
- Experience conducting vulnerability assessments and coordinating security remediation.
- Strong technical troubleshooting, analytical and documentation skills.
Technical Skills and Competencies
Microservices and Application Security
- Microservices architecture and distributed systems
- Secure application architecture
- Microservices threat modelling
- Service-to-service authentication and authorisation
- Zero Trust application security
- Secure software development lifecycle
- Application vulnerability assessments
- Secure coding principles
- OWASP Top 10
- OWASP API Security Top 10
API Security Technologies
- RESTful API security
- GraphQL API security
- OAuth 2.0
- OpenID Connect (OIDC)
- JSON Web Tokens (JWT)
- Mutual TLS (mTLS)
- API authentication and authorisation
- API gateways
- API rate limiting and request validation
- API vulnerability testing
Experience with platforms such as:
- Azure API Management
- AWS API Gateway
- Kong Gateway
- Apigee
- NGINX
- Other enterprise API management and security solutions
Container and Kubernetes Security
- Docker
- Kubernetes
- Kubernetes RBAC
- Kubernetes Network Policies
- Container image scanning
- Container runtime security
- Kubernetes secrets management
- Kubernetes security hardening
- Admission controllers and policy enforcement
- Container registry security
Experience with tools such as:
- Trivy
- Aqua Security
- Prisma Cloud
- Sysdig
- Falco
- Kubescape
- Other container and Kubernetes security platforms
DevSecOps and Application Security Testing
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- Infrastructure as Code security scanning
- CI/CD pipeline security
- Software supply chain security
- Dependency vulnerability management
- Secrets scanning
- Automated security testing
- Security policy enforcement
Experience with tools such as:
- SonarQube
- Checkmarx
- Fortify
- Snyk
- Veracode
- OWASP ZAP
- Burp Suite
- GitHub Advanced Security
- GitLab Security
Cloud-Native Security
- Microsoft Azure
- Amazon Web Services (AWS)
- Google Cloud Platform (GCP)
- Azure Kubernetes Service (AKS)
- Amazon Elastic Kubernetes Service (EKS)
- Google Kubernetes Engine (GKE)
- Cloud IAM and workload identity
- Cloud-native network security
- Secrets and key management
- Cloud workload protection
Service Mesh and Secure Communications
- Istio
- Linkerd
- Envoy
- Service mesh security
- Mutual TLS
- Service identity
- Traffic encryption
- Service-to-service authorisation
- Secure ingress and egress controls
- Network segmentation
Automation and Infrastructure as Code
- Terraform
- Kubernetes YAML
- Helm
- Dockerfiles
- GitHub Actions
- GitLab CI/CD
- Jenkins
- Azure DevOps
- Python
- Bash
- PowerShell
- Security automation and configuration validation
Security Monitoring and Incident Response
- Application security logging
- Kubernetes audit logging
- Cloud-native threat detection
- SIEM integration
- Container runtime monitoring
- API security monitoring
- Vulnerability management
- Security incident investigation
- Threat detection and remediation
Security Frameworks and Standards
- OWASP Top 10
- OWASP API Security Top 10
- OWASP Application Security Verification Standard (ASVS)
- NIST Secure Software Development Framework (SSDF)
- NIST Cybersecurity Framework
- ISO/IEC 27001
- CIS Kubernetes Benchmark
- Zero Trust security architecture
- Cloud-native security best practices
Relevant Certifications (Advantageous)
One or more of the following certifications would be beneficial:
- Certified Kubernetes Security Specialist (CKS)
- Certified Kubernetes Administrator (CKA)
- Certified Kubernetes Application Developer (CKAD)
- Certified Cloud Security Professional (CCSP)
- Certified Information Systems Security Professional (CISSP)
- Certified Ethical Hacker (CEH)
- CompTIA Security+
- Microsoft Certified: Azure Security Engineer Associate
- AWS Certified Security – Specialty
- Google Cloud Professional Cloud Security Engineer
- Relevant DevSecOps, application security or cloud-native security certifications
Key Personal Attributes
- Strong analytical and technical problem-solving abilities.
- Excellent understanding of modern application security threats.
- Strong attention to detail and security awareness.
- Ability to identify and remediate complex microservices security vulnerabilities.
- Proactive approach to secure application development and infrastructure protection.
- Excellent communication and stakeholder engagement skills.
- Ability to collaborate effectively with development, DevOps, cloud and cybersecurity teams.
- Strong organisational and technical documentation skills.
- Ability to manage multiple security priorities and technical projects.
- High levels of confidentiality, accountability and professional integrity.
Application Requirements
Interested candidates should submit an updated CV clearly detailing their practical microservices security, API security, container security and DevSecOps experience, together with copies of relevant academic qualifications and professional certifications.
Candidates should specifically highlight:
- Microservices architectures and distributed application environments they have secured.
- Experience implementing API authentication, authorisation and security controls.
- Practical experience with Docker, Kubernetes and container security.
- OAuth 2.0, OpenID Connect, JWT and mutual TLS implementation experience.
- API gateway security and service-to-service communication protection.
- Application security testing and vulnerability remediation experience.
- DevSecOps, CI/CD security and automated security testing experience.
- Cloud-native security implementations across Azure, AWS or GCP.
- Service mesh security, workload identity and secrets management experience.
- Security tools, platforms and technologies they have implemented or administered.
- Relevant microservices security, application security and cloud-native security projects.
- Professional certifications and specialised technical training.
Important: This is a specialist Microservices Security opportunity requiring demonstrable hands-on experience securing microservices architectures, APIs and cloud-native applications. General software development, infrastructure administration or cybersecurity experience without substantial microservices security expertise will not be sufficient.
Please note: Specific project requirements, remuneration, employment arrangements and working conditions will be confirmed during the recruitment process.
Originally posted on Himalayas