Apply now »

Threat Detection and Response Engineer

Date:  5 Aug 2026
Location: 

Midrand, Gauteng, ZA

Company:  Sanlam Group

Who are we?

MiWay is a direct financial services company. We are passionate about service excellence, convenience and offering our clients superior value products. Our Vision is to be a world-class direct financial services business that offers a complete array of services under one convenient umbrella – all managed online. We are positive that with the right people on board, we will continue to grow and give our clients the freedom to do things their way – free from worry and most importantly at peace with all the “what-ifs” of the world. Company values that every employee subscribes to are: Energy, Freedom, Accountability and Attitude. The ideal candidate is one who has the courage to be bold and subscribes to MiWay’s core values! Do you have a positive attitude, love a challenge, treat your colleagues with respect and look for solutions, not problems? If yes, then MiWay is the place for you!

What will you do?

The Threat Detection and Response Engineer is responsible for operating and enhancing the organization’s defensive security technologies across network, cloud, and database environments. This role focuses on identifying, mitigating, and preventing threats by managing next-generation security controls, monitoring critical systems, and supporting investigation and response activities. The ideal candidate combines strong technical depth in network and cloud security with hands-on expertise in threat detection and prevention.

What We Offer

•    Exposure to advanced, enterprise-grade security technologies.
•    Professional development and certification support.
•    Opportunity to contribute to proactive security improvements and threat reduction.
•    A collaborative, growth oriented cybersecurity environment.

What will make you successful in this role?

Required Qualifications


Education and Experience
•    3–5 years experience in Security Operations, Network Security, or Threat Management.
•    Hands-on experience with at least one major NGFW or NG threat platform.
•    Experience monitoring cloud environments (Azure, AWS, or GCP).
•    Strong background in networking fundamentals and packet-level analysis.


Technical Skills
•    Solid understanding of: 
o    NGFW, IPS, and threat prevention technologies
o    SIEM platforms (e.g., Sentinel)
o    EDR/XDR platforms
o    Cloud-native security tooling
o    Database auditing and activity monitoring
•    Ability to analyze and interpret logs from multiple systems.
•    Basic scripting capability (PowerShell, Python) is an advantage.


Certifications (Preferred but not required)
•    Network/security certifications such as: 
o    CompTIA Security+, CySA+, Network+
o    Fortinet NSE, (vendor-neutral acceptance)
o    AZ-500, MS-500, or equivalent cloud certs

Key Responsibilities

1. Firewall and Threat Prevention Administration
•    Administer and tune next-generation firewall (NGFW) platforms (vendor-agnostic).
•    Configure and optimize: 
o    Intrusion Prevention Systems (IPS)
o    Application Control and URL Filtering policies
o    Threat signature updates and custom signatures
o    SSL/TLS inspection policies where applicable
•    Monitor and analyze firewall logs to identify anomalies and potential threats.

 

2. Next-Generation Threat Management
•    Manage and optimize threat detection technologies, including: 
o    Support Endpoint/Extended Detection & Response (EDR/XDR)
o    Threat analytics and behavior-based detection platforms
o    Threat intelligence ingestion feeds 
•    Develop, tune, and maintain detection rules and behavioral policies.
•    Perform alert triage, preliminary investigations.
•    Participate in threat-hunting activities and continuous monitoring tasks.

 

3. Cloud Threat Monitoring
•    Monitor cloud workloads using: 
o    Microsoft Platforms, or similar.
o    CASB/SASE platforms for SaaS and cloud identity protection
•    Investigate cloud-generated alerts (IAM anomalies, workload threats, network anomalies).
•    Validate compliance with cloud security benchmarks (e.g., CIS, NIST).
•    Support secure configuration, access control governance, and cloud incident response.

 

4. Security Monitoring
•    Monitor database logs and security event streams for suspicious activity.
•    Manage and tune Database Activity Monitoring (DAM) or equivalent solutions.
•    Review privileged user access and sensitive data operations.
•    Active Directory security monitoring and hardening.
•    Authentication and identity threat detection.
•    Microsoft Entra ID security monitoring.
•    Analyze, prioritize, and coordinate remediation of vulnerabilities
•    Present findings and recommendations to application owners and management.
•    Support monitoring of data loss prevention (DLP) policies for database-driven exfiltration risks.

 

5. Advanced Networking and Security Foundations
•    Interpret and troubleshoot network-layer issues affecting threat visibility.
•    Strong understanding of: 
o    TCP/IP, routing, switching, VLANs
o    Packet analysis tools (Wireshark)
•    Apply network knowledge in support of security investigations and threat triage.



6. Network Address Translation (NAT)
•    Understand how NAT interacts with: 
o    Firewall policies
o    VPN topologies
o    Threat detection and network visibility

Soft Skills

•    Strong analytical and problem solving skills.
•    Ability to multi-task across several ongoing security tasks.
•    Clear written and verbal communication skills for reports and escalations.
•    Ability to work collaboratively with Security Administrator and Infrastructure teams.
•    High attention to detail and accuracy in security monitoring tasks.

Knowledge and Skills

Cyber Security Administration
Cyber Security Audits
Cyber Security Compliance
Assessing security risks
Assessment risk mitigation for the organisation

Personal Attributes

Plans and aligns - Contributing through others
Decision quality - Contributing through others
Optimises work processes - Contributing through others
Interpersonal savvy - Contributing through others

Build a successful career with us

We’re all about building strong, lasting relationships with our employees. We know that you have hopes for your future – your career, your personal development and of achieving great things. We pride ourselves in helping  our employees to realise their worth. Through its five business clusters – Sanlam Fintech, Sanlam Life and Savings, Sanlam Investment Group, Sanlam Allianz, Santam, as well as MiWay and the Group Office – the group provides many opportunities for growth and development.

Core Competencies

Being resilient - Contributing through others
Collaborates - Contributing through others
Cultivates innovation - Contributing through others
Customer focus - Contributing through others
Drives results - Contributing through others

Turnaround time

The shortlisting process will only start once the application due date has been reached. The time taken to complete this process will depend on how far you progress and the availability of managers. Deadline to apply: 12 August 2026. 

Our commitment to transformation

At MiWay we believe in cultivating a positive and dynamic working environment that gives you freedom and opportunity to succeed. MiWay is committed to transformation and embracing diversity. This is what drives us to achieve a multicultural workplace with employment equity as a key goal to create an inclusive workforce, reflective of the demographics of our society.

Apply now »