Capitec Bank Ltd

Cyber Security Engineer (Pen Tester)

Capitec Bank Ltd Stellenbosch, Western Cape, South Africa

Banking · 10,001+ employees

Jul 22
security Senior (5-10 yrs) Full-time South Africa
Log in to apply, save this posting, or score it against your profile with AI.

About the role

Conduct penetration testing across web applications, APIs, and internal systems to identify vulnerabilities. Engage with stakeholders to provide actionable remediation recommendations and support security research.

What they look for

Penetration testing Web application security API security Burp Suite OWASP Top 10 Python Bash PowerShell Java PHP Vulnerability assessment Security remediation Scoping Reporting Problem-solving

Requirements

Requires at least 6 years of professional penetration testing experience and proficiency in scripting languages like Python or Bash. Candidates must hold a grade 12 certification and a relevant tertiary qualification or IT security certification.

Benefits

Continuous learning Collaborative work environment

Full description

Apply by: 06 July 2026

We're on the lookout for energetic, self-motivated individuals who share our passion for service in the banking industry. To be part of the journey, follow the steps below:

1. To see what life at Capitec is all about and complete a short assessment, please click here!

2. Once you have completed the above finalize your application by clicking apply below.

Join a team that protects what matters

At Capitec, we’re building secure, innovative banking solutions and we need skilled professionals who can stay one step ahead of evolving cyber threats. As a Cyber Security Engineer, specialising in Penetration Testing, you’ll play a key role in safeguarding our systems, applications, and customer data by identifying vulnerabilities before they become risks.

What Will You Do?

  • Conduct penetration testing across web applications, APIs, and internal systems
  • Participate in scoping sessions with internal stakeholders to define testing requirements
  • Perform security assessments (primarily across API and web application environments)
  • Analyze findings and provide clear, actionable remediation recommendations
  • Engage with internal stakeholders to discuss vulnerabilities and resolution
  • Support research and continuous improvement of security testing practices
  • Collaborate with senior team members on escalations or complex issues

What Are We Looking For

  • At least 6 years of experience in penetration testing in a professional work environment
  • Strong exposure to web applications and API security
  • Experience using tools like Burp Suite or similar
  • Understanding of common vulnerabilities (e.g. OWASP Top 10)
  • Ability to read and understand at least one scripting/programming language (e.g. Python, Bash, PowerShell, Java, PHP)
  • Strong problem-solving skills and attention to detail
  • Ability to communicate technical findings clearly to non-technical stakeholders
  • Ability to own the full testing lifecycle from scoping through to reporting

Minimum Qualification

  • A grade 12 certification
  • Tertiary qualification OR relevant certification in IT / Cyber Security

Ideal Qualifications

  • OSCP (Offensive Security Certified Professional)
  • EWPT (eLearnSecurity Web Penetration Tester)
  • Burp Suite Practitioner Certification

Why Capitec?

  • Work on high-impact security challenges within a leading digital bank
  • Be part of a collaborative and forward-thinking security team
  • Continuous learning and exposure to modern fintech and API ecosystems
  • Opportunity to influence how security is embedded across the organisation

Additional Information

  • Clear criminal and credit record

Capitec is committed to diversity, applications to this position will strictly be considered in support of our employment equity goals.

Similar roles