KEYSTONE CYBER

Home For candidates

FOR CANDIDATES

Cyber security careers

We will not send your CV anywhere without asking you first, we will tell you when a role is not worth your time, and we will not pretend a market is hot when it is not.

How we work with you

Where the market is genuinely hiring

Some candid observations from the briefs we take, rather than the ones that make recruitment marketing look good.

STRONG DEMAND
Cloud security engineering, detection engineering, and mid-to-senior security operations. If you have real depth here you have leverage, and you should use it.
GROWING
GRC and privacy under POPIA in South Africa and DORA and NIS2 in the UK. More roles, but heavy competition from compliance generalists.
COMPETITIVE
Offensive security. Highly desirable, small pool of roles, and reputation matters more than in any other discipline.
CROWDED
Entry-level. L1 SOC is the realistic route in, and it means shifts. Anyone telling you otherwise is selling you a course.

What actually gets you shortlisted

Having read a great many security CVs, the pattern is consistent. Weak CVs list tools and certifications. Strong ones describe what changed because the person was there — an investigation they ran, a control they built, a backlog they reduced, a finding that led to a fix.

Certifications open doors early and matter less as you go. What replaces them is evidence: a repository, published research, a disclosure history, a detection you wrote. One concrete artefact outperforms three more acronyms.

If you are two years in and unsure which direction to specialise, that is a conversation worth having with us before you take the next role, not after. We would rather place you well once than three times badly.

Working with us across markets

We recruit across South Africa — mostly Cape Town and Johannesburg — and for United Kingdom employers, largely in London. For UK roles we tell you up front whether the employer requires UK presence and existing right to work, or is open to remote hiring from South Africa.

Common questions

Do you charge candidates anything?

No, never. Our fees are paid by employers. Any recruiter asking you for money is not one to work with.

Will you send my CV out without telling me?

No. Your CV goes to a specific employer only after you have agreed to that specific submission, and we tell you the organisation, the role and who is receiving it first. Our Candidate Data Notice is the binding version of that promise.

I am trying to break into cyber security. Can you help?

Honestly, sometimes not directly — most of our mandates require existing experience. Where we do place entry-level, it is usually L1 SOC analyst work, and Cape Town has more of it than the rest of South Africa because of the offshore delivery centres.

Can you get me a UK role from South Africa?

Sometimes, and we will be straight about the odds. Some UK employers hire remotely from South Africa, particularly for security operations. Many require UK presence and existing right to work. We will tell you which category a role falls into rather than let you hope.

What happens to my data if I stop looking?

You can ask us to delete your record at any time and we will, at no cost and without argument. Otherwise we hold candidate records for a defined period set out in the Candidate Data Notice.

Do you give feedback after interviews?

Yes, including when it is unflattering, and we chase clients for it. Vague feedback is usually a sign nobody wrote anything down, and we say that rather than invent a reason.

Have a conversation, not an application

No CV required to start. Tell us what you do and what you want next.