Principle Cyber Security Engineer
The Principal Cyber Security Engineer reports to the Chief Network Operations Officer and is a senior member of the Network Engineering Team. In this role, the incumbent is expected to provide authoritative technical leadership in the design, implementation, operation, and continuous improvement of network security controls that protect the confidentiality, integrity, and availability of the South African National Research and Education Network (SANREN) and its underlying infrastructure. The position is responsible for securing backbone and edge environments through advanced traffic analysis, continuous monitoring for anomalous behaviour, malware, and intrusion attempts, and for leading technical response activities during network security incidents. This includes alert triage, root- cause analysis, coordinated mitigation, and post-incident improvement. As a recognised technical authority, the role leads the secure evolution of network architecture in collaboration with the Network Engineering Team, encompassing segmentation, encryption, firewalling, and secure interconnection with national and international research and education networks. The role further owns network-focused threat intelligence and vulnerability management functions, driving proactive risk identification, remediation, and the continuous strengthening of defensive capabilities. A core responsibility of the role is to work closely with the SANReN security team to ensure alignment of security operations, tooling, and response processes, and to play a leading role in the establishment and operation of a singular, sector-wide Computer Security Incident Response Team (CSIRT) serving higher-education and research institutions connected to the SANReN network. In this capacity, the Principal Cyber Security Engineer acts as a key engineering liaison with national and international cybersecurity communities to enable coordinated incident response and shared threat intelligence across the sector. Job Functions Network Security Architecture and Engineering (Innovation, Research and Technical Leadership) Provide senior technical leadership in the design and implementation of secure network architectures for backbone, metro, and edge environments. Define and maintain engineering standards for network security, including segmentation, encryption, firewalling, secure routing, and interconnection. Work closely with the Network Engineering Team to ensure security-by-designprinciples are embedded into all new builds, upgrades, and architectural changes. Evaluate, recommend, and guide the adoption of security technologies and tooling aligned with operational requirements and industry best practice. Maintain awareness of global NREN security architectures and emerging threats to inform the secure evolution of the network. Security Monitoring, Detection, Incident Response and SOC Operations Establish and oversee the technical operation of a SOC function for the SANReN network, including the definition of monitoring objectives, detection use cases, escalation criteria, and operational workflows. Lead the selection, integration, and optimisation of SOC tooling, including network telemetry sources, logging, detection, and analysis platforms. Ensure continuous monitoring of backbone and edge network traffic for anomalous behaviour, malware activity, and intrusion attempts. Provide senior technical leadership in alert triage, investigation, and prioritisation, ensuring incidents are assessed accurately and escalated appropriately. Direct and participate in the technical response to network security incidents, including containment, mitigation, and recovery activities. Conduct and oversee detailed root-cause analysis of incidents, ensuring that lessons learned are translated into improved detection logic, engineering controls, and response procedures. Define and maintain SOC operational procedures aligned with SANReN security operations, sector CSIRT processes, and international best practice. Ensure SOC operations integrate effectively with the Network Engineering Team, SANReN security team, and external CSIRT partners to support coordinated incident response. Support regular testing, refinement, and continuous improvement of monitoring and response capabilities. Threat Intelligence and Vulnerability Management Own the network-focused threat intelligence function within TENET, including the ingestion, analysis, and operationalisation of relevant threat feeds. Conduct and coordinate vulnerability assessments of network infrastructure and services together with the SANReN CSIRT team across the SANREN infrastructure including the institutions that are clients of TENET (these include public South African universities and Science and research affiliated entities) Prioritise and drive remediation activities in collaboration with the Network Engineering Team and where applicable, security personnel from institutions. Track emerging threats and vulnerabilities relevant to research and education networks and assess potential impact. Report on threat and vulnerability trends to management and relevant governance structures. Secure Interconnection and Sector Collaboration Work closely with the SANReN security team to align security operations, tooling, and response processes. Play a leading engineering role in the establishment and ongoing operation of a unified, sector-wide CSIRT serving higher-education and research institutions. Act as a technical liaison with national and international cybersecurity communities, including CSIRTs and CERT-ZA, to enable coordinated response and information sharing. Support secure interconnection with regional and international research and education networks in accordance with agreed standards and policies. Governance, Standards, and Assurance Contribute to the development, maintenance, and enforcement of network security standards, procedures, and technical controls. Provide expert input into audits, assessments, and assurance activities relating to network security. Ensure that implemented controls align with relevant legislative, regulatory, and sector requirements. Produce technical documentation and reports suitable for operational, management, and governance audiences. Attend meetings with institutions and service delivery resources to advise on cybersecurity requirements for network connectivity where required. Penetration Testing and Security Validation Plan, conduct, and document authorised penetration testing activities against network infrastructure, systems, services, and security controls to identify exploitable weaknesses and validate the effectiveness of implemented defences. Use approved commercial and open-source vulnerability assessment and exploitation tools, including Rapid7 Nexpose, Metasploit, and other relevant platforms, to perform controlled testing, automate selected penetration-testing activities, and verify identified vulnerabilities. Define appropriate testing scopes, rules of engagement, safeguards, and reporting requirements to ensure penetration-testing activities are conducted in a controlled, ethical, and non-disruptive manner. Analyse penetration-testing results, assess the potential operational and security impact of identified weaknesses, and work with the Network Engineering Team, SANReN security team, and affected institutions to prioritise and validate remediation actions. Support the development, standardisation, and delivery of penetration-testing services as part of the broader CSIRT service offering to higher-education and research institutions, including the development of service methodologies, reporting standards, tooling requirements, and chargeable service models. Key Responsibility Areas and Weighting 1 - Network Security Architecture and Engineering - Weight: 20/100 2 - Security Monitoring, Incident Response and SOC Operations - Weight: 30/100 3 - Threat Intelligence and Vulnerability Management - Weight: 20/100 4 - Secure Interconnection and Sector Collaboration - Weight: 10/100 5 - Governance, Standards and Assurance - Weight: 10/100 6 - Penetration Testing and Security Validation - Weight: 10/100 Job Requirements Education / Qualifications / Experience At least five (5) years’ relevant experience in a senior or lead engineering role with direct responsibility for securing large-scale network infrastructure. Demonstrated experience in network security monitoring, incident response, vulnerability management, penetration testing and root-cause analysis. Hands-on experience with backbone and edge network security technologies, including firewalls, routing security, encryption, and traffic analysis. Experience working with or alongside CSIRTs, SOCs, or similar security operations functions. Prior experience in a higher education or research networking environment will be considered advantageous. Deep technical expertise in IP networking and network security engineering. Strong analytical and problem-solving capability in high-pressure operational environments. Ability to provide calm, authoritative technical leadership during security incidents. Strong documentation and communication skills, with the ability to convey complex technical issues clearly to both technical and non-technical audiences. Ability to work collaboratively across engineering, operations, and external partner communities. A disciplined, methodical approach to risk identification, remediation, and continuous improvement. Deep understanding of the relationship between IP networking, systems infrastructure, and security engineering. Proficient development and automation capability to enhance security tooling, integrate security platforms, and support current and future security engineering initiatives. #J-18808-Ljbffr