Principle Cyber Security Engineer

The Principal Cyber Security Engineer reports to the Chief Network Operations Officer and is a senior member of the Network Engineering Team. In this role, the incumbent is expected to provide authoritative technical leadership in the design, implementation, operation, and continuous improvement of network security controls that protect the confidentiality, integrity, and availability of the South African National Research and Education Network (SANREN) and its underlying infrastructure. The position is responsible for securing backbone and edge environments through advanced traffic analysis, continuous monitoring for anomalous behaviour, malware, and intrusion attempts, and for leading technical response activities during network security incidents. This includes alert triage, root- cause analysis, coordinated mitigation, and post-incident improvement. As a recognised technical authority, the role leads the secure evolution of network architecture in collaboration with the Network Engineering Team, encompassing segmentation, encryption, firewalling, and secure interconnection with national and international research and education networks. The role further owns network-focused threat intelligence and vulnerability management functions, driving proactive risk identification, remediation, and the continuous strengthening of defensive capabilities. A core responsibility of the role is to work closely with the SANReN security team to ensure alignment of security operations, tooling, and response processes, and to play a leading role in the establishment and operation of a singular, sector-wide Computer Security Incident Response Team (CSIRT) serving higher-education and research institutions connected to the SANReN network. In this capacity, the Principal Cyber Security Engineer acts as a key engineering liaison with national and international cybersecurity communities to enable coordinated incident response and shared threat intelligence across the sector. Job Functions Network Security Architecture and Engineering (Innovation, Research and Technical Leadership) Provide senior technical leadership in the design and implementation of secure network architectures for backbone, metro, and edge environments. Define and maintain engineering standards for network security, including segmentation, encryption, firewalling, secure routing, and interconnection. Work closely with the Network Engineering Team to ensure security-by-designprinciples are embedded into all new builds, upgrades, and architectural changes. Evaluate, recommend, and guide the adoption of security technologies and tooling aligned with operational requirements and industry best practice. Maintain awareness of global NREN security architectures and emerging threats to inform the secure evolution of the network. Security Monitoring, Detection, Incident Response and SOC Operations Establish and oversee the technical operation of a SOC function for the SANReN network, including the definition of monitoring objectives, detection use cases, escalation criteria, and operational workflows. Lead the selection, integration, and optimisation of SOC tooling, including network telemetry sources, logging, detection, and analysis platforms. Ensure continuous monitoring of backbone and edge network traffic for anomalous behaviour, malware activity, and intrusion attempts. Provide senior technical leadership in alert triage, investigation, and prioritisation, ensuring incidents are assessed accurately and escalated appropriately. Direct and participate in the technical response to network security incidents, including containment, mitigation, and recovery activities. Conduct and oversee detailed root-cause analysis of incidents, ensuring that lessons learned are translated into improved detection logic, engineering controls, and response procedures. Define and maintain SOC operational procedures aligned with SANReN security operations, sector CSIRT processes, and international best practice. Ensure SOC operations integrate effectively with the Network Engineering Team, SANReN security team, and external CSIRT partners to support coordinated incident response. Support regular testing, refinement, and continuous improvement of monitoring and response capabilities. Threat Intelligence and Vulnerability Management Own the network-focused threat intelligence function within TENET, including the ingestion, analysis, and operationalisation of relevant threat feeds. Conduct and coordinate vulnerability assessments of network infrastructure and services together with the SANReN CSIRT team across the SANREN infrastructure including the institutions that are clients of TENET (these include public South African universities and Science and research affiliated entities) Prioritise and drive remediation activities in collaboration with the Network Engineering Team and where applicable, security personnel from institutions. Track emerging threats and vulnerabilities relevant to research and education networks and assess potential impact. Report on threat and vulnerability trends to management and relevant governance structures. Secure Interconnection and Sector Collaboration Work closely with the SANReN security team to align security operations, tooling, and response processes. Play a leading engineering role in the establishment and ongoing operation of a unified, sector-wide CSIRT serving higher-education and research institutions. Act as a technical liaison with national and international cybersecurity communities, including CSIRTs and CERT-ZA, to enable coordinated response and information sharing. Support secure interconnection with regional and international research and education networks in accordance with agreed standards and policies. Governance, Standards, and Assurance Contribute to the development, maintenance, and enforcement of network security standards, procedures, and technical controls. Provide expert input into audits, assessments, and assurance activities relating to network security. Ensure that implemented controls align with relevant legislative, regulatory, and sector requirements. Produce technical documentation and reports suitable for operational, management, and governance audiences. Attend meetings with institutions and service delivery resources to advise on cybersecurity requirements for network connectivity where required. Penetration Testing and Security Validation Plan, conduct, and document authorised penetration testing activities against network infrastructure, systems, services, and security controls to identify exploitable weaknesses and validate the effectiveness of implemented defences. Use approved commercial and open-source vulnerability assessment and exploitation tools, including Rapid7 Nexpose, Metasploit, and other relevant platforms, to perform controlled testing, automate selected penetration-testing activities, and verify identified vulnerabilities. Define appropriate testing scopes, rules of engagement, safeguards, and reporting requirements to ensure penetration-testing activities are conducted in a controlled, ethical, and non-disruptive manner. Analyse penetration-testing results, assess the potential operational and security impact of identified weaknesses, and work with the Network Engineering Team, SANReN security team, and affected institutions to prioritise and validate remediation actions. Support the development, standardisation, and delivery of penetration-testing services as part of the broader CSIRT service offering to higher-education and research institutions, including the development of service methodologies, reporting standards, tooling requirements, and chargeable service models. Key Responsibility Areas and Weighting 1 - Network Security Architecture and Engineering - Weight: 20/100 2 - Security Monitoring, Incident Response and SOC Operations - Weight: 30/100 3 - Threat Intelligence and Vulnerability Management - Weight: 20/100 4 - Secure Interconnection and Sector Collaboration - Weight: 10/100 5 - Governance, Standards and Assurance - Weight: 10/100 6 - Penetration Testing and Security Validation - Weight: 10/100 Job Requirements Education / Qualifications / Experience At least five (5) years’ relevant experience in a senior or lead engineering role with direct responsibility for securing large-scale network infrastructure. Demonstrated experience in network security monitoring, incident response, vulnerability management, penetration testing and root-cause analysis. Hands-on experience with backbone and edge network security technologies, including firewalls, routing security, encryption, and traffic analysis. Experience working with or alongside CSIRTs, SOCs, or similar security operations functions. Prior experience in a higher education or research networking environment will be considered advantageous. Deep technical expertise in IP networking and network security engineering. Strong analytical and problem-solving capability in high-pressure operational environments. Ability to provide calm, authoritative technical leadership during security incidents. Strong documentation and communication skills, with the ability to convey complex technical issues clearly to both technical and non-technical audiences. Ability to work collaboratively across engineering, operations, and external partner communities. A disciplined, methodical approach to risk identification, remediation, and continuous improvement. Deep understanding of the relationship between IP networking, systems infrastructure, and security engineering. Proficient development and automation capability to enhance security tooling, integrate security platforms, and support current and future security engineering initiatives. #J-18808-Ljbffr

Back to blog

Other Jobs To Apply

No other job posts for this day.

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...