Cybersecurity Engineer
Herotel · Plattekloof, ZA · South Africa · On-site
Posted Sep 23, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Are you a sharp, detail driven cybersecurity professional who thrives on staying ahead of threats before they land? Join our Information Technology team as a Cybersecurity Engineer in Plattekloof , where you'll take hands on ownership of Herotel's day to day security operations, from monitoring and incident response to vulnerability management and infrastructure hardening.
This role is perfect for someone who is calm under pressure, curious by nature, and wants to build a career at the sharp end of a fast growing internet service provider's security programme.
What you'll do:
Monitor systems and networks for suspicious activity and security threats
Investigate and respond to security incidents and alerts in real time, performing root cause analysis and documenting findings
Manage and maintain the endpoint protection platform and security tooling (SIEM, SOC systems)
Develop, implement, and maintain comprehensive incident response plans
Manage real time information security incidents to minimise operational business impact and maximise service availability
Conduct regular vulnerability scans and assessments across infrastructure and applications
Perform auditable, proactive application and network penetration tests at least annually, including social engineering assessments
Track remediation progress and collaborate with infrastructure and IT teams to resolve identified risks
Review and harden server and infrastructure security configurations on an ongoing basis, contributing to hardening across cloud and on premises environments
Maintain and test disaster recovery and backup verification procedures with the infrastructure team, including regular DR simulations
Review new projects and system changes with IT and project teams to ensure they meet information security requirements before go live
Research and evaluate security vendors, products, and tooling to ensure robust detection, prevention, and monitoring capability
Implement and operate ISO 27001 Annex A technical controls in partnership with the GRC Officer, and provide control evidence for internal and certification audits
Support POPIA incident response with technical investigation, containment, and forensic evidence gathering
What you'll need:
Diploma or Degree in Computer Science, Information Technology, Cybersecurity, or a related field
3 to 5 years of hands on experience in cybersecurity engineering, SOC, or IT security roles
Proven experience in security monitoring, incident response, and vulnerability management
Experience managing endpoint protection platforms, SIEM systems, and security tooling
Exposure to cloud environments (Azure, AWS, GCP) and cloud security practices
Familiarity with threat frameworks such as MITRE ATT&CK
Proficiency in Windows OS, Entra ID/Azure AD, and networking fundamentals (TCP/IP, DNS, DHCP)
Knowledge of firewalls, networks, and security architecture
Scripting experience (BASH, Python) is advantageous
…