{"id":1142535,"url":"https://alion.io/job/herotel-cybersecurity-engineer","title":"Cybersecurity Engineer","company":{"id":177332,"name":"Herotel","domain":"herotel.com","url":"https://alion.io/company/herotel","size_band":null,"is_staffing_agency":false,"is_intermediary":false,"ats_vendor":"Breezy","truth_index":null},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"hiring_geo_confidence":"structured","locations":[],"countries":[],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":21000,"max_usd":51000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":337},"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":true,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"DHCP","optional":false},{"name":"DNS","optional":false},{"name":"GCP","optional":false},{"name":"ISO 27001","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"Python","optional":false},{"name":"SIEM","optional":false},{"name":"TCP/IP","optional":false},{"name":"Windows","optional":false}],"status":"live","first_seen_at":"2026-09-23T12:45:28Z","employer_posted_date":"2026-09-23","last_verified_at":"2026-09-24T03:19:05Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"Are you a sharp, detail driven cybersecurity professional who thrives on staying ahead of threats before they land? Join our Information Technology team as a Cybersecurity Engineer in Plattekloof, where you'll take hands on ownership of Herotel's day to day security operations, from monitoring and incident response to vulnerability management and infrastructure hardening.\nThis role is perfect for someone who is calm under pressure, curious by nature, and wants to build a career at the sharp end of a fast growing internet service provider's security programme.\nWhat you'll do:\nMonitor systems and networks for suspicious activity and security threats\nInvestigate and respond to security incidents and alerts in real time, performing root cause analysis and documenting findings\nManage and maintain the endpoint protection platform and security tooling (SIEM, SOC systems)\nDevelop, implement, and maintain comprehensive incident response plans\nManage real time information security incidents to minimise operational business impact and maximise service availability\nConduct regular vulnerability scans and assessments across infrastructure and applications\nPerform auditable, proactive application and network penetration tests at least annually, including social engineering assessments\nTrack remediation progress and collaborate with infrastructure and IT teams to resolve identified risks\nReview and harden server and infrastructure security configurations on an ongoing basis, contributing to hardening across cloud and on premises environments\nMaintain and test disaster recovery and backup verification procedures with the infrastructure team, including regular DR simulations\nReview new projects and system changes with IT and project teams to ensure they meet information security requirements before go live\nResearch and evaluate security vendors, products, and tooling to ensure robust detection, prevention, and monitoring capability\nImplement and operate ISO 27001 Annex A technical controls in partnership with the GRC Officer, and provide control evidence for internal and certification audits\nSupport POPIA incident response with technical investigation, containment, and forensic evidence gathering\nWhat you'll need:\nDiploma or Degree in Computer Science, Information Technology, Cybersecurity, or a related field\n3 to 5 years of hands on experience in cybersecurity engineering, SOC, or IT security roles\nProven experience in security monitoring, incident response, and vulnerability management\nExperience managing endpoint protection platforms, SIEM systems, and security tooling\nExposure to cloud environments (Azure, AWS, GCP) and cloud security practices\nFamiliarity with threat frameworks such as MITRE ATT&CK\nProficiency in Windows OS, Entra ID/Azure AD, and networking fundamentals (TCP/IP, DNS, DHCP)\nKnowledge of firewalls, networks, and security architecture\nScripting experience (BASH, Python) is advantageous\nWorking knowledge of ISP operations and procedures is advantageous\nDesirable certifications: CompTIA Security+, Microsoft SC 200 (Security Operations Analyst) or AZ 500 (Azure Security Engineer), CEH (Certified Ethical Hacker); CISSP or CISM advantageous as a growth path\nWhat we offer:\nExposure to a dynamic workplace\nA chance to grow your skills through our internal academy\nA friendly, team-driven environment\nGroup Risk Benefits\nMedical Benefits\nHealth and Lifestyle Programmes\nImportant Disclaimer:\nPlease ensure that the information you provide in your application is true, accurate, and correct.\nPreference will be given to candidates from Designated Groups, as defined by the Employment Equity Act and in line with Herotel's Employment Equity Plan.\nBy submitting an application, you consent to the processing of your personal information in accordance with POPIA for recruitment purposes. For more details on how we handle personal information, please refer to our Privacy Policy on our website.\nIf you do not hear from us within 14 days, please consider your application unsuccessful.","description_format":"text","description_chars":4035,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Equity"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Telecommunications"],"lifecycle":[{"event":"open","at":"2026-09-23T12:55:30Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":16,"reasons":["conf:0","win:early"],"computed_at":"2026-09-24T03:52:28Z"},"pay":null,"html_url":"https://alion.io/job/herotel-cybersecurity-engineer","json_url":"https://alion.io/job/herotel-cybersecurity-engineer.json","meta":{"generated_at":"2026-09-24T03:52:28Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}