Cyber Network Security Specialist
Role purpose:
We are seeking a skilled Cyber Network Security Specialist with expertise in both mobile networks and IP networks. The ideal candidate will be responsible for protecting our organization's network infrastructure from cyber threats, ensuring integrity, confidentiality, and availability of data. This role involves implementing security measures, monitoring network traffic, and responding to incidents across various platforms, including mobile devices and IP-based systems.
Must have technical / professional qualifications
- Candidate must be conversant with essential IP protocols and services including:
- Core IP protocols (IPv4/IPv6, ICMP, ARP, DNS, DHCP).
- Routing and Network control protocols (OSPF, BGP, EIGRP/RIP, VRRP/HSRP/GLBP, MPLS).
- Transport and session layer protocols (TCP, UDP, TLS/SSL, DTLS).
- Network management and monitoring (SNMP, Syslog, NetFlow/IPFIX, NTP).
- Remote access and administration (SSH, RDP, VNC, HTTP/HTTPS).
- Email messaging (SMTP, POP, IMAP); Directory services protocols (LDAP, Kerberos, NTLM, SAML).
- File transfer protocols (FTPS/SFTP, TFTP, SMB, NFS).
- VPN and secure tunneling (IPsec, GRE/L2TP/PPTP, SSL/TLS, OpenVPN/WireGuard).
- Authentication and authorization services (RADIUS, TACACS+, OAuth2/OpenID Connect) .
- Voice and media (VoIP/real-time services) (SIP, RTP, MGCP).
- Candidate expected to be comfortable with Mobile Network/Telephony Security including
- Understanding core components for 2G/3G/4G/5G (MSC, SGSN, GGSN, MME, HSS, PCRF, AMF, SMF, UPF, eNode/GNodeB).
- Signaling security (SS7, Diameter, SIP vulnerabilities and use of signaling firewalls).
- SIM and identity management (SIM provisioning, IMSI/IMEI management, EAP-AKA, USIM security, eSIM lifecycle management).
- 5G and LTE security (Knowledge of 5G SA/NSA, SBA, SEPP, network slicing security and virtualization risks).
- RAN security (securing eNodeBs/gNodeBs, backhaul encryption and physical site protection.
- VoLTE/VoWi-Fi/IMS security (SIP over TLS, SRTP, SBCs, IMS core security posture and lawful interception controls)
- Conduct regular network vulnerability assessments and implement remediation strategies.
- Monitor network traffic for anomalies and respond to security incidents.
- Develop, enforce, and educate on security policies for mobile and IP networks.
- Lead incident response efforts for mobile and IP network breaches.
- Assess risks of new technologies, services, and third-party vendors.
- Collaborate with Technology teams to integrate and maintain security measures.
- Deliver training on mobile and network security best practices.
- Stay current on cybersecurity trends and recommend infrastructure enhancements.
- Review and approve communication matrices and firewall rule changes.
- Prepare management reports on security incidents, vulnerabilities, and firewall posture.
- Perform additional tasks as assigned by the Line Manager.
Key performance indicators
- Minimum of 3-5 years of experience in Network Security.
- Bachelor's degree in computer science, information technology, cyber security, or a related field.
- Relevant networking and cyber security certifications such as Certified Information Systems Security Professional (CISSP), Cisco (CCNP Security), Palo Alto Networks (PCNSE), Fortinet (NSE), AWS/Azure/GCP (Networking Specialty), Certified Ethical Hacker (CEH) or equivalent would be beneficial
- GSMA Security training, ETSI/5G security workshops or vendor specific (Huawei HCIP, Nokia, Ericsson).
- Proficiency in security tools (firewalls, intrusion detection/prevention systems, SIEM).
- Familiarity with encryption technologies and secure coding practices
- Excellent analytical and problem-solving skills.
- Strong communication skills to effectively convey technical information to non-technical stakeholders.
- Ability to work independently and as part of a team in a fast-paced environment.
- This position may require occasional after-hours work for system maintenance or incident response.
- Strong analytical and problem-solving abilities to assess risks and respond effectively to incidents.
- Excellent verbal and written communication skills to convey technical information to non-technical stakeholders. [French and English].
- A keen eye for detail to detect anomalies in data and logs
- Knowledge of legal, regulatory and privacy requirements, such as Personally Identifiable Information (PII) Protection and Payment Card Industry (PCI)/Data Security Standards and GDPR