IT - Principal Network Engineer - Cape Town based - must have valid drivers & own car

Ambit Connect · Cape Town, Western Cape · Market related + benefits

Stop applying one at a time.

JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.

Start free — we apply for you →

Introduction

IT - Principal Network Engineer

Location: Cape Town CBD area

Permanent full time position

Working conditions : Office based during the week. Must have own car and valid driver's license

Years of Networking experience required: 10+ years experience; 8+ at senior L3/ L4 level

Industry: ISP / FNO

Reporting to: Technical Director & Board of Directors

Overview

Well established Cape Town based IT company is seeking a Senior Networking Engineer with 10+ years experience. The highly experienced Principal Network Engineer will have and provide technical leadership, architectural ownership, and strategic direction across a growing Internet Service Provider (ISP) network. This senior role is responsible for the design, governance, security, resilience, scalability, and continuous improvement of the ISP’s network infrastructure, spanning core, aggregation, access, wireless, peering, transit and customer-facing environments.

The successful candidate will act as the senior technical authority for network architecture and complex escalations, establishing engineering standards, driving architectural decisions, and ensuring the network evolves in line with customer growth, business objectives, and operational requirements.

Should the candidate not be based in Cape Town, then relocation to the Western Cape will be a requirement, at the candidate’s own account. Only candidates that were born in South Africa will be considered.

Duties & Responsibilities

Network Architecture and Technical Strategy

  • Own the technical architecture for the ISP core, aggregation, access, wireless, peering, transit, and customer edge environments.
  • Define network standards, design patterns, lifecycle roadmaps, and technology selection criteria aligned to business growth and service reliability.
  • Translate commercial, operational, and customer requirements into scalable high-level and low-level network designs.

Core Backbone, Peering and Routing

  • Design, operate, and optimise carrier-grade routing environments using BGP, OSPF, iBGP, eBGP, route filtering, route policy, communities, prefix management, and traffic
  • engineering.
  • Manage upstream transit, local peering, private interconnects, Internet exchange connectivity, and failover strategies to improve reachability, latency, and resiliency.
  • Provide technical direction for MPLS, VLAN, VXLAN, L2/L3 VPN, QoS, OTN, and backbone segmentation where required.

Network Monitoring and Optimization

  • Establish monitoring, alerting, telemetry, and capacity reporting for all critical network platforms, links, services, and customer-impacting systems.
  • Analyse utilisation, latency, packet loss, jitter, errors, saturation, and recurring incidents to drive proactive optimisation and capacity upgrades.
  • Define operational thresholds and escalation paths for NOC, Tier 3, and engineering teams.

Network Security

  • Define and govern network security architecture across firewalls, edge filtering, management access, VPNs, customer segmentation, DDoS mitigation, and secure routing policy.
  • Ensure network designs support least privilege access, auditability, secure device management, and separation of production, management, customer, and internal traffic.
  • Collaborate with security, systems, and operations teams on vulnerability remediation, incident response, and compliance requirements.

Technical Escalation and Incident Resolution

  • Act as the final technical escalation point for complex ISP, backbone, routing, customer, vendor, and multi-domain network incidents.
  • Lead major incident technical diagnosis, root cause analysis, corrective action planning, and post-incident improvement activities.
  • Support the NOC and engineering teams with structured troubleshooting methods and escalation procedures.

Network Documentation

  • Produce and maintain high-quality High Level Designs (HLD), Low Level Designs (LLD), as-built diagrams, standards, configuration templates, operational runbooks, IP plans, routing policies, and change records.
  • Ensure documentation is accurate, accessible, version-controlled, and updated after every material network change.

Core Backbone and Failover

  • Design resilient failover across core, aggregation, POP, customer edge, transit, peering, and management networks.
  • Validate redundancy through planned failover testing, route convergence reviews, diverse path planning, and elimination of single points of failure.

Subscriber Access and Authentication Platforms

  • Provide architecture oversight for subscriber access services, including PPPoE, DHCP,
  • RADIUS, IP pools, BRAS/BNG platforms, authentication, accounting, and capacity planning.
  • Ensure customer access platforms are resilient, scalable, monitored, and aligned to product and support requirements.

Projects, Customer Solutions and Service Delivery

  • Lead architecture and engineering input for network upgrades, new POP deployments, customer onboarding, access network expansion, core refreshes, vendor migrations, and service launches.
  • Provide technical assurance for project scope, design, implementation plans, rollback plans, acceptance testing, and operational handover.
  • Assist sales and pre-sales teams with complex customer solutions, feasibility assessments, technical proposals, and customer-facing design discussions.

Vendor Coordination

  • Manage technical engagement with fibre providers, upstream carriers, peering partners, data centres, hardware vendors, and managed service providers.
  • Review vendor designs, maintenance notices, escalations, outage reports, and SLA performance to protect network availability and customer experience.

Change Management and Governance

  • Review and approve high-risk network changes, ensuring peer review, impact assessment, customer communication, rollback planning, implementation evidence, and post-change validation.
  • Improve change success rates through standardised templates, automation, maintenance windows, and engineering governance.

IP Address Management and IPv6 Strategy

  • Own public and private IP address planning, subnetting, allocation, utilisation, summarisation, reverse DNS coordination, and IPAM accuracy.
  • Support IPv6 strategy, addressing design, customer allocation policy, and migration planning where applicable.

Routing Protocols Management

  • Define and maintain routing protocol standards for BGP, OSPF, iBGP/eBGP, route reflectors, filtering, redistribution, communities, local preference, MED, and failover behaviour.
  • Regularly review routing hygiene, route leaks, prefix filtering, convergence, asymmetry, and traffic engineering effectiveness.

Technical Leadership and Mentoring

  • Mentor engineers across NOC, Tier 3, and infrastructure teams, raising technical standards and improving troubleshooting capability.
  • Lead design reviews, knowledge-sharing sessions, technical workshops, and engineering governance forums.

Key Performance Indicators (KPIs)

  • Network availability and resilience: Maintain agreed availability targets for core, backbone, peering, transit, access, and customer-impacting network services.
  • Major incident ownership: Provide clear technical ownership for Priority 1 and Priority 2 incidents, including escalation, root cause analysis, corrective actions, and post-incident improvements.
  • Change quality and control: Improve change success rates through strong design review, risk assessment, rollback planning, implementation evidence, and post-change
  • validation.
  • Capacity and performance management: Maintain accurate capacity forecasts and performance visibility across core links, transit, peering, subscriber platforms, IP resources, and critical network infrastructure.
  • Architecture and documentation standards: Ensure major services, POPs, routing
  • policies, customer solutions, and network changes are supported by current HLDs, LLDs, as-built records, standards, and operational runbooks.
  • Technical escalation effec
Auto-apply to this jobView original posting ↗