E. NGOBENI / NETWORKS & SECURITY

Available now / 6-month WIL placement

Edwin
Ngobeni Computer networks & security.
Pretoria, Gauteng.

Final-year IT student at Tshwane University of Technology. All theory modules complete. The last thing standing between me and the diploma is six months of industrial exposure.

Fig. 1 / the stack I work in

Industrial Exposure 326R is the final requirement for my diploma. Six months, starting immediately, anywhere in Gauteng.

Note: competing at CHPC Nationals, 1–4 Dec

01 / Work

Three things worth explaining properly

A skills list tells you what I've touched. These tell you what I built with it, and what I want to be doing next.

Detection & response

Building a monitored host and watching what it caught

Ubuntu lab environment, Sept–Oct 2025

I built a small multi-subnet lab on Ubuntu and put a firewall and an intrusion detection sensor on the same host, so I could set a policy and then watch what the sensor made of the traffic that policy allowed through.

UFW started from default-deny inbound, then opened only what the lab actually needed: remote access, web traffic, one internal service restricted to a single trusted host, and an explicit block on a host I wanted shut out entirely. Adding a second interface and enabling forwarding between the subnets turned the box into a routing firewall rather than just a protected endpoint.

For detection I ran Snort against a custom ruleset alongside the distribution signatures, and configured Suricata on the same host to compare how the two engines behaved. Writing my own rules for ICMP, HTTP requests and SYN-flagged scans is what turns signature syntax from something you read about into something you can debug when a badly scoped rule floods your console.

What the sensor mostly caught was not attacks. Repeating service-discovery broadcasts, and a session using a port pairing that no longer makes sense on a modern network. Low-priority, easily explained, and exactly the reason triage matters more than alert volume. Learning to clear that kind of traffic quickly is what keeps a real alert visible.

Things breaking is where the useful part happens: a packet filter expression that wouldn't parse, a log Snort refused to replay because of its own format, UFW rejecting a protocol until the rule is written the way it expects. That is the loop I want to be in daily. Set a policy, watch what the sensors say about it, then cut the noise down so the alerts that matter stay visible.

Stack
Ubuntu, UFW, Snort, Suricata
Focus
Firewall policy, custom IDS rules, alert triage, inter-subnet forwarding
Context
Self-built lab, extending coursework
Policy & communication

Briefing a mock Cabinet through a national grid attack

IITPSA SIGCyber Student Cyber Challenge / CSIR, Pretoria, 29 Sept 2025 / 3rd place, Team CyberOps

Seven student teams were handed the same crisis. A hacktivist group had exploited unpatched control software to trigger a thirty-hour blackout, hospitals had been forced onto generators, eighty-nine people were dead, and the group had issued a seventy-two-hour ultimatum threatening to publish their exploit. We had to write a policy brief and defend it to a judging panel playing the President's Cabinet.

The technical picture was the easy half. A vendor patch existed, but rollout was uneven: two metros and a key gateway were still exposed, an internal change freeze had slowed updates, and there was evidence of insider-enabled access. The hard half was that the group's demands were popular ones. An independent security audit and open policy hearings are things you would want anyway. Agreeing to them under a deadline means agreeing to them under extortion.

We weighed three routes: harden and prosecute, concede and negotiate, or a hybrid. We recommended the hybrid. Lock down the operational network, finish the patch rollout with checksum validation, deploy emergency power support, announce an independent audit on our own terms, and signal civil society consultations to buy time. We named its weakness out loud rather than hiding it: coordination across that many departments is where it would most likely fail.

The habit I want to bring into a security team is what we attached to the recommendation. Explicit escalation and de-escalation triggers, so decision-makers know in advance what would change the plan. Metrics they can check for themselves: substations patched, residual access points closed, regional cooperation with Eswatini and Namibia through the Southern African Power Pool. A recommendation with no way to hold it accountable is just an opinion delivered confidently.

Security work reaches people who will never read a packet capture. I want to keep doing the technical half and stay able to explain it to the room that has to sign it off.

Result
3rd place, national field
Team
CyberOps
Format
Written policy brief + live panel defence
Host
IITPSA SIGCyber, at the CSIR
In progress

Captaining Switch Squad into the CHPC national finals

CHPC Student Cluster Competition 2026 / selection round July, nationals December

The CHPC Student Cluster Competition is the CSIR's flagship HPC programme: an intensive training week on remote cluster hardware in Cape Town, continuous assessment throughout, and only the ten strongest teams nationally go through to the finals.

I captained Switch Squad through selection and we qualified. In December we get a fixed budget and a hardware list, build a cluster on the conference exhibition floor, and are judged on benchmark results, application efficiency and design.

It reads like a different discipline to networking, but it isn't. A cluster is a network with unusually demanding neighbours. Addressing, routing, firewalls, NAT and SSH are the ground floor before a single benchmark runs.

Role
Team captain
Status
Qualified, nationals 1–4 Dec 2026
Stack
Linux, HPC cluster software stack, benchmarking
Run by
CHPC, a division of the CSIR
About the competition
02 / Toolkit

Skills and tools

Grouped by area, listed at the level I've actually worked at rather than the level I've read about.

Networking

  • Router & switch config
  • Routing
  • NAT
  • Wireless
  • Cisco Packet Tracer
  • Network management

Security

  • Firewalls / UFW
  • Snort IDS
  • Suricata IDS
  • Custom rule writing
  • Honeypots
  • Host hardening

IT support

  • Ticket logging & triage
  • End-user support
  • Hardware & software troubleshooting
  • Account & access requests

Systems & cloud

  • Linux administration
  • SSH
  • Microsoft Azure
  • HPC clusters

Programming

  • Java (advanced OOP)
  • PHP
  • HTML / CSS
  • SQL

Certifications in progress

  • CCNA: Switching, Routing & Wireless Essentials
  • CCNA: Enterprise Networking, Security & Automation
  • Ethical Hacker (Cisco)
  • Azure Fundamentals AZ-900
03 / Path

How I got here

04 / Recognition

Where that's been tested

3rd

IITPSA SIGCyber Student Cyber Challenge 2025

Multi-university field, hosted at the CSIR, Pretoria

Top 10

CHPC Student Cluster Competition 2026, team captain

Qualified for national finals through the CSIR selection round

3rd

Top Achiever Award, TUT residential level

Academic standing across residence

1st

Molototsi Circuit Physical Science top achiever

Grade 12, 2022

Languages

Xitsonga / home English isiZulu Sepedi Sesotho Setswana
05 / Contact

Start an email

Pick a reason and I'll draft the opening line. Edit anything you like before sending.

ngobeniew@gmail.com