Job Description

Your tasks

  • Prioritization, coordination and processing of security support tickets from internal teams as well as MDR/SOC alerts, including support in the analysis and handling of complex security incidents and advanced threats (including threat hunting and remediation)
  • Continuous monitoring of the threat situation as well as participation in the evaluation and improvement of existing security controls and detection/response capabilities.
  • Review, harmonization and optimization of security tool configurations (e.g. VPN, network, firewalls) to ensure a consistent security architecture
  • Further development of vulnerability management, including assessment, prioritization and tracking of vulnerabilities, as well as implementation of appropriate measures.
  • Expansion of security operations through automation and integration of workflows, as well as support for security awareness and handling of phishing incidents.
  • Creation and further development of security reports and dashboards (e.g., XDR compliance, KPIs, asset transparency)

Your profile

  • A completed degree in Information Security, Computer Science, or a related field. Alternatively, an equivalent practical qualification or a Cyber ​​Security Specialist (HF) qualification, along with initial practical experience or a strong interest in cybersecurity, security operations, or IT operations with a security focus.
  • Experience or strong interest in the analysis and handling of security incidents, as well as in dealing with SOC, MDR, or similar services.
  • Notable experience in operating Elastic environments
  • A sound and developing understanding of modern threat landscapes, attack techniques, and fundamental security principles; in addition, solid know-how in IT infrastructures, networks, security controls (endpoint, firewall, VPN, email, monitoring), and vulnerability management.
  • Experience or strong interest in security operations platforms (e.g., Cortex XDR, Microsoft Defender/Sentinel) and in the integration of systems via interfaces (APIs, JSON, webhooks)
  • Knowledge of scripting and automation (e.g., PowerShell, Python) as well as experience or interest in building and further developing workflows and automations across system boundaries.
  • Experience in collaborating with various stakeholders, as well as an analytical, structured and solution-oriented approach to work.
  • Very good German and English skills

our range

  • attractive employment conditions and good social benefits
  • good further training opportunities
  • A diverse and responsible role with a direct impact on the digital security of public IT infrastructures.
  • pleasant environment in a dedicated team
  • Annual working hours and the possibility of part-time work as well as working from home

Interested?

We look forward to receiving your application via the application link.
For further information, please contact Conrad Körber, Team Leader Security Operations Center (+41 41 594 30 27).

Your work environment

The Office for Information Technology and Organization (AIO) is the central provider of IT services for the cantonal administration and the judiciary. As a cross-cutting office, the AIO is responsible for the canton's IT infrastructure and supports the directorates, the State Chancellery, the High Court, the Administrative Court, as well as municipalities and administrative bodies in the use of information and communication technology. With its "Digital Zug" initiative, the AIO ensures the coordinated implementation of the Canton of Zug's digital strategy.
Further information can be found at www.zg.ch/aio.

Canton of Zug as an employer

Zug is a charming and vibrant canton with a strong economy, excellent educational opportunities, a rich cultural scene, and beautiful scenery. The Zug cantonal administration is also a highly sought-after employer. The seven directorates and approximately 50 offices cover a wide range of responsibilities. The cantonal administration is one of the largest employers in the canton, providing services to its residents and local businesses, encompassing security, health, the environment, and social services. Accordingly, the tasks and areas of work for our employees are diverse. Apprentices and interns are also welcome at the cantonal administration to gain initial professional experience.