Security engineering that works in everyday practice:Cybersecurity is not a theoretical discipline for us. Our infrastructure supports the daily operations of a large hospital environment and connects traditional ICT with clinical systems, medical devices, imaging systems, and high-availability services. Our environment is technically diverse and, in some cases, has evolved organically over time. Therefore, we are looking for an experienced individual who understands the interrelationships, remains calm even in the face of complex disruptions, and not only designs security solutions but also effectively operates and further develops them. For our Network & Connectivity team, we are seeking a Senior Cybersecurity Engineer specializing in firewalls, proxies, incident handling, and security engineering.
This is what you can expect
- Together with the team, you will be responsible for the operation and further development of our central security platforms, with a focus on firewalls and proxies.
- You will be working in a highly available environment with approximately 60 virtual firewall instances in our data centers.
- You analyze and process complex incidents and technical malfunctions in the extended second-level environment and at the interface with third-level topics.
- You plan and implement updates, changes and technical improvements, taking into account security requirements, network architectures and operational dependencies.
- You review and optimize rules, configurations and technical processes, and develop them further in a sustainable manner.
- You will contribute your experience to projects, especially in the further development of network segmentation and the implementation of our zone concept.
- You provide support with complex questions regarding VPN, Web Application Firewall and cloud-based security services.
- You act as a technical sparring partner for less experienced colleagues and pass on your knowledge in everyday work.
- You will work with internal departments, the business, and external partners, translating requirements into viable technical solutions.
This is what you bring with you
- Completed training in computer science, ideally with further education at the HF or FH level, or a comparable qualification with relevant practical experience.
- Several years of experience in the engineering and operation of security solutions in the enterprise environment, especially in the area of firewalls and proxies.
- Very good understanding of networks, network architectures, routing, communication flows and technical dependencies.
- Experience with incidents, changes, updates and structured operational processes.
- Good knowledge of VPN technologies and their integration into complex network environments.
- Experience with web application firewalls is an advantage. It's important that you understand how they work, how to integrate them, and their typical sources of error.
- Knowledge of cloud-related security topics, Microsoft 365, zero-trust approaches, or modern secure access concepts is welcome, but not a requirement.
- Good German skills as well as good technical English.
- Experience in a hospital setting or in another regulated or highly available environment is a plus.
What
's personally important to us:You work pragmatically, reliably, and with a focus on solutions. Even with complex issues, you proceed systematically and persevere until the cause and solution are clearly understood.
You take responsibility and enjoy not only designing solutions but also implementing and operating them. You enjoy working in a team but can also independently drive forward challenging technical topics.
You don't need to have an immediate answer to every problem. What's crucial is that you communicate openly, analyze thoroughly, and share your knowledge with others.
our range
- A technically demanding role with direct impact in a highly critical hospital environment.
- A versatile infrastructure with an exceptionally broad portfolio of devices, systems, and applications that need to be protected.
- A task that combines engineering, incident handling, operations, and further development.
- The opportunity to actively develop our network and security architecture.
- Exciting projects revolving around segmentation, zoning concepts and central security services.
- Collaborative teamwork in an environment where safety, availability, and clinical reality are considered together.
- A hybrid work model with up to 40 percent home office. Regular on-site presence in Bern is important for team collaboration and on company matters.
- No on-call service. Planned deployments outside of normal working hours may be necessary on an occasional basis for updates or major changes.
Good to know:This role is not a SOC analyst position. Our team doesn't primarily monitor and assess threats, but is responsible for the technical implementation and operation of core security measures.
We operate and modify the platforms on which firewall rules, proxy services, network segmentation, and other protection mechanisms are implemented. In doing so, we create the technical prerequisites for requirements from the SOC and other security departments.
This role is also not purely an architecture, governance, or project management position. It's a good fit for you if you enjoy working technically, taking on operational responsibility, and want to continuously improve an existing environment.
Direct applications are preferred.