Senior Cyber ​​Security Engineer – Focus on Incident Response and Threat Intelligence (all)

Job Description

Senior Cyber ​​Security Engineer – Focus on Incident Response and Threat Intelligence (all)

80-100% in Winterthur

Rapid detection and handling of cyberattacks is crucial; it requires a robust defense architecture, modern detection solutions, a reliable and state-of-the-art Security Operations Center, and people who take ownership. This is where you come in.
As a Senior Cyber ​​Security Engineer specializing in Incident Response and Threat Intelligence, you will play a central role in SWICA's Cyber ​​Security Team.
Thanks to our work-anywhere policy, you can work flexibly throughout Switzerland, combined with in-person interaction at our headquarters in Winterthur.

This is how you shape your health with

  • Optimization of processes for the detection, analysis and handling of security incidents and cyber threats, as well as implementation of measures to continuously increase team maturity.
  • Independent handling and coordination of security incidents (incident handler) as well as preparation and presentation of situation reports and recommendations for management.
  • Coordination and management of internal stakeholders and the external SOC and CSIRT partner
  • Conducting technical analyses, threat hunting, and incident response activities
  • Further development and automation of SIEM use cases and runbooks to improve security monitoring together with the SOC provider.
  • Development of cyber security playbooks and pre-approved containment measures
  • Support and execution of Blue Team exercises to strengthen defensive security measures

That's what makes you stand out.

  • Education or studies in computer science or information security
  • Quick comprehension and ability to break down complex issues into solvable work packages
  • At least 3 years of practical experience in the field of cyber security, especially in incident response, incident handling, and threat intelligence.
  • Solid knowledge of modern attack vectors, security frameworks and relevant tools e.g. SIEM / SOAR (MS Sentinel), XDR (MS Defender)
  • Certifications such as GIAC GSOM, GIAC GCIH, CERT CSIH, OSCP or similar are advantageous.
  • Scripting and automation skills (e.g., Python, PowerShell), experience with Infrastructure as Code or security automation are advantageous.
  • Experience in handling complex cybersecurity incidents and communicating with technical and non-technical audiences.
  • You are used to working with and managing external partners.
  • Structured, analytical and independent work style
  • Enjoyment in explaining technical topics in an understandable way and taking on professional responsibility.
  • Fluent German, both spoken and written, and very good English skills

Your workplace

Zürcherstrasse 31, 8401 Winterthur