Senior Cyber Security Engineer – Focus on Incident Response and Threat Intelligence (all)
80-100% in Winterthur
Rapid detection and handling of cyberattacks is crucial; it requires a robust defense architecture, modern detection solutions, a reliable and state-of-the-art Security Operations Center, and people who take ownership. This is where you come in.
As a Senior Cyber Security Engineer specializing in Incident Response and Threat Intelligence, you will play a central role in SWICA's Cyber Security Team.
Thanks to our work-anywhere policy, you can work flexibly throughout Switzerland, combined with in-person interaction at our headquarters in Winterthur.
This is how you shape your health with
- Optimization of processes for the detection, analysis and handling of security incidents and cyber threats, as well as implementation of measures to continuously increase team maturity.
- Independent handling and coordination of security incidents (incident handler) as well as preparation and presentation of situation reports and recommendations for management.
- Coordination and management of internal stakeholders and the external SOC and CSIRT partner
- Conducting technical analyses, threat hunting, and incident response activities
- Further development and automation of SIEM use cases and runbooks to improve security monitoring together with the SOC provider.
- Development of cyber security playbooks and pre-approved containment measures
- Support and execution of Blue Team exercises to strengthen defensive security measures
That's what makes you stand out.
- Education or studies in computer science or information security
- Quick comprehension and ability to break down complex issues into solvable work packages
- At least 3 years of practical experience in the field of cyber security, especially in incident response, incident handling, and threat intelligence.
- Solid knowledge of modern attack vectors, security frameworks and relevant tools e.g. SIEM / SOAR (MS Sentinel), XDR (MS Defender)
- Certifications such as GIAC GSOM, GIAC GCIH, CERT CSIH, OSCP or similar are advantageous.
- Scripting and automation skills (e.g., Python, PowerShell), experience with Infrastructure as Code or security automation are advantageous.
- Experience in handling complex cybersecurity incidents and communicating with technical and non-technical audiences.
- You are used to working with and managing external partners.
- Structured, analytical and independent work style
- Enjoyment in explaining technical topics in an understandable way and taking on professional responsibility.
- Fluent German, both spoken and written, and very good English skills
Your workplace
Zürcherstrasse 31, 8401 Winterthur