jobsswitzerland.ch
← All jobs

IT Security Manager 80-100 %, (m/f/d)

Jobup

Employment type
Full-time
Location
Zürich
First posted
Apply now
  • 01 September 2026
  • 80 - 100%
  • Indefinite period
  • Zürich

ZHdK has approximately 2100 bachelor and master students, making it one of the largest and most diverse art universities in Europe. The fields of study and research cover artistic education, design, cinema, fine arts, music, dance, theatre and transdisciplinarity. In the heart of Zurich, ZHdK is a dynamic place where passionate people from more than 75 countries work, study, teach, research and train. The school includes many exhibition and performance venues where student work is presented to the public.

-

The Information Technology Centre (ITZ) of the Zurich University of the Arts (ZHdK) is composed of approximately 50 specialists who manage the IT infrastructure of ZHdK, lead projects, develop software and provide active support.

-

For the management and development of IT security, provided by the IT department for all areas of ZHdK, we are looking from 1 January 2027 or by agreement for a person employed as

IT Security Manager 80-100 %, (m/f/d) #

Your tasks:

  • As IT security manager, you assume the operational and technical security tasks of ZHdK and ensure the effective implementation of IT security measures in operations as well as in projects and initiatives.
  • You implement the IT security strategy tactically and operationally, support the IT service in its implementation and monitor its effectiveness.
  • You monitor threats, assess security risks in the ICT environment and perform operational risk assessments.
  • You derive the necessary measures and implement them autonomously or in collaboration with IT staff, or supervise their implementation.
  • You develop and update security concepts for specific systems and solutions, implement them technically and develop secure design principles. You contribute to cross-cutting IT security architectures and concepts as well as to project management related to security and IT architecture.
  • Evaluation & acquisition: You evaluate, specify and acquire appropriate security systems, install and integrate security components. You also develop technical proposals and decision bases within economic, organizational and technical frameworks, supporting the IT service and specialized departments.
  • Vulnerability & patch management: You perform technical security tests, analyze and document vulnerabilities and ensure transparency, including the technical assessment of risks. Your results are transmitted to patch management.
  • Incident management: You analyze security incidents, identify and coordinate countermeasures, order immediate measures if necessary, document them and perform post-mortem analyses.
  • Control & audits: You monitor compliance with security measures, support operational controls of the internal control system (ICS) and participate in security audits.
  • Guidelines & advice: You draft security, operational and monitoring guidelines, advise ZHdK members and project managers on IT security issues. You also approve deviations at the operational level.
  • You play a leading role in the IT governance committee and evaluate new projects from the perspective of IT security issues. You formulate recommendations or impose requirements and accompany the project team in implementation.
  • You establish your own budget for IT security measures as well as an annual planning of your tasks which you prioritize based on risks. You work in close collaboration with the CISO of ZHdK, the head of the IT department and the entire IT team.

Your profile:

  • Education & experience: Several years of experience in information and IT security as well as in technical project management, complemented by good knowledge of architecture and deep ICT skills. Higher education (university or equivalent) in IT or equivalent qualification.
  • Security expertise: Expert knowledge at the level of an ICT security engineer / security analyst as well as a deep understanding of current threats and modern attack and defense techniques and methods.
  • Fields: Affinity and experience in various cybersecurity domains: secure design principles, IAM, PAM, network security, security monitoring, vulnerability management, cloud technologies/cloud security, application security, WAF and advanced threat prevention / IDS/IPS.
  • Technologies: Knowledge in securing Azure/M365, Defender XDR, Microsoft AD, Linux, macOS, virtualization, container services and SIEM.
  • Standards & certifications: Basic knowledge of common security standards (notably NIST CSF, ISO 27001) and relevant certifications.
  • Regulatory understanding: Basic knowledge of relevant legal requirements regarding information security (revised DSG, cantonal IDG) as well as experience with internal controls (ICS) and security audits.
  • Autonomy: You work autonomously, are able to prioritize your tasks and advance their implementation even in the face of resistance.
  • Personality: Persuasiveness for technical issues, ability to technically lead project and IT staff, skills in

Automatically translated from the original.

Posted today

Location

View on Google Maps