Senior Cyber Security Engineer - Focus on Incident Response and Threat Intelligence (all)
- Employment type
- Full-time
- Location
- Winterthur · Remote possible
- First posted
Senior Cyber Security Engineer - Focus on Incident Response and Threat Intelligence (all) #
80-100% in Winterthur ##
The rapid detection and treatment of cyber attacks is more important than ever; it requires a strong defence architecture, modern detection solutions, a reliable and modern Security Operations Center, and people who take responsibility. This is exactly where you come into play.
As a Senior Cyber Security Engineer with a focus on Incident Response and Threat Intelligence, you will take on a central role in the Cyber Security team of SWICA.
Thanks to our Work-Anywhere regulation, you will work flexibly throughout Switzerland, combined with personal exchange at our headquarters in Winterthur.
How you shape health with ###
• Optimization of processes for the detection, analysis, and treatment of security incidents and cyber threats, as well as implementation of measures for the continuous increase of team maturity
• Independent processing and coordination of security incidents (Incident Handler) as well as creation and presentation of situation reports and recommendations for action for management
• Coordination and management of internal stakeholders and the external SOC and CSIRT partner
• Execution of technical analyses, threat hunting, and incident response activities
• Further development and automation of SIEM use cases and runbooks to improve security monitoring together with the SOC provider
• Development of cyber security playbooks and pre-approved containment measures
• Support and execution of blue team exercises to strengthen defensive security measures
What distinguishes you ###
• Education or studies in computer science or information security
• Quick comprehension and ability to break down complex issues into solvable work packages
• At least 3 years of practical experience in the field of cyber security, especially in incident response, incident handling, threat intelligence
• Profound knowledge of modern attack vectors, security frameworks, and relevant tools e.g. SIEM / SOAR (MS Sentinel), XDR (MS Defender)
• Certifications such as GIAC GSOM, GIAC GCIH, CERT CSIH, OSCP or comparable are an advantage
• Scripting and automation skills (e.g. Python, PowerShell), experience with Infrastructure as Code or security automation is an advantage
• Experience in handling complex cyber security incidents as well as communication to technical and non-technical target groups
• You are used to working with and leading external partners
• Structured, analytical, and independent way of working
• Enjoyment in conveying technical topics in an understandable way and taking professional responsibility
• Confident German in spoken and written form and very good English skills
Your place of work ###
Zürcherstrasse 31, 8401 Winterthur
Automatically translated from the original.
Posted 1 week ago