Incident Engineer (w/m)

Cassa Dei Medici

Schweiz

On-site

EUR 96,742 - 161,238

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Ärztekasse Genossenschaft is seeking an experienced security engineer to strengthen our incident response capabilities as we renew our datacenter. You will triage alerts from Defender, investigate incidents and coordinate remediation with engineering and operations teams.

The role requires hands-on Defender for Endpoint experience, SIEM familiarity, and scripting skills. You’ll help harden our environments on Windows and Linux while participating in on-call rotations and continuous detection

Qualifications

  • 3+ years of experience in security incident response, SOC or similar roles.
  • Hands-on experience with Microsoft Defender for Endpoint (EDR).
  • Strong knowledge of security monitoring, SIEM, and detection engineering.
  • Experience with Windows and Linux security; Kubernetes is a plus.
  • Scripting in Bash, Python, or Go; relevant certifications (GCIH, GCIA, OSCP) are a plus.
  • English required; German or French a plus.

Responsibilities

  • Triage, investigate and resolve endpoint security alerts from Microsoft Defender.
  • Detect, analyse and respond to security incidents across endpoints, infrastructure and applications.
  • Lead incident response activities and coordinate remediation with engineering and operations teams.
  • Tune detection rules to reduce false positives and continuously improve alert quality.
  • Develop and maintain incident response playbooks, processes and tooling.
  • Monitor security events and alerts (Microsoft Defender, SIEM, IDS/IPS) and drive continuous detection improvements.
  • Conduct post-incident reviews and root-cause analysis, and track corrective actions.
  • Participate in future on-call rotation.
  • Implement security best practices and harden systems against emerging threats.

Skills

Incident response
Microsoft Defender for Endpoint
SIEM
Attack techniques knowledge
Windows security
Linux security
Scripting Bash/Python/Go
Certifications (GCIH GCIA OSCP)
English
German/French knowledge

Tools

Microsoft Defender for Endpoint
SIEM tooling
Kubernetes

Job description

Ärztekasse Genossenschaft provides business process outsourcing and eHealth solutions to health professionals so they get relief from administration and can focus on medical work.

Ärztekasse is renewing its entire datacenter and the products affected by this transformation. To support this digitalization step, we are looking for smart and experienced engineers to contribute and shape clever and creative solutions for a meaningful industry.

Pensum: 80-100%
Start: immediately or by appointment
Duration: unlimited
Location: Geneva area (Thônex) or Zurich area (Urdorf)

Main Tasks
  • Triage, investigate and resolve endpoint security alerts from Microsoft Defender across employee machines
  • Detect, analyse and respond to security incidents across our endpoints, infrastructure and applications
  • Lead incident response activities and coordinate remediation with engineering and operations teams
  • Tune detection rules to reduce false positives and continuously improve alert quality
  • Develop and maintain incident response playbooks, processes and tooling
  • Monitor security events and alerts (Microsoft Defender, SIEM, IDS/IPS) and drive continuous detection improvements
  • Conduct post-incident reviews and root-cause analysis, and track corrective actions
  • Implement security best practices and harden systems against emerging threats
  • Participate in future on-call rotation
Requirements
  • 3+ years of experience in security incident response, SOC or a similar role
  • Hands-on experience with Microsoft Defender for Endpoint (EDR) and endpoint security
  • Strong understanding of security monitoring, SIEM and detection engineering
  • Knowledge of attack techniques and incident handling frameworks (e.g. NIST, MITRE ATT&CK)
  • Experience with Windows and Linux security; Kubernetes is a plus
  • Scripting and automation skills, preferably in Bash, Python or Go
  • Relevant certifications (e.g. GCIH, GCIA, OSCP) are a plus
  • Analytical, calm under pressure and a strong communicator; English required, German and French a plus
Further information

A stimulating environment helps to find cool solutions to challenging complex requirements. We work in small agile teams where you can have impact and influence. You will find sharp engineers to have inspiring discussions with. We are solution-driven, but we don’t neglect the fun factor.

We look forward to receiving your application!
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

System Engineer VM / Server (w/m)
System Engineer VM / Server (w/m)

Caisse Des Medecins • Schweiz

On-site
EUR 129,757 - 162,196
CI/CD & Developer Support Engineer (w/m)
CI/CD & Developer Support Engineer (w/m)

Caisse Des Medecins • Schweiz

On-site
EUR 97,317 - 140,570
CI/CD & Developer Support Engineer (w/m)
CI/CD & Developer Support Engineer (w/m)

Cassa Dei Medici • Schweiz

On-site
EUR 118,241 - 161,238
Database Engineer (w/m)
Database Engineer (w/m)

Cassa Dei Medici • Schweiz

On-site
EUR 118,241 - 171,987
Senior Security Consultant Fokus Application Security & DevSecOps (80-100%)
Senior Security Consultant Fokus Application Security & DevSecOps (80-100%)

Redguard AG • Schweiz

On-site
EUR 140,570 - 194,635
Test Automation Engineer (m/f)
Test Automation Engineer (m/f)

Ärztekasse Genossenschaft • Lavamünd

On-site
EUR 96,000 - 138,000
40 hours per week
Highly motivated team
Modern office space
+2
CI/CD & Developer Platform Engineer
CI/CD & Developer Platform Engineer

Caisse Des Medecins • Schweiz

On-site
EUR 97,317 - 140,570
Security Consultant Fokus Application Security & DevSecOps (80-100%)
Security Consultant Fokus Application Security & DevSecOps (80-100%)

Redguard AG • Schweiz

On-site
EUR 97,317 - 129,757
(Senior) Incident Responder (80-100%)
(Senior) Incident Responder (80-100%)

Redguard AG • Lavamünd

On-site
EUR 55,000 - 90,000
(Senior) Incident Responder (80-100%)
(Senior) Incident Responder (80-100%)

Redguard • Lavamünd

On-site
EUR 116,000 - 158,000