Incident Response Engineer: Lead Detection & Playbooks

Cassa Dei Medici

Schweiz

Vor Ort

EUR 96.742 - 161.238

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

Ärztekasse Genossenschaft is seeking an experienced security engineer to strengthen our incident response capabilities as we renew our datacenter. You will triage alerts from Defender, investigate incidents and coordinate remediation with engineering and operations teams.

The role requires hands-on Defender for Endpoint experience, SIEM familiarity, and scripting skills. You’ll help harden our environments on Windows and Linux while participating in on-call rotations and continuous detection

Qualifikationen

  • 3+ years of experience in security incident response, SOC or similar roles.
  • Hands-on experience with Microsoft Defender for Endpoint (EDR).
  • Strong knowledge of security monitoring, SIEM, and detection engineering.
  • Experience with Windows and Linux security; Kubernetes is a plus.
  • Scripting in Bash, Python, or Go; relevant certifications (GCIH, GCIA, OSCP) are a plus.
  • English required; German or French a plus.

Aufgaben

  • Triage, investigate and resolve endpoint security alerts from Microsoft Defender.
  • Detect, analyse and respond to security incidents across endpoints, infrastructure and applications.
  • Lead incident response activities and coordinate remediation with engineering and operations teams.
  • Tune detection rules to reduce false positives and continuously improve alert quality.
  • Develop and maintain incident response playbooks, processes and tooling.
  • Monitor security events and alerts (Microsoft Defender, SIEM, IDS/IPS) and drive continuous detection improvements.
  • Conduct post-incident reviews and root-cause analysis, and track corrective actions.
  • Participate in future on-call rotation.
  • Implement security best practices and harden systems against emerging threats.

Kenntnisse

Incident response
Microsoft Defender for Endpoint
SIEM
Attack techniques knowledge
Windows security
Linux security
Scripting Bash/Python/Go
Certifications (GCIH GCIA OSCP)
English
German/French knowledge

Tools

Microsoft Defender for Endpoint
SIEM tooling
Kubernetes

Jobbeschreibung

Ärztekasse Genossenschaft is seeking an experienced security engineer to strengthen our incident response capabilities as we renew our datacenter. You will triage alerts from Defender, investigate incidents and coordinate remediation with engineering and operations teams.

The role requires hands-on Defender for Endpoint experience, SIEM familiarity, and scripting skills. You’ll help harden our environments on Windows and Linux while participating in on-call rotations and continuous detection

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Incident Engineer (w/m)
Incident Engineer (w/m)

Cassa Dei Medici • Schweiz

Vor Ort
EUR 96.000 - 162.000
Security Operations Analyst: SIEM/XDR & Incident Response
Security Operations Analyst: SIEM/XDR & Incident Response

OMICRON Lab • Gemeinde Klaus

Vor Ort
EUR 65.000 - 95.000
Flexible work
Learning & development
International environment
+3
Cybersecurity SOC Lead - Incident Response & Threat Defense
Cybersecurity SOC Lead - Incident Response & Threat Defense

Bechtle Austria GmbH • St. Pölten

Vor Ort
EUR 45.000 - 55.000
Jobticket
Jobrad
Essenszuschuss
+2
Security Analyst – Incident Detection & Response (Remote)
Security Analyst – Incident Detection & Response (Remote)

Wiener Stadtwerke Group • Wien

Remote
EUR 33.000 - 40.000
Jobticket
Home Office
Flexible Arbeitszeiten
+2
Security Operations Analyst – SIEM/XDR, Flexible & Growth
Security Operations Analyst – SIEM/XDR, Flexible & Growth

OMICRON electronics GmbH • Gemeinde Klaus

Vor Ort
EUR 55.000 - 85.000
Flexible working models
Learning & development opportunities
International environment with English
+3
Managed Detection & Response Advisor (Remote)
Managed Detection & Response Advisor (Remote)

NVISO Security • Wien

Hybrid
EUR 68.000 - 90.000
Annual salary 68k-90k EUR
Training budget 10,000€
Klimaticket reimbursement
+2
Senior Security IR Engineer - AI-Driven Incident Response
Senior Security IR Engineer - AI-Driven Incident Response

Menlo Ventures • Schweiz

Vor Ort
EUR 104.000 - 156.000
Senior SOC & Incident Response Lead — Hybrid
Senior SOC & Incident Response Lead — Hybrid

Vienna • Österreich

Vor Ort
Flache Hierarchien
Hundefreundliches Büro
Home‑Office-Möglichkeit nach Einschul`
+4
Incident & Threat Response Analyst (AI Security)
Incident & Threat Response Analyst (AI Security)

Bundesrechenzentrum GmbH • Wien

Vor Ort
EUR 50.000 - 70.000
IT-Security Spezialist – Windows, EDR & Incident Response
IT-Security Spezialist – Windows, EDR & Incident Response

Getzner Textil Aktiengesellschaft • Bludenz

Vor Ort
EUR 52.000 - 76.000