Incident Engineer (w/m)

Caisse Des Medecins

Genf

Vor Ort

CHF 120.000 - 180.000

Vollzeit

14 Tage+
Bewerbungsgenerator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Ärztekasse Genossenschaft seeks experienced security engineers to triage and resolve Defender alerts, detect and respond to incidents, and lead remediation with engineering and operations teams.

Role involves tuning rules, developing playbooks, monitoring events, and conducting post-incident reviews. 80-100% pensum, immediate start, Geneva/Zurich area, on-site. English required; German/French a plus.

Qualifikationen

  • 3+ years of experience in security incident response, SOC or a similar role.
  • Hands-on experience with Microsoft Defender for Endpoint (EDR) and endpoint security.
  • Strong understanding of security monitoring, SIEM and detection engineering.
  • Knowledge of attack techniques and incident handling frameworks (e.g. NIST, MITRE ATT&CK).

Aufgaben

  • Triage, investigate and resolve endpoint security alerts from Microsoft Defender across employee machines.
  • Detect, analyse and respond to security incidents across endpoints, infrastructure and applications.
  • Lead incident response activities and coordinate remediation with engineering and operations teams.
  • Tune detection rules to reduce false positives and continuously improve alert quality.
  • Develop and maintain incident response playbooks, processes and tooling.
  • Monitor security events and alerts (Microsoft Defender, SIEM, IDS/IPS) and drive continuous detection improvements.
  • Conduct post-incident reviews and root-cause analysis, and track corrective actions.
  • Implement security best practices and harden systems against emerging threats.
  • Participate in future on-call rotation.

Kenntnisse

Security incident response
Endpoint security
SIEM & detection engineering
NIST & MITRE ATT&CK
Windows security
Linux security
Kubernetes (plus)
Scripting (Bash, Python, Go)
English communication
Analytical mindset

Ausbildung

None

Tools

Kubernetes

Jobbeschreibung

Ärztekasse Genossenschaft provides business process outsourcing and eHealth solutions to health professionals so they get relief from administration and can focus on medical work.

Ärztekasse is renewing its entire datacenter and the products affected by this transformation. To support this digitalization step, we are looking for smart and experienced engineers to contribute and shape clever and creative solutions for a meaningful industry.

Pensum: 80-100%
Start: immediately or by appointment
Duration: unlimited
Location: Geneva area (Thônex) or Zurich area (Urdorf)

Main Tasks
  • Triage, investigate and resolve endpoint security alerts from Microsoft Defender across employee machines
  • Detect, analyse and respond to security incidents across our endpoints, infrastructure and applications
  • Lead incident response activities and coordinate remediation with engineering and operations teams
  • Tune detection rules to reduce false positives and continuously improve alert quality
  • Develop and maintain incident response playbooks, processes and tooling
  • Monitor security events and alerts (Microsoft Defender, SIEM, IDS/IPS) and drive continuous detection improvements
  • Conduct post-incident reviews and root-cause analysis, and track corrective actions
  • Implement security best practices and harden systems against emerging threats
  • Participate in future on-call rotation
Requirements
  • 3+ years of experience in security incident response, SOC or a similar role
  • Hands-on experience with Microsoft Defender for Endpoint (EDR) and endpoint security
  • Strong understanding of security monitoring, SIEM and detection engineering
  • Knowledge of attack techniques and incident handling frameworks (e.g. NIST, MITRE ATT&CK)
  • Experience with Windows and Linux security; Kubernetes is a plus
  • Scripting and automation skills, preferably in Bash, Python or Go
  • Relevant certifications (e.g. GCIH, GCIA, OSCP) are a plus
  • Analytical, calm under pressure and a strong communicator; English required, German and French a plus
Further information

A stimulating environment helps to find cool solutions to challenging complex requirements. We work in small agile teams where you can have impact and influence. You will find sharp engineers to have inspiring discussions with. We are solution-driven, but we don’t neglect the fun factor.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Database Engineer (w/m)
Database Engineer (w/m)

Caisse Des Medecins • Genf

Vor Ort
CHF 120.000 - 150.000
Security Incident Engineer - Detect, Respond & Harden Endpoints
Security Incident Engineer - Detect, Respond & Harden Endpoints

Caisse Des Medecins • Genf

Vor Ort
CHF 120.000 - 180.000
Product Owner Security (w/m)
Product Owner Security (w/m)

Cassa Dei Medici • Zürich

Vor Ort
CHF 110.000 - 170.000
Product Owner Security (w/m)
Product Owner Security (w/m)

Caisse Des Medecins • Zürich

Vor Ort
CHF 110.000 - 170.000
Product Owner Security (w/m)
Product Owner Security (w/m)

Ärztekasse Genossenschaft • Zürich

Vor Ort
CHF 120.000 - 160.000
Head of Platform Engineering (w/m)
Head of Platform Engineering (w/m)

Cassa Dei Medici • Zürich

Vor Ort
CHF 180.000 - 240.000
Site Reliability Engineer (SRE) (w/m)
Site Reliability Engineer (SRE) (w/m)

Cassa Dei Medici • Genf

Vor Ort
CHF 120.000 - 180.000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Allps • Bern

Vor Ort
Confidential
40% Home Office
Security Engineer
Security Engineer

Consult & Pepper AG • Bezirk Solothurn

Vor Ort
CHF 90.000 - 120.000
Senior Security Consultant Fokus Application Security & DevSecOps (80-100%)
Senior Security Consultant Fokus Application Security & DevSecOps (80-100%)

Redguard AG • Zürich

Vor Ort
CHF 120.000 - 180.000