Incident Response Engineer - Create & Lead Security Playbooks

Ärztekasse Genossenschaft

Thônex

Vor Ort

CHF 120.000 - 180.000

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

Ärztekasse Genossenschaft is renewing its datacenter and we are looking for smart and experienced engineers to contribute and shape clever and creative solutions for a meaningful industry. The role focuses on security incident response and proactive threat detection in a modern, agile environment.

You will triage Defender for Endpoint alerts, lead incident response, tune detections, develop playbooks, and collaborate with cross-functional teams in Geneva or Zurich.

Qualifikationen

  • 3+ years of experience in security incident response, SOC or a similar role.
  • Hands-on experience with Microsoft Defender for Endpoint (EDR) and endpoint security.
  • Strong understanding of security monitoring, SIEM and detection engineering.
  • Knowledge of attack techniques and incident handling frameworks (e.g. NIST, MITRE ATT&CK).
  • Experience with Windows and Linux security; Kubernetes is a plus.
  • Scripting and automation skills, preferably in Bash, Python or Go.
  • Relevant certifications (e.g. GCIH, GCIA, OSCP) are a plus.
  • Analytical, calm under pressure and a strong communicator; English required, German and French a plus.

Aufgaben

  • Triage, investigate and resolve endpoint security alerts from Microsoft Defender across employee machines.
  • Detect, analyse and respond to security incidents across our endpoints, infrastructure and applications.
  • Lead incident response activities and coordinate remediation with engineering and operations teams.
  • Tune detection rules to reduce false positives and continuously improve alert quality.
  • Develop and maintain incident response playbooks, processes and tooling.
  • Monitor security events and alerts (Microsoft Defender, SIEM, IDS/IPS) and drive continuous detection improvements.
  • Conduct post-incident reviews and root-cause analysis, and track corrective actions.
  • Implement security best practices and harden systems against emerging threats.
  • Participate in future on-call rotation.

Kenntnisse

Security incident response
Defender for Endpoint
SIEM
Detection engineering
Threat frameworks
Windows security
Linux security
Kubernetes
Scripting (Bash)
Python
Go
Certifications
English
German
French

Jobbeschreibung

Ärztekasse Genossenschaft is renewing its datacenter and we are looking for smart and experienced engineers to contribute and shape clever and creative solutions for a meaningful industry. The role focuses on security incident response and proactive threat detection in a modern, agile environment.

You will triage Defender for Endpoint alerts, lead incident response, tune detections, develop playbooks, and collaborate with cross-functional teams in Geneva or Zurich.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Security Incident Engineer - Detect, Respond & Harden Endpoints
Security Incident Engineer - Detect, Respond & Harden Endpoints

Caisse Des Medecins • Genf

Vor Ort
CHF 120.000 - 180.000
Incident Engineer (w/m)
Incident Engineer (w/m)

Ärztekasse Genossenschaft • Thônex

Vor Ort
CHF 120.000 - 180.000
Incident Engineer (w/m)
Incident Engineer (w/m)

Caisse Des Medecins • Genf

Vor Ort
CHF 120.000 - 180.000
Cybersecurity Operations & Incident Response Engineer
Cybersecurity Operations & Incident Response Engineer

Rehaklinik Tschugg AG • Zollikofen

Vor Ort
CHF 80.000 - 100.000
Flexibles Arbeitszeitmodell
Personalrestaurant
Gratisparkplätze
+1
Hybrid Cyber Defense Lead & Incident Response
Hybrid Cyber Defense Lead & Incident Response

Crossell • Zürich

Hybrid
CHF 128.000 - 192.000
Cybersecurity Ops Engineer — Hybrid & Incident Response
Cybersecurity Ops Engineer — Hybrid & Incident Response

Die Securitas Gruppe • Zollikofen

Hybrid
CHF 90.000 - 120.000
Personalrestaurant
Fringe Benefits
Aktive Unterstützung in der Aus- und Weiterbildung
Senior IT Security Infrastructure Engineer
Senior IT Security Infrastructure Engineer

Experis Switzerland • Burgdorf

Vor Ort
CHF <1.000
Senior Cyber Security Engineer – Incident Response & Threat Intel
Senior Cyber Security Engineer – Incident Response & Threat Intel

SWICA Organisation de Santé • Winterthur

Hybrid
CHF 110.000 - 190.000
Product Owner – Security & Compliance for Healthcare IT
Product Owner – Security & Compliance for Healthcare IT

Caisse Des Medecins • Zürich

Vor Ort
CHF 110.000 - 170.000
IT Security Infrastructure Engineer – Incident Response
IT Security Infrastructure Engineer – Incident Response

Helvetica Partners • Bern

Hybrid
CHF 120.000 - 170.000