IT Security Analyst – Cyber Defence Center (CDC)

Who is Hiring

Zürich

On-site

CHF 110,000 - 150,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

The University of Zurich is seeking an IT Security Analyst for the Cyber Defence Center to strengthen operational cyber security and drive detection, analysis, and response capabilities.

You will handle security alerts, conduct threat hunting, and develop detection rules using Microsoft Defender XDR, Defender for Endpoint, and KQL, while collaborating on vulnerability management and incident response.

Qualifications

  • Completed degree in computer science, cyber security or a comparable qualification.
  • Practical professional experience in security operations, SOC, CDC, incident response, or IT security.
  • Very good knowledge of SIEM systems, security logs, and detection use cases.
  • Good knowledge of the Microsoft security platform (Defender XDR, Defender for Endpoint, Microsoft 365 Security).
  • Experience with KQL for analyzing events; exposure and vulnerability management.
  • Strong knowledge in network, endpoint, identity, and cloud security; handling IOC and incidents.
  • Scripting skills (PowerShell, Python, Bash) are an advantage.
  • Analytical and communicative, with good German and English skills.

Responsibilities

  • Analyze, triage, and handle security alerts and incidents from SIEM, Defender XDR, endpoints, networks, identity, cloud, and other sources.
  • Perform in-depth analyses and threat hunting using Advanced Hunting and KQL.
  • Correlate events across systems; investigate suspicious activity and initiate incident response measures.
  • Block and manage IOC data such as IPs, domains, URLs, or hashes.
  • Develop detection, hunting, and response use cases in SIEM and Microsoft security stack.
  • Create and optimize KQL queries, rules, and automation; collaborate on vulnerability management.
  • Document incidents and analyses; contribute to IT security reporting.

Skills

Security operations
SIEM
Threat hunting
KQL
PowerShell
Python
Bash
Microsoft Defender XDR
Defender for Endpoint
Microsoft 365 Security
Advanced Hunting
Vulnerability management
IOC handling
Analytical thinking
German and English

Education

Bachelor's degree in computer science, cyber security or equivalent

Tools

SIEM systems
Microsoft Defender XDR
Defender for Endpoint
Microsoft 365 Security
KQL (Kusto Query Language)

Job description

The Central IT provides IT services for students, researchers, institutes, faculties, and central services of the University of Zurich. For our Cyber Defence Center (CDC), we are looking for a committed IT Security Analyst who will strengthen our operational cyber security and actively contribute to the detection, analysis, and handling of security incidents as well as the further development of our detection and response capabilities.

IT Security Analyst -- Cyber Defence Center (CDC)
Responsibilities
  • Analysis, triage, and handling of security alerts and incidents from SIEM, Microsoft Defender XDR, endpoint, network, identity, cloud, and other security sources
  • Conducting in-depth analyses and threat hunting in the Microsoft Defender portal, especially using Advanced Hunting and KQL or other tools in our SIEM
  • Correlation and evaluation of events across different systems, log sources, and security products
  • Investigation of suspicious activities, attack indicators, and possible compromises as well as initiation of appropriate incident response measures
  • Blocking and managing indicators of compromise (IOC) such as IP addresses, domains, URLs, or hashes, etc.
  • Further development of detection, hunting, and response use cases in the SIEM as well as within the Microsoft 365 and Defender security platform
  • Development and optimisation of KQL queries, detection rules, alerting logics, and automations
  • Collaboration in vulnerability management, especially in the assessment, prioritisation, and follow-up of identified vulnerabilities
  • Continuous improvement of our security monitoring, detection, and response processes in the CDC
  • Documentation of incidents, analyses, and measures as well as collaboration in IT security reporting
Profile

For this demanding position, we are looking for an analytically strong, independent, and trustworthy individual with enthusiasm for technical security analysis, threat hunting, and incident response.

  • A completed degree, vocational baccalaureate, or higher education in computer science, cyber security, or a comparable qualification
  • Practical professional experience in security operations, SOC, CDC, incident response, or IT security
  • Very good knowledge of SIEM systems, security logs, and detection use cases
  • Good knowledge of the Microsoft security platform, especially Microsoft Defender XDR, Defender for Endpoint, Microsoft 365 Security, and Advanced Hunting
  • Practical experience with KQL (Kusto Query Language) for analysing, correlating, and detecting security-relevant events
  • Experience in exposure management, including vulnerability management
  • Sound knowledge in the areas of network, endpoint security, identity, and cloud security as well as common attack and detection methods
  • Experience in analysing and handling indicators of compromise (IOC) and security incidents
  • Scripting skills, for example in PowerShell, Python, or Bash, are an advantage
  • Structured, precise, and efficient working style as well as good analytical and communication skills
  • Good German and English language skills
We offer

Our employees benefit from diverse and attractive offers.

Learn more at: https://www.uzh.ch/de/explore/work.html.

Workplace Central IT

Application information Further information Questions about the position Sacha Schweizer Head of Cyber Defence Center +41 44 634 00 91 sacha.schweizer@uzh.ch

Working at UZH

As the largest university in Switzerland, the University of Zurich offers a variety of attractive positions in different academic fields and professional areas. With around 10,000 employees and currently 12 vocational profiles for apprentices, the university provides an inspiring working environment in cutting-edge research and education.

Put your talent and skills to use with us.

Learn more about UZH as an employer!

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT-Security Analyst – Cyber Defense Center
IT-Security Analyst – Cyber Defense Center

Universität Zürich • Zürich

On-site
CHF 110,000 - 140,000
IT-Security Analyst – Cyber Defense Center (CDC)
IT-Security Analyst – Cyber Defense Center (CDC)

University of Zurich • Zürich

On-site
CHF 110,000 - 140,000
Cyber Defense Security Analyst – SIEM & Threat Hunting
Cyber Defense Security Analyst – SIEM & Threat Hunting

Universität Zürich • Zürich

On-site
CHF 110,000 - 140,000
Cyber Defense Analyst: Threat Hunter & Incident Response
Cyber Defense Analyst: Threat Hunter & Incident Response

Who is Hiring • Zürich

On-site
CHF 110,000 - 150,000
Fachverantwortung \"Cyber Defense Center\"
Fachverantwortung \"Cyber Defense Center\"

Swiss National Bank • Zürich

Hybrid
CHF 150,000 - 190,000
Cyber Defense Analyst - Threat Hunting & Incident Response
Cyber Defense Analyst - Threat Hunting & Incident Response

University of Zurich • Zürich

On-site
CHF 110,000 - 140,000
ICT-System-Engineer
ICT-System-Engineer

Universität Zürich • Zürich

On-site
CHF 110,000 - 150,000
Cyber Defense Analyst/in 80%-100%
Cyber Defense Analyst/in 80%-100%

Kanton Basel-Stadt • Basel

On-site
CHF 90,000 - 120,000
Cyber Defense Analyst/in (80%–100%)
Cyber Defense Analyst/in (80%–100%)

Kanton Basel-Stadt • Basel

Hybrid
CHF 110,000 - 140,000
Flexible Arbeitszeiten
Homeoffice
Jobsharing
Cyber Defense Analyst/in 80%–100%
Cyber Defense Analyst/in 80%–100%

Kanton Basel-Stadt, Finanzdepartement • Basel

On-site
CHF 110,000 - 140,000
Homeoffice
Gleitzeit/Teilzeit
Jobsharing