Senior IT Security Engineer (ID2140)

AO Foundation

Davos

Hybrid

CHF 120.000 - 160.000

Vollzeit

Vor 4 Tagen
Sei unter den ersten Bewerbenden

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Benefits dieser Stelle

Flexible hours
Global team
Modern infrastructure
Social benefits
Education support

Zusammenfassung

AO Foundation in Davos, Switzerland, seeks a Security Engineer to lead automation of SOC Level 1 and 2 processes and support incident response. You will design, implement, and maintain runbooks using Logic Apps, Power Automate, and AI Foundry components to enable scalable security operations.

The ideal candidate has a Bachelor's degree in IT or CS, 5 years in security, 2+ years in SOC Level 1/2 and Level 3 incident response, Python or PowerShell, and expertise with Microsoft Sentinel and

Qualifikationen

  • Bachelor’s degree in Information Technology, Computer Science, or related field.
  • 5 years of professional experience in relevant field.
  • Minimum 2 years of hands-on experience with SOC Level 1 and Level 2 operations and Level 3 incident response.
  • Programming skills in Python or PowerShell.
  • Deep familiarity with Microsoft security products, including Microsoft Sentinel, Defender XDR components and KQL.
  • Strong understanding of Azure infrastructure, identity, and security architecture.
  • Understanding of security baselining, network hardening, and zero trust principles.
  • Ability to work in cross-functional DevSecOps environment.
  • Fluency in English; German or other languages are a plus.

Aufgaben

  • Develop and maintain automated SOC Level 1 and Level 2 runbooks and playbooks using Logic Apps, Power Automate, and AI Foundry components.
  • Engineer detection rules, workbooks, and playbooks in Microsoft Sentinel/Microsoft XDR platforms.
  • Integrate and optimize Microsoft Defender for Endpoint, Identity, Cloud, and Office 365 within the XDR framework.
  • Apply AI-driven threat detection and response using Microsoft Copilot for Security and related tools.
  • Collaborate with internal teams and external partners to embed security into CI/CD pipelines and IT delivery models.
  • Provide SOC Level 3 support for complex incidents, including forensic analysis and threat containment.
  • Contribute to the DevSecOps organization.
  • Support the implementation of an ISO 27000-aligned ISMS and assist with governance and compliance efforts.

Kenntnisse

SOC operations
Incident response
Python
PowerShell
Microsoft Sentinel
Azure security
CI/CD security
English fluency

Ausbildung

Bachelor's degree in IT/CS

Tools

Logic Apps
Power Automate
AI Foundry
Microsoft Defender for Endpoint
XDR
KQL

Jobbeschreibung

Select how often (in days) to receive an alert:

The AO is a medically guided, not-for-profit organization, a global network of surgeons, and the world's leading education, innovation, and research organization specializing in the surgical treatment of trauma and musculoskeletal disorders. We are home to people from all over the world, from different backgrounds, with diverse talents and specialist areas. What binds us together is our passion for excellence, our dedication to our mission of improving patient care, and our understanding that we are stronger together: we are one AO.
For more information, visit: https://www.aofoundation.org/

As part of the AO’s support units, our IT department offers information technology services to maintain and oversee computer infrastructure across the AO Foundation.

Workload percentage / Pensum: 100%

Short Description

We are seeking a Security Engineer to lead the automation of SOC Level 1 and Level 2 processes and support advanced incident response. This role is critical to future security operations. The engineer will design, implement, and maintain automated runbooks using Microsoft’s security technologies and AI capabilities, ensuring scalable and efficient security operations.

Main Responsibilities
  • Develop and maintain automated SOC Level 1 and Level 2 runbooks and playbooks using Logic Apps, Power Automate, and AI Foundry components
  • Engineer detection rules, workbooks, and playbooks in Microsoft Sentinel/Microsoft XDR platforms
  • Integrate and optimize Microsoft Defender for Endpoint, Identity, Cloud, and Office 365 within the XDR framework
  • Apply AI-driven threat detection and response using Microsoft Copilot for Security and related tools
  • Collaborate with internal teams and external partners to embed security into CI/CD pipelines and IT delivery models
  • Provide SOC Level 3 support for complex incidents, including forensic analysis and threat containment
  • Contribute to the DevSecOps organization
  • Support the implementation of an ISO 27000-aligned ISMS and assist with governance and compliance efforts
Main Requirements
  • Bachelor’s degree in Information Technology, Computer Science, or related field
  • 5 years of professional experience in relevant field
  • Minimum 2 years of hands-on experience with SOC Level 1 and Level 2 operations and Level 3 incident response
  • Programming skills in Python or Powershell
  • Deep familiarity with Microsoft security products, including Microsoft Sentinel, Defender XDR components and KQL
  • Strong understanding of Azure infrastructure, identity, and security architecture
  • Understanding of security baselining, network hardening, and zero trust principles
  • Ability to work in cross-functional DevSecOps environment
  • Fluency in English. Fluency in German or any other languages will be considered as an added value

Preferred Qualifications:

  • Microsoft certifications in security technologies (e.g., SC-200, SC-300)
  • Experience with agentic AI standards and responsible AI practices
  • Familiarity with governance models and risk assessment frameworks
  • Understanding of structured threat intelligence and enrichment workflows
  • Familiarity with MITRE ATT&CK mapping and detection coverage assessments
  • Familiarity with detection-as-code pipelines and version control systems
  • Familiarity with Web Application Firewall (WAF) principles and rule tuning

We offer

  • An interesting and varied job in an exciting and innovative organization
  • The opportunity to be part of a highly committed international team
  • Modern infrastructure
  • High degree of flexibility regarding working hours and location (depending on operational requirements)
  • Generous package of social benefits, including supplementary vacation days and pension scheme contributions
  • Internal skills training opportunities and support for continued education
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior IT Security Engineer (ID2140)
Senior IT Security Engineer (ID2140)

AO Foundation • Schweiz

Hybrid
CHF 120.000 - 160.000
Flexible hours
Hybrid work
Pension and vacation benefits
+1
Senior IT Security Engineer
Senior IT Security Engineer

AO Foundation • Davos

Hybrid
CHF 120.000 - 190.000
Flexible hours
Flexible location
Social benefits
+3
Senior Security Engineer: SOC Automation & AI Security
Senior Security Engineer: SOC Automation & AI Security

AO Foundation • Davos

Hybrid
CHF 120.000 - 190.000
Flexible hours
Flexible location
Social benefits
+3
Security Engineer: SOC Automation & AI-Driven Defenses
Security Engineer: SOC Automation & AI-Driven Defenses

AO Foundation • Davos

Hybrid
CHF 120.000 - 160.000
Flexible hours
Global team
Modern infrastructure
+2
Senior Security Engineer: AI-Driven SOC Automation (Remote)
Senior Security Engineer: AI-Driven SOC Automation (Remote)

AO Foundation • Schweiz

Hybrid
CHF 120.000 - 160.000
Flexible hours
Hybrid work
Pension and vacation benefits
+1
Cloud Security Engineer
Cloud Security Engineer

Swisslinx • Basel

Vor Ort
CHF 110.000 - 160.000
50% remote work
Remote work abroad 20 days/year
Central Basel office
Security Engineer (gn) Microsoft Modern Workplace
Security Engineer (gn) Microsoft Modern Workplace

SoftwareONE Deutschland GmbH • Tolochenaz

Hybrid
CHF 140.000 - 210.000
Mentor and career growth
Presidents Club recognition
Flexible work arrangements
+2
IT Vendor Management Specialist, 80% (ID2134)
IT Vendor Management Specialist, 80% (ID2134)

AO Foundation • Davos

Vor Ort
CHF 110.000 - 140.000
Training opportunities
Pension scheme contributions
Flexible working hours
Associate Technical Account Manager - Cybersecurity
Associate Technical Account Manager - Cybersecurity

Ontinue • Zürich

Vor Ort
CHF 120.000 - 180.000
Security Engineer (gn) Microsoft Modern Workplace
Security Engineer (gn) Microsoft Modern Workplace

SoftwareOne • Tolochenaz

Hybrid
CHF 140.000 - 180.000
Mentor support
Flexible work