CISTEC AG
Zürich
8 hours ago
Senior Security Engineer (80 – 100%)
- 06 February 2026
- 80 – 100%
- Permanent position
- Zürich
Job summary
Join CISTEC as a Senior Security Engineer in healthcare innovation.
Tasks
- Lead and mentor Security Champions in best practices.
- Integrate security principles early in software development.
- Consult on application security for agile teams.
Skills
- Degree in IT, with experience in security measures.
- Proficiency in React, TypeScript, Node.js, and more.
- Strong understanding of OWASP standards and security tools.
Is this helpful?
About the job
Senior Security Engineer (80 – 100%)
Shape the future of healthcare with us.
At CISTEC, we develop and operate KISIM, one of the leading clinical information systems in Switzerland. Our product supports medical professionals, nursing staff, and specialists in everyday clinical practice – from regional hospitals to university hospitals, from psychiatry to rehabilitation. What drives us is the conviction that good software relieves people and improves patient care.
Grow with us.
Since our beginnings with two employees, we have developed into a market-leading IT company with over 250 dedicated professionals – and we continue to grow. With us, competence, team spirit, and passion come together. If you want to be part of a success story that shapes the Swiss healthcare system daily, then you are exactly right with us.
Innovative together. For more time with people.
As an ISO, you are responsible for the technical implementation of information security, integrating security into operations and projects, pragmatically managing risks, and ensuring effective, actionable protective measures in everyday CISTEC life. You operate at the interface of governance, technology, and management. You are the central contact person for information and cybersecurity topics.
Your tasks
- Professional leadership of our Security Champions, promoting knowledge exchange, and responsible for building our Security Champion guild considering our internal security policies, best practices, and secure coding guidelines.
- Establishing "Shift-Left-Security" and early anchoring of security principles throughout the software development lifecycle.
- Central contact person for all aspects of application security and advising our agile development teams on implementing secure software.
- Participation in the development of modern web apps (mobile, widescreen, desktop) in the extensive ecosystem of our clinical information system KISIM.
- Leading threat modelings as well as supporting secure code reviews and coordinating external penetration tests.
- Evaluating, implementing, and optimizing our security tools (SAST, DAST, SCA) with integration into our CI/CD pipelines.
In this role, you work closely with the CISO, product owners, software architects, DevOps engineers, and developers to effectively implement security requirements.
Your profile
- Completed studies in computer science, business informatics, or a similar education.
- Several years of practical experience as a software engineer with tech stack React, TypeScript, Node.js, GraphQL, GitLab CI, Argo CD, Kubernetes, and Postgres.
- Solid experience in implementing IT security measures in software projects as well as confident handling of common security standards, attack scenarios, and tools (OWASP Top 10, SAST, DAST, SCA).
- Knowledge of SaMD and ISO-81001-5-1 is an advantage.
- You enjoy sharing your knowledge, coaching others, and independently driving an initiative forward. Initial experience in mentoring or leading a community of practice is a big plus.
- You can explain complex technical issues clearly and convince at all levels.
- Fluent German skills in spoken and written form.
We offer you
Meaningful work with impact: You work on exciting projects at the interface of AI and healthcare – in an interdisciplinary team that creates real added value.
Innovative environment: Together we develop pioneering solutions that sustainably improve clinical everyday life – with noticeable impact for health professionals.
Flexible working: Part-time work, flexible working hours, and home office are a matter of course. After the probation period, you can work remotely up to four days a week.
Learning and innovation culture: We actively promote your further education and support you in attending professional conferences and trade fairs. Flat hierarchies and an open, agile team environment create space for personal and professional development.
Attractive benefits: Enjoy 5 weeks of vacation per year. Unpaid leave is possible by arrangement.
Shared experiences: We celebrate successes together – at lunch barbecues, on snow days, or at our team and company events.
Application
Please send your complete application documents by e-mail to: moc.cetsic@gnubreweb
Note for recruiters and headhunters:
We kindly ask you not to send us applications from headhunters or recruitment agencies. Thank you for your understanding.
Diversity and inclusion:
CISTEC stands for equal opportunities and diversity. We welcome applications from all people regardless of personal characteristics or backgrounds.