Senthorus SA
Zurich
Security Analyst L2
- 03 September 2026
- 100%
- Zurich
Job summary
Join Senthorus as a Security Analyst in Zurich, a leading SOC unit. Work in a dynamic environment offering 24/7 support for top-tier clients.
Tasks
- Monitor and analyze security events to identify threats.
- Support containment and recovery during security incidents.
- Proactively hunt for indicators of compromise through analysis.
Skills
- Bachelor's degree in IT or related field; 2-4 years SOC experience.
- Strong knowledge of SIEM and XDR solutions.
- Experience with intrusion analysis and digital forensics.
Is this helpful?
About the job
Your role at Senthorus!
Senthorus is a SOC unit supporting the Swiss market with first-class managed security solutions from Switzerland. All data remains in Switzerland. Our services are aimed at Swiss and European customers.
As a Security (SOC) Analyst – L2, you support our global customers in ensuring their IT security and in detecting and defending against cybersecurity threats at an early stage.
You will be part of a dynamic SOC team and take on a central role in monitoring, detecting, investigating, and responding to security incidents. This helps to minimise the impact of security incidents and ensure that our customers' business-critical processes can continue as smoothly as possible.
At the same time, you are an important technical contact for our Level 1 analysts and support the continuous development of our security operations and detection capabilities.
Important: The position is based in Zurich and involves working in a rotating 24/7/365 shift model, including night and weekend shifts.
Your tasks
- Monitoring and analysing security events and alerts from various sources, including SIEM, network, and endpoint detection and response solutions
- Supporting containment, eradication, and recovery during security incidents
- Proactively identifying indicators of compromise (IOCs) through targeted threat hunting
- Analysing network and log data to distinguish actual threats from false positives and escalating possible intrusions and attacks
- Creating tickets, documenting security incidents, and escalating to higher-level security analysts when necessary
- Taking on the role of technical escalation point and supporting and mentoring analysts at lower levels
- Triaging incoming security issues, assessing priority, and evaluating associated risks
- Collaborating with our customers on the implementation of hardware and software monitoring systems
- Continuously monitoring the current cyber threat landscape
Our offer
- Opportunity to expand your expertise through diverse projects and unique products, the latest technologies, and customers from various industries
- Attractive prospects through continuous training, coaching, and an internal career path
- Our culture makes the difference! We actively live flat hierarchies and open, helpful collaboration across all disciplines and departments
- We organise regular events such as brown bag lunches and coding events as well as cosy and sporty offsite gatherings
- Good work-life balance (41 hours/week with flexible hours, home office), modern and flexible workplace in a multicultural environment
- Top benefits such as: purchasing up to 13 days of holiday, contribution to private mobile phone or business phone, half-fare travelcard, business travel in first class, flexible pension schemes, coverage of daily sickness and accident insurance (private, worldwide), and much more
Your profile
- A bachelor’s degree in Information Security, Computer Science or a comparable IT field
- 2–4 years of practical experience in a SOC/CSIRT environment
- Willingness to work in a 24/7/365 shift model, including night and weekend shifts
- Experience in creating and updating documentation such as incident reports, runbooks, and post-incident analyses
- Strong team skills
- Experience in intrusion analysis, digital forensics, penetration testing or related areas
- Knowledge and practical experience with XDR and SIEM solutions
- Knowledge of threat vectors and attack methods, especially MITRE ATT&CK
- Good knowledge of query languages such as KQL and SQL
- The ability to analyse event logs and detect signs of intrusions and cyberattacks
- The ability to work professionally and productively even in demanding and time-critical situations
- Enjoyment of direct collaboration with customers and the ability to understand their requirements and feedback on security services
- Knowledge of software development or scripting, for example with Python
- Fluent German and English skills (C1 level)
Advantageous
- Industry-standard security certifications such as CompTIA Security+, CySA+, GSEC, GCIA, GCIH, CEH or comparable certifications
- Experience in cloud security monitoring with AWS, Azure or GCP
Ready for your next challenge?
Do you want to apply your experience in the cybersecurity field, develop professionally, and contribute significantly to the security of our customers together with a dedicated team?
Then we look forward to meeting you and learning more about your experience and motivation.