yellowshark
Luzern
Cyber Security Engineer
- 06 October 2026
- 100%
- Permanent position
- CHF 105 000 - 120 000 /year
- 6005 Luzern
About the job
For our client, an established IT service provider (Managed Services Provider) with renowned corporate clients in Central Switzerland, we are looking for reinforcement. The company plans, builds and operates IT infrastructure solutions from basic infrastructure through network and security to the modern workplace, on-premises, in the Microsoft cloud or in its own data centre.
This advertisement is aimed at professionals who work or have worked at an IT service provider, system house or MSP. You are familiar with the everyday customer business, changing environments and working in projects and operations.
Alarms from the SOC land with you. You check whether a real attack is behind an anomaly, involve the affected accounts and systems and help to contain and properly clean up an incident. You document your findings in writing and explain to the customer in clear language what happened and what follows.
Co-design security projects with customers
You accompany projects from requirement clarification to handover: build protection mechanisms and systems, test them in practice, document and accept them together with the customer. The environment ranges from classic server environments through hybrid setups to pure cloud.
Manage vulnerabilities
Scan results interest you not only as a list. You classify them, decide together with the customers what to tackle first, and ensure that gaps, weak configurations and excessive access rights actually disappear. Afterwards, you check whether the measure is effective.
Maintain security platform
You keep our own security platform running. If data is missing or an evaluation seems implausible, you look for the cause and pass on improvement ideas to development.
Continuously sharpen detection
With the team, you build and test detection rules, clear false alarms, write investigation steps into playbooks and replace manual work with scripts and automation.
- You have IT training or equivalent knowledge. A part-time degree you are currently completing is not an obstacle.
- You have already worked at an IT service provider in system engineering or cyber security and know the work for several customers in different environments.
- Windows servers and clients, Active Directory, Entra ID and Microsoft 365 are familiar to you, and you know how identities, systems and networks interact.
- You have already gained some security practice, for example in hardening systems, with endpoint protection, evaluating alerts or securing accounts and rights.
- Advantages: Microsoft Defender XDR, Sentinel, PowerShell, KQL.
Personal
- You explain technology so that customers understand it and enjoy working in direct exchange with them.
- You work cleanly and reliably and handle sensitive data responsibly.
- Even under time pressure, you keep an overview, set priorities and speak openly if you do not know something.
- Above-average number of holidays, with the possibility to buy or sell holiday days
- Up to five learning hours per week and financial support for further training
- An experienced team that shares knowledge and room for your own ideas
- Additional time for charitable engagement, team events and an open corporate culture
Please only apply if you currently work or have previously worked at an IT service provider. Send us your complete application dossier (CV, references, diplomas and certificates). Unfortunately, incomplete documents cannot be considered.
This advertisement is aimed at professionals who work or have worked at an IT service provider, system house or MSP. You are familiar with the everyday customer business, changing environments and working in projects and operations.
Tasks
Analyse and resolve security incidentsAlarms from the SOC land with you. You check whether a real attack is behind an anomaly, involve the affected accounts and systems and help to contain and properly clean up an incident. You document your findings in writing and explain to the customer in clear language what happened and what follows.
Co-design security projects with customers
You accompany projects from requirement clarification to handover: build protection mechanisms and systems, test them in practice, document and accept them together with the customer. The environment ranges from classic server environments through hybrid setups to pure cloud.
Manage vulnerabilities
Scan results interest you not only as a list. You classify them, decide together with the customers what to tackle first, and ensure that gaps, weak configurations and excessive access rights actually disappear. Afterwards, you check whether the measure is effective.
Maintain security platform
You keep our own security platform running. If data is missing or an evaluation seems implausible, you look for the cause and pass on improvement ideas to development.
Continuously sharpen detection
With the team, you build and test detection rules, clear false alarms, write investigation steps into playbooks and replace manual work with scripts and automation.
Profile
Professional- You have IT training or equivalent knowledge. A part-time degree you are currently completing is not an obstacle.
- You have already worked at an IT service provider in system engineering or cyber security and know the work for several customers in different environments.
- Windows servers and clients, Active Directory, Entra ID and Microsoft 365 are familiar to you, and you know how identities, systems and networks interact.
- You have already gained some security practice, for example in hardening systems, with endpoint protection, evaluating alerts or securing accounts and rights.
- Advantages: Microsoft Defender XDR, Sentinel, PowerShell, KQL.
Personal
- You explain technology so that customers understand it and enjoy working in direct exchange with them.
- You work cleanly and reliably and handle sensitive data responsibly.
- Even under time pressure, you keep an overview, set priorities and speak openly if you do not know something.
Additional information
- Flexible working models: 4-day week or home office by arrangement- Above-average number of holidays, with the possibility to buy or sell holiday days
- Up to five learning hours per week and financial support for further training
- An experienced team that shares knowledge and room for your own ideas
- Additional time for charitable engagement, team events and an open corporate culture
Please only apply if you currently work or have previously worked at an IT service provider. Send us your complete application dossier (CV, references, diplomas and certificates). Unfortunately, incomplete documents cannot be considered.