SWICA Gesundheitsorganisation
Winterthur
Senior Cyber Security Engineer – Focus on Incident Response and Threat Intelligence (all)
- 07 August 2026
- 80 – 100%
- Permanent position
- German (Basic knowledge)
About the job
80-100%
The rapid detection and handling of cyber attacks is more important than ever; it requires a strong defence architecture, modern detection solutions, a reliable and modern Security Operations Centre, and people who take responsibility. This is exactly where you come in.
As a Senior Cyber Security Engineer with a focus on Incident Response and Threat Intelligence, you play a central role in SWICA's Cyber Security team.
Thanks to our Work-Anywhere policy, you work flexibly throughout Switzerland, combined with personal exchange at our headquarters in Winterthur.
Your workplace
Winterthur
The rapid detection and handling of cyber attacks is more important than ever; it requires a strong defence architecture, modern detection solutions, a reliable and modern Security Operations Centre, and people who take responsibility. This is exactly where you come in.
As a Senior Cyber Security Engineer with a focus on Incident Response and Threat Intelligence, you play a central role in SWICA's Cyber Security team.
Thanks to our Work-Anywhere policy, you work flexibly throughout Switzerland, combined with personal exchange at our headquarters in Winterthur.
Senior Cyber Security Engineer – Focus on Incident Response and Threat Intelligence (all)
This is how you shape health
- Optimising processes for detecting, analysing, and handling security incidents and cyber threats, as well as implementing measures to continuously increase team maturity
- Independent handling and coordination of security incidents (Incident Handler) as well as creating and presenting situation reports and recommendations for action to management
- Coordination and management of internal stakeholders and the external SOC and CSIRT partners
- Conducting technical analyses, threat hunting, and incident response activities
- Further development and automation of SIEM use cases and runbooks to improve security monitoring together with the SOC provider
- Developing cyber security playbooks and pre-approved containment measures
- Supporting and conducting blue team exercises to strengthen defensive security measures
What sets you apart
- Education or degree in computer science or information security
- Quick comprehension and ability to break down complex issues into manageable work packages
- At least 3 years of practical experience in cyber security, especially in incident response, incident handling, threat intelligence
- Solid knowledge of modern attack vectors, security frameworks, and relevant tools e.g. SIEM / SOAR (MS Sentinel), XDR (MS Defender)
- Certifications such as GIAC GSOM, GIAC GCIH, CERT CSIH, OSCP or comparable are advantageous
- Scripting and automation skills (e.g. Python, PowerShell), experience with infrastructure as code or security automation is a plus
- Experience in handling complex cyber security incidents and communicating to technical and non-technical audiences
- You are accustomed to working with and leading external partners
- Structured, analytical, and independent working style
- Enjoy explaining technical topics clearly and taking professional responsibility
- Fluent German in spoken and written form and very good English skills
Why SWICA
- We build on humanity. That is why openness, respect, and trust are at the centre of our everyday work. We take action, assume responsibility, and think in solutions – together, for our customers. This is also why we have been number 1 in customer satisfaction for many years.
- We trust you and give you space. With annual working hours, at least 5 weeks of holiday, and the option to buy additional leave. With part-time models and generous home office options within the possibilities of the role, you can organise your everyday life largely flexibly.
- We appreciate and reward your work – with a market-appropriate salary, up to 1500 francs annual allowance for personal wishes, and generous contributions to basic and supplementary insurance for you and your family.
- We offer you prospects. With a generous training regulation, we support your professional and personal development – for your current role and your goals for tomorrow.
- Because health is everything. With our corporate health management and region-specific offers, we take care of your well-being. And if things go differently: 100% net salary continuation.
- We think long-term. With three savings plans, workload-dependent coordination deductions, and benefits well above the legal minimum, you are well provided for your future.
Your workplace
Winterthur
Do you have questions?
Vanessa Tobler, HR Recruiting, will be happy to provide information.
+41 52 244 26 25
Only direct applications will be considered.