Employment type
Permanent
Industry
Public sector
Area
IT
Location
German-speaking Switzerland
Remote from abroad?
No
Home office?
Flexible
01
Tasks and responsibilities
- Assess the information security and compliance posture of new IT equipment, systems, and external service providers through structured due diligence
- Review vendor security credentials, certifications, and audit reports (e.g. ISO 27001, SOC 2, ISAE 3402) during procurement and contract negotiations
- Help define, maintain, and evolve security requirements for internal IT resources and third-party suppliers
- Plan, run, and oversee security audits, and track the implementation of agreed remediation measures
- Deliver security awareness training and guidance to technical and non-technical staff across the organisation
- Advise colleagues on information security matters in an accessible, practical way
- Identify improvement opportunities to continuously strengthen the information security programme
- Work closely with the agile ICT team, other security functions, and the data protection officer
02
Must-have criteria
- Practical experience in information security, IT risk management, or governance, risk & compliance (GRC), IT audit, or a comparable function
- Relevant training or further education in information security
- Solid working knowledge of client and server operating systems, networking, and cloud technologies
- Strong grasp of information security, data protection, and IT general controls, with the ability to assess risks clearly and derive pragmatic measures
- Familiarity with key standards and frameworks such as ISO 27001, ISAE 3402 Type 2, or SOC 1 Type 2
- Analytical, structured, and solution-oriented working style with strong attention to quality
- Excellent communication skills for explaining complex technical topics to varied audiences
03
Nice-to-have criteria
- Exposure to generative AI and agentic AI technologies and their security implications
- Active interest in current cyber security trends, emerging attack techniques, and protective measures
- Experience supporting procurement and contract negotiations from a security standpoint
- Recognised security certifications (e.g. CISA, CISM, CISSP, ISO 27001 Lead Auditor)
- Team-oriented personality with an independent, reliable, and service-oriented approach
04
Language requirements
- Fluent German (spoken and written), at C1 level or above
- Good working English (spoken and written), B2 level or above
05
Application form