Employment type
Permanent
Industry
Public Sector
Area
IT
Location
Zurich
Remote from abroad?
No
Home office?
By arrangement
01
Tasks and responsibilities
- Manage operational and technical security tasks, ensuring effective implementation of IT security measures in daily operations and projects.
- Implement the IT security strategy tactically and operationally, supporting the IT department and monitoring its effectiveness.
- Monitor threat landscapes, assess security risks in the ICT environment, and conduct operational risk assessments.
- Derive and implement necessary security measures independently or collaboratively with IT staff, or oversee their implementation.
- Create and update security concepts for individual systems and solutions, implementing them technically and developing secure design principles.
- Contribute to overarching IT security architectures and concepts, and to the management of security-related projects and IT architecture.
- Evaluate, specify, and procure suitable security systems, and install and integrate security components.
- Develop technical solutions and decision-making criteria within economic, organisational, and technical frameworks, supporting IT and other relevant departments.
- Conduct technical security tests, analyse and document vulnerabilities, ensure transparency, and forward findings to the patch management team.
- Analyse security incidents, identify and coordinate countermeasures, order immediate actions if necessary, document them, and conduct post-mortem analyses.
- Monitor compliance with safety measures, support operational internal controls, and participate in security audits.
- Create security, operational, and monitoring guidelines, advise colleagues and project managers on IT security issues, and approve operational exceptions.
- Play a leading role in the IT governance committee, assessing new projects for IT security implications and issuing recommendations or requirements.
- Create a budget for IT security measures and an annual plan, prioritising tasks based on risk.
- Collaborate closely with the Chief Information Security Officer, the head of the IT department, and the wider IT team.
02
Must-have criteria
- Several years of experience in information and IT security, as well as in technical project management.
- Completed university education in computer science or an equivalent qualification.
- Expert knowledge at the level of an ICT Security Engineer or Security Analyst.
- Sound understanding of current threats and modern attack and defence techniques and methods.
- Affinity and experience in various cybersecurity fields, including secure design principles, IAM, PAM, network security, security monitoring, vulnerability management, cloud technologies/cloud security, application security, WAF, and advanced threat prevention/IDS/IPS.
- Knowledge of securing Azure/M365, Defender XDR, Microsoft AD, Linux, macOS, virtualisation, container services, and SIEM.
- Basic knowledge of common security standards, including NIST CSF and ISO 27001, and relevant certifications.
- Basic knowledge of relevant legal requirements for information security (revised DSG, cantonal IDG) and experience with internal controls (ICS) and security audits.
- Independence, assertiveness, project management skills, and perseverance.
03
Language requirements
- Very good German
- Good English skills
04
Application form