Cyber Security Analyst
📍 5001 Aarau
Rolle und Verantwortlichkeiten
You are a member of the Cyber Defense Center, applying your skills and actively contributing recommendations for its further development. You perform threat modelling and identify new SIEM use cases. You analyse attacks, develop countermeasures, and coordinate them during a security incident. You further develop the incident response process. You conduct forensic analyses on compromised systems and actively hunt for threats (threat hunting). You stay up to date on the international threat landscape, especially in the energy sector. You lead engineering projects and improve existing tools or introduce new ones. You maintain active communication with SOCs and CERTs of other critical infrastructure operators and authorities. You participate in on-call duty (approx. 6-8 weeks per year).
Team / Beschreibung
The Cyber Security team at Swissgrid monitors the infrastructure of the Swiss electricity grid operator and responds to security incidents. We continuously observe the evolving threat landscape and develop effective countermeasures — it’s part of our daily routine.
Qualifikationen und Fähigkeiten
You bring at least 3–4 years of hands-on experience as a SOC Analyst and/or Incident Responder
You hold a degree in Information Security, Information Technology, or a related field
You have an understanding of industrial control systems (ICS) and knowledge of technical issues in substations is an advantage
You are well-versed in technologies such as SIEM, EDR, or NDR
Analysing and triaging security incidents is part of your skill set
You have experience using consoles and scripting languages (PowerShell, Bash, Python)
You enjoy tackling challenges and solving serious problems, without forgetting the importance of humour
Team spirit is important to you, and you enjoy working in a diverse environment
You speak very good English; German skills are an advantage