Cette offre n'est plus disponible
Cette offre a expire le 30/08/2026. Elle n'accepte plus de candidatures.
Incident Response and Forensic Analyst – CSIRT Member
Swiss Post Cybersecurity · Aarau
Description du poste
About the role
Swiss Post Cybersecurity is expanding its Incident Response Team and seeks an experienced analyst to join as a CSIRT member. You will work directly with clients to detect, contain, and remediate advanced cyber threats while contributing to the continuous improvement of the team’s processes and tools.
Key responsibilities
- Investigate and triage suspicious activity on workstations and information systems, from initial doubt to confirmed incident.
- Assist clients during security incidents such as APT intrusions, ransomware, BEC, data exfiltration, insider threats, web‑application compromises, phishing and credential theft.
- Conduct proactive threat hunting to uncover past or ongoing compromises.
- Support crisis management, including containment, eradication, and recovery phases.
- Lead kickoff meetings and deliver clear, actionable analyses and reconstruction plans.
- Collaborate with the SOC to enhance real‑time detection capabilities.
- Participate in tabletop exercises, threat‑intelligence sharing, and methodology development.
- Develop, test, and share tools; deliver training sessions in academic or professional settings.
Required profile
- Minimum 3 years experience in a SOC/CSIRT environment, with at least 2 years of hands‑on incident response on advanced threats.
- Strong verbal and written communication in German (C1) and English (C1); French is a plus.
- Willingness to join a 24/7 on‑call rotation and travel to customer sites if needed.
- Residence within one hour of Aarau or Zurich, or readiness to relocate.
Required skills
- Deep knowledge of Windows internals, Win32 API, Active Directory, and GNU/Linux.
- Hands‑on forensic and incident‑response experience in public‑cloud environments (Azure, AWS, GCP, Microsoft 365/Entra ID).
- Familiarity with incident‑response tools such as Velociraptor, KAPE, and Plaso.
- Scripting or development skills for automation (e.g., Python, PowerShell).
- Understanding of reverse engineering and, optionally, macOS or mobile (Android/iOS) forensics.
What we offer
- A collaborative, friendly work environment focused on continuous learning.
- Opportunities to influence CSIRT processes, publish research, and develop new tools.
- Access to advanced security technologies and ongoing professional development.
Questions fréquentes
Pourquoi signalez-vous cette offre ?
Aller plus loin
Salaires, guides et recherches en Suisse.
Une question sur cette offre ?
Posez-la ici : vous recevrez le récapitulatif de l'offre par e-mail, tout de suite.
Publie il y a 3 mois
29 vues · 0 interesses
Boostez vos chances
Importez votre CV : nous vous proposons les offres qui matchent votre profil.
Analyse de votre CV en cours...
Swiss Post Cybersecurity
Aarau
Offres similaires
-
Security Operations Specialist (m/w/d)
Rocken® Härkingen -
Associate Programme Officer – CBRN
United Nations Interregional Crime and Justice Research Institute GENEVA -
Security, Health & Safety Intern
VF Corporation Stabio -
Head of Cybersecurity
KIDAN Allaman -
Sicherheitsbeauftragte/r SIBE (80‑100 %)
Mediclinic Hirslanden Salem-Spital