📢 Nouveau : recevez les offres du jour sur notre canal WhatsApp
Jobiglo

Aucun resultat.

Cette offre n'est plus disponible

Cette offre a expire le 19/08/2026. Elle n'accepte plus de candidatures.

Incident Response & Forensic Analyst (CSIRT Member)

Swiss Post Cybersecurity · Aarau

🇬🇧 English
Velociraptor KAPE Plaso Azure AWS GCP M365 Entra ID Windows internals Win32 API Active Directory GNU/Linux reverse engineering scripting

Description du poste

About the role

We are seeking an experienced Incident Response and Forensic Analyst to join our CSIRT in Aarau. The role involves protecting customers from cyber‑attacks by investigating, containing and learning from security incidents.

Key responsibilities

  • Investigate and triage suspicious activity on workstations and information systems, from initial doubt to confirmed incident.
  • Assist clients with security incidents such as APT intrusions, ransomware, BEC, data exfiltration, insider threats, web‑application compromises, phishing and credential theft.
  • Conduct proactive threat hunting to uncover past or ongoing compromises.
  • Lead kick‑off meetings and present clear, actionable analyses to clients.
  • Collaborate with the SOC to improve real‑time detection capabilities.
  • Participate in tabletop exercises, threat‑intelligence activities and develop or test security tools.
  • Create and deliver training sessions and promote CSIRT activities through publications.

Required profile

  • Minimum 3 years experience in a SOC/CSIRT environment, including at least 2 years of hands‑on incident response with advanced threats.
  • Strong understanding of operating‑system internals and reverse engineering (Windows, Active Directory, GNU/Linux).
  • Hands‑on forensic and incident‑response experience in public‑cloud environments (Azure, AWS, GCP, M365/Entra ID).
  • Fluency in German and strong English; French is a plus.
  • Willingness to work onsite in Aarau, participate in a 24/7 on‑call rotation and travel to customer sites if needed.

Required skills

  • Incident‑response tools such as Velociraptor, KAPE and Plaso.
  • Scripting or development for automation of detection scenarios.
  • Threat‑hunting methodologies.
  • Knowledge of APT, ransomware, BEC, phishing and credential‑theft techniques.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Swiss Post Cybersecurity.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Pourquoi signalez-vous cette offre ?

Merci pour votre signalement. Nous allons examiner cette offre.

Une question sur cette offre ?

Posez-la ici : vous recevrez le récapitulatif de l'offre par e-mail, tout de suite.

💬 Contactez-nous sur Telegram

Publie il y a 3 mois

20 vues · 0 interesses

Boostez vos chances

Importez votre CV : nous vous proposons les offres qui matchent votre profil.

Analyse de votre CV en cours...

Swiss Post Cybersecurity

Aarau