📢 Nouveau : recevez les offres du jour sur notre canal WhatsApp
Jobiglo

Aucun resultat.

Cette offre n'est plus disponible

Cette offre a expire le 15/08/2026. Elle n'accepte plus de candidatures.

Incident Response & Forensic Analyst – CSIRT Team

Swiss Post Cybersecurity · Aarau

🇬🇧 English
Velociraptor KAPE Plaso Windows internals Win32 API Active Directory GNU/Linux Azure AWS GCP M365 Entra ID macOS Android iOS

Description du poste

About the role

Swiss Post Cybersecurity is expanding its Incident Response Team and seeks an experienced Incident Response and Forensic Analyst to join the CSIRT. The role involves protecting customers from advanced cyber‑attacks, conducting investigations, and supporting crisis management.

Key responsibilities

  • Investigate and triage suspicious activity on workstations and information systems from initial detection to confirmed incident.
  • Assist clients with APT intrusions, ransomware, BEC, data exfiltration, insider threats, web‑application compromises, phishing, and credential theft.
  • Perform proactive threat hunting to uncover past or ongoing compromises.
  • Support clients during containment, eradication, and recovery phases of security incidents.
  • Lead kickoff meetings, present actionable analyses, and provide reconstruction recommendations.
  • Collaborate with the SOC to enhance real‑time detection capabilities.
  • Contribute to tabletop exercises, threat‑intelligence activities, and methodology improvements.
  • Develop, test, and share tools; deliver training sessions in academic or professional settings.
  • Promote CSIRT activities through publications.

Required profile

  • Minimum 3 years experience in a SOC/CSIRT environment, including at least 2 years of hands‑on incident response with advanced threats.
  • Strong verbal and written communication skills in German (C1) and English (C1); French is a plus.
  • Willingness to participate in a 24/7 on‑call rotation and travel to customer sites if required.
  • Residence within one hour of Aarau or Zurich, or willingness to relocate.

Required skills

  • Deep knowledge of Windows internals, Win32 API, Active Directory, and GNU/Linux.
  • Hands‑on forensics and incident response in public cloud environments (Azure, AWS, GCP, M365, Entra ID).
  • Familiarity with incident‑response tools such as Velociraptor, KAPE, and Plaso.
  • Proficiency in scripting or development for automation of detection scenarios.
  • Bonus: experience with macOS, Android, or iOS forensics.

What we offer

  • Collaborative and friendly work environment.
  • Opportunities to work on cutting‑edge cyber‑security challenges.
  • Professional development through training and research activities.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Swiss Post Cybersecurity.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Pourquoi signalez-vous cette offre ?

Merci pour votre signalement. Nous allons examiner cette offre.

Une question sur cette offre ?

Posez-la ici : vous recevrez le récapitulatif de l'offre par e-mail, tout de suite.

💬 Contactez-nous sur Telegram

Publie il y a 3 mois

24 vues · 0 interesses

Boostez vos chances

Importez votre CV : nous vous proposons les offres qui matchent votre profil.

Analyse de votre CV en cours...

Swiss Post Cybersecurity

Aarau