La Caisse des Médecins est une coopérative suisse proposant des services administratifs et informatiques aux cabinets médicaux et aux autres professionnels de santé indépendants. Elle intervient notamment dans la facturation, la gestion des créances et les logiciels de cabinet.
Incident Engineer (w/m)
Am I a fit — voir ma compatibilitéL’Incident Engineer contribue à la détection, l’analyse et la résolution des incidents de sécurité au sein d’équipes d’ingénierie et d’opérations agiles. Le poste est basé dans la région de Genève (Thônex) ou de Zurich (Urdorf) et implique notamment l’utilisation de Microsoft Defender, d’un SIEM et d’outils de scripting.
Repères sur Ärztekasse – Caisse des Médecins
- Domaine officiel
- aerztekasse.ch
- Offres ouvertes
- 25
Détails de l’offre
La description complète publiée par Ärztekasse – Caisse des Médecins.
Description de l’offre
Ärztekasse Genossenschaft provides business process outsourcing and eHealth solutions to health professionals so they get relief from administration and can focus on medical work. Ärztekasse is renewing its entire datacenter and the products affected by this transformation. To support this digitalization step, we are looking for smart and experienced engineers to contribute and shape clever and creative solutions for a meaningful industry.
Incident Engineer (w/m) Pensum: 80-100% Start: immediately or by appointment Duration: unlimited Location: Geneva area (Thônex) or Zurich area (Urdorf) Main Tasks
- Triage, investigate and resolve endpoint security alerts from Microsoft Defender across employee machines
- Detect, analyse and respond to security incidents across our endpoints, infrastructure and applications
- Lead incident response activities and coordinate remediation with engineering and operations teams
- Tune detection rules to reduce false positives and continuously improve alert quality
- Develop and maintain incident response playbooks, processes and tooling
- Monitor security events and alerts (Microsoft Defender, SIEM, IDS/IPS) and drive continuous detection improvements
- Conduct post-incident reviews and root-cause analysis, and track corrective actions
- Implement security best practices and harden systems against emerging threats
- Participate in future on-call rotation
Requirements
3+ years of experience in security incident response, SOC or a similar role
- Hands-on experience with Microsoft Defender for Endpoint (EDR) and endpoint security
- Strong understanding of security monitoring, SIEM and detection engineering
- Knowledge of attack techniques and incident handling frameworks (e.g. NIST, MITRE ATT&CK)
- Experience with Windows and Linux security; Kubernetes is a plus
- Scripting and automation skills, preferably in Bash, Python or Go
- Relevant certifications (e.g. GCIH, GCIA, OSCP) are a plus
- Analytical, calm under pressure and a strong communicator; English required, German and French a plus Further information A stimulating environment helps to find cool solutions to challenging complex requirements. We work in small agile teams where you can have impact and influence. You will find sharp engineers to have inspiring discussions with. We are solution-driven, but we don’t neglect the fun factor. We look forward to receiving your application! We look forward to receiving your application by e-mail at E-Mail schreiben .
Prérequis
- Strong understanding of security monitoring, SIEM and detection engineering
- Knowledge of attack techniques and incident handling frameworks
- Analytical
- calm under pressure
- strong communicator