Senior IT Security Engineer (ID2140)
AO Foundation Davos, Grisons, Switzerland
Research Services · 51-200 employees
About the role
The engineer will lead the automation of SOC Level 1 and Level 2 processes while supporting advanced incident response and forensic analysis. They will also design and maintain automated runbooks using Microsoft security technologies and AI-driven threat detection tools.
What they look for
Requirements
Candidates must hold a bachelor's degree in a relevant field and possess at least 5 years of professional experience, including 2 years in SOC operations. Proficiency in Python or PowerShell and deep familiarity with the Microsoft security stack are essential requirements.
Full description
Short Description
We are seeking a Security Engineer to lead the automation of SOC Level 1 and Level 2 processes and support advanced incident response. This role is critical to future security operations. The engineer will design, implement, and maintain automated runbooks using Microsoft’s security technologies and AI capabilities, ensuring scalable and efficient security operations.
Main Responsibilities
- Develop and maintain automated SOC Level 1 and Level 2 runbooks and playbooks using Logic Apps, Power Automate, and AI Foundry components
- Engineer detection rules, workbooks, and playbooks in Microsoft Sentinel/Microsoft XDR platforms
- Integrate and optimize Microsoft Defender for Endpoint, Identity, Cloud, and Office 365 within the XDR framework
- Apply AI-driven threat detection and response using Microsoft Copilot for Security and related tools
- Collaborate with internal teams and external partners to embed security into CI/CD pipelines and IT delivery models
- Provide SOC Level 3 support for complex incidents, including forensic analysis and threat containment
- Contribute to the DevSecOps organization
- Support the implementation of an ISO 27000-aligned ISMS and assist with governance and compliance efforts
Main Requirements
- Bachelor’s degree in Information Technology, Computer Science, or related field
- 5 years of professional experience in relevant field
- Minimum 2 years of hands-on experience with SOC Level 1 and Level 2 operations and Level 3 incident response
- Programming skills in Python or Powershell
- Deep familiarity with Microsoft security products, including Microsoft Sentinel, Defender XDR components and KQL
- Strong understanding of Azure infrastructure, identity, and security architecture
- Understanding of security baselining, network hardening, and zero trust principles
- Ability to work in cross-functional DevSecOps environment
- Fluency in English. Fluency in German or any other languages will be considered as an added value
Preferred Qualifications:
- Microsoft certifications in security technologies (e.g., SC-200, SC-300)
- Experience with agentic AI standards and responsible AI practices
- Familiarity with governance models and risk assessment frameworks
- Understanding of structured threat intelligence and enrichment workflows - Familiarity with MITRE ATT&CK mapping and detection coverage assessments - Familiarity with detection-as-code pipelines and version control systems - Familiarity with Web Application Firewall (WAF) principles and rule tuning
Similar roles
-
Senior Security Engineer - DevSecOps
carsales Sydney, New South Wales, Australia
-
Lead Cloud Security Engineer (DevSecOps)
Bilue Taguig, National Capital District, Philippines
-
Senior Security Engineer - Detection Engineering
LinkedIn United States · $129K–$212K/yr
-
Security Engineer
AlertMedia Austin, Texas, United States
-
F-35 Air Systems Information System Security Engineer | Active Secret clearance
General Dynamics Information Technology Eglin AFB, Florida, United States · $128K–$172K/yr
-
Full-Stack Engineers (Cybersecurity): Feedback On CI/CD Workflows
Terac United States · $218K/yr