Senior Security Engineer
jobgether
Switzerland
Vollzeit
Diese Anzeige stammt von Lever
Accountabilities
- Architect and oversee advanced security monitoring and threat detection frameworks across diverse systems and log sources.
- Design automated detection logic capable of identifying complex attack patterns and improving the quality and accuracy of security alerts.
- Serve as a senior escalation point for high-impact security incidents and recurring security issues, engineering systemic solutions rather than relying solely on manual remediation.
- Lead the integration of security into the software development lifecycle, including Security-as-Code and automated SAST, DAST, and SCA capabilities within CI/CD pipelines.
- Partner with engineering leaders to establish appropriate security gates and provide expert guidance on complex architectural weaknesses and critical vulnerabilities.
- Own the end-to-end vulnerability management strategy across infrastructure and applications, prioritizing remediation according to business risk and exploitability.
- Lead cross-functional initiatives to address systemic security weaknesses and coordinate technical relationships with external penetration testers and bug bounty researchers.
- Design, implement, and optimize security infrastructure including EDR, Zero Trust, IAM, DLP, and security orchestration and automation capabilities.
- Drive SOAR and other automation initiatives to reduce manual security operations and ensure consistent enforcement of security controls across multi-cloud environments.
- Lead the technical response to critical security incidents, coordinating containment, eradication, recovery, communications, and post-incident activities.
- Conduct detailed root-cause analyses and translate findings into long-term engineering roadmaps that reduce the likelihood of recurring incidents.
- Lead security audits, maturity assessments, and assurance activities while ensuring technical environments align with applicable standards and regulations.
- Define technical standards for validating the effectiveness of security controls and supporting compliance with frameworks such as ISO 27001.
- Act as a strategic security advisor for major business and technology initiatives, assessing new technologies and third-party vendors through a Security-by-Design approach.
- Establish standards for security procedures, runbooks, technical documentation, and operational practices.
- Mentor junior and mid-level security engineers and help raise the team's overall technical capabilities and consistency.
- Extensive professional experience in Information Security Engineering, with a proven track record of architecting and deploying resilient security systems at scale.
- Strong ability to translate high-level security policies into practical, enforceable technical standards and drive security initiatives across multiple departments.
- Expert-level knowledge of major cloud platforms, particularly AWS and/or GCP, including secure multi-tenant architecture and deep security configuration assessment.
- Deep expertise in cloud-native and container security, particularly Kubernetes.
- Advanced Infrastructure-as-Code experience with technologies such as Terraform and/or CloudFormation, including the ability to create automated security guardrails for compliant deployments.
- Strong scripting and programming capabilities using modern, actively supported programming languages to develop security tooling, automate SecOps processes, and implement sophisticated detection logic.
- Proven experience architecting and optimizing enterprise security technologies such as SIEM, SOAR, and EDR.
- Strong understanding of detection engineering, alert tuning, security monitoring, and building high-fidelity detection pipelines while minimizing operational noise.
- Demonstrated experience leading DevSecOps initiatives and embedding security into complex CI/CD environments without unnecessarily slowing development velocity.
- Comprehensive knowledge of security and compliance frameworks including ISO 27001, SOC 2, and NIST.
- Understanding of international data protection and security regulations, with practical experience preparing for and supporting security audits.
- Strong incident response and digital forensics capabilities, with experience leading technical responses to critical security events.
- Ability to turn complex technical findings and incident root causes into actionable, long-term security strategies.
- Strong architectural thinking, analytical skills, and technical judgment.
- Excellent communication and stakeholder-management skills, with the ability to influence both technical and non-technical audiences.
- Strong leadership and mentoring capabilities, with a willingness to establish standards and raise engineering quality across the wider team.
- Comfortable operating in a fast-paced, distributed environment and taking ownership of high-impact security initiatives.
- Willingness to travel occasionally for team gatherings or specific partner engagements, with travel expected to remain limited.
- Remote working opportunity within Europe.
- Flexible environment designed to support distributed collaboration.
- Opportunity to work on security challenges across a large-scale digital platform and global technology ecosystem.
- High level of technical ownership and influence over enterprise security architecture and engineering standards.
- Exposure to modern cloud, container, infrastructure automation, DevSecOps, detection, and incident response technologies.
- Opportunity to shape security strategy and implement automation across multi-cloud environments.
- Collaborative environment with opportunities to mentor and support other security professionals.
- Opportunity to contribute to high-impact security initiatives spanning engineering, infrastructure, compliance, and business operations.
- Occasional travel opportunities for team gatherings and selected partner engagements.
- Inclusive workplace committed to equal opportunity and fair employment practices.
- Opportunity to work in a technology-driven environment connected to global gaming and esports communities.
Diese Anzeige stammt von Lever. Originalanzeige ansehen ↗