Kudelski Group seeks a Senior Security Operations Engineer in Cheseaux, CH, to support its Managed Detection and Response (MDR) services. The role involves client liaison, incident response, and enhancing security operations for clients through close collaboration with the Cyber Fusion Center.
This position is part of Kudelski Security’s Managed Detection and Response (MDR) team, focusing on delivering tailored MDR services. The Security Engineer serves as the primary link between clients and the Cyber Fusion Center, ensuring effective communication and coordination for all security operations. The goal is to help clients reduce visibility gaps and strengthen their security posture throughout the MDR service lifecycle.
Responsibilities
- Act as the primary contact between the Cyber Fusion Center and the client’s team
- Assist with core Cyber Fusion Center tasks including threat monitoring, endpoint detection and response, and vulnerability scanning
- Investigate and resolve incidents escalated from the Cyber Fusion Center or internal client teams
- Develop customized incident response playbooks for clients
- Design, test, and deploy use cases, correlation rules, threat hunting, and threat intelligence activities tailored to clients
- Support large-scale incident response efforts
- Tune client SIEM rules during operations
- Contribute to rules factory initiatives to enhance global detection capabilities
- Evaluate, analyze, and recommend new data source integrations
- Collaborate with product teams to develop new services aligned with operational needs
- Participate in client security projects
- Implement tools or scripts to improve security operations efficiency
- Ensure client satisfaction and success of managed services
- Suggest improvements to Standard Operating Procedures
- Propose enhancements to tools and workflows
- Document actions in tickets for clear internal and client communication
- Follow established policies, procedures, and security best practices
Requirements
- At least 5 years of experience in information security, especially in cyber operations
- Strong client-facing service and communication abilities
- Understanding of incident response workflows including detection, triage, analysis, remediation, and reporting
- Experience with SIEM platforms (Splunk, Sentinel), EDR/NGAV solutions (Crowdstrike, MDE), vulnerability scanning, and managed attacker deception
- Ability to review and analyze log data and network packet captures
- Solid knowledge of Windows/Linux operating systems, network protocols, and scripting (Python)
- Familiarity with cloud computing infrastructures and platforms
- Comprehensive understanding of the security landscape and visibility solutions (SIEM vs EDR)
- Professional proficiency in both French and English
Nice to have
- Technical certifications in vendor products, especially Splunk
- Additional language skills are beneficial
Quelle: öffentlich zugängliche Karriereseite des Arbeitgebers. Batchly ist nicht der Arbeitgeber und steht nicht notwendigerweise in einem Vertragsverhältnis mit dem Unternehmen.