Rolex SOC & CSIRT Engineer
Rolex is a world‑leading Swiss watchmaker recognised for technical excellence, precision engineering and uncompromising quality. As an employer it offers a discreet, high‑performance environment anchored in craftsmanship and long‑term stability, with an emphasis on professional rigor and cross‑disciplinary collaboration.
- Manage, maintain and optimise SOC technologies and platforms to ensure high availability and detection fidelity.
- Plan, implement and configure new security solutions to enhance detection and response capabilities.
- Continuously monitor SOC tooling to identify opportunities for technical and operational improvement.
- Provide advanced technical support for forensic analysis, threat hunting and insider‑threat detection.
- Lead investigations for critical or complex security incidents, coordinate remediation and oversee containment measures.
- Develop, review and update incident response plans and procedures; drive post‑incident lessons learned and continuous improvement.
- Design and refine detection use cases (SIEM rules, SOAR playbooks, EDR workflows) in collaboration with SOC analysts.
- Deploy and run programmes such as self‑assessments, CTI, deception and red‑team/blue‑team exercises to strengthen security posture.
- Train and coach SOC team members on tool usage, investigative techniques and incident response best practices.
- Work closely with Security Architecture & Engineering to ensure seamless integration of new security products and alignment with organisational standards.
- Higher education degree in computer science, information systems security or a closely related discipline.
- Minimum five years of practical experience in a SOC or incident response function, including project management and technology deployment.
- Proven experience deploying and operating SIEM, SOAR, EDR and network detection systems (IDS/IPS).
- Demonstrable expertise in cloud security platforms and tooling (O365, Defender, Sentinel, Google SCC).
- Advanced skills in forensic analysis, proactive threat hunting, CTI and deception techniques.
- Familiarity with recognised security frameworks and standards (ISO 27001, NIST, MITRE ATT&CK).
- Ability to lead and resolve critical incidents autonomously, rapidly diagnose breaches and define containment/remediation actions.
- Strong communication, stakeholder management and team coaching capabilities; resilient under pressure and highly autonomous.
- SIEM
- SOAR
- EDR
- IDS/IPS
- O365
- Defender
- Sentinel
- Google SCC
- forensic analysis
- threat hunting
- CTI
- deception
- ISO 27001
- NIST
- MITRE ATT&CK
- SIEM rules
- SOAR automation
Minimum five years of hands‑on experience in SOC operations and incident response, including deployment and lifecycle management of SIEM, SOAR, EDR and network detection technologies.
Higher education degree in computer science, information systems security, cybersecurity or a related field.
This position is listed in Geneva, Geneva, in Switzerland. Rolex is actively recruiting for this and 728 other open jobs in Switzerland.
Flexible working arrangements; comprehensive social benefits.
The workplace culture privileges craftsmanship, precision and discretion, combining high technical standards with long‑term career stability. Teams are collaborative and multidisciplinary, with an expectation of professionalism, continuous improvement and respect for confidentiality.
Rolex Careers
-
Today
-
Today
-
Today
-
Today
-
Today
-
Today
-
Today
-
Today
-
Today
-
Today
Continue Your Search
We invite you to review more currently available roles: