Rolex SOC & CSIRT Engineer

Employment
Full-Time
Seniority
Senior
Posted
Mar 21, 2026

About Rolex

Rolex is a world‑leading Swiss watchmaker recognised for technical excellence, precision engineering and uncompromising quality. As an employer it offers a discreet, high‑performance environment anchored in craftsmanship and long‑term stability, with an emphasis on professional rigor and cross‑disciplinary collaboration.

Rolex (Geneva, Switzerland) seeks a SOC & CSIRT Engineer to manage SOC tooling, lead incident response and conduct advanced forensic investigations.

Role & Responsibilities

  • Manage, maintain and optimise SOC technologies and platforms to ensure high availability and detection fidelity.
  • Plan, implement and configure new security solutions to enhance detection and response capabilities.
  • Continuously monitor SOC tooling to identify opportunities for technical and operational improvement.
  • Provide advanced technical support for forensic analysis, threat hunting and insider‑threat detection.
  • Lead investigations for critical or complex security incidents, coordinate remediation and oversee containment measures.
  • Develop, review and update incident response plans and procedures; drive post‑incident lessons learned and continuous improvement.
  • Design and refine detection use cases (SIEM rules, SOAR playbooks, EDR workflows) in collaboration with SOC analysts.
  • Deploy and run programmes such as self‑assessments, CTI, deception and red‑team/blue‑team exercises to strengthen security posture.
  • Train and coach SOC team members on tool usage, investigative techniques and incident response best practices.
  • Work closely with Security Architecture & Engineering to ensure seamless integration of new security products and alignment with organisational standards.

Qualifications

  • Higher education degree in computer science, information systems security or a closely related discipline.
  • Minimum five years of practical experience in a SOC or incident response function, including project management and technology deployment.
  • Proven experience deploying and operating SIEM, SOAR, EDR and network detection systems (IDS/IPS).
  • Demonstrable expertise in cloud security platforms and tooling (O365, Defender, Sentinel, Google SCC).
  • Advanced skills in forensic analysis, proactive threat hunting, CTI and deception techniques.
  • Familiarity with recognised security frameworks and standards (ISO 27001, NIST, MITRE ATT&CK).
  • Ability to lead and resolve critical incidents autonomously, rapidly diagnose breaches and define containment/remediation actions.
  • Strong communication, stakeholder management and team coaching capabilities; resilient under pressure and highly autonomous.

Skills

SIEM SOAR EDR IDS/IPS O365 Defender Sentinel Google SCC forensic analysis threat hunting CTI deception ISO 27001 NIST MITRE ATT&CK SIEM rules SOAR automation

Experience

Minimum five years of hands‑on experience in SOC operations and incident response, including deployment and lifecycle management of SIEM, SOAR, EDR and network detection technologies.

Education

Higher education degree in computer science, information systems security, cybersecurity or a related field.

Workplace

This position is based in Geneva, Geneva, Switzerland.

Benefits

Flexible working arrangements; comprehensive social benefits.

Culture

The workplace culture privileges craftsmanship, precision and discretion, combining high technical standards with long‑term career stability. Teams are collaborative and multidisciplinary, with an expectation of professionalism, continuous improvement and respect for confidentiality.

About Cerulean

Cerulean is the definitive career portal for the global luxury industry. We match exceptional professionals with exclusive opportunities at the world's most prestigious brands. From haute couture and fine watchmaking to prestige beauty, hospitality, and boutique retail, Cerulean centralises luxury employment to help you find the career for which you were destined.

Frequently Asked Questions

A.

The luxury industry is characterised by a diverse and nuanced nomenclature. Esteemed houses frequently employ proprietary terminology, and even within a single organisation like Rolex, titles may vary across global markets to reflect local conventions. To ensure absolute clarity, Cerulean assigns a standardised, industry-coherent canonical title to every listing. However, it is worth noting that this role is functionally synonymous with «Security Operations Engineer», «Incident Response Engineer (SOC/CSIRT)», «Senior SOC Analyst», «Cybersecurity Engineer — SOC & IR», and other variations. Our sophisticated search architecture anticipates these variations, ensuring that inquiries using related terms will seamlessly yield the exact roles you desire.

Rolex

Rolex SOC & CSIRT Engineer

Geneva, Switzerland

Continue to the application.