Job matched to your search
IT Infrastructure Security Engineer
SII Group Switzerland · Olten
Free · Join 5,000+ job seekers using Qarera
How well do you match this role?
Tap the skills you already have — then see your real match score, what’s missing, and your resume fixed for this job.
Job description
Who we are
SII Group is a trusted technology partner, SII provides high value added solutions for the IT projects of many large corporations. Since its founding in 1979, the Company has been providing solutions adapted to its clients’ needs, by relying on :
> Its acknowledged expertise in various industries and sectors
> Proven 'turnkey' solutions
> An efficient quality system
> Adaptable, evolving services
Today, with a staff of more than 18'000, SII Group is supporting companies across 20 countries.
At SII Switzerland we pay attention to the personal and professional wellbeing of our employees. We place our collaborators at the heart of our actions and activities. If you are motivated by the perspective of joining a big, trusted and recognized group, then let's meet !
To develop our consulting offer and support one of our clients, we are looking for a talented IT Infrastructure Security Engineer.
Missions
- Configure, run and tune Tenable WAS scans: templates, crawl scope, exclusions, throttling, scan windows including authenticated scans (recorded logins, SSO, token/header auth) and API scanning from OpenAPI/Swagger definitions.
- Define and agree naming and tagging conventions up front in the platform (scans, targets, tags, folders, user groups) and in documentation so results stay consistently structured, filterable and reportable as the portfolio grows.
- Analyse each application before scanning: architecture, auth flow, tech stack, SPA/JS behaviour, WAF and bot protection, prod vs. non-prod, blast radius.
- Consult application responsible roles (application owners, product owners, dev leads, third-party suppliers) on scope, credentials, scan timing, and result validation. No scan goes live without agreed scope and an identified owner.
- Provision and store all scan credentials in the corporate credential store, never in scan configurations, exports or local files, with defined rotation and least-privilege scoping.
- Build and maintain the reporting layer: coverage, findings by severity/age, SLA compliance, remediation trend.
- Maintain the documentation baseline: configurations and their rationale, per-application scope agreements and credentials handling, operating procedure – so the scanning setup is auditable and transferable, not held in one person's head.
Profile
- Strong understanding of application roles, privilege levels, and scanning contexts (anonymous, authenticated, privileged; internet-facing vs. internal).
- Knowledge of application security principles, including OWASP Top 10, API Security Top 10, authentication, authorization, and session management.
- Proficiency in Python and SQL, with experience handling CSV/JSON data, REST APIs, and data analysis; Power BI is a plus.
- Experience with CMDBs, including application/service ownership and data quality management.
- Familiarity with ITSM processes, including change management, incident/request handling, and workflow coordination.
For information
- Start date: ASAP
- Location: remote from Switzerland
- Languages: Fluent English, German is a plus
- Requirement: European citizen
Browse related jobs
Don’t just read the job — see if you’ll get it.
Get your match score, a resume tailored to this exact role, and jobs like it — free.
Check my fit for this job