Job Description Template: Information Security Engineer
This template helps Swiss employers write a clear job posting for an Information Security Engineer. It covers core responsibilities like threat assessment and security policy development, must-have skills in risk management and compliance, nice-to-haves such as cloud security expertise, and compensation benchmarks. Adapt the Pensum percentage, canton, and salary range to your business and market.
An Information Security Engineer protects your company's digital assets, systems, and data from cyber threats. They design and maintain security infrastructure, respond to incidents, and ensure compliance with regulations relevant to your industry and canton.
This template gives you a starting point. Adjust the Pensum (part-time or full-time percentage), location name, language requirements, and compensation to match your needs and Swiss market rates.
The Role: What This Person Does
The Information Security Engineer owns day-to-day security operations. They monitor systems for threats, manage firewalls and access controls, and respond to security incidents. They also keep security policies and documentation up to date.
This role bridges technical security work and business needs. The engineer advises other departments on security best practices, conducts risk assessments, and helps the company stay compliant with data protection laws (such as the Federal Data Protection Act in Switzerland).
- Monitor network traffic, logs, and security alerts for suspicious activity
- Install, configure, and maintain firewalls, intrusion detection, and endpoint security tools
- Respond to security incidents: contain, investigate, and remediate breaches
- Conduct vulnerability assessments and penetration tests
- Develop and update security policies, procedures, and documentation
- Support compliance audits and regulatory requirements (e.g. ISO 27001, GDPR where applicable)
Must-Have Requirements
Look for candidates with hands-on experience in IT security operations or systems administration. They should understand network architecture, common attack vectors, and how to use industry-standard security tools.
Technical certifications and a methodical approach to problem-solving matter more than a specific degree. Practical experience managing firewalls, SIEM systems, or vulnerability management is essential.
- 3–5 years of experience in IT security operations or network/systems administration
- Proficiency with firewalls, VPNs, intrusion detection/prevention systems, and endpoint protection
- Strong knowledge of networking (TCP/IP, DNS, HTTP/HTTPS) and common security protocols
- Familiarity with security compliance frameworks (ISO 27001, NIST, or Swiss/EU data protection rules)
- Excellent problem-solving and documentation skills
- Fluent in [specify: German, French, Italian, English] — working language of your office
Nice-to-Have Requirements & What We Offer
Candidates with cloud security experience (AWS, Azure, Google Cloud), incident response expertise, or security certifications (CISSP, CEH, Security+) stand out. Open-source security tools knowledge is also valuable.
Compensation in Switzerland varies by experience, location (Zurich and Geneva pay more than rural cantons), and company size. Offer a transparent salary range in CHF, Pensum percentage (e.g. 80–100%), and mention 13th-month bonus if applicable. Include vacation days, flexible work options, and professional development budgets to attract top talent.
- Experience with cloud platforms and cloud-native security (containers, Kubernetes)
- Incident response or forensics background
- Security certifications (CISSP, GIAC, CEH, or equivalent)
- Salary range: [state CHF annual gross — benchmarks vary by canton and experience; consult local salary surveys]
- Pensum: [state percentage, e.g. 80–100%]; 4–5 weeks annual leave; [13th month bonus if standard for your company]
- Home office, professional development budget, and flexible hours where operationally feasible
Frequently asked questions
- What salary should I list for an Information Security Engineer in Switzerland?
- Salaries vary by canton, experience, and company size. Entry-level engineers (3–5 years) in rural areas earn around CHF 90,000–120,000 gross annually; in Zurich or Geneva, CHF 120,000–150,000 or more. Use current Swiss salary surveys and consult local HR advisors to set a competitive range. Always state a range rather than a single figure.
- Should I require a specific language?
- Yes. Name the required working language(s) in the job posting. If your office is in the German-speaking region, German (and often English) is standard. In French-speaking cantons, French is expected. This prevents misunderstandings and sets clear expectations. If multilingualism is preferred but not mandatory, move it to nice-to-haves.
- How do I describe Pensum correctly in a Swiss job ad?
- State the percentage of a full-time position, e.g. '80–100% Pensum' or '100% Pensum'. This tells candidates whether the role is part-time or full-time. Always include it prominently, as Swiss jobseekers expect this detail. Pair it with the canton or city (e.g. 'Zurich', 'Geneva', 'Bern') so candidates know the location.
General information for Swiss employers, not legal advice. Have a lawyer confirm anything with legal consequences.