Security Engineer CV: Example and Template
How to structure your CV as a Security Engineer in Switzerland so that certifications, detection metrics and compliance experience are immediately recognisable.
Currently 32 open Security Engineer positions in Switzerland, across 6 cantons, 4 of them from the last 7 days. vontobel advertises the most.
CV example — two-page template
This template is editable straight away — or upload your existing CV and it is carried into this layout automatically.
What qualifications do you need to become a Security Engineer in Switzerland?
A degree in computer science or an IT apprenticeship with further training is enough - what matters is recognised certifications and demonstrable practical experience.
The classic path leads through a BSc in Computer Science at a university of applied sciences (ZHAW, FHNW, HSLU, BFH) or a degree in Computer Science at ETH/EPFL, often supplemented by the Joint Master of Science in Engineering with a specialisation in Cyber Security. Equally common, and explicitly accepted in job postings, is the path via an EFZ as an ICT specialist (platform development or systems engineering) followed by higher vocational education, such as the Federal Diploma as an ICT Security Expert or the Federal Certificate as a Cyber Security Specialist. Always state your qualification with its correct Swiss title and year, as HR systems filter precisely on this.
Certificates are not a nice-to-have in this role but a selection criterion. List them in their own block with year and issuing organisation: OSCP or GIAC certificates (GCIH, GCIA, GPEN) for technical depth, CISSP or CISM for senior and leadership positions, plus platform-specific credentials such as AZ-500, SC-200 or AWS Security Specialty. If a certificate expires (CISSP CPE cycle, GIAC renewal), state the validity period.
If you lack a formal qualification, compensate with verifiable practice: Hack The Box or CTF rankings, published Sigma rules or tools on GitHub, CVE numbers from your own findings, talks at Area41, Swiss Cyber Storm or BSides Zurich. This kind of evidence often carries more weight with technical hiring managers than a diploma, but it rarely replaces one at banks and insurers, where compliance requirements demand formal qualifications.
How should you present your professional experience as a Security Engineer?
For each role, describe environment size, technology stack and results in numbers - not your list of tasks.
For every position, start with context: industry, number of assets or endpoints, daily log volume, cloud vs on-premises split, SOC model (in-house, co-managed, MSSP) and regulator. A sentence such as 'hybrid Azure environment, 2'400 endpoints, 1.8 TB SIEM ingest per day, FINMA-supervised' tells a recruiter more about your level than three lines of task description. Follow this with three to four bullet points, each containing a measurable result.
Use the metrics that security teams actually track: MTTD and MTTR, false-positive rate, ATT&CK technique coverage, patch SLA compliance, number of critical findings in the backlog, compliance score in Defender for Cloud, degree of automation in alert triage, or licence and analyst cost savings in CHF. Express before-and-after figures, e.g. 'reduced false positives from 34% to 7%'. Avoid statements like 'responsible for IT security' - they are true for every role and therefore worthless.
Clearly separate engineering from operations. If you worked as a SOC analyst, describe alert volume and escalation quality; as an engineer, describe the rules, pipelines, infrastructure-as-code modules and hardening standards you built. Mention on-call and shift models as well as standby duty explicitly, as many Swiss employers are specifically buying that availability. Projects such as a SIEM migration, a PAM rollout or an IEC 62443 segmentation deserve their own bullet points with duration and team size.
Length, photo and Swiss conventions - what should you pay attention to?
Two pages, a photo is optional but common, and clean documentation of work permit, languages and security clearances.
Keep the CV to two pages, or a maximum of three with over ten years of experience. Summarise older positions in a single line. A professional portrait photo remains common in Switzerland and is expected by many recruitment agencies, though it is not mandatory. In the header, add your place of residence, nationality or permit type (C, B, G) and availability date - relevant for security roles at banks, federal agencies or in the defence industry, where personnel security clearances under PSPV or clearance requirements may apply.
Languages matter more often than you'd think: in German-speaking Switzerland, German plus fluent English is often enough, while employers in Geneva, Lausanne or federal-adjacent organisations see French as a genuine advantage. State levels according to the CEFR (C1, B2) rather than vague descriptions, and mention if you have conducted incident communication or audit discussions in a foreign language. Only state a salary expectation if requested; market ranges for Security Engineers are roughly between CHF 105'000 and CHF 160'000 per year, depending on experience and region.
Pay attention to discretion and traceability. Do not name internal system details, unresolved vulnerabilities of former employers, or client names if you worked at an MSSP - write 'large bank, 12'000 endpoints' instead. Save the file as a PDF with the naming pattern CV_Lastname_Firstname.pdf, use a clean, ATS-readable structure without graphics for skill bars, and link to LinkedIn and GitHub. A brief note that references are 'available on request' is standard practice; submit employment references only with the application dossier or when requested.
Where Security Engineer are hired in Switzerland
How the 32 open positions are spread across the cantons.
Figures as a table
| Canton | postings |
|---|---|
| Zürich | 7 |
| Waadt | 3 |
| Zug | 2 |
| Basel-Stadt | 2 |
| Aargau | 2 |
| Bern | 2 |
Which languages the postings require
Of 30 postings that state a language — in brackets, those requiring professional level.
Figures as a table
| Language | postings |
|---|---|
| German | 22 (21) |
| English | 13 (13) |
Who hires Security Engineer in Switzerland
Employers with the most open positions. Staffing agencies are excluded.
Figures as a table
| Employer | postings |
|---|---|
| vontobel | 2 |
| Axians in Switzerland | 1 |
| die Mobiliar | 1 |
| Idorsia Pharmaceuticals Ltd | 1 |
| SoftwareOne | 1 |
| AMAG Group | 1 |
Full-time or part-time?
How the positions are advertised.
Figures as a table
| Workload | postings |
|---|---|
| Vollzeit / plein temps | 28 |
The CV in full
To read through and reuse.
Nicolas Brunschwiler
Security Engineer, MSc Cyber Security (BFH) · OSCP · CISSP
Security Engineer with 8 years of experience building and operating detection and response capabilities in regulated environments (banking, insurance, critical infrastructure). Focus areas are SIEM engineering with Microsoft Sentinel and Splunk ES, hardening Azure and Kubernetes landscapes to CIS Benchmarks, and purple-team exercises aligned with MITRE ATT&CK. I work closely with the CISO, Internal Audit and external auditors, translating requirements from ISO/IEC 27001, FINMA Circular 2023/1 and the revised Swiss Data Protection Act (revDSG) into robust technical controls.
What sets me apart
Detection Engineering as Code: Over 180 Sigma and KQL rules managed in Git, with a CI/CD pipeline and automated unit tests against Atomic Red Team - reduced the false-positive rate from 34% to 7%.
Regulatory requirements translated into technical practice: Experience with FINMA Circular 2023/1 (Operational Risks), ISO/IEC 27001:2022 Annex A and NIS2 requirements from EU parent companies - including evidence documentation for external audits with no major findings.
Cloud and container hardening: Hardened Azure Landing Zones and AKS clusters to CIS Benchmark Level 2, policy-as-code with Azure Policy and Kyverno - increased compliance score from 61% to 94%.
OT/IT interface: Segmentation according to the IEC 62443 zone-conduit model for an energy utility, including Purdue-level separation and passive anomaly detection across 14 substations.
Incident response under pressure: Lead responder in 23 security incidents, 4 of them ransomware-related - average containment time of 47 minutes, no data leakage requiring notification under Art. 24 DSG.
Key achievements
Reduced MTTD from 9 hours to 22 minutes. Rebuilt the log onboarding strategy for 2'400 endpoints and 190 servers: normalised EDR, Entra ID and firewall telemetry (ASIM), covering 62 prioritised ATT&CK techniques.
Saved CHF 210'000 in licence costs per year. Halved SIEM ingest from 1.8 TB to 0.9 TB per day by filtering at the data-source level and offloading audit logs to a data lake - while maintaining the same use-case coverage.
Zero-findings audit under ISO/IEC 27001:2022. Automated the provision of technical evidence for 43 controls (vulnerability management, patch SLA, privileged access); 2024 recertification with no deviations, cutting audit preparation effort by 120 person-hours.
Experience
Senior Security Engineer — Helvenda Financial Services AG, Zurich, 03/2021 - present
FINMA-licensed asset manager, 1'100 employees, hybrid Azure/on-premises environment, co-managed SOC model.
- Led the SIEM migration from QRadar to Microsoft Sentinel for 2'400 assets in 7 months, migrated 180 detection rules as code, reducing MTTD from 9h to 22 min.
- Introduced automated response with Logic Apps and Defender for Endpoint: 68% of phishing alerts fully auto-triaged, freeing up 310 analyst-hours per year.
- Redesigned vulnerability management with CVSS and EPSS prioritisation: critical findings on a 7-day patch SLA, reduced backlog from 4'700 to 620 findings.
- Technical point of contact for Internal Audit and the FINMA audit firm; passed the 2024 ISO/IEC 27001:2022 recertification with no major finding.
Security Engineer — Alpstein Grid Services AG, Bern, 08/2018 - 02/2021
Grid operator with OT infrastructure (14 substations), classified as critical infrastructure, subject to reporting obligations to the NCSC.
- Implemented network segmentation according to IEC 62443 across 14 substations, inventoried 640 OT assets, reduced flat networks to 9 zones with defined conduits.
- Introduced passive anomaly detection for Modbus and IEC-104 traffic, achieved 100% asset visibility in the process network, decommissioned 3 undocumented remote access points.
- Created incident response playbooks for 6 OT scenarios and tested them in 2 tabletop exercises with 28 participants; shortened the alerting chain from 4h to 35 min.
- Automated rollout of CIS Benchmark hardening standards for 190 Windows servers via Ansible, reducing configuration deviations by 87%.
Junior Security Engineer / SOC Analyst L2 — Cyberia Managed Security AG, Basel, 09/2016 - 07/2018
MSSP serving 40 clients in the Swiss SME sector, 24/7 SOC operating on a follow-the-sun model.
- Analysed and escalated around 1'800 alerts per year in Splunk ES, reducing the false-escalation rate from 19% to 6%.
- Developed and documented 42 Splunk correlation rules for client environments, 11 of which were adopted as a standard package for all new clients.
- Supported the SIEM onboarding of 14 new clients, reducing average time-to-value from 21 to 12 days.
- Built an internal knowledge base with 95 runbooks, shortening onboarding time for new L1 analysts from 6 to 4 weeks.
Education
Master of Science, Cyber Security (Joint Master) — Bern University of Applied Sciences BFH · 2016
Bachelor of Science, Computer Science, IT Security specialisation — ZHAW School of Engineering, Winterthur · 2013
Federal VET Diploma (EFZ), ICT Specialist EFZ, Systems Engineering — Vocational School Baden · 2009
OSCP - Offensive Security Certified Professional (2020) · CISSP - ISC2 (2022) · Microsoft AZ-500: Azure Security Engineer Associate (2023) · GIAC GCIH - Certified Incident Handler (2019)