We are hiring an IT Systems & Security Engineer to strengthen the stability, security, and efficiency of our internal IT services. This role blends hands-on systems engineering with security operations. You will operate and improve endpoint security and device management, administer Microsoft 365, run vulnerability management, and enhance monitoring/SIEM workflows.
A core expectation of this position is continuous optimization of our IT and security operations: reducing manual work through automation, lowering operational cost where possible, and improving response times and service quality for employees.
You will work closely with the CISO and act as Deputy to the CISO during planned absences (e.g., holidays), ensuring operational continuity and effective decision-making.
Job requirements
Strong hands-on experience with Microsoft 365 administration, including Entra ID and Intune.
Practical experience operating Microsoft Defender (alert triage, investigations, policy tuning).
Proven endpoint management across macOS and Windows in a business environment.
Working knowledge of JAMF administration (profiles, policies, deployments, compliance reporting).
Working knowledge of vulnerability management with Nessus (or equivalent).
Familiarity with SIEM/logging concepts (ELK and/or other SIEM): ingestion, dashboards, alerting, operational improvement.
Solid network fundamentals relevant to IT security (DNS/DHCP/VPN, segmentation concepts, troubleshooting).
Strong documentation discipline (access management, operational procedures, incident notes).
Ability to operate effectively in ticketed environments and manage priorities (ITIL-inspired practices are a plus).
Demonstrable continuous-improvement mindset: simplify, automate, standardize, measure outcomes; bias for reducing manual effort, lowering cost, and improving response times.
Hands-on exposure to AI tools and workflows, with the ability to support secure, practical adoption in a business environment (e.g., testing and enabling use cases, understanding risks around data handling, and contributing to user guidance/guardrails).
- Certifications (required or obtained within the first 6–12 months)
CompTIA Security+ (or equivalent baseline security certification/competence).
CompTIA Network+ (or equivalent demonstrated networking competence).
- Nice to have (certifications)
Microsoft certifications: SC-200 (Security Operations Analyst), SC-300 (Identity & Access Administrator), MD-102 (Endpoint Administrator), MS-102 (Microsoft 365 Administrator) or equivalents.
Jamf certification: Jamf Certified Tech / Admin (or current Jamf certification track).
ITIL Foundation (service management discipline).
SIEM/security analytics training or vendor certifications (helpful, not required).
- Nice to have (skills/experience)
Automation/scripting (PowerShell, Bash, Python) applied to IT/security operations.
Experience improving SIEM detection use cases and telemetry correlation.
Experience in regulated environments (audit readiness, investigations, evidence handling).
Experience translating security requirements into pragmatic employee guidance (policies, playbooks, enablement).
Job responsibilities
1) Endpoint Security Operations (Microsoft Defender)
Operate Defender day-to-day: monitor alerts, investigate incidents, tune policies, reduce noise, and improve detection quality.
Support security incident handling: triage, containment coordination, evidence collection, remediation follow-up, and lessons learned.
Improve endpoint security posture via policy hardening, baselining, and measurable reduction of repeated issues.
Administer Microsoft 365 services with a focus on security, reliability, and operational hygiene.
Maintain access governance: joiner/mover/leaver lifecycle, role assignments, privileged access patterns, and conditional access support (where applicable).
Improve identity and device-based controls in partnership with the CISO (e.g., MFA coverage, device compliance gates, administrative separation).
Manage endpoint lifecycle and compliance across Apple and Windows fleets.
Administer JAMF for macOS (profiles, deployments, compliance reporting, hardening).
Manage Windows endpoints primarily through Intune (configuration, application deployment, compliance, configuration baselines).
Standardize and streamline onboarding/offboarding and device replacement processes.
Run and improve vulnerability scanning coverage, schedules, and reporting.
Prioritize remediation by risk and business impact; track closure with clear ownership and deadlines.
Establish durable reporting cadence and measurable remediation performance.
Improve SIEM effectiveness: ingestion health, source coverage, dashboards, alerting, and correlation across endpoint and infrastructure telemetry.
Help operationalize detection use cases (high-signal alerts, playbooks, reporting that supports decision-making).
Produce concise operational reporting for stakeholders (security posture, trends, improvements, key risks).
Operate and improve Jira Service Management/Confluence workflows: queues, SLAs, request types, automation rules, and documentation standards.
Support GitLab access and enablement from an IT/security operations perspective (e.g., identity, access controls, user lifecycle), as applicable.
Ensure IT services are reliable, measurable, and continuously improving.
Enable and support secure use of AI tools and workflows across the company in collaboration with the CISO and key stakeholders.
Help define and implement practical guardrails (approved tools, data handling rules, access controls, logging/monitoring considerations, user guidance).
Support employees with secure adoption: documentation, onboarding guidance, and pragmatic reviews of new AI use cases.
Identify and implement automation opportunities (e.g., identity/device lifecycle, ticket workflows, alert triage, reporting).
Reduce operational friction and manual work while improving service speed and quality.
Maintain cost awareness: rationalize tooling/configurations where appropriate, reduce waste, and improve vendor/service ownership clarity.
Coordinate with suppliers for hardware/services: delivery tracking, escalation paths, renewal visibility, and operational performance issues.
Maintain runbooks and operational procedures to ensure resilience and audit readiness.
Act as Deputy to the CISO during absences: maintain day-to-day security operations, coordinate incident response activities, and escalate appropriately.
Provide operational leadership as needed to keep internal IT and security services stable and responsive.
How we evaluate success (first 3–6 months)
Defender operations: triage workflow is consistent; alert noise is reduced; repeated endpoint issues decrease; incident handling is timely and well-documented.
M365 / Intune / JAMF: device compliance is reliable; onboarding/offboarding is smooth and measurable; admin and access hygiene is improved.
Vulnerability management: scanning coverage is consistent; remediation tracking is risk-driven; clear ownership and closure cadence is established.
SIEM / visibility: ingestion stability improves; dashboards and alerts become more actionable; stakeholders get concise, useful reporting.
Optimization: multiple tangible automation/standardization improvements delivered that reduce manual work, reduce cycle times for employee requests, and/or reduce operational costs.
Deputy coverage: operational continuity is demonstrably strong during CISO absence, with appropriate escalation and decision-making.
Benefits
- Competitive Salary.
- Hybrid Work Model: Enjoy the flexibility of remote work while staying connected with at least 40% of your time spent in our vibrant Lisbon office.
- 25 Days of Vacation: Recharge and thrive with above-market holiday time, reflecting our people-first approach to work-life balance.
- Bi-Annual International Retreats: Collaborate, relax, and explore at company offsites in beautiful locations like Switzerland, Italy, and beyond.
- Empowered to Make an Impact: Every voice matters—you're encouraged to drive improvements, contribute ideas, and create real value from day one.
- Learn from the Best: Grow your skills in a high-performing, international team of experienced and talented professionals.
- Delicious Perks: Enjoy free lunches, snacks, and drinks daily—because fuel matters.
- Meal allowance, health insurance coverage, and public transportation allowance.
- Work for a company committed to sustainability—our data centers operate climate-neutral.
Skills Required
- Strong hands-on experience administering Microsoft 365, including Entra ID and Intune
- Practical experience operating Microsoft Defender, including alert triage, investigations, and policy tuning
- Proven endpoint management experience across macOS and Windows in a business environment
- Working knowledge of JAMF administration, including profiles, policies, deployments, and compliance reporting
- Working knowledge of vulnerability management using Nessus or an equivalent tool
- Familiarity with SIEM and logging concepts, including ELK or another SIEM
- Solid network fundamentals covering DNS, DHCP, VPN, segmentation, and troubleshooting
- Strong documentation discipline for access management, procedures, and incident notes
- Ability to work in ticketed environments and manage priorities
- Continuous-improvement mindset focused on automation, standardization, measurement, cost reduction, and faster response times
- Hands-on exposure to AI tools and workflows, including secure data handling, use-case testing, and user guidance
- CompTIA Security+ or equivalent baseline security competence, required or obtainable within 6–12 months
- CompTIA Network+ or equivalent demonstrated networking competence, required or obtainable within 6–12 months
- Microsoft security, identity, endpoint, or Microsoft 365 certifications such as SC-200, SC-300, MD-102, or MS-102
- Jamf Certified Tech, Jamf Administrator, or current equivalent Jamf certification
- ITIL Foundation certification
- SIEM or security analytics training or vendor certifications
- Automation or scripting experience with PowerShell, Bash, or Python
- Experience improving SIEM detection use cases and telemetry correlation
- Experience in regulated environments, including audit readiness, investigations, or evidence handling
- Experience translating security requirements into employee guidance, policies, playbooks, or enablement
What We Do
DSwiss AG develops SecureSafe, a Swiss-hosted secure data platform for businesses and individuals. The platform combines encrypted password management, file storage, secure document exchange, and postbox services in one solution. It is designed for regulated and security-conscious organizations, emphasizing data sovereignty, compliance, access control, auditability, and protection of sensitive information across professional and personal use cases.

.png)






