Head of IT Security Operations & Controls
Role details
Job location
Tech stack
Job description
Reporting to our Chief Information Security Officer, you will lead the bank's Operational Security function - owning our SoC (analysts and engineering), incident response, and the effectiveness of our frontline security controls. Your mission is to maximize the safe use of our digital assets, protect customers information, and keep the business fast, compliant, and resilient., * Manage a team of approx. 4 individuals: hiring, coaching, and creating an environment where people do the best work of their careers.
-
SoC leadership & incident response: Run day to day SoC operations, elevate detection & response maturity, and lead major incident command calmly under pressure. Ensure investigations are rigorous, evidence based, and drive tactical fixes as well as strategic improvements.
-
Strategy & modernization: Define and execute the SoC strategy for the next 2-3 years, including pragmatic adoption of cloud and AI assisted threat detection, triage, and automation (SOAR).
-
Security control operations: Own the operating effectiveness of key controls (e.g., vulnerability management, baseline security, DLP). Ensure continuous control monitoring, coverage metrics, and clear KRIs/KPIs that matter to the business.
-
Establish, own, and execute the bank's penetration testing, red team, and purple team roadmap -coordinating internal capabilities and external partners to simulate realistic adversary behaviors and ensure continuous improvement of detection, response, and control effectiveness.
-
Oversee the operational workflow of the security team, including triaging incoming support tickets, security requests, and operational tasks. Ensure efficient dispatching and prioritization of work across the CISO organization and maintain clear service level expectations with internal stakeholders.
-
Enterprise & engineering integration: Partner closely with Architecture, Engineering, Infrastructure, IT Ops, and Developers to land controls and patterns that scale.
-
Resilience & recovery: Strengthen incident readiness, tabletop exercises, and post incident "close call" learning to boost resilience and reduce repeat issues.
-
Stakeholder trust: Engage customers, auditors, and internal leaders; translate risk into clear business context; advocate for secure by default choices., * Mission centric, humble leadership that attracts talent and grows careers.
-
Pragmatic risk management
-
Comfortable operating in degrees of risk, not absolutes.
-
Intellectual curiosity and bias for action; you improve processes, not just operate them. TECHNICAL ENVIRONMENT You don't need all of these on day one-but you should be fluent in the landscape and know how to choose and operate the right tools at the right depth.
-
SoC stack: SIEM, SOAR (automation/playbooks), EDR/XDR/NDR, threat intel platforms, sandboxing, case management
-
Controls operations: Vulnerability scanning/management configuration baseline & hardening, DLP email security, web proxy, endpoint protection, PAM/IAM, secrets management.
-
Cloud & data: logging, monitoring, and security services, CSPM, SSPM, container security, data security posture management.
-
Engineering integration: CI/CD hooks for security tests, detection as code, infrastructure as code baselines, policy as code, ticketing & workflow.
-
Risk & assurance: KRIs/KPIs dashboards, control coverage and effectiveness reporting, continuous control monitoring; support for audits/assessments. Our Maison's DNA is defined by five core values. Excellence drives us to be the best at what we do, while Innovation fuels our progress. Respect underpins every interaction, and Integrity shapes our actions. Together, we are One Team, united in serving our clients with unwavering dedication. As a responsible and supportive employer, we promote a diverse and inclusive work environment for our employees and candidates. Diversity, Equity and Inclusion are woven into the fabric of our Maison's DNA, and we strive to ensure that our employees can fulfill both their personal and professional aspirations by encouraging internal mobility and individual upskilling programs. We firmly believe that building Diverse Teams contributes to our successes and to deliver on this, we actively embed Diversity, Equity and Inclusion in our business strategy. It is an exciting time to join our Teams. All applications will be handled in the strictest confidence.
Requirements
-
10+ years in cybersecurity with direct leadership of SoC and Incident Response functions, including people leadership (hiring, coaching, performance).
-
Demonstrated success running security operations in complex environments (on premise and cloud)
-
Strong systems thinking; you connect detections, controls, processes, and behaviors into a coherent operating model with measurable outcomes (KRIs/KPIs and OKRs).
-
Evidence of automation mindset (e.g., SOAR playbooks, detection as code, continuous control monitoring).
-
Excellent communicator and partner to architecture, engineering, and infrastructure team.
-
Calm and accountable during incidents.
-
Resident in Switzerland or willingness to relocate Nice to haves:
-
Experience in a regulated industry (e.g., banking/financial services) and familiarity with audit/alignment frameworks (e.g., ISO 27001, NIST CSF, ISAE, data protection requirements).
-
Track record introducing AI/ML or analytics to SoC workflows (e.g., assisted triage, enrichment, detection engineering).
-
Customer facing or regulator engagement experience and security advocacy.