Winterthur
IT Security Analyst, Risk & Compliance 80-100 % (hybrid, fixed-term)
- 09 September 2026
- 80 – 100%
- Temporary
- German (Intermediate)
- Winterthur
About the job
Whether cloud service, AI solution or new specialist application - you assess IT resources and IT service providers from the perspective of information security, accompany and shape the due diligence process, and support ZHAW in ensuring that digitalisation and innovation at ZHAW are implemented securely and responsibly.IT Security Analyst, Risk & Compliance 80-100 % (hybrid, fixed-term)
Department:
Finance & Services
Start of employment:
From 1.1.2027 fixed-term until 31.8.2027
Tasks
- Conducting due diligence checks of new IT resources and IT service providers regarding information security and compliance
- Reviewing security certificates, certifications and audit reports (e.g. ISO 27001, SOC 2, ISAE 3402) in the context of procurement and contract conclusions
- Contributing to the definition and further development of security requirements for IT resources and external service providers
- Conducting and accompanying security audits as well as following up on the implementation of agreed measures
- Training and raising awareness of internal staff on information security
- Advising technically and non-technically skilled staff across the university
- Identifying areas for action to continuously improve information security
- Close collaboration with the agile ICT team, other security functions and the data protection officer of ZHAW.
Profile
- Practical experience in the field of information security, IT risk management, governance, risk & compliance (GRC), IT audit or a comparable function
- Education and further training in the field of information security
- Good knowledge in the areas of client, server operating systems, network and cloud technologies, generative AI and agentic AI
- Proven very good knowledge of information security, data protection and IT general controls as well as the ability to assess risks understandably and derive pragmatic measures
- Analytical, structured and solution-oriented working style with a quick grasp and a strong awareness of quality
- Great interest in current trends and developments in the areas of cyber security as well as new attack techniques and protective measures
- Knowledge of relevant standards and frameworks, such as ISAE 3402 Type 2 or SOC 1 Type 2 and ISO 27001
- Very good communication skills to clearly present complex technical issues and convey them in a target group- and subject-specific manner
- Team-oriented personality with an independent, reliable and service-oriented working style
- Very good German skills as well as good English skills in spoken and written form
What we stand for
ZHAW Zurich University of Applied Sciences is one of the largest multi-disciplinary universities of applied sciences in Switzerland with over 14,000 students and over 11,000 continuing education participants as well as around 3,700 employees.
The ICT Security team in the Finance & Services staff is responsible for university-wide cyber risk management, digital compliance, ICT emergency and cyber incident management, vendor risk management, the internal ICT control system as well as security awareness and thus makes a central contribution to the secure and compliant digital operation of the university.
ZHAW is committed to gender-mixed and diverse teams to promote equality, diversity and innovation.
What we offer
We offer university-appropriate working and employment conditions and actively promote the personnel development of our employees and managers. A detailed description of the benefits can be found on the page Working at ZHAW . Here are the main points:
Contact
Marc McGuinness
Chief Information Security Officer
Jocelyn Schaad
Recruiting Manager