Zürich
Digital Forensics & Incident Response Specialist
- 27 August 2026
- 100%
- Permanent position
- German (Fluent), English (Intermediate)
About the job
What to Expect
As a Digital Forensics & Incident Response Specialist, you will support organisations of various sizes, industries, and security maturity levels alongside experienced team colleagues during their most challenging moments in a cyber incident (Incident Response). You will conduct in-depth investigations on systems or networks (Digital Forensics) and help clients prepare for such situations (Digital Forensics & Incident Response Consulting).
During the first three to six months of your employment, you will undergo an introductory and training programme. The content and duration will depend on your level of knowledge. During the training phase, you will already be involved in client projects.
After the introductory phase, you will carry out the following activities alone or as part of a team:
- Incident Response & Client Support: You are the cyber fire brigade for our clients. In the event of a cyber incident, you accompany and support them in close communication – on-site or remotely.
- Digital Forensics & Analysis: You conduct technical analyses, professionally secure evidence, investigate various IT systems, and analyse malware.
- Crisis Preparedness: In quieter periods, you prepare clients for cyber incidents, conduct tabletop and crisis management exercises, and support them in further developing their SOC and CSIRT capabilities.
- Reporting: You always document your findings precisely, with high quality, structured, and target group-oriented in written final reports in German or English.
- On-call Duty: You provide on-call service every 6–7 weeks (24/7).
The scope of duties and their focus will also be influenced by your education, professional experience, and interests.
What We Offer You
At Oneconsult, a structured induction programme and the team are very important to us. When facing challenges, you will always find someone who takes time for you and supports you. We also place great value on your personal development, which we support through coaching and various internal and external training opportunities.
You can also look forward to the following:
- A "du" culture where mutual respect, tolerance, and appreciation are lived, and feedback is an important part of our daily routine
- Modern and spacious offices, 2 minutes from Saalsporthalle and Sihlcity stations, with ergonomic workstations featuring sit/stand desks
- Possibility for home office
- Contribution to health-promoting measures up to 500 CHF
- Smartphone with flat-rate subscription
- Team events
- Internal and external training opportunities
- 40-hour week and at least 5 weeks of holiday
- Additional day off on your birthday
- …and much more
What You Bring
You love challenges and remain calm under pressure. You can also be a night owl and are willing and flexible to provide 7×24 on-call service and emergency deployments.
We look forward to meeting you personally if the following qualifications complete your profile:
- Completed basic training in the field of computer science
- Strong interest in cybersecurity and the ability to quickly learn new topics
- You bring practical experience in the IT or security environment (e.g. CTFs, private lab, IT operations experience, and similar).
- Professional experience in SOC, DFIR, or CSIRT areas is a plus.
- Professional demeanour and high resilience in demanding and time-critical situations
- Fluent German and good English skills in spoken and written form; additional national languages are an advantage
- Impeccable reputation (proof by current criminal and debt register extract)
Application
Have we ignited the fire in you? We look forward to your call or your application documents directly. It is important to us that we can feel your passion for cybersecurity in your insightful application, so we leave it up to you how you want to convince us.
Please only direct applications: enquiries from recruiters / headhunters are not desired.