IT Security EngineersciCORE is the center of competence for scientific computing at the University of Basel, the oldest university in Switzerland and consistently ranked among the best universities in the world. The University is highly research-oriented, with particular strengths in life sciences and medicine, as well as growing strategic focus areas in data science and artificial intelligence. sciCORE provides advanced infrastructure and expert services for data- and compute-intensive research, including high-performance computing, scientific data processing and storage, secure research data environments, consulting, and training. Our work supports a community of over 2000 researchers across disciplines and connects large-scale technical infrastructure with sensitive data environments, national and international research initiatives, and close collaboration with university and external partners.To strengthen the security of our research computing environments, we invite applications for an IT Security Engineer, 80–100%. The position is embedded within sciCORE and works closely with the Systems Team, the Head of sciCORE, university security bodies, and external partners such as the Swiss Personalized Health Network (SPHN/BioMedIT), and the Swiss Institute of Bioinformatics (SIB).At sciCORE, you will be part of a highly motivated and collaborative team of specialists, including systems administrators, scientific software engineers, data infrastructure managers, data analysts, and research-support professionals. You will contribute to enabling cutting-edge research by helping ensure that our infrastructure, services, and workflows are secure, reliable, auditable, and aligned with data protection and compliance requirements.Your positionAct as the primary security subject matter expert for sciCORE infrastructures and research-support servicesContribute proactively to the secure architecture and operation of sciCORE services, including security-related tools, HPC systems, web applications, trusted research environments (sciCORE+), networking and related tools, identity and access management, shared filesystems, data-transfer services, and scientific software environmentsPerform risk assessments and security reviews for new services, research projects, infrastructure changes, and external collaborationsTranslate security requirements into practical, researcher-friendly solutions that preserve scientific usability while managing institutional and technical riskAlign technical security measures with data classification, data protection requirements, institutional policies, and relevant security frameworksIdentify and address security gaps in sciCORE systems by monitoring current threats, reviewing vulnerabilities and configurations, and validating the effectiveness of security controlsConduct and review vulnerability scans, hardening assessments, configuration checks, access-control reviews, and other security-control validationsMaintain and improve security practices, policies, procedures, technical documentation, and audit evidence for sciCORE environmentsSupport secure identity and access management practices, including user and project access lifecycles, SSH key and MFA policies, privileged access, service-account governance, and periodic access reviewsCollaborate closely with the Systems Team, the Head of sciCORE, university security bodies, researchers, and external partners on security-related projects and operational security topicsAdvise researchers and internal service teams on secure implementation of scientific workflows, especially where sensitive data, external collaborations, automated data transfers, cloud services, or AI/ML tools are involvedParticipate in regional, national, and international research IT security communities, including working groups, conferences, and workshopsYour profileMaster's degree in computer science, cybersecurity, information systems, computational science, or equivalent professional experienceAt least three years of experience in IT security, systems security, or secure infrastructure operations in Linux-based environments, preferably in research computing, HPC, cloud, large-scale storage, or web-application environmentsStrong practical experience with core IT security processes, including risk assessment, vulnerability management, system hardening, logging, monitoring, auditing, control validation, penetration testing and evidence collection, and technical documentationFamiliarity with networking technologies and architectures (VLANs, DMZ, firewall management) and virtual environmentsExperience with identity and access management in complex environments, including SSH, MFA, service accounts, privileged access, group- or project-based access controls, and access reviewsFamiliarity with implementation of security frameworks and compliance-oriented security controls, such as the NIST Cybersecurity Framework, CIS Controls, and ISO 27001, considering data classification and data protection regulations, and audit requirementsExperience with automation and reproducible infrastructure practices, including infrastructure as code, version control, configuration management, shell scripting, and PythonAbility to write clear technical documentation, reports, and audit-oriented evidence for technical and non-technical audiencesStrong communication and coordination skills, with the ability to work effectively with technical peers, researchers, management, institutional security teams, SOCs, and external partnersHigh level of integrity, reliability, discretion, and accountabilityAdditional desirable qualificationsPractical understanding of HPC or research computing environments, including multi-user systems, batch schedulers, shared file systems, scientific workflows, data-transfer services, and their specific security challengesFamiliarity with software supply-chain security, including package managers, software container images, dependency risks, code provenance, vulnerability scanning, and reproducible deployment practicesUnderstanding of backup, recovery, and ransomware-resilience concepts in large-scale Linux and storage environmentsAbility to understand and adapt code, queries, or configuration in other languages commonly encountered in research computing environmentsKnowledge of the rapidly evolving AI/LLM landscapeWorking knowledge of Windows and macOSWe offer youAn essential role securing research infrastructure at the University of BaselThe opportunity to work at the interface of high-performance computing, sensitive research data, cybersecurity, and scientific innovationA collaborative and interdisciplinary working environment with highly qualified technical and scientific colleaguesThe opportunity to shape security practices for a complex academic research computing environmentClose collaboration with university security bodies, national research infrastructure initiatives, and external security communitiesSupport for your professional development through training, continuing education, and participation in relevant conferences, workshops, and professional networksThe University of Basel is an equal opportunity and family-friendly employer committed to excellence through diversity.
Inserat ansehen