Contribute to a safer Sweden!
Do you want to work with cybersecurity and not just monitor alarms, but understand how attackers operate, develop new detections, and strengthen the protection of critical infrastructure?
At the Swedish Transport Administration (Trafikverket), you'll step into the heart of Sweden's digital infrastructure. You'll work in a nationwide and complex IT environment with an advanced threat landscape and high pace as part of Sweden's total defense.
Responsibilities
This is a role for you if you want to be at the forefront of cybersecurity and help develop the next generation's ability to detect and stop sophisticated attacks. We're now seeking cybersecurity analysts specializing in Detection Engineering.
Trafikverket's Cybersecurity Defense CERT - As part of Trafikverket's CERT, you work closely with operations, technology, and the threats directed at Sweden's critical infrastructure. Our mission is to strengthen the organization's ability to detect, analyze, and manage advanced cyber threats. In your role as Detection Engineer, you develop and improve our ability to identify and detect cyberattacks. You translate knowledge of attackers' methods and behaviors into effective detections, automations, and analytical capabilities.
You will work with:
Developing and improving detection rules and use cases
Identifying gaps in existing detection capabilities
Analyzing incidents and translating experience into improved detections
Working with SIEM, EDR, and XDR platforms
Collaborating closely with SOC, Incident Response, Threat Hunting, and other cybersecurity functions
Contributing to the development of automated security capabilities
We also welcome you if you currently work in related areas and want to take the next step toward Detection Engineering. This could be, for example, in Penetration Testing, Threat Hunting, Incident Response, Digital Forensics, SOC Analysis, or Purple Team activities. The most important thing is that you have a genuine interest in how attackers operate and how their activities can be detected and stopped.
What we offer you
Relevant onboarding and continuous professional development
Opportunity to work with critical infrastructure systems and real threats
Flexibility in your daily work with the possibility of remote work up to two days per week
Work hours primarily during daytime
On-call duty may occur
Colleagues with high expertise and great commitment to cybersecurity
A modern workplace where we meet each other with respect, trust, and care
We are proud to have been named one of Sweden's best employers.
Qualifications
To succeed in this role, you have strong analytical skills and easily see connections, you are curious and have a desire to stay updated and continuously take in knowledge about new attacks, threats, and tools. Since this position involves extensive dialogue and collaboration with multiple parties within and outside Trafikverket, you need to be confident and unpretentious in your collaboration and clear and trustworthy in your communication. You are structured in your approach, good at documenting and sharing your experience with colleagues. You have a proactive holistic perspective and a take-initiative attitude where you contribute to developing and improving operations.
As a person, you are a team player who understands the importance of participation and drives development together with your group and in collaboration with others.
We are looking for you who have
University/college education or other post-secondary education in IT, or other education combined with experience that we consider equivalent
Several years of relevant experience in one or more areas such as incident handling, security monitoring, detections, or analytical work
Several years of current and relevant experience in cybersecurity, IT security, or related areas
Good knowledge of Swedish and English (spoken and written)
Driver's license or currently working on obtaining a category B license
It is meriting if you have
Relevant experience in developing and adapting detection rules
Relevant experience in cybersecurity areas such as in a CSIRT, CERT, or SOC operation
Relevant experience with automation and/or SOAR solutions
Current experience with SIEM platforms
Experience with MITRE ATT&CK and attackers' tactics, techniques, and procedures (TTPs)
Good knowledge of security mechanisms in Windows and/or Linux operating systems
Current experience in Scripting/programming such as PowerShell, bash, Python, or similar
Relevant experience in IDS/IPS, such as Zeek, Suricata, or Snort or similar
Relevant experience with EDR/XDR solutions
Relevant experience in Threat Hunting
Other Information
The position is placed in security classification. Employment requires a passed security vetting as conducted in accordance with the Security Protection Act (2018:585).
Work location is Borlänge, Stockholm, or Örebro. Do you want a flexible daily routine with the possibility of working from home? In this role, you can work remotely up to two days per week. #LI-Hybrid
Web-based tests will be used as part of the selection process in this recruitment.
Application
The questions you answer when submitting your application will form the basis for our first selection. Unless otherwise stated in the ad, we want you to attach your CV. We have stopped requesting cover letters as we do not include them in our selection materials. If you have protected personal data, you should contact the responsible manager for the recruitment so that your application is handled according to special procedures. You will find the manager's name and contact information in the ad.Contribute to a safer Sweden!
Do you want to work with cybersecurity and not just monitor alarms, but understand how attackers operate, develop new detections, and strengthen the protection of critical infrastructure?
At the Swedish Transport Administration (Trafikverket), you'll step into the heart of Sweden's digital infrastructure. You'll work in a nationwide and complex IT environment with an advanced threat landscape and high pace as part of Sweden's total defense.
Responsibilities
This is a role for you if you want to be at the forefront of cybersecurity and help develop the next…