Job Bromma, Sweden

Incident Handler for Sweden's National CSIRT

Learn this skill
Employer
FÖRSVARETS RADIOANSTALT
Employment type
Full-time
Experience required
Yes

1 position(s). Do you want to contribute to society and strengthen Sweden's collective ability to handle cyber threats? The National Cybersecurity Center, NCSC, is now seeking an incident handler to participate in building up the center's operations at FRA. If you are the person we are looking for, we can offer varied work in a knowledge-intensive environment where you can make a difference every day. Your Assignment As an incident handler, you work at NCSC and the office for operational and technical cybersecurity. The office is responsible for operational cybersecurity in support of society by preventing, detecting, and supporting coordination and management of IT incidents. The office's mission includes developing comprehensive situational pictures of adversarial cyber threats and IT incidents, providing technical advice and support to private and public actors, and maintaining a national situational awareness. In the role of incident handler, you work operatively with identifying, analyzing, and managing cybersecurity incidents. You are part of the CSIRT's operational team and contribute to the development of methods, processes, and collaboration, both nationally and internationally. Your main work tasks consist primarily of: · Managing and coordinating cybersecurity incidents · Conducting technical analysis (log analysis, forensics, malware) · Conducting threat hunting and analysis of threat indicators · Contributing to vulnerability management and risk assessment · Developing processes and methods within CSIRT operations · Collaborating with national and international partners In addition to operational work, you will collaborate with various functions within the agency and contribute to our operational development. You Can We are looking for someone who has: · Technical education at university level or equivalent knowledge acquired through work experience · Several years of experience in incident handling within CSIRT/CERT, SOC, or equivalent function · Experience managing cyber incidents · Strong technical competence in networks, operating systems, and log analysis · Experience in forensics, malware analysis, or threat hunting · Good understanding of attacker behavior · Experience in vulnerability management including CVD processes · Good knowledge of Swedish and English We consider it an advantage if you have: · Experience with international collaboration within CSIRT networks · Experience in leading roles in incident handling · Experience with cloud security or industrial systems · Certifications in cybersecurity, e.g., GIAC, CISSP, SANS 504/508 · Experience in threat intelligence · Driver's license category B You Are We are looking for someone with the following qualities: · Stable – You are calm, stable, and controlled in stressful or pressured situations. You maintain a realistic perspective on situations and focus on the right things. · Structured – You plan, organize, and prioritize work efficiently. You set and maintain timelines. · Expert Knowledge – You understand the professional aspects of the work particularly well. You continuously maintain your expert knowledge. You are a knowledge resource for others. · Problem-Solving Analytical Ability – You work well with complex issues. You analyze and break down problems into their components and solve complicated problems. About NCSC and FRA NCSC is the hub for Sweden's cybersecurity and coordinates the management of serious cyberattacks affecting society. Through support and advice, we help organizations strengthen their resilience against threats in the digital environment. We collaborate with business, the public sector, civil society, organizations, and academia. By sharing current and relevant knowledge, we contribute to raising cybersecurity throughout society. Our mission is to strengthen Sweden's ability to prevent, detect, and manage cyber threats, and as part of FRA, we contribute to a more resilient Sweden. NCSC is currently in an expansive development phase where you have the opportunity to help build a central point of contact for Sweden's cybersecurity. As a new employee at FRA, you will receive comprehensive introductory training and continuous professional development, which gives you the opportunity to develop your skills and become even better at what you are passionate about. Our organization is multifaceted and consists of different competencies and personalities, where each individual has unique characteristics and conditions. We strive to create an environment where everyone feels welcome and safe. In addition to a stimulating work environment, we also offer an attractive benefits package, which you can read more about at www.fra.se (http://www.fra.se/). If you want to know more about the National Cybersecurity Center, you can visit www.ncsc.se (http://www.ncsc.se/) For Your Security. For Our Democracy. Every Day. Year-Round. More Information The workplace is currently located in Tomteboda, Solna. Within a few years, new premises will be ready in Bergshamra. Swedish citizenship is required as employment at FRA involves placement in a security class. A requirement for employment is approved security clearance with record check. The security clearance will be conducted in accordance with the provisions of the Security Protection Act. Employment entails an obligation to be assigned for wartime placement. We use a six-month probationary period. For more information, please contact recruiting manager Jonas Sjölander at phone 010-382 80 43. Union representatives can be reached at 010-557 46 00. We accept applications via www.fra.se no later than 2026-09-06. Reference number 2025FRA1341-3. As we have already decided on the recruitment channels we wish to use for this recruitment, we decline further offers of advertising and recruitment assistance. Keywords: incident handler, incident manager, IT security specialist, CSIM Employment Type: Permanent employment. Duration: Permanent. Working Hours: Daytime.

Profession
IT-säkerhetsanalytiker
Salary type
Fixed monthly, weekly or hourly pay
Open positions
1
Contact person
Jonas Sjölander
Employer Workplace
FRA, NCSC
Region
Stockholms län
Occupation Field
Data/IT
Postcode
16126
Duration
Ongoing
Scope Of Work
100–100 %
Working Hours
Full-time
Driving License
Yes
Employment Type Label
Permanent
City
Bromma
Address
Box 301
GPS
59.3540027, 17.9550408
Published
17. 8. 2026
Loading map…

Ask AI

Common questions about this listing — opens your AI with a ready-made prompt including the listing link.

  • Is the salary in this job offer competitive for the role and location?
    Open in
  • What questions should I ask at the interview for this position?
    Open in
  • Which skills should I highlight in my application for this job?
    Open in
Call