Swissquote

Cybersecurity SOAR Playbook Engine Developer

Gland, VD, CH
Python YAML Git Splunk QRadar CrowdStrike
Description

Cybersecurity SOAR Playbook Engine Developer – 6 Month Internship

Location: Gland, VD, ch

Company Description

Building the bank of tomorrow takes more than skills. 

It means combining our differences to imagine, discuss, code, develop, test, learn… and celebrate every step together. Share our vibes? Join Swissquote to unleash your potential.

We are the Swiss Leader in Online Banking and we provide trading, investing and banking services to +650’000 clients, through our performant and secured digital platforms.

Our +1200 employees work in a flexible way, without dress code and in multicultural teams. 

By having a huge impact on the industry, they are growing their skills portfolio and boosting their career in a fast-pace environment. Have a look behind the scenes by checking Humans of Swissquote on Instagram.

We are all in at Swissquote. As an equal opportunity employer, we welcome candidates from all backgrounds, experiences and perspectives to join our team and contribute to our shared success.

Are you all in? Don’t be shy, apply!

Job Description

Join our Security Operations Center (SOC) Team, a team of four engineers within the Cybersecurity Department. You will work in a dynamic environment, gaining key skills in security automation and incident response while becoming familiar with the banking and finance threat landscape.

Under the supervision of the Security Operation Manager, you will take part in the following projects:

  • Playbook Engine Development: Building and enhancing the core SOAR playbook execution engine using Python 3.9+. Implementing YAML parser, workflow executor, conditional logic evaluator, and decision tree engine.
  • Playbook Creation: Designing YAML-based SOAR playbooks for automated incident response. Creating workflows for phishing detection, malware analysis, ransomware response, threat intelligence enrichment, and IOC blocking.
  • Custom Utility Development: Developing Python utility functions and helpers to extend playbook capabilities. Building data transformation logic and security analysis functions. Execution Framework: Implementing error handling, logging, monitoring, performance optimization, parallel execution, and async operations.
  • Testing & Quality Assurance: Writing unit tests and creating regression test suites. Testing playbooks with realistic security scenarios and validating end-to-end automation flows. Implementing and enforcing coding standards through linting tools.
  • Collaboration: Working closely with the Integration Intern to understand available connectors and ensure playbooks effectively utilize all integrations.
     

Qualifications

  • Good proficiency in Python
  • Good knowledge of YAML syntax and workflow definition
  • Basic understanding of cybersecurity fundamentals and incident response
  • Interest in security operations and SOC processes
  • Familiarity with threat landscapes and security concepts
  • Basic experience writing tests or willingness to learn
  • Experience with version control (Git)


Nice-to-Have Skills

  • Experience with SOAR platforms (Splunk SOAR, Cortex XSOAR, etc.)
  • Familiarity with security tools (Splunk, QRadar, Chronicle, CrowdStrike)
  • Experience with linting tools
  • Knowledge of workflow engines or orchestration systems

Additional Information

Availability: from July 1st 2026

SQ2

Swissquote
Swissquote

0 applies

0 views

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 452 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
  • We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
  • We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
  • Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
  • Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
  • Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅

What Fellow Engineers Say