{"data":{"id":157271,"slug":"incident-handler-till-sveriges-nationella-csirt","type":"job","title":"Incident Handler for Sweden's National CSIRT","description":"1 position(s). \r\n\r\nDo you want to contribute to society and strengthen Sweden's collective ability to handle cyber threats? The National Cybersecurity Center, NCSC, is now seeking an incident handler to participate in building up the center's operations at FRA. If you are the person we are looking for, we can offer varied work in a knowledge-intensive environment where you can make a difference every day.\nYour Assignment\nAs an incident handler, you work at NCSC and the office for operational and technical cybersecurity. The office is responsible for operational cybersecurity in support of society by preventing, detecting, and supporting coordination and management of IT incidents. The office's mission includes developing comprehensive situational pictures of adversarial cyber threats and IT incidents, providing technical advice and support to private and public actors, and maintaining a national situational awareness.\nIn the role of incident handler, you work operatively with identifying, analyzing, and managing cybersecurity incidents. You are part of the CSIRT's operational team and contribute to the development of methods, processes, and collaboration, both nationally and internationally. \r\n\nYour main work tasks consist primarily of:\n\u00b7 Managing and coordinating cybersecurity incidents\n\u00b7 Conducting technical analysis (log analysis, forensics, malware)\n\u00b7 Conducting threat hunting and analysis of threat indicators\n\u00b7 Contributing to vulnerability management and risk assessment\n\u00b7 Developing processes and methods within CSIRT operations\n\u00b7 Collaborating with national and international partners\nIn addition to operational work, you will collaborate with various functions within the agency and contribute to our operational development.\nYou Can\nWe are looking for someone who has:\n\u00b7 Technical education at university level or equivalent knowledge acquired through work experience\n\u00b7 Several years of experience in incident handling within CSIRT\/CERT, SOC, or equivalent function\n\u00b7 Experience managing cyber incidents\n\u00b7 Strong technical competence in networks, operating systems, and log analysis\n\u00b7 Experience in forensics, malware analysis, or threat hunting\n\u00b7 Good understanding of attacker behavior\n\u00b7 Experience in vulnerability management including CVD processes\n\u00b7 Good knowledge of Swedish and English\nWe consider it an advantage if you have:\n\u00b7 Experience with international collaboration within CSIRT networks\n\u00b7 Experience in leading roles in incident handling\n\u00b7 Experience with cloud security or industrial systems\n\u00b7 Certifications in cybersecurity, e.g., GIAC, CISSP, SANS 504\/508\n\u00b7 Experience in threat intelligence\n\u00b7 Driver's license category B\nYou Are\nWe are looking for someone with the following qualities:\n\u00b7 Stable \u2013 You are calm, stable, and controlled in stressful or pressured situations. You maintain a realistic perspective on situations and focus on the right things.\n\u00b7 Structured \u2013 You plan, organize, and prioritize work efficiently. You set and maintain timelines.\n\u00b7 Expert Knowledge \u2013 You understand the professional aspects of the work particularly well. You continuously maintain your expert knowledge. You are a knowledge resource for others.\n\u00b7 Problem-Solving Analytical Ability \u2013 You work well with complex issues. You analyze and break down problems into their components and solve complicated problems.\nAbout NCSC and FRA\nNCSC is the hub for Sweden's cybersecurity and coordinates the management of serious cyberattacks affecting society. Through support and advice, we help organizations strengthen their resilience against threats in the digital environment. We collaborate with business, the public sector, civil society, organizations, and academia. By sharing current and relevant knowledge, we contribute to raising cybersecurity throughout society. Our mission is to strengthen Sweden's ability to prevent, detect, and manage cyber threats, and as part of FRA, we contribute to a more resilient Sweden. NCSC is currently in an expansive development phase where you have the opportunity to help build a central point of contact for Sweden's cybersecurity.\nAs a new employee at FRA, you will receive comprehensive introductory training and continuous professional development, which gives you the opportunity to develop your skills and become even better at what you are passionate about. Our organization is multifaceted and consists of different competencies and personalities, where each individual has unique characteristics and conditions. We strive to create an environment where everyone feels welcome and safe. In addition to a stimulating work environment, we also offer an attractive benefits package, which you can read more about at www.fra.se (http:\/\/www.fra.se\/). If you want to know more about the National Cybersecurity Center, you can visit www.ncsc.se (http:\/\/www.ncsc.se\/)\nFor Your Security. For Our Democracy. Every Day. Year-Round.\nMore Information\nThe workplace is currently located in Tomteboda, Solna. Within a few years, new premises will be ready in Bergshamra. Swedish citizenship is required as employment at FRA involves placement in a security class. A requirement for employment is approved security clearance with record check. The security clearance will be conducted in accordance with the provisions of the Security Protection Act. Employment entails an obligation to be assigned for wartime placement. We use a six-month probationary period. For more information, please contact recruiting manager Jonas Sj\u00f6lander at phone 010-382 80 43. Union representatives can be reached at 010-557 46 00.\nWe accept applications via www.fra.se no later than 2026-09-06. \nReference number 2025FRA1341-3.\nAs we have already decided on the recruitment channels we wish to use for this recruitment, we decline further offers of advertising and recruitment assistance.\nKeywords: incident handler, incident manager, IT security specialist, CSIM\nEmployment Type: Permanent employment.\nDuration: Permanent.\nWorking Hours: Daytime.","language":"sv","is_translated":true,"title_original":"Incident handler till Sveriges Nationella CSIRT ","description_original":"1 plats(er). \r\n\r\n\nVill du g\u00f6ra samh\u00e4llsnytta och st\u00e4rka Sveriges samlade f\u00f6rm\u00e5ga att hantera cyberhot? Nationellt cybers\u00e4kerhetscenter, NCSC, s\u00f6ker nu en incident handler med uppgift att delta i arbetet med att bygga upp centrets verksamhet vid FRA. \u00c4r du den vi s\u00f6ker kan vi erbjuda ett varierande arbete i en kunskapsintensiv milj\u00f6 d\u00e4r du f\u00e5r vara med och g\u00f6ra skillnad varje dag.\nDitt uppdrag\nSom incident handler arbetar du vid NCSC och kontoret f\u00f6r operativ och teknisk cybers\u00e4kerhet. Kontoret ansvarar f\u00f6r operativ cybers\u00e4kerhet till st\u00f6d f\u00f6r samh\u00e4llet genom att f\u00f6rebygga, uppt\u00e4cka och st\u00f6dja koordinering och hantering av it-incidenter. Kontorets uppdrag omfattar att ta fram samlade l\u00e4gesbilder av antagonistiska cyberhot och it-incidenter, l\u00e4mna tekniska r\u00e5d och st\u00f6d till privata och offentliga akt\u00f6rer samt uppr\u00e4tth\u00e5lla en nationell l\u00e4gesuppfattning.\nI rollen som incident handler arbetar du operativt med att identifiera, analysera och hantera cybers\u00e4kerhetsincidenter. Du ing\u00e5r i CSIRT`s operativa team och bidrar till utveckling av metoder, processer och samverkan, b\u00e5de nationellt och internationellt. \r\n\r\nDina huvudsakliga arbetsuppgifter best\u00e5r fr\u00e4mst av att:\n\u00b7 Hantera och koordinera cybers\u00e4kerhetsincidenter\n\u00b7 Genomf\u00f6ra teknisk analys (logganalys, forensik, malware)\n\u00b7 Bedriva threat hunting och analys av hotindikatorer\n\u00b7 Bidra till s\u00e5rbarhetshantering och riskbed\u00f6mning\n\u00b7 Utveckla processer och metoder inom CSIRT-verksamheten\n\u00b7 Samverka med nationella och internationella partners\nUt\u00f6ver det operativa arbetet kommer du att samverka med olika funktioner inom myndigheten och bidra till v\u00e5r verksamhetsutveckling.\nDu kan\nVi s\u00f6ker dig som har:\n\u00b7 Teknisk utbildning p\u00e5 universitetsniv\u00e5 eller motsvarande kunskap f\u00f6rv\u00e4rvad genom arbetslivserfarenhet\n\u00b7 Fler\u00e5rig erfarenhet av incidenthantering inom CSIRT\/CERT, SOC eller motsvarande funktion\n\u00b7 Erfarenhet av att hantera cyberincidenter\n\u00b7 Stark teknisk kompetens inom n\u00e4tverk, operativsystem och logganalys\n\u00b7 Erfarenhet av forensik, malwareanalys eller threat hunting\n\u00b7 God f\u00f6rst\u00e5else f\u00f6r angripsbeteenden\n\u00b7 Erfarenhet av s\u00e5rbarhetshantering inklusive CVD processer\n\u00b7 Goda kunskaper i svenska och engelska\nVi ser det som meriterande om du har:\n\u00b7 Erfarenhet av internationell samverkan inom CSIRT-n\u00e4tverk\n\u00b7 Erfarenhet av ledande roller i incidenthantering\n\u00b7 Erfarenhet av molns\u00e4kerhet eller industriella system\n\u00b7 Certifieringar inom cybers\u00e4kerhet t.ex. GIAC, CISSP, SANS 504\/508\n\u00b7 Erfarenhet av threat intelligence\n\u00b7 B-k\u00f6rkort\nDu \u00e4r\nVi s\u00f6ker dig med f\u00f6ljande egenskaper:\n\u00b7 Stabil \u2013 \u00c4r lugn, stabil och kontrollerad i stressituationer eller pressade situationer. Beh\u00e5ller ett realistiskt perspektiv p\u00e5 situationer och fokuserar p\u00e5 r\u00e4tt saker.\n\u00b7 Strukturerad \u2013 Planerar, organiserar och prioriterar arbetet p\u00e5 ett effektivt s\u00e4tt. S\u00e4tter upp och h\u00e5ller tidsramar.\n\u00b7 Specialistkunskap \u2013 F\u00f6rst\u00e5r de fackm\u00e4ssiga aspekterna av arbetet s\u00e4rskilt bra. Underh\u00e5ller kontinuerligt sin specialistkunskap. \u00c4r en kunskapsresurs f\u00f6r andra.\n\u00b7 Probleml\u00f6sande analysf\u00f6rm\u00e5ga \u2013 Arbetar bra med komplexa fr\u00e5gor. Analyserar och bryter ner problem i sina best\u00e5ndsdelar och l\u00f6ser komplicerade problem.\nOm NCSC och FRA\nNCSC \u00e4r navet f\u00f6r Sveriges cybers\u00e4kerhet och samordnar hanteringen av allvarliga cyberangrepp som p\u00e5verkar samh\u00e4llet. Genom st\u00f6d och r\u00e5dgivning hj\u00e4lper vi organisationer att st\u00e4rka sin motst\u00e5ndskraft mot hot i den digitala milj\u00f6n. Vi samverkar med n\u00e4ringslivet, offentlig sektor, civilsamh\u00e4llet, organisationer och akademin. Genom att dela aktuell och relevant kunskap bidrar vi till att h\u00f6ja cybers\u00e4kerheten i hela samh\u00e4llet. V\u00e5rt uppdrag \u00e4r att st\u00e4rka Sveriges f\u00f6rm\u00e5ga att f\u00f6rebygga, uppt\u00e4cka och hantera cyberhot, och som en del av FRA bidrar vi till ett mer motst\u00e5ndskraftigt Sverige. Just nu \u00e4r NCSC i en expansiv utvecklingsfas d\u00e4r du f\u00e5r m\u00f6jlighet att vara med och bygga upp en central kontaktpunkt f\u00f6r Sveriges cybers\u00e4kerhet.\nSom nyanst\u00e4lld p\u00e5 FRA f\u00e5r du en omfattande introduktionsutbildning och kontinuerlig kompetensutveckling, vilket ger dig m\u00f6jlighet att utveckla dina f\u00e4rdigheter och bli \u00e4nnu b\u00e4ttre p\u00e5 det du brinner f\u00f6r. V\u00e5r organisation \u00e4r m\u00e5ngfacetterad och best\u00e5r av olika kompetenser och personligheter, d\u00e4r varje individ har unika egenskaper och f\u00f6ruts\u00e4ttningar. Vi str\u00e4var efter att skapa en milj\u00f6 d\u00e4r alla k\u00e4nner sig v\u00e4lkomna och trygga. Ut\u00f6ver en stimulerande arbetsmilj\u00f6 erbjuder vi ocks\u00e5 ett attraktivt f\u00f6rm\u00e5nspaket, som du kan l\u00e4sa mer om p\u00e5 www.fra.se  (http:\/\/www.fra.se\/). Vill du veta mer om Nationellt cybers\u00e4kerhetscenter kan du bes\u00f6ka www.ncsc.se (http:\/\/www.ncsc.se\/)\nF\u00f6r din trygghet. F\u00f6r v\u00e5r demokrati. Varje dag. \u00c5ret om.\nMer information\nArbetsplatsen ligger f\u00f6r n\u00e4rvarande i Tomteboda, Solna. Inom n\u00e5gra \u00e5r ska nya lokaler st\u00e5 klara i Bergshamra. Svenskt medborgarskap \u00e4r ett krav d\u00e5 anst\u00e4llning vid FRA inneb\u00e4r placering i s\u00e4kerhetsklass. Ett krav f\u00f6r att f\u00e5 anst\u00e4llning \u00e4r godk\u00e4nd s\u00e4kerhetspr\u00f6vning med registerkontroll. S\u00e4kerhetspr\u00f6vningen kommer att genomf\u00f6ras i enlighet med best\u00e4mmelser i s\u00e4kerhetsskyddslagen. Med anst\u00e4llning f\u00f6ljer en skyldighet att krigsplaceras. Vi till\u00e4mpar sex m\u00e5naders provanst\u00e4llning. F\u00f6r mer information \u00e4r du v\u00e4lkommen att kontakta rekryterande chef Jonas Sj\u00f6lander p\u00e5 telefon 010-382 80 43. Fackliga f\u00f6retr\u00e4dare n\u00e5s p\u00e5 010-557 46 00.\nVi tar emot ans\u00f6kningar via www.fra.se senast 2026-09-06. \r\nReferensnummer 2025FRA1341-3.\nD\u00e5 vi inf\u00f6r denna rekrytering redan tagit st\u00e4llning till de rekryteringskanaler vi \u00f6nskar anv\u00e4nda undanber vi oss att bli kontaktade f\u00f6r ytterligare erbjudanden om annonserings- och rekryteringshj\u00e4lp.\nS\u00f6kord: incidenthanterare, incidentledare, IT-s\u00e4kerhetsspecialist, CSIM\nAnst\u00e4llningsform: Tillsvidareanst\u00e4llning.\r\nVaraktighet: Tillsvidare.\r\nArbetstid: Dagtid.","price":null,"currency":"SEK","status":"active","noindex":true,"location":{"address":"Box 301","full_address":null,"city":"Bromma","country":"SE","latitude":59.3540027,"longitude":17.9550408},"metadata":{"region":"Stockholms l\u00e4n","duration":"Tills vidare","employer":"F\u00d6RSVARETS RADIOANSTALT","postcode":"16126","positions":1,"profession":"IT-s\u00e4kerhetsanalytiker","salary_type":"Fast m\u00e5nads- vecko- eller timl\u00f6n","scope_of_work":"100\u2013100 %","working_hours":"Heltid","contact_person":"Jonas   Sj\u00f6lander","driving_license":true,"employment_type":"full_time","occupation_field":"Data\/IT","employer_workplace":"FRA, NCSC","experience_required":true,"employment_type_label":"Vanlig anst\u00e4llning"},"user_id":null,"is_sponsored":false,"views_count":5,"ai_views_count":2,"ai_vendor_counts":{"other":1,"anthropic":1},"visibility":"public","submission_source":null,"submission_ai_name":null,"has_owner_email":true,"can_contact_owner":true,"phone":"+46103828043","owner_email":"rekrytering@fra.se","images":[],"published_at":"2026-08-17T01:35:58+00:00","expires_at":"2026-09-06T23:59:59+00:00","created_at":"2026-08-17T03:14:33+00:00","updated_at":"2026-08-24T03:05:44+00:00"}}