Trafikverket - Logo

Cybersecurity Analyst – Detection Engineer

Trafikverket

Stockholms län, Stockholm

Previous experience is desired

29 days left
to apply for the job

Contribute to a safer Sweden!

Do you want to work with cybersecurity, not just monitor alarms, but understand how attackers operate, develop new detections, and strengthen the protection of societal-critical systems?

At Trafikverket, you step into the heart of Sweden's digital infrastructure. You work in a nationwide and complex IT environment with an advanced threat landscape and high pace as part of Sweden's total defense.

Responsibilities

This is a role for you who wants to be at the forefront of cybersecurity and help develop the next generation's ability to detect and stop sophisticated attacks. We are now looking for cybersecurity analysts with a focus on Detection Engineering.

Trafikverket's Cyber Defense CERT - As part of Trafikverket's CERT, you work close to the operations, technology, and threats directed against Sweden's critical infrastructure. Our mission is to strengthen the organization's ability to detect, analyze, and handle advanced cyber threats. In the role of Detection Engineer, you develop and improve our ability to identify and detect cyberattacks. You translate knowledge of attackers' methods and behaviors into effective detections, automations, and analytical capabilities.

You will work with:

  • Developing and improving detection rules and use cases
  • Identifying gaps in existing detection capabilities
  • Analyzing incidents and translating experience into improved detections
  • Working with SIEM, EDR, and XDR platforms
  • Collaborating closely with SOC, Incident Response, Threat Hunting, and other cybersecurity functions
  • Contributing to the development of automated security capabilities

We also welcome you who currently work in adjacent fields and want to take the next step towards Detection Engineering. This could be, for example, within Penetration Testing, Threat Hunting, Incident Response, Digital Forensics, SOC Analysis, or Purple Teaming. The most important thing is that you have a genuine interest in how attackers operate and how their activities can be detected and stopped.

What we offer
  • A relevant introduction and continuous competence development
  • Opportunity to work with societal-critical systems and real threats
  • Flexibility in daily life with the possibility of remote work up to two days per week
  • Working hours mainly during daytime
  • On-call duty may occur
  • Colleagues with high competence and great commitment to cybersecurity
  • A modern workplace where we meet each other with respect, trust, and care

We are proud to have been named one of Sweden's best employers.

Qualifications

To succeed in the role, you have good analytical skills and an easy ability to see connections. You are curious and have a desire to stay updated and continuously acquire knowledge about new attacks, threats, and tools. Since the position involves a lot of dialogue and collaboration with several parties within and outside Trafikverket, you need to be confident and unpretentious in your collaboration, as well as clear and trustworthy in your communication. You are structured in your approach, good at documenting, and sharing your experience with your colleagues. You have a proactive holistic thinking and an initiative-taking attitude where you contribute to developing and improving operations.

As a person, you are a team player who understands the importance of participation and drives development together with your group and in collaboration with others.

We are looking for you who have

  • A university/college degree or other post-secondary education in IT, or alternatively other education combined with experience that we collectively assess as equivalent
  • Several years of relevant experience in one or more areas within incident management, security monitoring, detections, or analysis work
  • Several years of current and relevant experience within cybersecurity, IT security, or adjacent fields.
  • Good knowledge of Swedish and English (spoken and written)
  • Driver's license or currently obtaining a B-driver's license

It is meritorious if you have

  • Relevant experience in creating and adapting detection rules
  • Relevant experience within the cybersecurity field, such as in a CSIRT, CERT, or SOC operation
  • Relevant experience in automation and/or SOAR solutions
  • Current experience with SIEM platforms
  • Experience with MITRE ATT&CK and attackers' tactics, techniques, and procedures (TTPs)
  • Good knowledge of operating system security mechanisms in Windows and/or Linux
  • Current experience in scripting/programming such as PowerShell, bash, Python, or similar
  • Relevant experience within IDS/IPS, such as Zeek, Suricata, or Snort, or similar
  • Relevant experience within EDR/XDR solutions
  • Relevant experience with Threat Hunting
Other information

The position is security-classified. Employment requires a passed security clearance check, conducted in accordance with the provisions of the Security Protection Act (2018:585).

The location is Borlänge, Stockholm, or Örebro. Do you want a flexible daily life with the possibility of working from home? In this role, you can work remotely up to two days a week. #LI-Hybrid

In this recruitment, web-based tests are used as part of the selection process.

Application

The questions you will answer when submitting your application will form the basis for the first selection we make. If nothing else is stated in the advertisement, we want you to attach your CV. We have stopped requesting cover letters as we do not include them as part of the selection material. If you have protected personal data, you should contact the responsible manager for the recruitment so that your application is handled according to special routines. You will find the name and contact details of the manager in the advertisement.

🖐 Was this job fit for someone?
Share

Other jobs in the same field

Maybe it’s time to broaden the search with these available jobs

Keyword / Occupation
Similar jobs
Latest posts
  • Promocode - Discount code for Timarco SE
    Sat, 25 Jul 2026 - 00:00
  • Public Opinion - Novus Opinion Poll 2026-06-17 – Social Democrats Lose
    Wed, 17 Jun 2026 - 09:35
  • National Debt - National Debt – Level, GDP Share, and Development to 2026
    Mon, 8 Jun 2026 - 09:59
  • Inflation - Inflation May 2026 – KPIF Rises to 1.5 Percent
    Thu, 4 Jun 2026 - 08:30