Madrid, Spain Hybrid Full-time

Nexthink is hiring a Senior Corporate Security Engineer

Responsibilities

  • Contribute to the design and support the implementation of passwordless authentication and Zero Trust principles.
  • Manage secure provisioning and lifecycle management, ensuring least-privilege access across all business systems.
  • Partner with HR and IT to streamline onboarding/offboarding workflows, ensuring timely access revocation and auditability.
  • Define and enforce security baselines for our diverse fleet of endpoints (Windows, macOS) and mobile devices via MDM (Intune/Jamf).
  • Manage and tune EDR/XDR solutions to ensure high-fidelity detection on workstations and servers (Windows, Linux, macOS).
  • Secure the corporate Azure footprint, ensuring proper configuration of subscriptions, networking, and resources distinct from our production product environment.
  • Proactively identify and mitigate security risks in our corporate environment, conducting regular security assessments and vulnerability scans.
  • Coordinate vulnerability management and patch management
  • Collaborate with IT to automate endpoint compliance checks and remediation workflows.
  • Support the development and maintenance of Infrastructure-as-Code.
  • Ensure hardening and compliance of endpoints and servers.
  • Assess and secure third-party SaaS integrations (e.g., Salesforce apps, browser extensions, productivity tools) to prevent data leakage and over-privileged access.
  • Collaborate with Legal and Compliance to vet new vendors and tools.
  • Configure and maintain CASB and DLP policies to safeguard sensitive corporate data without hindering productivity.
  • Lead incident response activities for corporate security events (phishing, malware, lost devices).
  • Develop automation scripts (Python/PowerShell) and workflows (SOAR) to automate manual security tasks, evidence collection, and response actions.
  • Proactively hunt for threats within the corporate network and identity providers.
  • Develop incident response playbooks including technology specific procedures and forensics collection
  • Design and implement security controls to safeguard corporate resources, including endpoints, data storage, networking, computing and identity and access management.
  • Support and automate evidence collection for audits.
  • Act as the primary security liaison to the IT Department and business teams, helping them build security into their operations (DevSecOps for IT).
  • Design and deliver technical security training and awareness campaigns for engineering and business teams.

Requirements

  • Experience in securing identity, devices, and applications in a corporate environment.
  • Experience with identity-centric security including passwordless authentication and Zero Trust principles.
  • Proficiency in managing endpoint security via MDM solutions such as Intune and Jamf.
  • Experience with EDR/XDR solutions across Windows, Linux, and macOS platforms.
  • Hands-on experience securing Azure environments.
  • Experience conducting vulnerability assessments, patch management, and security scanning.
  • Ability to develop automation scripts using Python or PowerShell.
  • Experience with SOAR platforms and incident response workflows.
  • Experience configuring and maintaining CASB and DLP solutions.
  • Strong understanding of least-privilege access and lifecycle management.
  • Experience developing incident response playbooks and conducting forensic evidence collection.
  • Proven ability to collaborate with IT, HR, Legal, and Compliance teams.
  • Experience delivering technical security training and awareness programs.
Required Skills
Linux
About company
Nexthink
Nexthink is the leader in digital employee experience management software. The company provides IT leaders with unprecedented insight allowing them to see, diagnose and fix issues at scale impacting employees anywhere, with any application or network, before employees notice the issue.
All jobs at Nexthink Visit website
Job Details
Department Corporate Security & Compliance
Category security
Posted a month ago