Senior Corporate Security Engineer

Nexthink Spain
Relocation
This Job is No Longer Active This position is no longer accepting applications
AI Summary

As a Senior Corporate Security Engineer at Nexthink, you will be responsible for the security of our internal environment. You will own the security of a complex SaaS ecosystem, and lead detection and response for the corporate environment. You will report directly into the CISO organization and have a tangible impact on the daily lives of employees and the safety of the company.

Key Highlights
Identity-Centric Security Architecture
Endpoint & Infrastructure Security
Security Engineering
Key Responsibilities
Identity-Centric Security Architecture
Endpoint & Infrastructure Security
Security Engineering
SaaSSecurity & Integration
Detection, Response & Automation
Audits and Compliance
Culture & Collaboration
Technical Skills Required
Python Terraform PowerShell Okta Microsoft Entra ID FIDO2/WebAuthn EDR/XDR solutions MDM/UEM tools SIEM log analysis
Benefits & Perks
Permanent Contract
Competitive compensation package
Amazing centrally located offices
Private Health Insurance
Daily meal vouchers
Hybrid work model
Flexible Hours
Unlimited vacation
Gym subscription
Flexible compensation plan for childcare & public transportation
Reimbursement of English & Spanish classes
Fresh fruit, cookies, soft drinks and protein shakes at the office
Regular company and team events
Bonuses for referring successful hires
Nice to Have
Identity Expertise
Experience securing Cloud Infrastructure (Azure/AWS)

Job Description




Company Description

Nexthink is the leader in digital employee experience management software. The company provides IT leaders with unprecedented insight allowing them to see, diagnose and fix issues at scale impacting employees anywhere, with any applicationor network, before employees notice the issue. As the first solutionto allow IT to progress from reactive problem solving to proactive optimization, Nexthink enables its more than 1,300 customers to provide better digital experiences to more than 18 millionemployees. Dual headquartered in Lausanne, Switzerland and Boston, Massachusetts, Nexthink has 9 offices worldwide.

Job Description

As aSenior Corporate Security Engineerat Nexthink, you willbe responsible forthe security of our internal environment. Youwon'tjust bemonitoringlogs; you will be architecting the security fabric that enables our rapid growth.

Working in close partnership with IT, business teamsand,partnering with our Cloud and Application Security teams, you will secure the identity, devices, and applications used by "Nexthinkers" worldwide. You will ownthesecurity ofa complex SaaS ecosystem, andleaddetection and response for the corporate environment.

What You Will Do

Identity-Centric SecurityArchitecture

  • Contribute tothe designandsupporttheimplementation ofpasswordlessauthentication and Zero Trust principles.
  • Manage secure provisioning and lifecycle management, ensuring least-privilege access across all business systems.
  • Partner with HR and IT to streamline onboarding/offboarding workflows, ensuringtimelyaccess revocation and auditability.

Endpoint& Infrastructure Security

  • Define and enforce security baselines for our diverse fleet of endpoints (Windows, macOS) and mobile devices via MDM (Intune/Jamf).
  • Manage and tune EDR/XDR solutions to ensure high-fidelity detection on workstations and servers(Windows, Linux, macOS).
  • Secure the corporate Azure footprint, ensuring proper configuration of subscriptions, networking, and resources distinct from our production product environment.
  • Proactivelyidentifyand mitigate security risks in our corporate environment, conducting regular security assessments and vulnerability scans.
  • Coordinate vulnerability management and patch management
  • Collaborate with IT to automate endpoint compliance checks and remediation workflows.

Security Engineering

  • Support the development and maintenance ofInfrastructure-as-Code.
  • Ensure hardening and complianceofendpoints and servers.

SaaSSecurity & Integration

  • Assess and secure third-party SaaS integrations (e.g.,Salesforceapps, browser extensions, productivity tools) to prevent data leakage and over-privileged access.
  • Collaborate with Legal and Compliance to vet new vendors and tools.
  • Configure and maintain CASB and DLP policies to safeguard sensitive corporate data without hindering productivity.

Detection, Response & Automation

  • Lead incident response activities for corporate security events (phishing, malware, lost devices).
  • Develop automation scripts (Python/PowerShell) and workflows (SOAR) to automate manual security tasks, evidence collection, and response actions.
  • Proactively hunt for threats within the corporate network and identity providers.
  • Developincident responseplaybooksincludingtechnology specific procedures andforensics collection

Audits and Compliance

  • Designand implement security controls to safeguard corporate resources, including endpoints,data storage, networking,computing andidentityand access management.
  • Support and automate evidence collection for audits.

Culture & Collaboration

  • Act as the primary security liaison to the IT Departmentandbusinessteams, helping them build security into their operations (DevSecOpsfor IT).
  • Design and deliver technical security training and awareness campaigns for engineering and business teams.

Qualifications

  • 5-8years of hands-on experience in Corporate Security, IT Security Engineering,or a SOC roleina cloud-first environment.
  • Endpoint Mastery: Experience hardening operating systems (macOS/Windows) and managing security via MDM/UEM tools.
  • Vulnerability management:Proven experience inhelping IT and businessteamspatching systems and infrastructures.
  • Coding Skills:Proficiencyin PythonandTerraformfor automating APIs and security workflows.
  • Security Ops: Proven experience with EDR tools and SIEM log analysis.
  • Communication: Fluent in English with the ability to explain complex risks to non-technical stakeholders.
  • Proven ability to influence and drive security best practices across non-security teams.
  • Experience with security awareness training platforms and phishing simulation tools.

Bonus Points

  • Identity Expertise: Deep technical knowledge of Okta and Microsoft Entra ID (Authentication policy,Conditional Access, SSO, SCIM, OIDC/SAML).
  • Experience implementing FIDO2/WebAuthn(Passwordless).
  • Proficient inPowerShell.
  • Familiarity with compliance standards (ISO 27001/27701, SOC 2,FedRAMP)
  • Experience securing Cloud Infrastructure (Azure/AWS) specifically for internal/corporate workloads.

Why Join Nexthink Security?

  • Impact: You will report directly into the CISO organization and have a tangible impact on the daily lives of employees and the safety of the company.
  • Opportunity to work oncutting-edgesecurity projects, with visibility and support from executive leadership.
  • Technology: We use top-tier security stacks. Youwon’tbe fighting with legacyon-premisehardware; we arecloud-native.
  • Culture: We value "Security as an Enabler," not a blocker. You will work in a supportive, highly technical environment in our Madrid hub

Additional Information

We are the pioneers and trailblazers of a global IT Market Category (DEX) that is shaping the future of how the world works, giving our customers’ IT Teams total digital visibility across their enterprise. Our innovative solutions integrate real-time analytics, automation, and employee feedback across all endpoints. This enables our IT teams to solve complex technical challenges, create ever more productive workplaces, and deliver happy, satisfied employees in the digital workplace.

With over 1000 employees across 5 continents, Nexthink operates as One Team, connecting, collaborating and innovating to continuously grow. We call our employees ‘Nexthinkers’ and our commitment to diversity, inclusion, and equity is second to none. We currently have over 75 nationalities working with us, from all cultures and backgrounds, speaking many different languages.

If you are looking for a change and like a nice atmosphere, lots of challenges, and having fun while working, this is a great opportunity for you!Check what we offer:

  • Permanent Contract and a competitive compensation package.
  • 📍 Amazing centrally located offices near the Bernabeu Stadium.
  • 🩺 Private Health Insurance (Sanitas) and daily meal vouchers of 11 EURwill be entirely covered by us.
  • 🏡 Hybrid work model balancing office and remote work, with a structured approach for new hires to foster connections and onboarding.
  • 🏖️ Flexible Hours and unlimited vacation (employees have unlimited paid time off on top of the 23 days of holidays we offer)plus 3 company-paid volunteer days.
  • 🤸 Up to 25 EUR per month for a gym subscription.
  • 🛴 Flexible compensation plan for childcare & public transportation.
  • 🧑‍🏫 Reimbursement of up to 50% of the cost of English & Spanish classes.
  • 🍉 Fresh fruit, cookies,soft drinks and protein shakes at the offie.
  • 🍕Regular company and team events like Pizza talks, Team Building activities, Christmas parties, hosting Meetups at the office and more!
  • 📣 Bonuses for referring successful hires after three months of continuous employment.
  • 🚚 We offer a relocation package to people who are coming from another country.

Please note that not all the benefits listed above are available for temporary, contract, and internship roles. To ensure you have the most up-to-date information, we recommend checking with your Recruitment Partner.


Similar Jobs

Explore other opportunities that match your interests

Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

GMV

Spain

Application Security Analyst

Cyber Security
1w ago
Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Mid-Senior level

worldwiders recruitment

Spain

Junior IT & Security Technician

Cyber Security
2w ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Entry level

lace lithography

Spain

Subscribe our newsletter

New Things Will Always Update Regularly