About The Position

Nexthink is a leader in digital employee experience management software, providing IT leaders with unprecedented insight to diagnose and fix issues impacting employees. As a Senior Corporate Security Engineer, you will be responsible for the security of Nexthink's internal environment, architecting the security fabric to enable rapid growth. This role involves working closely with IT, business teams, and partnering with Cloud and Application Security teams to secure the identity, devices, and applications used by 'Nexthinkers' worldwide. You will own the security of a complex SaaS ecosystem and lead detection and response for the corporate environment.

Requirements

  • 5-8 years of hands-on experience in Corporate Security, IT Security Engineering, or a SOC role in a cloud-first environment.
  • Endpoint Mastery: Experience hardening operating systems (macOS/Windows) and managing security via MDM/UEM tools.
  • Vulnerability management: Proven experience in helping IT and business teams patching systems and infrastructures.
  • Coding Skills: Proficiency in Python and Terraform for automating APIs and security workflows.
  • Security Ops: Proven experience with EDR tools and SIEM log analysis.
  • Communication: Fluent in English with the ability to explain complex risks to non-technical stakeholders.
  • Proven ability to influence and drive security best practices across non-security teams.
  • Experience with security awareness training platforms and phishing simulation tools.

Nice To Haves

  • Identity Expertise: Deep technical knowledge of Okta and Microsoft Entra ID (Authentication policy, Conditional Access, SSO, SCIM, OIDC/SAML).
  • Experience implementing FIDO2/WebAuthn (Passwordless).
  • Proficient in PowerShell.
  • Familiarity with compliance standards (ISO 27001/27701, SOC 2, FedRAMP).
  • Experience securing Cloud Infrastructure (Azure/AWS) specifically for internal/corporate workloads.

Responsibilities

  • Contribute to the design and support the implementation of passwordless authentication and Zero Trust principles.
  • Manage secure provisioning and lifecycle management, ensuring least-privilege access across all business systems.
  • Partner with HR and IT to streamline onboarding/offboarding workflows, ensuring timely access revocation and auditability.
  • Define and enforce security baselines for our diverse fleet of endpoints (Windows, macOS) and mobile devices via MDM (Intune/Jamf).
  • Manage and tune EDR/XDR solutions to ensure high-fidelity detection on workstations and servers (Windows, Linux, macOS).
  • Secure the corporate Azure footprint, ensuring proper configuration of subscriptions, networking, and resources distinct from our production product environment.
  • Proactively identify and mitigate security risks in our corporate environment, conducting regular security assessments and vulnerability scans.
  • Coordinate vulnerability management and patch management.
  • Collaborate with IT to automate endpoint compliance checks and remediation workflows.
  • Support the development and maintenance of Infrastructure-as-Code.
  • Ensure hardening and compliance of endpoints and servers.
  • Assess and secure third-party SaaS integrations (e.g., Salesforce apps, browser extensions, productivity tools) to prevent data leakage and over-privileged access.
  • Collaborate with Legal and Compliance to vet new vendors and tools.
  • Configure and maintain CASB and DLP policies to safeguard sensitive corporate data without hindering productivity.
  • Lead incident response activities for corporate security events (phishing, malware, lost devices).
  • Develop automation scripts (Python/PowerShell) and workflows (SOAR) to automate manual security tasks, evidence collection, and response actions.
  • Proactively hunt for threats within the corporate network and identity providers.
  • Develop incident response playbooks including technology specific procedures and forensics collection.
  • Design and implement security controls to safeguard corporate resources, including endpoints, data storage, networking, computing and identity and access management.
  • Support and automate evidence collection for audits.
  • Act as the primary security liaison to the IT Department and business teams, helping them build security into their operations (DevSecOps for IT).
  • Design and deliver technical security training and awareness campaigns for engineering and business teams.

Benefits

  • Permanent Contract and a competitive compensation package.
  • Amazing centrally located offices near the Bernabeu Stadium.
  • Private Health Insurance (Sanitas) and daily meal vouchers of 11 EUR will be entirely covered by us.
  • Hybrid work model balancing office and remote work, with a structured approach for new hires to foster connections and onboarding.
  • Flexible Hours and unlimited vacation (employees have unlimited paid time off on top of the 23 days of holidays we offer) plus 3 company-paid volunteer days.
  • Up to 25 EUR per month for a gym subscription.
  • Flexible compensation plan for childcare & public transportation.
  • Reimbursement of up to 50% of the cost of English & Spanish classes.
  • Fresh fruit, cookies, soft drinks and protein shakes at the offie.
  • Regular company and team events like Pizza talks, Team Building activities, Christmas parties, hosting Meetups at the office and more!
  • Bonuses for referring successful hires after three months of continuous employment.
  • We offer a relocation package to people who are coming from another country.

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Senior

Education Level

No Education Listed

Number of Employees

501-1,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service