Experteer Overview
In this role you will design and implement security for Nexthink’s internal environment in a fast-growing, cloud-first setting. You’ll partner with IT, HR, and security teams to secure identities, devices, and applications across Nexthinkers worldwide, leading detection and response for a complex SaaS ecosystem. You’ll balance governance with rapid delivery, scaling security controls as the company grows. The position offers opportunities to shape a proactive security program and work with a world-class security stack.
Compensaciones / Beneficios
• Design and support passwordless authentication and Zero Trust initiatives
• Manage provisioning, lifecycle management, and least-privilege access across business systems
• Onboard/offboard workflows with HR and IT ensuring timely access revocation and auditability
• Define security baselines for endpoints (Windows, macOS) and mobile devices via MDM (Intune/Jamf)
• Tune EDR/XDR for high-fidelity detection on workstations and servers (Windows, Linux, macOS)
• Secure corporate Azure footprint, including subscriptions, networking, and resources
• Identify and mitigate security risks; conduct regular assessments and vulnerability scans
• Coordinate vulnerability and patch management; collaborate on automated remediation workflows
• Support Infrastructure-as-Code and ensure endpoint/server hardening and compliance
• Assess and secure third-party SaaS integrations (e.g.,
Salesforce apps) and maintain CASB/DLP policies
• Lead incident response for corporate security events; develop automation scripts and SOAR workflows
• Proactively hunt for threats; develop incident response playbooks and forensics procedures
• Design and implement security controls for endpoints, data storage, networking, computing, and IAM
• Automate evidence collection for audits; serve as security liaison to IT and business teams
• Deliver technical security training and awareness campaigns
Responsabilidades
• 5-8 years in Corporate Security, IT Security Engineering, or SOC in a cloud-first environment
• Endpoint hardening experience for macOS/Windows and MDM/UEM tooling
• Vulnerability management experience with patching coordination
• Proficiency in Python and Terraform for automating security workflows
• Security operations experience with EDR tools and SIEM log analysis
• Fluent English with ability to explain complex risks to non-technical stakeholders
• Proven ability to influence security best practices across non-security teams
• Experience with security awareness training platforms and phishing simulation tools
Requisitos principales
• Permanent contract
• Hybrid work model
• Private health insurance
• Adaptable hours and unlimited vacation
• Gym subscription reimbursement
• Relocation package
📌 Senior Corporate Security Engineer (Madrid)
🏢 Talent
📍 Madrid