Unparalleled Visibility Into Issue Detection, Diagnosis, and Remediation
Senior Corporate Security Engineer
Location
Spain
Posted
3 days ago
Salary
0
Seniority
Senior
Job Description
Senior Corporate Security Engineer
Nexthink
Company Description Nexthink is the leader in digital employee experience management software. The company provides IT leaders with unprecedented insight allowing them to see, diagnose and fix issues at scale impacting employees anywhere, with any application or network, before employees notice the issue. As the first solution to allow IT to progress from reactive problem solving to proactive optimization, Nexthink enables its more than 1,300 customers to provide better digital experiences to more than 18 million employees. Dual headquartered in Lausanne, Switzerland and Boston, Massachusetts, Nexthink has 9 offices worldwide. Job Description As a Senior Corporate Security Engineer at Nexthink, you will be responsible for the security of our internal environment. You won't just be monitoring logs; you will be architecting the security fabric that enables our rapid growth. Working in close partnership with IT, business teams and, partnering with our Cloud and Application Security teams, you will secure the identity, devices, and applications used by "Nexthinkers" worldwide. You will own the security of a complex SaaS ecosystem, and lead detection and response for the corporate environment. What You Will Do Identity-Centric Security Architecture - Contribute to the design and support the implementation of passwordless authentication and Zero Trust principles. - Manage secure provisioning and lifecycle management, ensuring least-privilege access across all business systems. - Partner with HR and IT to streamline onboarding/offboarding workflows, ensuring timely access revocation and auditability. Endpoint & Infrastructure Security - Define and enforce security baselines for our diverse fleet of endpoints (Windows, macOS) and mobile devices via MDM (Intune/Jamf). - Manage and tune EDR/XDR solutions to ensure high-fidelity detection on workstations and servers (Windows, Linux, macOS). - Secure the corporate Azure footprint, ensuring proper configuration of subscriptions, networking, and resources distinct from our production product environment. - Proactively identify and mitigate security risks in our corporate environment, conducting regular security assessments and vulnerability scans. - Coordinate vulnerability management and patch management - Collaborate with IT to automate endpoint compliance checks and remediation workflows. Security Engineering - Support the development and maintenance of Infrastructure-as-Code. - Ensure hardening and compliance of endpoints and servers. SaaS Security & Integration - Assess and secure third-party SaaS integrations (e.g., Salesforce apps, browser extensions, productivity tools) to prevent data leakage and over-privileged access. - Collaborate with Legal and Compliance to vet new vendors and tools. - Configure and maintain CASB and DLP policies to safeguard sensitive corporate data without hindering productivity. Detection, Response & Automation - Lead incident response activities for corporate security events (phishing, malware, lost devices). - Develop automation scripts (Python/PowerShell) and workflows (SOAR) to automate manual security tasks, evidence collection, and response actions. - Proactively hunt for threats within the corporate network and identity providers. - Develop incident response playbooks including technology specific procedures and forensics collection Audits and Compliance - Design and implement security controls to safeguard corporate resources, including endpoints, data storage, networking, computing and identity and access management. - Support and automate evidence collection for audits. Culture & Collaboration - Act as the primary security liaison to the IT Department and business teams, helping them build security into their operations (DevSecOps for IT). - Design and deliver technical security training and awareness campaigns for engineering and business teams. Qualifications - 5-8 years of hands-on experience in Corporate Security, IT Security Engineering, or a SOC role in a cloud-first environment. - Endpoint Mastery: Experience hardening operating systems (macOS/Windows) and managing security via MDM/UEM tools. - Vulnerability management: Proven experience in helping IT and business teams patching systems and infrastructures. - Coding Skills: Proficiency in Python and Terraform for automating APIs and security workflows. - Security Ops: Proven experience with EDR tools and SIEM log analysis. - Communication: Fluent in English with the ability to explain complex risks to non-technical stakeholders. - Proven ability to influence and drive security best practices across non-security teams. - Experience with security awareness training platforms and phishing simulation tools. Bonus Points - Identity Expertise: Deep technical knowledge of Okta and Microsoft Entra ID (Authentication policy, Conditional Access, SSO, SCIM, OIDC/SAML). - Experience implementing FIDO2/WebAuthn (Passwordless). - Proficient in PowerShell. - Familiarity with compliance standards (ISO 27001/27701, SOC 2, FedRAMP) - Experience securing Cloud Infrastructure (Azure/AWS) specifically for internal/corporate workloads. Why Join Nexthink Security? - Impact: You will report directly into the CISO organization and have a tangible impact on the daily lives of employees and the safety of the company. - Opportunity to work on cutting-edge security projects, with visibility and support from executive leadership. - Technology: We use top-tier security stacks. You won't be fighting with legacy on-premise hardware; we are cloud-native. - Culture: We value "Security as an Enabler," not a blocker. You will work in a supportive, highly technical environment in our Madrid hub Additional Information We are the pioneers and trailblazers of a global IT Market Category (DEX) that is shaping the future of how the world works, giving our customers' IT Teams total digital visibility across their enterprise. Our innovative solutions integrate real-time analytics, automation, and employee feedback across all endpoints. This enables our IT teams to solve complex technical challenges, create ever more productive workplaces, and deliver happy, satisfied employees in the digital workplace. With over 1000 employees across 5 continents, Nexthink operates as One Team, connecting, collaborating and innovating to continuously grow. We call our employees 'Nexthinkers' and our commitment to diversity, inclusion, and equity is second to none. We currently have over 75 nationalities working with us, from all cultures and backgrounds, speaking many different languages. If you are looking for a change and like a nice atmosphere, lots of challenges, and having fun while working, this is a great opportunity for you! Check what we offer: - Permanent Contract and a competitive compensation package. - Amazing centrally located offices near the Bernabeu Stadium. - Private Health Insurance (Sanitas) and daily meal vouchers of 11 EUR will be entirely covered by us. - Hybrid work model balancing office and remote work, with a structured approach for new hires to foster connections and onboarding. - Flexible Hours and unlimited vacation (employees have unlimited paid time off on top of the 23 days of holidays we offer) plus 3 company-paid volunteer days. - Up to 25 EUR per month for a gym subscription. - Flexible compensation plan for childcare & public transportation. - Reimbursement of up to 50% of the cost of English & Spanish classes. - Fresh fruit, cookies, soft drinks and protein shakes at the offie. - Regular company and team events like Pizza talks, Team Building activities, Christmas parties, hosting Meetups at the office and more! - Bonuses for referring successful hires after three months of continuous employment. - We offer a relocation package to people who are coming from another country. Please note that not all the benefits listed above are available for temporary, contract, and internship roles. To ensure you have the most up-to-date information, we recommend checking with your Recruitment Partner.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Provide technical support to internal users, identifying and resolving complex IT and security-related issues. • Manage and configure IT assets and ensure secure and compliant environments. • Oversee identity and access management, including user provisioning, de-provisioning, and enforcement of least privilege principles. • Administer and configure endpoint protection tools, antivirus, patch management systems, and Mobile Device Management (MDM) solutions. • Support the implementation and maintenance of internal IT and security procedures and documentation. • Collaborate with the security and compliance teams in conducting risk assessments, internal audits, and implementing GRC controls aligned with privacy and other applicable legislation and the CIS Critical Security Controls framework. • Ensure best practices are followed in day-to-day operations regarding systems, access, and incident response. • Keep up with industry trends and threats to advise on improvements and preventive measures. • Educate employees on security policies, awareness, and safe practices. • Administer AWS environments and apply best security practices, including provisioning access and permissions, implement security features, monitoring and investigating suspicious activities. • Collaborate with the engineering team to improve the security of CI/CD pipelines, assist in remediating vulnerabilities, and perform security reviews of changes involving Infrastructure as Code (IaC). • Assist clients in implementing and maintaining SSO integrations. • Collaborate on strategic planning for the department in alignment with business needs, utilizing OKRs, roadmaps, business plans, and budget planning.
Senior Enterprise Architect, Security
WillHireNow Magnit - Follow our new LinkedIn account https://www.linkedin.com/company/magnitglobal
• Use deep technology and security expertise to lead strategic conversations • Deliver high-impact presentations demonstrating Workday’s platform value • Build trusted relationships with CIOs, CISOs, security leaders, enterprise architects, and business executives • Mentor others by sharing best practices and feedback
• Define and implement security strategies for applications, including those that integrate LLMs and generative AI components • Collaborate with development teams to integrate security practices from the beginning of the software development lifecycle • Conduct architecture, code, and design reviews to identify potential vulnerabilities and security issues • Define guardrails and standards for LLM-based applications, addressing risks such as prompt injection, insecure output handling, data leakage through outputs, excessive agent autonomy, and cost-abuse (denial-of-wallet) • Establish guidelines for the safe use of AI-assisted development tools by engineering teams • Develop and promote security standards and best practices across the development organization • Provide technical guidance and security training • Be familiar with tools for automated quality validation in the CI/CD pipeline such as SAST, DAST, SCA and Secret Scanning • Stay up to date with security threats and evolving attack techniques and continuously update protective measures • Develop creative solutions to complex security problems • Use your security expertise and intuition to hunt for threats in corporate and production environments • Read and communicate in English
Escalation Engineer - AI Security
ZscalerZscaler helps leading organizations in 180+ countries securely transform their networks and applications for a mobile and cloud-first world. Founded in 2008, th
Title: Escalation Engineer - AI Security Location: Bangalore, IND; Mohali, IND Role We are looking for an experienced Escalation Engineer to join our Customer Success team. This is a hybrid role based in Bangalore, you will report to the Escalation Manager. Our Customer Success Strategy & Operations team uses valuable data and market research to help our customers succeed and drive value. You'll be an integral part of solving challenges faced by our client-facing teams to help make Zscaler more efficient in meeting our customers' needs. What you’ll do (Role Expectations) - Own and resolve the highest-severity technical escalations through deep analysis, ensuring fast resolution and managing the on-call rotation for critical issues - Troubleshoot and resolve complex issues across Zscaler cloud security services, configuration, policy engines, APIs, and AI-assisted capabilities - Investigate and resolve scenarios related to the secure use of AI models, governance of AI agents, data protection, and inference security - Perform detailed log, telemetry, and packet-level analysis to identify the root cause, reproducing complex defects, providing engineering-ready bug reports, and validating fixes - Drive cross-functional collaboration with Engineering, Cloud Ops, and Product Management, while also creating advanced troubleshooting documentation and acting as a technical mentor to uplift support capability Who You Are (Success Profile) - You thrive in ambiguity. You're comfortable building the path as you walk it. You thrive in a dynamic environment, seeing ambiguity not as a hindrance, but as the raw material to build something meaningful. - You act like an owner. Your passion for the mission fuels your bias for action. You operate with integrity because you genuinely care about the outcome. True ownership involves leveraging dynamic range: the ability to navigate seamlessly between high-level strategy and hands-on execution. - You are a problem-solver. You love running towards the challenges because you are laser-focused on finding the solution, knowing that solving the hard problems delivers the biggest impact. - You are a high-trust collaborator. You are ambitious for the team, not just yourself. You embrace our challenge culture by giving and receiving ongoing feedback—knowing that candor delivered with clarity and respect is the truest form of teamwork and the fastest way to earn trust. - You are a learner. You have a true growth mindset and are obsessed with your own development, actively seeking feedback to become a better partner and a stronger teammate. You love what you do and you do it with purpose. What We’re Looking for (Minimum Qualifications) - 4–10 years of deep technical support, cloud support engineering, or escalation engineering experience - Strong understanding of AI model security, data governance, AI agent behavior, and safe enterprise deployment principles - Proficiency with APIs, JSON, logging frameworks, Linux CLI, debugging tools, and cloud-based distributed systems - Exposure to cloud platforms (AWS/GCP/Azure) and identity, policy, or proxy-based architectures - Ability to reproduce complex issues, correlate across layers (client → edge → cloud), and articulate clear RCAs What Will Make You Stand Out (Preferred Qualifications) - Demonstrated experience with Zscaler products (ZIA, ZPA, ZDX) or similar cloud security platforms, including knowledge of enterprise networking, TLS/SSL inspection, and authentication flows - Familiarity with LLM-based system behavior, data leakage prevention in AI, and establishing model access policy controls - Proficiency in scripting for automation, efficient troubleshooting, and reproducing complex customer environments #LI-RR #LI-Hybrid At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure. Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including: - Various health plans - Time off plans for vacation and sick time - Parental leave options - Retirement options - Education reimbursement - In-office perks, and more!




