> Markdown version of [/jobs/ext/1690443-senior-corporate-security-engineer](https://www.wearedevelopers.com/jobs/ext/1690443-senior-corporate-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Corporate Security Engineer - **Company:** Nexthink - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Apple Mac Systems, Microsoft Azure, Software as a Service, Cyber Security, Linux, Identity and Access Management, Python (Programming Language), Log Analysis, Phishing, Zero Trust Network Access, Security Information and Event Management, Systems Integration, Software Vulnerability Management, Data Storage Technologies, Microsoft InTune, Patch Management, Casper Suite, CIS Benchmarks, Terraform, Network Server, Vulnerability Analysis - **Published:** July 31, 2026 - **Apply:** https://www.buscojobs.com.es/senior-corporate-security-engineer-en-madrid-ID-364270681 ## About the Role This is a mission-driven opportunity to shape Nexthink's security fabric in a cloud-first, high-growth context.Compensaciones / Beneficios* Contribute to passwordless authentication design and Zero Trust implementation* Manage secure provisioning and lifecycle management with least-privilege access* Streamline onboarding/offboarding workflows with HR/IT and ensure auditability* Define security baselines for Windows/macOS endpoints and mobile devices via MDM (Intune/Jamf)* Tune and manage EDR/XDR for workstations and servers (Windows/Linux/macOS)* Secure corporate Azure footprint, including subscriptions, networking, and resources* Conduct regular security assessments and vulnerability scans; coordinate patch management* Automate endpoint compliance checks and remediation workflows with IT* Develop and maintain Infrastructure-as-Code; ensure endpoint and server hardening* Assess and secure third-party SaaS integrations; configure CASB/DLP policies* Lead incident response for corporate security events; develop automation and SOAR workflows* Proactively hunt threats; develop incident response playbooks and forensics procedures* Design and implement security controls for endpoints, data storage, networking, computing, and IAM* Support automated evidence collection for audits* Act as security liaison to IT and business teams; deliver security training and awareness campaignsResponsabilidades* 5-8 years of hands-on experience in Corporate Security, IT Security Engineering, xqbhyrx or SOC in a cloud-first environment* Endpoint mastery with OS hardening and MDM/UEM tools* Vulnerability management and patching experience* Proficiency in Python and Terraform for automating security workflows* Experience with EDR tools and SIEM log analysis* Fluent English and ability to explain risks to non-technical stakeholders* Proven ability to influence security best practices across non-security teams* Experience with security awareness training platforms and phishing simulationsRequisitos ## Description Experteer Overview Aumente sus posibilidades de conseguir una entrevista leyendo la siguiente descripción general de este puesto antes de presentar su candidatura.In this Senior Corporate Security Engineer role, you will architect and secure Nexthink's internal environment to support rapid growth.You'll collaborate with IT, HR, and security teams to design identity-centric controls, enforce least-privilege access, and automate onboarding and offboarding.You'll own detection and response for the corporate SaaS ecosystem, balancing strong security with productivity.You will work hands-on to harden endpoints, manage EDR/XDR, and lead risk mitigation across cloud and on-prem resources.This is a mission-driven opportunity to shape Nexthink's security fabric in a cloud-first, high-growth context.Compensaciones / Beneficios* Contribute to passwordless authentication design and Zero Trust implementation* Manage secure provisioning and lifecycle management with least-privilege access* Streamline onboarding/offboarding workflows with HR/IT and ensure auditability* Define security baselines for Windows/macOS endpoints and mobile devices via MDM (Intune/Jamf)* Tune and manage EDR/XDR for workstations and servers (Windows/Linux/macOS)* Secure corporate Azure footprint, including subscriptions, networking, and resources* Conduct regular security assessments and vulnerability scans; coordinate patch management* Automate endpoint compliance checks and remediation workflows with IT* Develop and maintain Infrastructure-as-Code; ensure endpoint and server hardening* Assess and secure third-party SaaS integrations; configure CASB/DLP policies* Lead incident response for corporate security events; develop automation and SOAR workflows* Proactively hunt threats; develop incident response playbooks and forensics procedures* Design and implement security controls for endpoints, data storage, networking, computing, and IAM* Support automated evidence collection for audits* Act as security liaison to IT and business teams; deliver security training and awareness campaignsResponsabilidades* 5-8 years of hands-on experience in Corporate Security, IT Security Engineering, xqbhyrx or SOC in a cloud-first environment* Endpoint mastery with OS hardening and MDM/UEM tools* Vulnerability management and patching experience* Proficiency in Python and Terraform for automating security workflows* Experience with EDR tools and SIEM log analysis* Fluent English and ability to explain risks to non-technical stakeholders* Proven ability to influence security best practices across non-security teams* Experience with security awareness training platforms and phishing simulationsRequisitos principales* Permanent contract* Private health insurance* Hybrid work model* Unlimited vacation* Gym subscription subsidy* Relocation package ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Spanish Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/353-spanish-business-culture-and-etiquette) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)