> Markdown version of [/jobs/ext/3047661-corporate-security-engineer](https://www.wearedevelopers.com/jobs/ext/3047661-corporate-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Corporate Security Engineer - **Company:** Nexthink - **Location:** Madrid, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Amazon Web Services, Apple Mac Systems, User Authentication, Microsoft Azure, Business Systems, Software as a Service, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Information Leak Prevention, Linux, Identity and Access Management, Python (Programming Language), Log Analysis, OpenID, Windows PowerShell, Productivity Software, Azure Active Directory, Phishing, Zero Trust Network Access, Salesforce.Com, Security Assertion Markup Language (SAML), Security Information and Event Management, Software Vulnerability Management, Enterprise Data Management, Data Storage Technologies, Okta, Software Security, Microsoft InTune, Patch Management, Casper Suite, CIS Benchmarks, Software Coding, Terraform, Devsecops - **Published:** September 24, 2026 - **Apply:** https://www.adzuna.es/contact-us.html ## About the Role + 5-8 years of hands-on experience in Corporate Security, IT Security Engineering, or a SOC role in a cloud-first environment. + Endpoint Mastery: Experience hardening operating systems (macOS/Windows) and managing security via MDM/UEM tools. + Vulnerability management: Proven experience in helping IT and business teams patching systems and infrastructures. + Coding Skills: Proficiency in Python and Terraform for automating APIs and security workflows. + Security Ops: Proven experience with EDR tools and SIEM log analysis. + Communication: Fluent in English with the ability to explain complex risks to non-technical stakeholders. + Proven ability to influence and drive security best practices across non-security teams. + Experience with security awareness training platforms and phishing simulation tools. Bonus Points + Identity Expertise: Deep technical knowledge of Okta and Microsoft Entra ID (Authentication policy, Conditional Access, SSO, SCIM, OIDC/SAML). + Experience implementing FIDO2/WebAuthn (Passwordless). + Proficient in PowerShell. + Familiarity with compliance standards (ISO 27001/27701, SOC 2, FedRAMP) + Experience securing Cloud Infrastructure (Azure/AWS) specifically for internal/corporate workloads. ## Description As a Senior Corporate Security Engineer at Nexthink, you will be responsible for the security of our internal environment. You won't just be monitoring logs; you will be architecting the security fabric that enables our rapid growth. Working in close partnership with IT, business teams and, partnering with our Cloud and Application Security teams, you will secure the identity, devices, and applications used by "Nexthinkers" worldwide. You will own the security of a complex SaaS ecosystem, and lead detection and response for the corporate environment. What You Will Do Identity-Centric Security Architecture + Contribute to the design and support the implementation of passwordless authentication and Zero Trust principles. + Manage secure provisioning and lifecycle management, ensuring least-privilege access across all business systems. + Partner with HR and IT to streamline onboarding/offboarding workflows, ensuring timely access revocation and auditability. Endpoint & Infrastructure Security + Define and enforce security baselines for our diverse fleet of endpoints (Windows, macOS) and mobile devices via MDM (Intune/Jamf). + Manage and tune EDR/XDR solutions to ensure high-fidelity detection on workstations and servers (Windows, Linux, macOS). + Secure the corporate Azure footprint, ensuring proper configuration of subscriptions, networking, and resources distinct from our production product environment. + Proactively identify and mitigate security risks in our corporate environment, conducting regular security assessments and vulnerability scans. + Coordinate vulnerability management and patch management + Collaborate with IT to automate endpoint compliance checks and remediation workflows. Security Engineering + Support the development and maintenance of Infrastructure-as-Code. + Ensure hardening and compliance of endpoints and servers. SaaS Security & Integration + Assess and secure third-party SaaS integrations (e.g., Salesforce apps, browser extensions, productivity tools) to prevent data leakage and over-privileged access. + Collaborate with Legal and Compliance to vet new vendors and tools. + Configure and maintain CASB and DLP policies to safeguard sensitive corporate data without hindering productivity. Detection, Response & Automation + Lead incident response activities for corporate security events (phishing, malware, lost devices). + Develop automation scripts (Python/PowerShell) and workflows (SOAR) to automate manual security tasks, evidence collection, and response actions. + Proactively hunt for threats within the corporate network and identity providers. + Develop incident response playbooks including technology specific procedures and forensics collection Audits and Compliance + Design and implement security controls to safeguard corporate resources, including endpoints, data storage, networking, computing and identity and access management. + Support and automate evidence collection for audits. Culture & Collaboration + Act as the primary security liaison to the IT Department and business teams, helping them build security into their operations (DevSecOps for IT). + Design and deliver technical security training and awareness campaigns for engineering and business teams., + Impact: You will report directly into the CISO organization and have a tangible impact on the daily lives of employees and the safety of the company. + Opportunity to work on cutting-edge security projects, with visibility and support from executive leadership. + Technology: We use top-tier security stacks. You won't be fighting with legacy on-premise hardware; we are cloud-native. + Culture: We value "Security as an Enabler," not a blocker. You will work in a supportive, highly technical environment in our Madrid hub ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)