Senior Corporate Security Engineer

<section class="job-section" id="st-companyDescription"><div><p class="googlejobs-paragraph--empty"></p><h2 class="title">Company Description</h2></div><div class="wysiwyg"><p>Nexthink is the leader in digital employee experience management software. The company provides IT leaders with unprecedented insight allowing them to see, diagnose and fix issues at scale impacting employees anywhere, with any application or network, before employees notice the issue. As the first solution to allow IT to progress from reactive problem solving to proactive optimization, Nexthink enables its more than 1,300 customers to provide better digital experiences to more than 18 million employees. Dual headquartered in Lausanne, Switzerland and Boston, Massachusetts, Nexthink has 9 offices worldwide.</p></div></section><section class="job-section" id="st-jobDescription"><div><p class="googlejobs-paragraph--empty"></p><h2 class="title">Job Description</h2></div><div class="wysiwyg" itemprop="responsibilities"><p>As a Senior Corporate Security Engineer at Nexthink, you will be responsible for the security of our internal environment. You won't just be monitoring logs; you will be architecting the security fabric that enables our rapid growth. </p><p>Working in close partnership with IT, business teams and, partnering with our Cloud and Application Security teams, you will secure the identity, devices, and applications used by "Nexthinkers" worldwide. You will own the security of a complex SaaS ecosystem, and lead detection and response for the corporate environment. </p><p><strong>What You Will Do </strong></p><p><strong>Identity-Centric Security Architecture </strong></p><ul><li>Contribute to the design and support the implementation of passwordless authentication and Zero Trust principles. </li><li>Manage secure provisioning and lifecycle management, ensuring least-privilege access across all business systems. </li><li>Partner with HR and IT to streamline onboarding/offboarding workflows, ensuring timely access revocation and auditability. </li></ul><p><strong>Endpoint & Infrastructure Security </strong></p><ul><li>Define and enforce security baselines for our diverse fleet of endpoints (Windows, macOS) and mobile devices via MDM (Intune/Jamf). </li><li>Manage and tune EDR/XDR solutions to ensure high-fidelity detection on workstations and servers (Windows, Linux, macOS). </li><li>Secure the corporate Azure footprint, ensuring proper configuration of subscriptions, networking, and resources distinct from our production product environment. </li><li>Proactively identify and mitigate security risks in our corporate environment, conducting regular security assessments and vulnerability scans. </li><li>Coordinate vulnerability management and patch management  </li><li>Collaborate with IT to automate endpoint compliance checks and remediation workflows. </li></ul><p><strong>Security Engineering </strong></p><ul><li>Support the development and maintenance of Infrastructure-as-Code. </li><li>Ensure hardening and compliance of endpoints and servers. </li></ul><p><strong>SaaS Security & Integration </strong></p><ul><li>Assess and secure third-party SaaS integrations (e.g., Salesforce apps, browser extensions, productivity tools) to prevent data leakage and over-privileged access. </li><li>Collaborate with Legal and Compliance to vet new vendors and tools. </li><li>Configure and maintain CASB and DLP policies to safeguard sensitive corporate data without hindering productivity. </li></ul><p><strong>Detection, Response & Automation </strong></p><ul><li>Lead incident response activities for corporate security events (phishing, malware, lost devices). </li><li>Develop automation scripts (Python/PowerShell) and workflows (SOAR) to automate manual security tasks, evidence collection, and response actions. </li><li>Proactively hunt for threats within the corporate network and identity providers. </li><li>Develop incident response playbooks including technology specific procedures and forensics collection </li></ul><p><strong>Audits and Compliance </strong></p><ul><li>Design and implement security controls to safeguard corporate resources, including endpoints, data storage, networking, computing and identity and access management. </li><li>Support and automate evidence collection for audits. </li></ul><p><strong>Culture & Collaboration </strong></p><ul><li>Act as the primary security liaison to the IT Department and business teams, helping them build security into their operations (DevSecOps for IT). </li><li>Design and deliver technical security training and awareness campaigns for engineering and business teams. </li></ul></div></section><section class="job-section" id="st-qualifications"><div><p class="googlejobs-paragraph--empty"></p><h2 class="title">Qualifications</h2></div><div class="wysiwyg" itemprop="qualifications"><ul><li>5-8 years of hands-on experience in Corporate Security, IT Security Engineering, or a SOC role in a cloud-first environment. </li><li>Endpoint Mastery: Experience hardening operating systems (macOS/Windows) and managing security via MDM/UEM tools. </li><li>Vulnerability management: Proven experience in helping IT and business teams patching systems and infrastructures. </li><li>Coding Skills: Proficiency in Python and Terraform for automating APIs and security workflows. </li><li>Security Ops: Proven experience with EDR tools and SIEM log analysis. </li><li>Communication: Fluent in English with the ability to explain complex risks to non-technical stakeholders. </li><li>Proven ability to influence and drive security best practices across non-security teams. </li><li>Experience with security awareness training platforms and phishing simulation tools. </li></ul><p><strong>Bonus Points</strong> </p><ul><li>Identity Expertise: Deep technical knowledge of Okta and Microsoft Entra ID (Authentication policy, Conditional Access, SSO, SCIM, OIDC/SAML). </li><li>Experience implementing FIDO2/WebAuthn (Passwordless). </li><li>Proficient in PowerShell. </li><li>Familiarity with compliance standards (ISO 27001/27701, SOC 2, FedRAMP) </li><li>Experience securing Cloud Infrastructure (Azure/AWS) specifically for internal/corporate workloads. </li></ul><p><strong>Why Join Nexthink Security? </strong></p><ul><li>Impact: You will report directly into the CISO organization and have a tangible impact on the daily lives of employees and the safety of the company. </li><li>Opportunity to work on cutting-edge security projects, with visibility and support from executive leadership. </li><li>Technology: We use top-tier security stacks. You won’t be fighting with legacy on-premise hardware; we are cloud-native. </li><li>Culture: We value "Security as an Enabler," not a blocker. You will work in a supportive, highly technical environment in our Madrid hub</li></ul></div></section><section class="job-section" id="st-additionalInformation"><div><p class="googlejobs-paragraph--empty"></p><h2 class="title">Additional Information</h2></div><div class="wysiwyg" itemprop="incentives"><p>We are the pioneers and trailblazers of a global IT Market Category (DEX) that is shaping the future of how the world works, giving our customers’ IT Teams total digital visibility across their enterprise. Our innovative solutions integrate real-time analytics, automation, and employee feedback across all endpoints. This enables our IT teams to solve complex technical challenges, create ever more productive workplaces, and deliver happy, satisfied employees in the digital workplace.</p><p>With over 1000 employees across 5 continents, Nexthink operates as One Team, connecting, collaborating and innovating to continuously grow. We call our employees ‘Nexthinkers’ and our commitment to diversity, inclusion, and equity is second to none. We currently have over 75 nationalities working with us, from all cultures and backgrounds, speaking many different languages.</p><p>If you are looking for a change and like a nice atmosphere, lots of challenges, and having fun while working, this is a great opportunity for you! <strong>Check what we offer:</strong></p><ul><li>💼 Permanent Contract and a competitive compensation package  </li><li>🏖️ Flexible Hours and unlimited vacation (employees have unlimited paid time off on top of the 30 days of holidays we offer) plus 3 company-paid volunteer days. </li><li>🏡 100% remote work with occasional travels to meet with colleagues and customers </li><li>📚 Free access to professional training platforms to explore your interests and enhance your skills. </li><li>🍼 16 weeks of fully paid leave for primary caregivers, extendable up to 8 additional months unpaid, and 6 weeks of fully paid leave for secondary caregivers. </li><li>🏥 Feel protected with 24/7 accident insurance coverage for any accidents at work or during free time. </li><li>📣  Bonuses for referring successful hires after three months of continuous employment. </li></ul><p>Please note that not all the benefits listed above are available for temporary, contract, and internship roles. To ensure you have the most up-to-date information, we recommend checking with your Recruitment Partner.</p></div></section><li class="job-detail">Department: Corporate Security & Compliance</li><li class="job-detail">Dept: Corporate Security & Compliance</li><li class="job-detail">Division: Engineering</li>

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...