More jobs:
Job Description & How to Apply Below
Company Description
Nexthink is the leader in digital employee experience management software. The company provides IT leaders with unprecedented insight allowing them to see, diagnose and fix issues at scale impacting employees anywhere, with any application or network, before employees notice the issue. As the first solution to allow IT to progress from reactive problem solving to proactive optimization, Nexthink enables its more than 1,300 customers to provide better digital experiences to more than 18 million employees.
Dual headquartered in Lausanne, Switzerland and Boston, Massachusetts, Nexthink has 9 offices worldwide.
Job Description
As a Senior Corporate Security Engineer at Nexthink, you will be responsible for the security of our internal environment. You won't just be monitoring logs; you will be architecting the security fabric that enables our rapid growth.
Working in close partnership with IT, business teams and, partnering with our Cloud and Application Security teams, you will secure the identity, devices, and applications used by "Nexthinkers" worldwide. You will own the security of a complex SaaS ecosystem, and lead detection and response for the corporate environment.
What You Will Do
Identity-Centric Security Architecture
Contribute to the design and support the implementation of passwordless authentication and Zero Trust principles.
Manage secure provisioning and lifecycle management, ensuring least-privilege access across all business systems.
Partner with HR and IT to streamline onboarding/offboarding workflows, ensuring timely access revocation and auditability.
Endpoint & Infrastructure Security
Define and enforce security baselines for our diverse fleet of endpoints (Windows, macOS) and mobile devices via MDM (Intune/Jamf).
Manage and tune EDR/XDR solutions to ensure high-fidelity detection on workstations and servers (Windows, Linux, macOS).
Secure the corporate Azure footprint, ensuring proper configuration of subscriptions, networking, and resources distinct from our production product environment.
Proactively identify and mitigate security risks in our corporate environment, conducting regular security assessments and vulnerability scans.
Coordinate vulnerability management and patch management
Collaborate with IT to automate endpoint compliance checks and remediation workflows.
Security Engineering
Support the development and maintenance of Infrastructure-as-Code.
Ensure hardening and compliance of endpoints and servers.
SaaS Security & Integration
Assess and secure third-party SaaS integrations (e.g., Salesforce apps, browser extensions, productivity tools) to prevent data leakage and over-privileged access.
Collaborate with Legal and Compliance to vet new vendors and tools.
Configure and maintain CASB and DLP policies to safeguard sensitive corporate data without hindering productivity.
Detection, Response & Automation
Lead incident response activities for corporate security events (phishing, malware, lost devices).
Develop automation scripts (Python/Power Shell) and workflows (SOAR) to automate manual security tasks, evidence collection, and response actions.
Proactively hunt for threats within the corporate network and identity providers.
Develop incident response playbooks including technology specific procedures and forensics collection
Audits and Compliance
Design and implement security controls to safeguard corporate resources, including endpoints, data storage, networking, computing and identity and access management.
Support and automate evidence collection for audits.
Culture & Collaboration
Act as the primary security liaison to the IT Department and business teams, helping them build security into their operations (Dev Sec Ops for IT).
Design and deliver technical security training and awareness campaigns for engineering and business teams.
Qualifications
8-15 years of hands-on experience in Corporate Security, IT Security Engineering, or a SOC role in a cloud-first environment.
Endpoint Mastery:
Experience hardening operating systems (macOS/Windows) and managing security via MDM/UEM tools.
Vulnerability management:
Proven experience in helping IT and business teams patching systems and infrastructures.
Coding
Skills:
Proficiency in Python and Terraform for automating APIs and security workflows.
Security Ops:
Proven experience with EDR tools and SIEM log analysis.
Communication:
Fluent in English with the ability to explain complex risks to non-technical stakeholders.
Proven ability to influence and drive…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×