About the job
As a Senior Corporate Security Engineer at Nexthink, you will play a pivotal role in safeguarding our internal environment. Your responsibilities will extend beyond mere log monitoring to architecting a robust security framework that supports our rapid growth.
In collaboration with IT, business units, and our Cloud and Application Security teams, you will fortify the identity, devices, and applications utilized by Nexthinkers globally. You will take ownership of the security within a complex SaaS ecosystem and spearhead detection and response initiatives for the corporate environment.
Your Key Responsibilities:
Identity-Centric Security Architecture:
- Contribute to the design and assist in implementing passwordless authentication and Zero Trust principles.
- Oversee secure provisioning and lifecycle management, ensuring least-privilege access across all business systems.
- Collaborate with HR and IT to enhance onboarding/offboarding workflows, ensuring prompt access revocation and accountability.
Endpoint & Infrastructure Security:
- Establish and enforce security standards for our diverse fleet of endpoints (Windows, macOS) and mobile devices through MDM (Intune/Jamf).
- Manage and optimize EDR/XDR solutions for high-fidelity detection across workstations and servers (Windows, Linux, macOS).
- Secure our corporate Azure environment, ensuring proper configuration of subscriptions, networking, and resources separate from our production environment.
- Proactively identify and mitigate security vulnerabilities in our corporate landscape, conducting regular assessments and scans.
- Coordinate vulnerability management and patching processes.
- Work with IT to automate compliance checks and remediation workflows for endpoints.
Security Engineering:
- Support the development and upkeep of Infrastructure-as-Code.
- Ensure that endpoints and servers are hardened and compliant.
SaaS Security & Integration:
- Evaluate and secure third-party SaaS integrations (e.g., Salesforce apps, browser extensions, productivity tools) to prevent data leakage and unauthorized access.
- Collaborate with Legal and Compliance to assess new vendors and tools.
- Configure and maintain CASB and DLP policies to protect sensitive corporate data while maintaining productivity.
Detection, Response & Automation:
- Lead incident response activities for corporate security events (e.g., phishing, malware, lost devices).

