EU remote
IT Infrastructure Security Engineer
About this role
We are looking for an Infrastructure Security Engineer who will engineer and operate the technical security controls protecting Nexthink's corporate infrastructure, spanning non-cloud, cloud, and internal network environments. You will report to the Infrastructure Security Lead, executing the hardening, patching, cloud posture, and segmentation. This role requires a hands-on engineer who is comfortable operating in a fast-moving environment, owning infrastructure security controls end-to-end: designing them, automating them, documenting them, and defending them with security, GRC, and audit stakeholders.
Your main responsibilities will include: Contribute to hardening baselines across the VM fleet (Windows, Linux) Support security controls and initiative for Active Directory, Group Policy, and Microsoft Entra ID Take part in patch automation, helping drive emergency patching coverage to SLA for critical CVEs Contribute to cloud security posture management across Azure and AWS Help implement and maintain policy-as-code for cloud configuration baselines, and support remediation of configuration drift Help implement micro-segmentation policies and trust-model controls Help validate east-west traffic flows and network security control compliance against corporate standards Maintain patch, vulnerability, and configuration evidence to support compliance and certification audits Track and help remediate assigned exceptions and audit findings within defined timelines Take part in internal and external security audits, including evidence gathering, auditor coordination, and control walkthroughs Own technical control documentation and evidence for infrastructure security controls Defend implementation choices with GRC/security teams 4+ years in infrastructure or security engineering, with exposure to both non-cloud and cloud environments Experience hardening Windows Server, Linux, and VMware vSphere and hybrid infrastructure environments Working experience with Active Directory, Group Policy, and Microsoft Entra ID Experience with Azure/AWS security controls Scripting fluency in Python, PowerShell, or Bash with the ability to automate repeatable security and infrastructure tasks Experience with Infrastructure as Code, such as Terraform or Ansible Knowledge of GitHub and GitHub Actions for CI/CD pipelines, with a notion of HashiCorp Vault for secrets management Familiarity with vulnerability management platforms, cloud security certification (Azure/AWS), and ISO/SOC 2 Type 2/FedRAMP exposure are a plus Professional level of spoken and written English, Spanish is a plus Please apply with a copy of your CV in English.