
IT Infrastructure Security Engineer
Hover or tap a row for full statistics (EUR / month on this chart).
Salary analysis
Compared with the selected benchmark ("All roles in Madrid, Spain"), this listing's salary midpoint is about 62% lower. The offer still falls within the benchmark range (€3,324–€15,737). The listed pay band (€2,750–€4,583) is tighter than the benchmark, which suggests lower salary variability. This benchmark is based on 17 comparable listings.
| Market | Lower bound (25th percentile) | Median | Upper bound (75th percentile) |
|---|---|---|---|
| All roles in Madrid, Spain | €3,324/per month | €7,003/per month | €15,737/per month |
| From job ad (Mid-Level) | €2,750/per month | €3,667/per month | €4,583/per month |
IT Infrastructure Security Engineer at Nexthink is responsible for engineering and operating the technical security controls protecting Nexthink's corporate infrastructure, spanning non-cloud, cloud, and internal network environments. You will report to the Infrastructure Security Lead, executing the hardening, patching, cloud posture, and segmentation. Your main responsibilities include: Contribute to hardening baselines across the VM fleet (Windows, Linux); Support AD, GP, and Microsoft Entra ID; Patch automation; Cloud security posture across Azure and AWS; Policy-as-code; Micro-segmentation; East-west traffic validation; Patch, vulnerability, configuration evidence; Remediation of exceptions and audits; Participate in security audits. Qualifications: 4+ years in infra or security engineering; Windows/Linux/vSphere; AD/GP/Entra ID; Azure/AWS security; Scripting (Python/PowerShell/Bash); IaC (Terraform/Ansible); GitHub Actions; Vulnerability management; English required, Spanish a plus. Apply with CV in English. Additional info about the company and benefits, salary range €33k–€49k base, €36k–€54k OTE, hybrid work, etc.
Job Details
Responsibilities
- Contribute to hardening baselines across the VM fleet (Windows, Linux)
- Support security controls and initiative for Active Directory, Group Policy, and Microsoft Entra ID
- Take part in patch automation
- Contribute to cloud security posture management across Azure and AWS
- Help implement policy-as-code for cloud configuration baselines, and support remediation of configuration drift
- Help implement micro-segmentation policies and trust-model controls
- Help validate east-west traffic flows and network security control compliance
- Maintain patch, vulnerability, and configuration evidence to support compliance and audits
- Track and remediate assigned exceptions and audit findings
- Take part in internal and external security audits
Skills & Technologies

Related Opportunities
Discover more opportunities that match your interests and skills