← Back to your search

Cyber Instincts AB

Technical Lead – Identity & Secure Access (Microsoft Entra)

Security

Employment

Not stated

Level

Lead

Team

Cyber Security
Not doable from Austria

Country assessment

Not doable from Austria because the employer's own board marks it as not remote.

Our assessment is guidance. Confirm arrangements with the employer.

Job description

Are you the person other engineers come to when a Zero Trust access problem needs solving, not just documenting? We're looking for a Technical Lead to help build out a secure, scalable remote access platform on Microsoft Entra — starting with Entra Private Access — for a large enterprise environment.

The role in short

You'll take technical ownership of a growing Global Secure Access platform, working closely with a Product Owner and cross-functional teams spanning Identity, Network, Endpoint, Security, SOC, Service Desk, and application teams. This isn't a purely architectural role — you'll be hands-on with configuration, troubleshooting, and platform evolution, while also setting the technical direction others follow.

  • Location: Södertälje, hybrid

  • Applicants must currently reside in Sweden

The assignment is projectbased at our client and will continue till 2027-10-08 with possibilities for extension.

What you'll be doing

  • Own the technical design and ongoing development of the Microsoft Entra Global Secure Access platform

  • Design and maintain a scalable Entra Private Access setup — connectors, connector groups, high availability, failover, capacity planning, application segmentation, and regional resilience

  • Configure and govern application access through Entra ID, security groups, Conditional Access, device compliance, MFA, and Zero Trust principles

  • Lead the migration of internal applications from VPN-based access to Private Access

  • Analyze application connectivity requirements — DNS, TCP/IP, ports, routing, authentication, TLS

  • Set technical standards, configuration baselines, deployment patterns, and rollback procedures

  • Monitor platform health: connector availability, capacity, traffic flows, authentication, policy sync

  • Lead complex incident resolution and root-cause analysis

  • Maintain operational documentation, runbooks, and troubleshooting guides

  • Support security assessments, risk reviews, and audit activities

  • Coordinate with Microsoft Support and internal platform teams

  • Contribute to future expansion, including Entra Internet Access where relevant

  • Mentor other engineers and help establish consistent technical practices

  • Work within proper change-management and release processes

What we're looking for

Microsoft Entra & Identity

  • Strong, hands-on Entra ID experience in a large enterprise setting

  • Practical experience with identity-based access control, security groups, application assignments, entitlement models

  • Solid understanding of Conditional Access (user, device, location, risk, session-based controls)

  • Experience implementing or running MFA and Zero Trust access controls

  • Good understanding of device identity/compliance, ideally with Intune and Defender

Global Secure Access & Private Access

  • Hands-on experience with Microsoft Entra Global Secure Access, Entra Private Access, or a comparable ZTNA solution

  • Practical understanding of Private Network Connectors, connector groups, registration, certificates, outbound connectivity

  • Experience designing for high availability, failover, resilience, capacity management

  • Ability to troubleshoot traffic forwarding, policy sync, and application connectivity issues

Networking & Application Connectivity

  • Strong knowledge of DNS, TCP/IP, routing, firewalls, ports, TLS, HTTP/HTTPS

  • Experience troubleshooting connectivity to internal apps, servers, databases, infrastructure services

  • Understanding of network segmentation and access control across application/user groups

  • Ability to analyze connectivity needs for file services, RDP, engineering tools, databases, enterprise platforms

Operations & Service Management

  • Experience running business-critical services in production

  • Strong monitoring, logging, incident management, and root-cause analysis skills

  • Experience with change/release management, technical documentation, operational handover

  • Ability to define support models, runbooks, escalation paths

  • Experience working alongside Security Operations/SOC teams during investigations

Technical Leadership & Collaboration

  • Track record as a Technical Lead, Platform Lead, or Senior Engineer

  • Sound technical decision-making and clear communication to technical and non-technical audiences

  • Experience coordinating across Identity, Network, Endpoint, Security, Infrastructure, and application teams

  • Strong ownership mentality, comfortable working independently in an evolving product area

  • Ability to mentor and set consistent technical standards

Nice to have

  • Experience with PAM, PIM, JIT access, and access governance

  • Experience with ServiceNow, Jira, or similar ITSM/workflow platforms

  • Knowledge of ISO 27001, NIST Zero Trust, DORA, GDPR, or similar frameworks

  • Experience with risk assessments (BIA, TVA, IRAM, or comparable)

  • Experience supporting both macOS and Windows access scenarios

Who you are

Structured, analytical, and pragmatic — equally comfortable in strategic architecture discussions and hands-on troubleshooting. You proactively spot risks and dependencies, take ownership without waiting to be told, and communicate clearly across technical and non-technical stakeholders. You know how to balance security, user experience, resilience, and delivery speed.