Job Description
Are you the person other engineers come to when a Zero Trust access problem needs solving, not just documenting? We're looking for a Technical Lead to help build out a secure, scalable remote access platform on Microsoft Entra — starting with Entra Private Access — for a large enterprise environment.
The role in short
You'll take technical ownership of a growing Global Secure Access platform, working closely with a Product Owner and cross-functional teams spanning Identity, Network, Endpoint, Security, SOC, Service Desk, and application teams. This isn't a purely architectural role — you'll be hands-on with configuration, troubleshooting, and platform evolution, while also setting the technical direction others follow.
- Location: Södertälje, hybrid
- Applicants must currently reside in Sweden
The assignment is projectbased at our client and will continue till 2027-10-08 with possibilities for extension.
What you'll be doing
- Own the technical design and ongoing development of the Microsoft Entra Global Secure Access platform
- Design and maintain a scalable Entra Private Access setup — connectors, connector groups, high availability, failover, capacity planning, application segmentation, and regional resilience
- Configure and govern application access through Entra ID, security groups, Conditional Access, device compliance, MFA, and Zero Trust principles
- Lead the migration of internal applications from VPN-based access to Private Access
- Analyze application connectivity requirements — DNS, TCP/IP, ports, routing, authentication, TLS
- Set technical standards, configuration baselines, deployment patterns, and rollback procedures
- Monitor platform health: connector availability, capacity, traffic flows, authentication, policy sync
- Lead complex incident resolution and root-cause analysis
- Maintain operational documentation, runbooks, and troubleshooting guides
- Support security assessments, risk reviews, and audit activities
- Coordinate with Microsoft Support and internal platform teams
- Contribute to future expansion, including Entra Internet Access where relevant
- Mentor other engineers and help establish consistent technical practices
- Work within proper change-management and release processes
What we're looking for
Microsoft Entra & Identity
- Strong, hands-on Entra ID experience in a large enterprise setting
- Practical experience with identity-based access control, security groups, application assignments, entitlement models
- Solid understanding of Conditional Access (user, device, location, risk, session-based controls)
- Experience implementing or running MFA and Zero Trust access controls
- Good understanding of device identity/compliance, ideally with Intune and Defender
Global Secure Access & Private Access
- Hands-on experience with Microsoft Entra Global Secure Access, Entra Private Access, or a comparable ZTNA solution
- Practical understanding of Private Network Connectors, connector groups, registration, certificates, outbound connectivity
- Experience designing for high availability, failover, resilience, capacity management
- Ability to troubleshoot traffic forwarding, policy sync, and application connectivity issues
Networking & Application Connectivity
- Strong knowledge of DNS, TCP/IP, routing, firewalls, ports, TLS, HTTP/HTTPS
- Experience troubleshooting connectivity to internal apps, servers, databases, infrastructure services
- Understanding of network segmentation and access control across application/user groups
- Ability to analyze connectivity needs for file services, RDP, engineering tools, databases, enterprise platforms
Operations & Service Management
- Experience running business-critical services in production
- Strong monitoring, logging, incident management, and root-cause analysis skills
- Experience with change/release management, technical documentation, operational handover
- Ability to define support models, runbooks, escalation paths
- Experience working alongside Security Operations/SOC teams during investigations
Technical Leadership & Collaboration
- Track record as a Technical Lead, Platform Lead, or Senior Engineer
- Sound technical decision-making and clear communication to technical and non-technical audiences
- Experience coordinating across Identity, Network, Endpoint, Security, Infrastructure, and application teams
- Strong ownership mentality, comfortable working independently in an evolving product area
- Ability to mentor and set consistent technical standards
Nice to have
- Experience with PAM, PIM, JIT access, and access governance
- Experience with ServiceNow, Jira, or similar ITSM/workflow platforms
- Knowledge of ISO 27001, NIST Zero Trust, DORA, GDPR, or similar frameworks
- Experience with risk assessments (BIA, TVA, IRAM, or comparable)
- Experience supporting both macOS and Windows access scenarios
Who you are
Structured, analytical, and pragmatic — equally comfortable in strategic architecture discussions and hands-on troubleshooting. You proactively spot risks and dependencies, take ownership without waiting to be told, and communicate clearly across technical and non-technical stakeholders. You know how to balance security, user experience, resilience, and delivery speed.