IT Security Specialist - 19718
Huy Tran
HR Administrator
Efterfrågade kompetenser
Om tjänsten
Role Summary
An experienced Technical Lead for Microsoft Entra Global Secure Access is needed to design, implement, operate and continuously develop a scalable, secure and resilient enterprise access platform. The initial focus will be on Microsoft Entra Private Access, supporting the migration of internal applications from VPN-based and similar access solutions to a Zero Trust Network Access model.
The assignment combines technical leadership, platform engineering, application onboarding, operational ownership and advanced troubleshooting within a large enterprise environment. You will work closely with the Product Owner, IAM function and stakeholders across Network, Endpoint, Security, SOC, Service Desk, Infrastructure and application teams.
Key Responsibilities
- Own the technical design, architecture and continued development of the Microsoft Entra Global Secure Access platform, with emphasis on Entra Private Access.
- Design and maintain Private Network Connector architecture, connector groups, connector registration, certificates, outbound connectivity, high availability, failover, regional resilience and capacity management.
- Configure and govern application access through Microsoft Entra ID, including application assignments, security groups, entitlement models, Conditional Access, device compliance and multifactor authentication.
- Lead the onboarding and migration of internal applications from VPN and comparable solutions to Entra Private Access.
- Analyse application connectivity and authentication requirements, including DNS, TCP/IP, routing, ports, TLS and HTTP/HTTPS dependencies.
- Define technical standards, configuration baselines, deployment patterns, rollback procedures, support models and escalation paths.
- Monitor platform health, connector availability, capacity, traffic flows and policy synchronisation, and lead complex incident resolution, root-cause analysis and problem management.
- Maintain operational documentation, runbooks and troubleshooting guides, and support operational handover and service-readiness activities.
- Coordinate technical activities with Microsoft Support, internal platform teams and Security Operations during investigations and incidents.
- Contribute to the future evolution of the service, including Microsoft Entra Internet Access where relevant, and mentor engineers to establish consistent technical practices.
Technical Stack & Requirements
- Strong hands-on experience with Microsoft Entra ID in large enterprise environments.
- Practical experience with Microsoft Entra Global Secure Access, Entra Private Access or a comparable Zero Trust Network Access solution.
- Deep knowledge of Conditional Access, including user-, device-, location-, risk- and session-based controls.
- Experience with multifactor authentication, identity-based access control, application assignments, security groups and entitlement models.
- Knowledge of device identity and compliance, preferably using Microsoft Intune and Microsoft Defender.
- Strong networking knowledge covering DNS, TCP/IP, routing, firewalls, ports, TLS, HTTP/HTTPS, traffic forwarding and network segmentation.
- Experience operating production-critical services, including monitoring, logging, incident management, release management and change management.
- Experience with ServiceNow, Jira or comparable IT service-management and workflow platforms is advantageous.
Qualifications & Experience
You should have experience working as a Technical Lead, Platform Lead or Senior Engineer in an identity, security or enterprise platform environment. The role requires the ability to make technically sound decisions, communicate clearly with technical and non-technical stakeholders, and coordinate work across multiple engineering teams.
Experience with privileged access management, Privileged Identity Management (PIM), just-in-time access and access governance is advantageous. Familiarity with ISO 27001, NIST Zero Trust, DORA, GDPR and comparable security or compliance frameworks is considered beneficial. Experience with risk assessments, Business Impact Analysis (BIA), Threat and Vulnerability Assessment (TVA), IRAM or similar information-security processes is also valued. Exposure to Windows and macOS access scenarios is beneficial.
The successful consultant is structured, analytical and pragmatic, with the ability to balance security, resilience, user experience and delivery speed while identifying technical risks, dependencies and operational weaknesses.