Technical Lead – Microsoft Entra / Global Secure
We at WeQuel are now looking for an experienced Technical Lead – Microsoft Entra / Global Secure Access in Södertälje, where you will become a key part of the IAM team, with a focus on the design, implementation, operation and continued development of Microsoft Entra Global Secure Access, initially Entra Private Access. The assignment combines technical leadership, platform engineering, application onboarding, operational responsibility and complex troubleshooting within a large enterprise environment. You will take a leading technical role in developing a scalable and resilient Global Secure Access platform, and you will also contribute to the maintenance, support and continued development of other functionality within Microsoft Entra.
As a consultant with us, you will have the opportunity to work with one of our clients, who are leading companies within industry, technology and IT security. You will help strengthen secure access, implement Zero Trust solutions and build resilient, sustainable platforms.
Your responsibilities
Ownership of the technical design and continued development of the Microsoft Entra Global Secure Access platformDesign and maintenance of scalable Entra Private Access architecture, covering Private Network Connectors, connector groups, high availability, failover, capacity planning, application segmentation and regional/data-centre resilienceConfiguration and governance of application access through Microsoft Entra ID, security groups, application assignments, Conditional Access, device compliance, MFA and Zero Trust principlesLeading the onboarding and migration of internal applications from VPN and similar solutions to Private AccessAnalysis of application connectivity requirements, including DNS, TCP/IP, ports, routing, authentication and TLSEstablishing technical standards, configuration baselines, deployment patterns and rollback proceduresMonitoring of platform health, connector availability, capacity, traffic flows, authentication and policy synchronisationLeading complex incident resolution, root-cause analysis and problem managementDeveloping and maintaining operational documentation, runbooks, troubleshooting guides and support proceduresSupport for security assessments, risk management, audit activities and service readiness reviewsCoordination of technical activities with Microsoft Support and internal platform teamsContribution to future service expansion, including Entra Internet Access where relevantMentoring of other engineers and promoting knowledge sharing across the organisationImplementing changes through appropriate change-management and release processes
You will work closely with the Product Owner and the wider IAM team, as well as the Network, Endpoint/Client, Security, SOC, Service Desk, infrastructure and application teams. In this role you drive the technical direction independently while collaborating across many interfaces within the organisation.
Requirements
Microsoft Entra & Identity
Strong hands-on experience with Microsoft Entra ID in a large enterprise environmentPractical experience with identity-based access control, security groups, application assignments and entitlement modelsStrong understanding of Conditional Access, including user, device, location, risk and session-based controlsExperience implementing or operating MFA and Zero Trust access controlsGood understanding of device identity and compliance, preferably with Microsoft Intune and Microsoft Defender
Global Secure Access & Private Access
Hands-on experience with Microsoft Entra Global Secure Access, Entra Private Access or a similar ZTNA solutionPractical understanding of Private Network Connectors, connector groups, connector registration, certificates and outbound connectivityExperience designing for high availability, failover, resilience and capacity managementTroubleshooting of traffic forwarding, policy synchronisation and application connectivity
Networking & Application Connectivity
Strong knowledge of DNS, TCP/IP, routing, firewalls, ports, TLS and HTTP/HTTPSExperience troubleshooting connectivity to internal applications, servers, databases or infrastructure servicesUnderstanding of network segmentation and access control for different application and user groupsAnalysis of technical requirements for file services, RDP, engineering tools, databases and enterprise platforms
Operations & Service Management
Experience operating business-critical services in productionStrong skills in monitoring, logging, incident management and root-cause analysisExperience with change management, release management, technical documentation and operational handoverAbility to define support models, runbooks, escalation paths and service-management processesExperience working with Security Operations/SOC teams during investigations and incidents
Technical Leadership & Collaboration
Proven experience as a Technical Lead, Platform Lead or Senior EngineerSound technical decision-making and clear communication to technical and non-technical stakeholdersExperience coordinating across Identity, Network, Endpoint, Security, Infrastructure and application teamsStrong ownership mentality and ability to work independently in a developing product areaAbility to mentor engineers and establish consistent technical ways of working
Language
Fluent English required
Meriting
Privileged access management, PIM, JIT access and access governanceServiceNow, Jira or similar ITSM and workflow platformsKnowledge of ISO 27001, NIST Zero Trust, DORA, GDPR or similar security and compliance frameworksRisk assessments, BIA, TVA, IRAM or comparable information-security processesSupport of macOS and Windows access scenarios
Personal qualities
Structured, analytical and pragmatic, comfortable with both strategic architecture and detailed troubleshootingProactive in identifying risks, dependencies and operational weaknessesComfortable taking ownership and making technical decisions in an evolving product and operating modelClear and confident communicator with technical and non-technical stakeholdersCollaborative and service-oriented, comfortable coordinating across multiple teams and technical domainsAble to balance security, user experience, resilience and delivery speedComfortable mentoring engineers, sharing knowledge and contributing to consistent technical standards
Assignment details
Start: As soon as possibleEnd: Estimated 1-year assignmentLocation: Södertälje, SwedenWorkload: 100% (full-time)Remote: Hybrid, minimum 3 days/week on-site
We offer
At WeQuel, you become part of a consultant team that values people first. We believe success is created through engagement, collaboration and development. We offer a flat organisation with short decision paths, a strong sense of community and the opportunity to shape your own development.
