Responsibilities
- Own the technical design and continued development of the Microsoft Entra Global Secure Access platform.
- Design and maintain scalable Entra Private Access architecture, including Private Network Connectors, connector groups, high availability, failover, capacity planning, application segmentation, and regional/data-centre resilience.
- Configure and govern access to applications using Microsoft Entra ID, security groups and application assignments, Conditional Access, device compliance, multifactor authentication, and Zero Trust principles.
- Lead the onboarding and migration of internal applications from VPN and similar solutions to Private Access.
- Analyse application connectivity requirements, including DNS, TCP/IP, ports, routing, authentication, and TLS.
- Establish technical standards, configuration baselines, deployment patterns, and rollback procedures.
- Monitor platform health, connector availability, capacity, traffic flows, authentication, and policy synchronisation.
- Lead complex incident resolution, root-cause analysis, and problem management.
- Develop and maintain operational documentation, runbooks, troubleshooting guides, and support procedures.
- Support security assessments, risk management, audit activities, and service readiness reviews.
- Coordinate technical activities with Microsoft Support and internal platform teams.
- Contribute to future expansion of the service, including Entra Internet Access where relevant.
- Mentor other engineers and promote knowledge sharing across the organisation.
- Ensure changes are implemented through appropriate change-management and release processes.
Required Skills
Microsoft Entra & Identity
- Strong hands-on experience with Microsoft Entra ID in a large enterprise environment.
- Practical experience with identity-based access control, security groups, application assignments, and entitlement models.
- Strong understanding of Conditional Access, including user, device, location, risk, and session-based controls.
- Experience implementing or operating multifactor authentication and Zero Trust access controls.
- Good understanding of device identity and compliance, preferably involving Microsoft Intune and Microsoft Defender.
Global Secure Access & Private Access
- Hands-on experience with Microsoft Entra Global Secure Access, Entra Private Access, or a similar Zero Trust Network Access (ZTNA) solution.
- Practical understanding of Private Network Connectors, connector groups, connector registration, certificates, and outbound connectivity.
- Experience designing for high availability, failover, resilience, and capacity management.
- Ability to troubleshoot traffic forwarding, policy synchronisation, and application connectivity issues.
Networking & Application Connectivity
- Strong knowledge of DNS, TCP/IP, routing, firewalls, ports, TLS, and HTTP/HTTPS.
- Experience troubleshooting connectivity to internal applications, servers, databases, or infrastructure services.
- Understanding of network segmentation and access control for different application and user groups.
- Ability to analyse technical requirements for applications such as file services, RDP, engineering tools, databases, and enterprise platforms.
Operations & Service Management
- Experience operating business-critical services in production.
- Strong skills in monitoring, logging, incident management, and root-cause analysis.
- Experience with change management, release management, technical documentation, and operational handover.
- Ability to define support models, runbooks, escalation paths, and service-management processes.
- Experience working with Security Operations or SOC teams during investigations and incidents.
Technical Leadership & Collaboration
- Demonstrated experience as a Technical Lead, Platform Lead, or Senior Engineer.
- Ability to make sound technical decisions and communicate them clearly to technical and non-technical stakeholders.
- Experience coordinating work across Identity, Network, Endpoint, Security, Infrastructure, and application teams.
- Strong ownership mentality and ability to work independently in a developing product area.
- Ability to mentor engineers and establish consistent technical ways of working.
Desired Skills
- Experience with privileged access management, PIM, JIT access, and access governance.
- Experience with ServiceNow, Jira, or similar IT service-management and workflow platforms.
- Knowledge of ISO 27001, NIST Zero Trust, DORA, GDPR, or similar security and compliance frameworks.
- Experience with risk assessments, BIA, TVA, IRAM, or comparable information-security processes.
- Experience supporting macOS and Windows access scenarios.