Security Specialist: IAM, API Security & Penetration Testing

Göteborg
Behovsanställning
Sista ansökningsdag:
2027-02-13
Publicerad:
2026-08-17

Om jobbet

Cyber Instincts is a Gothenburg-based cybersecurity consultancy helping organizations build digital resilience across IT, OT, and automotive environments. We work with clients in automotive, manufacturing, banking and finance, retail, and healthcare, offering everything from penetration testing to Cybersecurity-as-a-Service. We're building our bench for upcoming client engagements across three specific areas: Identity & Access Management (IAM), API and application security, and penetration testing. If you work in one or more of these areas we want to hear from you.

Whether you specialize in one of these areas or bring broader security experience across several you are welcome to apply.

Identity & Access Management (IAM)

• Hands-on experience with IAM platforms such as Entra ID / Azure AD, Okta, Ping Identity, or SailPoint

• Experience designing or managing access control models (RBAC/ABAC), SSO, MFA, and privileged access management (PAM)

• Familiarity with provisioning and deprovisioning workflows and identity governance in enterprise environments

API & Application Security

• Practical experience testing or securing REST/GraphQL APIs, including authentication flows, authorization logic, rate limiting, and input validation

• Hands-on use of tools such as Burp Suite, Postman, or OWASP ZAP

• Solid grasp of the OWASP API Security Top 10 and OWASP Top 10, and the ability to translate findings into remediation guidance developers can act on

Penetration Testing

• Experience running or assisting web application, network, or infrastructure penetration tests

• Comfortable with tools such as Burp Suite, Nmap, Metasploit, or Nessus

• CTF experience (Hack The Box, TryHackMe, PortSwigger Web Security Academy) or a home lab counts just as much as job experience

Across all tracks, we're looking for:

• At least 1 to 2 years of hands-on experience in your area, gained through work, internships, or serious self-driven practice

• Comfort working in Linux and/or Windows environments, with solid networking fundamentals

• Certifications are a plus, not a requirement. Examples include CEH, eJPT, OSCP, CompTIA Security+, or relevant IAM vendor certifications

• Clear written and verbal communication: you'll need to explain findings to both engineers and non-technical stakeholders

• Discretion and a strong ethical grounding, as you'll be working inside client systems and sensitive data

This is a Sweden-based role, with placements at client sites across the country. You'll be employed or engaged on a freelance basis and placed directly with us based at our clients for the duration of each engagement.