Security Specialist: IAM, API Security & Penetration Testing

Cyber Instincts AB · Göteborg

Don’t apply blind. See how your CV matches Security first — free, in 30 seconds.

You will leave NewLuxJob. We do not receive or handle applications.

Company
Cyber Instincts AB
Location
Göteborg
Employment type
Contract
Posted
August 17, 2026

About this job

Cyber Instincts is a Gothenburg-based cybersecurity consultancy helping organizations build digital resilience across IT, OT, and automotive environments. We work with clients in automotive, manufacturing, banking and finance, retail, and healthcare, offering everything from penetration testing to Cybersecurity-as-a-Service. We're building our bench for upcoming client engagements across three specific areas: Identity & Access Management (IAM), API and application security, and penetration testing. If you work in one or more of these areas we want to hear from you. Whether you specialize in one of these areas or bring broader security experience across several you are welcome to apply. Identity & Access Management (IAM) • Hands-on experience with IAM platforms such as Entra ID / Azure AD, Okta, Ping Identity, or SailPoint • Experience designing or managing access control models (RBAC/ABAC), SSO, MFA, and privileged access management (PAM) • Familiarity with provisioning and deprovisioning workflows and identity governance in enterprise environments API & Application Security • Practical experience testing or securing REST/GraphQL APIs, including authentication flows, authorization logic, rate limiting, and input validation • Hands-on use of tools such as Burp Suite, Postman, or OWASP ZAP • Solid grasp of the OWASP API Security Top 10 and OWASP Top 10, and the ability to translate findings into remediation guidance developers can act on Penetration Testing • Experience running or assisting web application, network, or infrastructure penetration tests • Comfortable with tools such as Burp Suite, Nmap, Metasploit, or Nessus • CTF experience (Hack The Box, TryHackMe, PortSwigger Web Security Academy) or a home lab counts just as much as job experience Across all tracks, we're looking for: • At least 1 to 2 years of hands-on experience in your area, gained through work, internships, or serious self-driven practice • Comfort working in Linux and/or Windows environments, with solid networking fundamentals • Certifications are a plus, not a requirement. Examples include CEH, eJPT, OSCP, CompTIA Security+, or relevant IAM vendor certifications • Clear written and verbal communication: you'll need to explain findings to both engineers and non-technical stakeholders • Discretion and a strong ethical grounding, as you'll be working inside client systems and sensitive data This is a Sweden-based role, with placements at client sites across the country. You'll be employed or engaged on a freelance basis and placed directly with us based at our clients for the duration of each engagement.

Want to know if you're a fit? Check your CV against this role — free, in 30 seconds.

Most-requested skills in Sweden

Based on 137 Sweden vacancies that list requirements, these are the skills employers ask for most often.

  • Reporting89% of postings
  • CCTV11% of postings
  • Access Control9% of postings
  • First Aid1% of postings
  • Patrol1% of postings
Security skills

Similar jobs

See if your CV fits this job

Paste your CV for an instant match score against this role — and get a tailored cover letter in one click.

  • Instant match score for this role
  • Tailored cover letter in one click
  • Free — no credit card
Check my CV — free