Nebius logo
Nebius
Posted 11 days agoVerified live 2d ago

Cloud Workplace Engineer

Brief overview

Remote
MastersOr in progress
3+ yrsMinimum
Microsoft Entra ID AdministrationMicrosoft 365 AdministrationGoogle Workspace and Cloud Identity AdministrationGoogle Cloud IAMPowerShell and Microsoft Graph APISAML 2.0OIDC and OAuth 2.0SCIM 2.0 ProvisioningIdentity Lifecycle Automation

About the company

The Nebius AI Cloud brings powerful full-stack infrastructure for AI developers and practitioners across startups, enterprises and science institutes to build and deploy generative AI applications and rapidly deliver scientific breakthroughs by training and running ML models within a secure, high-performance, and cost-optimized cloud environment.

Job description

Summary

Nebius is building a full-stack AI cloud platform for developers and enterprises. The Cloud Workplace Engineer will own the company’s identity provider and access lifecycle across Microsoft Entra ID, Microsoft 365, Google Workspace, Cloud Identity, and Google Cloud IAM, while serving as the escalation point for identity incidents and developing secure automation.

Responsibilities

  • Users, dynamic and assigned groups, administrative units, directory roles, service principals, workload identities
  • Conditional Access design and rollout: named locations, client app and platform conditions, session controls, sign-in frequency, break-glass exclusions, report-only staging
  • Authentication methods policy and phishing-resistant factors
  • Application onboarding over SAML 2.0 (NameID, claims mapping, signing certificate rollover, encrypted assertions) and OIDC / OAuth 2.0 (authorization code with PKCE, client credentials, device code)
  • App registrations: redirect URIs, permissions, admin consent workflow, secret and certificate lifecycle. – SCIM 2.0 provisioning: attribute mappings, scoping filters, expression transformations, quarantined jobs, drift reconciliation
  • Tenant consent settings, OAuth grant review, remediation of over-permissioned and stale applications; defensible controls for SaaS without SSO or SCIM support
  • Joiner-mover-leaver as an automated pipeline: provisioning, group-based licensing, revocation with session and refresh token invalidation
  • Least privilege for admin access: scoped role assignments, RBAC, PIM, access reviews, entitlement management access packages
  • Service account and workload identity governance: ownership, credential rotation, permission scoping, decommissioning
  • Microsoft 365 tenant settings, licensing, admin roles; access and permission issues in Exchange Online, SharePoint Online, Power Platform
  • Diagnostics from sign-in, audit, and provisioning logs, with diagnostic settings routed to Log Analytics and KQL queries
  • Cross-tenant access settings and B2B external collaboration
  • Google Workspace and Cloud Identity: users, groups, organizational units, admin roles and privileges, licensing, 2-Step Verification enforcement, session controls
  • Third-party SSO profiles with Microsoft Entra ID as SAML IdP, automated provisioning into Cloud Identity, OU- and group-scoped SSO exclusions
  • Context-Aware Access policies, third-party OAuth app access control, domain-wide delegation, Drive sharing and external access controls. 2
  • Google Cloud IAM: project and folder membership, predefined and custom roles, allow policies, service accounts and key hygiene, workload identity federation, API enablement, OAuth clients
  • PowerShell tooling on the Microsoft Graph PowerShell SDK and Graph REST API: lifecycle, licensing, access reporting, recertification
  • Google-side automation through the Admin SDK Directory API, Cloud Identity API, and gcloud
  • Scheduled and event-driven workflows in Azure Automation Runbooks, Azure Logic Apps, or Power Automate
  • Unattended execution on managed identities and narrowly scoped app registrations, with credential rotation, structured logging, error handling, and retries
  • Automation treated as production code: version control, peer review, documented rollback

Skills

  • * Decode a SAML assertion or JWT and pinpoint the failure — audience mismatch, NameID format, expired signing certificate, missing claim — without escalating to the vendor
  • * Diagnose a failing SCIM job and tell scoping from attribute mapping, transformation expressions, or target schema
  • * Replace a manual lifecycle process with automation that logs, retries, and can be handed to someone else to run
  • * 3+ years administering Microsoft Entra ID in production as a primary responsibility
  • * Enterprise applications, app registrations, consent and permission models, automated provisioning
  • * Microsoft 365 administration: tenant settings, licensing, admin roles, and access troubleshooting across Exchange Online, SharePoint Online, and Power Platform
  • * Google Workspace and Cloud Identity administration: organizational units, groups, admin roles, SSO profiles, access settings
  • * Google Cloud IAM: projects, roles and policies, service accounts, API access, OAuth credentials
  • * Strong PowerShell with the Microsoft Graph PowerShell SDK and direct REST API work
  • * Azure Automation Runbooks, Azure Logic Apps, Power Automate, or comparable platforms
  • * Least privilege, secure administration, change management, and the discipline to leave configurations documented
  • * Written and spoken English at B2 or higher
  • Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire
  • * SC-300, MS-102, or SC-401 — or equivalent demonstrable expertise
  • * Microsoft Entra ID Governance: entitlement management, lifecycle workflows, Privileged Identity Management
  • * Microsoft Purview (DLP, retention, eDiscovery), Microsoft Defender for Cloud Apps, or Microsoft Sentinel
  • * Google Cloud workload identity federation, custom roles, organization policy constraints
  • * Git, CI/CD practices, Pester, Bicep, or Terraform
  • * Access evidence for SOC 2, ISO 27001, or comparable audit cycles

Qualifications

Must Haves

  • * Decode a SAML assertion or JWT and pinpoint the failure — audience mismatch, NameID format, expired signing certificate, missing claim — without escalating to the vendor
  • * Diagnose a failing SCIM job and tell scoping from attribute mapping, transformation expressions, or target schema
  • * Replace a manual lifecycle process with automation that logs, retries, and can be handed to someone else to run
  • * 3+ years administering Microsoft Entra ID in production as a primary responsibility
  • * Enterprise applications, app registrations, consent and permission models, automated provisioning
  • * Microsoft 365 administration: tenant settings, licensing, admin roles, and access troubleshooting across Exchange Online, SharePoint Online, and Power Platform
  • * Google Workspace and Cloud Identity administration: organizational units, groups, admin roles, SSO profiles, access settings
  • * Google Cloud IAM: projects, roles and policies, service accounts, API access, OAuth credentials
  • * Strong PowerShell with the Microsoft Graph PowerShell SDK and direct REST API work
  • * Azure Automation Runbooks, Azure Logic Apps, Power Automate, or comparable platforms
  • * Least privilege, secure administration, change management, and the discipline to leave configurations documented
  • * Written and spoken English at B2 or higher
  • Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire

Nice to Haves

  • * SC-300, MS-102, or SC-401 — or equivalent demonstrable expertise
  • * Microsoft Entra ID Governance: entitlement management, lifecycle workflows, Privileged Identity Management
  • * Microsoft Purview (DLP, retention, eDiscovery), Microsoft Defender for Cloud Apps, or Microsoft Sentinel
  • * Google Cloud workload identity federation, custom roles, organization policy constraints
  • * Git, CI/CD practices, Pester, Bicep, or Terraform
  • * Access evidence for SOC 2, ISO 27001, or comparable audit cycles

Benefits

  • Career growth and learning opportunities
  • Flexibility and ownership
  • Collaborative and innovative culture
  • Opportunity to work on impactful AI projects
  • International environment and talented teams

More jobs like this