Nebius Logo

Nebius

Cloud Workplace Engineer

Reposted 27 Days Ago
Remote
Hiring Remotely in United States
Mid level
Remote
Hiring Remotely in United States
Mid level
Design, build, and maintain automation workflows and integrations across Microsoft 365, Google Workspace, and other SaaS platforms using PowerShell, Python, Azure services, and APIs. Automate user management, notifications, data sync, and access workflows while implementing secure logging, monitoring, error handling, and documentation. Collaborate with IT, Security, and business teams to optimize processes and reduce manual work.
The summary above was generated by AI

About Nebius:

Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.

Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.

Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.

About the Role

You own the company's identity provider: who signs in, from where, with which factors, into which applications — and how that access is granted, reviewed, and revoked.

Microsoft Entra ID is the primary identity plane and the center of gravity for the role. Google Workspace, Cloud Identity, and Google Cloud IAM form a second substantial domain, and you own the federation and provisioning path between them. Microsoft 365 is in scope for tenant, licensing, and access administration.

You are the escalation point for identity incidents from operations, security, service desk, and application teams — expected to resolve them, not route them onward.

What You'll Own

Microsoft Entra ID and Microsoft 365

  • Users, dynamic and assigned groups, administrative units, directory roles, service principals, workload identities.
  • Conditional Access design and rollout: named locations, client app and platform conditions, session controls, sign-in frequency, break-glass exclusions, report-only staging.
  • Authentication methods policy and phishing-resistant factors.
  • Application onboarding over SAML 2.0 (NameID, claims mapping, signing certificate rollover, encrypted assertions) and OIDC / OAuth 2.0 (authorization code with PKCE, client credentials, device code).
  • App registrations: redirect URIs, permissions, admin consent workflow, secret and certificate lifecycle. – SCIM 2.0 provisioning: attribute mappings, scoping filters, expression transformations, quarantined jobs, drift reconciliation.
  • Tenant consent settings, OAuth grant review, remediation of over-permissioned and stale applications; defensible controls for SaaS without SSO or SCIM support.
  • Joiner-mover-leaver as an automated pipeline: provisioning, group-based licensing, revocation with session and refresh token invalidation.
  • Least privilege for admin access: scoped role assignments, RBAC, PIM, access reviews, entitlement management access packages.
  • Service account and workload identity governance: ownership, credential rotation, permission scoping, decommissioning.
  • Microsoft 365 tenant settings, licensing, admin roles; access and permission issues in Exchange Online, SharePoint Online, Power Platform.
  • Diagnostics from sign-in, audit, and provisioning logs, with diagnostic settings routed to Log Analytics and KQL queries.
  • Cross-tenant access settings and B2B external collaboration.

Google Workspace, Cloud Identity, and Google Cloud

  • Google Workspace and Cloud Identity: users, groups, organizational units, admin roles and privileges, licensing, 2-Step Verification enforcement, session controls.
  • Third-party SSO profiles with Microsoft Entra ID as SAML IdP, automated provisioning into Cloud Identity, OU- and group-scoped SSO exclusions.
  • Context-Aware Access policies, third-party OAuth app access control, domain-wide delegation, Drive sharing and external access controls. 2
  • Google Cloud IAM: project and folder membership, predefined and custom roles, allow policies, service accounts and key hygiene, workload identity federation, API enablement, OAuth clients.

Automation 

  • PowerShell tooling on the Microsoft Graph PowerShell SDK and Graph REST API: lifecycle, licensing, access reporting, recertification.
  • Google-side automation through the Admin SDK Directory API, Cloud Identity API, and gcloud.
  • Scheduled and event-driven workflows in Azure Automation Runbooks, Azure Logic Apps, or Power Automate.
  • Unattended execution on managed identities and narrowly scoped app registrations, with credential rotation, structured logging, error handling, and retries.
  • Automation treated as production code: version control, peer review, documented rollback.

What You'll Bring

We care about what you can do, not which products appear on your CV. Concretely, you can:

  • Decode a SAML assertion or JWT and pinpoint the failure — audience mismatch, NameID format, expired signing certificate, missing claim — without escalating to the vendor.
  • Diagnose a failing SCIM job and tell scoping from attribute mapping, transformation expressions, or target schema.
  • Replace a manual lifecycle process with automation that logs, retries, and can be handed to someone else to run.

Experience We Expect

  • 3+ years administering Microsoft Entra ID in production as a primary responsibility.
  • Enterprise applications, app registrations, consent and permission models, automated provisioning.
  • Microsoft 365 administration: tenant settings, licensing, admin roles, and access troubleshooting across Exchange Online, SharePoint Online, and Power Platform.
  • Google Workspace and Cloud Identity administration: organizational units, groups, admin roles, SSO profiles, access settings.
  • Google Cloud IAM: projects, roles and policies, service accounts, API access, OAuth credentials.
  • Strong PowerShell with the Microsoft Graph PowerShell SDK and direct REST API work.
  • Azure Automation Runbooks, Azure Logic Apps, Power Automate, or comparable platforms.
  • Least privilege, secure administration, change management, and the discipline to leave configurations documented.
  • Written and spoken English at B2 or higher

Nice to Have

  • SC-300, MS-102, or SC-401 — or equivalent demonstrable expertise.
  • Microsoft Entra ID Governance: entitlement management, lifecycle workflows, Privileged Identity Management.
  • Microsoft Purview (DLP, retention, eDiscovery), Microsoft Defender for Cloud Apps, or Microsoft Sentinel.
  • Google Cloud workload identity federation, custom roles, organization policy constraints.
  • Git, CI/CD practices, Pester, Bicep, or Terraform.
  • Access evidence for SOC 2, ISO 27001, or comparable audit cycles.

Benefits & Perks:

  • Competitive compensation
  • Career growth and learning opportunities
  • Flexibility and ownership
  • Collaborative and innovative culture
  • Opportunity to work on impactful AI projects
  • International environment and talented teams

What's it like to work at Nebius:

Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI 

Equal Opportunity Statement:

Nebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.

Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire. 

If you need accommodations during the application process, please let us know.

Similar Jobs

8 Minutes Ago
Easy Apply
Remote
United States
Easy Apply
53K-75K Annually
Entry level
53K-75K Annually
Entry level
Cloud • Security • Software • Cybersecurity • Automation
Generates qualified meetings and sales pipeline through inbound lead management, account research, discovery conversations, and multichannel outreach. Collaborates with marketing and sales teams to develop target lists, messaging, and call strategies. Tracks activities in Salesforce and Outreach.io, reports results, documents processes, and mentors new SDRs. The role is fully remote and includes onboarding and training in GitLab and DevOps.
Top Skills: DevsecopsGitlabOutreach.IoSalesforce
8 Minutes Ago
Easy Apply
Remote
United States
Easy Apply
223K-380K Annually
Expert/Leader
223K-380K Annually
Expert/Leader
Cloud • Security • Software • Cybersecurity • Automation
Provide technical direction for GitLab Dedicated, a managed single-tenant SaaS platform. Lead architecture and transformation across resilience, failover, tenant orchestration, change management, automation, and platform integrations. Identify systemic reliability and scalability risks, establish reusable platform patterns, strengthen service ownership, and guide cross-team technical decisions. Mentor senior engineers and advance engineering excellence across the organization.
Top Skills: Cloud InfrastructureDevsecopsDistributed SystemsGoInfrastructure As CodeObservabilityPythonRuby
19 Minutes Ago
In-Office or Remote
109K-251K Annually
Senior level
109K-251K Annually
Senior level
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Field-based specialty pharmaceutical sales role promoting rare cardiac therapies across an assigned territory. Responsibilities include engaging cardiology healthcare professionals, building compliant customer relationships, delivering approved product and disease-state messaging, supporting patient access and reimbursement navigation, identifying referral opportunities, and collaborating with cross-functional teams. The role requires territory travel, strategic account planning, digital engagement, and expertise in complex cardiac diseases, biologics, and specialty reimbursement.
Top Skills: Veeva EngageZoom

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account