Identity & Workplace Engineer
Nebius
- Location
- Remote - United States
- Work model
- Remote
- Level
- Mid
- Posted
- 1h ago
Skills
About this role
About Nebius
Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.
Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.
Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.
About the Role
You own the company's identity provider: who signs in, from where, with which factors, into which applications — and how that access is granted, reviewed, and revoked.
Microsoft Entra ID is the primary identity plane and the center of gravity for the role. Google Workspace, Cloud Identity, and Google Cloud IAM form a second substantial domain, and you own the federation and provisioning path between them. Microsoft 365 is in scope for tenant, licensing, and access administration.
You are the escalation point for identity incidents from operations, security, service desk, and application teams — expected to resolve them, not route them onward.
What You'll Own
Microsoft Entra ID and Microsoft 365
• Users, dynamic and assigned groups, administrative units, directory roles, service principals, workload identities.
• Conditional Access design and rollout: named locations, client app and platform conditions, session controls, sign-in frequency, break-glass exclusions, report-only staging.
• Authentication methods policy and phishing-resistant factors.
• Application onboarding over SAML 2.0 (NameID, claims mapping, signing certificate rollover, encrypted assertions) and OIDC / OAuth 2.0 (authorization code with PKCE, client credentials, device code).
• App registrations: redirect URIs, permissions, admin consent workflow, secret and certificate lifecycle. – SCIM 2.0 provisioning: attribute mappings, scoping filters, expression transformations, quarantined jobs, drift reconciliation.
• Tenant consent settings, OAuth grant review, remediation of over-permissioned and stale applications; defensible controls for SaaS without SSO or SCIM support.
• Joiner-mover-leaver as an automated pipeline: provisioning, group-based licensing, revocation with session and refresh token invalidation.
• Least privilege for admin access: scoped role assignments, RBAC, PIM, access reviews, entitlement management access packages.
• Service account and workload identity governance: ownership, credential rotation, permission scoping, decommissioning.
• Microsoft 365 tenant settings, licensing, admin roles; access and permission issues in Exchange Online, SharePoint Online, Power Platform.
• Diagnostics from sign-in, audit, and provisioning logs, with diagnostic settings routed to Log Analytics and KQL queries.
• Cross-tenant access settings and B2B external collaboration.
Google Workspace, Cloud Identity, and Google Cloud
• Google Workspace and Cloud Identity: users, groups, organizational units, admin roles and privileges, licensing, 2-Step Verification enforcement, session controls.
• Third-party SSO profiles with Microsoft Entra ID as SAML IdP, automated provisioning into Cloud Identity, OU- and group-scoped SSO exclusions.
• Context-Aware Access policies, third-party OAuth app access control, domain-wide delegation, Drive sharing and external access controls. 2
• Google Cloud IAM: project and folder membership,