WorkaemКарьерная платформа
  • Вакансии
  • Компании
  • Зарплаты
  • Что спрашивают
  • Сервисы
  • Блог
  • Работодателям
Workaem

Карьерная платформа для IT-специалистов: вакансии напрямую с карьерных страниц 300+ компаний, из телеграм-каналов, с международных площадок и от работодателей напрямую. Разбор условий, детектор мёртвых вакансий, AI-инструменты для резюме. Базовые функции бесплатны.

Подпишись, присылаем лучшие вакансии недели
Или читай канал в телеграме
Соискателям
Все вакансииЗа границейУдалёнка в долларахКомпании с РУ основателямиЗарплатыТренды рынкаОфферыВопросы с собеседованийВозможностиИИ-инструментыПроверка резюме без входаСоветыСоздать резюмеТренировка интервьюИгра «Путь джуна»
По технологиям
Вакансии PythonВакансии JavaScriptВакансии ReactВакансии JavaВакансии GoВакансии Docker
По профессиям
РазработкаДизайнQA / ТестированиеАналитикаProduct / Project ManagerМаркетинг
Работодателям
Разместить вакансиюТарифыБаза кандидатовСвязаться с нами
Кабинет
РегистрацияВойтиЛичный кабинетМои откликиСохранённыеУведомления
Компания
О проектеПредложенияКонтактыБлогКонфиденциальностьУсловия использования
© 2026 Workaem. Все права защищены.КонфиденциальностьУсловияОферта
Made by IT, for IT 💛
Identity & Workplace Engineer
ВердиктОписаниеИнструментыКомпания
  1. Главная
  2. /
  3. Вакансии
  4. /
  5. Identity & Workplace Engineer

Nebius·Remote - United States·15 июня

Identity & Workplace Engineer

🌍 УдалённоMiddleПолная занятость🌐 Глобал
Зарплата не указана
Вилки нет, про деньги придётся договариваться с нуля.
Нажмите на сигнал, чтобы увидеть, на чём он основан

Наша компания

Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure. Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI. Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.

Чем предстоит заниматься

You own the company's identity provider: who signs in, from where, with which factors, into which applications — and how that access is granted, reviewed, and revoked
Microsoft Entra ID is the primary identity plane and the center of gravity for the role. Google Workspace, Cloud Identity, and Google Cloud IAM form a second substantial domain, and you own the federation and provisioning path between them. Microsoft 365 is in scope for tenant, licensing, and access administration
You are the escalation point for identity incidents from operations, security, service desk, and application teams — expected to resolve them, not route them onward
What You'll Own

Наши требования

We care about what you can do, not which products appear on your CV. Concretely, you can
Decode a SAML assertion or JWT and pinpoint the failure — audience mismatch, NameID format, expired signing certificate, missing claim — without escalating to the vendor
Diagnose a failing SCIM job and tell scoping from attribute mapping, transformation expressions, or target schema
Replace a manual lifecycle process with automation that logs, retries, and can be handed to someone else to run
SC-300, MS-102, or SC-401 — or equivalent demonstrable expertise
Microsoft Entra ID Governance: entitlement management, lifecycle workflows, Privileged Identity Management
Microsoft Purview (DLP, retention, eDiscovery), Microsoft Defender for Cloud Apps, or Microsoft Sentinel
Google Cloud workload identity federation, custom roles, organization policy constraints
Git, CI/CD practices, Pester, Bicep, or Terraform
Access evidence for SOC 2, ISO 27001, or comparable audit cycles

Мы предлагаем

Competitive compensation
Career growth and learning opportunities
Flexibility and ownership
Collaborative and innovative culture
Opportunity to work on impactful AI projects
International environment and talented teams

Дополнительно

Users, dynamic and assigned groups, administrative units, directory roles, service principals, workload identities
Conditional Access design and rollout: named locations, client app and platform conditions, session controls, sign-in frequency, break-glass exclusions, report-only staging
Authentication methods policy and phishing-resistant factors
Application onboarding over SAML 2.0 (NameID, claims mapping, signing certificate rollover, encrypted assertions) and OIDC / OAuth 2.0 (authorization code with PKCE, client credentials, device code)
App registrations: redirect URIs, permissions, admin consent workflow, secret and certificate lifecycle. – SCIM 2.0 provisioning: attribute mappings, scoping filters, expression transformations, quarantined jobs, drift reconciliation
Tenant consent settings, OAuth grant review, remediation of over-permissioned and stale applications; defensible controls for SaaS without SSO or SCIM support
Joiner-mover-leaver as an automated pipeline: provisioning, group-based licensing, revocation with session and refresh token invalidation
Least privilege for admin access: scoped role assignments, RBAC, PIM, access reviews, entitlement management access packages
Service account and workload identity governance: ownership, credential rotation, permission scoping, decommissioning
Microsoft 365 tenant settings, licensing, admin roles; access and permission issues in Exchange Online, SharePoint Online, Power Platform
Diagnostics from sign-in, audit, and provisioning logs, with diagnostic settings routed to Log Analytics and KQL queries
Cross-tenant access settings and B2B external collaboration
Google Workspace and Cloud Identity: users, groups, organizational units, admin roles and privileges, licensing, 2-Step Verification enforcement, session controls
Third-party SSO profiles with Microsoft Entra ID as SAML IdP, automated provisioning into Cloud Identity, OU- and group-scoped SSO exclusions
Context-Aware Access policies, third-party OAuth app access control, domain-wide delegation, Drive sharing and external access controls. 2
Google Cloud IAM: project and folder membership, predefined and custom roles, allow policies, service accounts and key hygiene, workload identity federation, API enablement, OAuth clients
PowerShell tooling on the Microsoft Graph PowerShell SDK and Graph REST API: lifecycle, licensing, access reporting, recertification
Google-side automation through the Admin SDK Directory API, Cloud Identity API, and gcloud
Scheduled and event-driven workflows in Azure Automation Runbooks, Azure Logic Apps, or Power Automate
Unattended execution on managed identities and narrowly scoped app registrations, with credential rotation, structured logging, error handling, and retries
Automation treated as production code: version control, peer review, documented rollback
3+ years administering Microsoft Entra ID in production as a primary responsibility
Enterprise applications, app registrations, consent and permission models, automated provisioning
Microsoft 365 administration: tenant settings, licensing, admin roles, and access troubleshooting across Exchange Online, SharePoint Online, and Power Platform
Google Workspace and Cloud Identity administration: organizational units, groups, admin roles, SSO profiles, access settings
Google Cloud IAM: projects, roles and policies, service accounts, API access, OAuth credentials
Strong PowerShell with the Microsoft Graph PowerShell SDK and direct REST API work
Azure Automation Runbooks, Azure Logic Apps, Power Automate, or comparable platforms
Least privilege, secure administration, change management, and the discipline to leave configurations documented
Written and spoken English at B2 or higher
Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI
N
Nebius
Remote - United States

ГрейдMiddle
ЗанятостьПолная занятость
РегионСША
ФорматУдалённо
ИсточникСкрыто
Опубликовано15 июня
Все вакансии компании

AI-помощник

под эту вакансию
Войди, чтобы AI оценил твоё соответствие вакансии и написал сопроводительное письмо
Мы против мошенников на площадке: если тебя просят заплатить, продиктовать код или установить непонятное приложение, прекращай общение и сразу пиши нам (чат с основателем или форма обратной связи).