All vacancies
Cloud Workplace Engineer
Nebius
Remote · United StatesSalary not disclosedfull-timeVerified recentlyOver a month oldNebius Careers
You own the company's identity provider: who signs in, from where, with which factors, into which applications — and how that access is granted, reviewed, and revoked. Microsoft Entra ID is the primary identity plane and the center of gravity for the role.
Responsibilities
- Microsoft Entra ID and Microsoft 365
- Users, dynamic and assigned groups, administrative units, directory roles, service principals, workload identities.
- Conditional Access design and rollout: named locations, client app and platform conditions, session controls, sign-in frequency, break-glass exclusions, report-only staging.
- Authentication methods policy and phishing-resistant factors.
- Application onboarding over SAML 2.0 (NameID, claims mapping, signing certificate rollover, encrypted assertions) and OIDC / OAuth 2.0 (authorization code with PKCE, client credentials, device code).
- App registrations: redirect URIs, permissions, admin consent workflow, secret and certificate lifecycle. – SCIM 2.0 provisioning: attribute mappings, scoping filters, expression transformations, quarantined jobs, drift reconciliation.
- Tenant consent settings, OAuth grant review, remediation of over-permissioned and stale applications; defensible controls for SaaS without SSO or SCIM support.
- Joiner-mover-leaver as an automated pipeline: provisioning, group-based licensing, revocation with session and refresh token invalidation.
- Least privilege for admin access: scoped role assignments, RBAC, PIM, access reviews, entitlement management access packages.
- Service account and workload identity governance: ownership, credential rotation, permission scoping, decommissioning.
Languages
- Work format
- Remote
- Seniority
- Mid
- Posted
- 15 Jun 2026 (3mo ago)
- Last verified
- 4 Oct 2026
