Skip to content
ITA Jobs
All vacancies
Nebius logo

Cloud Workplace Engineer

Nebius

Remote · United StatesSalary not disclosedfull-timeVerified recentlyOver a month oldNebius Careers

You own the company's identity provider: who signs in, from where, with which factors, into which applications — and how that access is granted, reviewed, and revoked. Microsoft Entra ID is the primary identity plane and the center of gravity for the role.

Responsibilities

  • Microsoft Entra ID and Microsoft 365
  • Users, dynamic and assigned groups, administrative units, directory roles, service principals, workload identities.
  • Conditional Access design and rollout: named locations, client app and platform conditions, session controls, sign-in frequency, break-glass exclusions, report-only staging.
  • Authentication methods policy and phishing-resistant factors.
  • Application onboarding over SAML 2.0 (NameID, claims mapping, signing certificate rollover, encrypted assertions) and OIDC / OAuth 2.0 (authorization code with PKCE, client credentials, device code).
  • App registrations: redirect URIs, permissions, admin consent workflow, secret and certificate lifecycle. – SCIM 2.0 provisioning: attribute mappings, scoping filters, expression transformations, quarantined jobs, drift reconciliation.
  • Tenant consent settings, OAuth grant review, remediation of over-permissioned and stale applications; defensible controls for SaaS without SSO or SCIM support.
  • Joiner-mover-leaver as an automated pipeline: provisioning, group-based licensing, revocation with session and refresh token invalidation.
  • Least privilege for admin access: scoped role assignments, RBAC, PIM, access reviews, entitlement management access packages.
  • Service account and workload identity governance: ownership, credential rotation, permission scoping, decommissioning.

Languages

    Work format
    Remote
    Seniority
    Mid
    Posted
    15 Jun 2026 (3mo ago)
    Last verified
    4 Oct 2026

    Keep looking