1,115,425open jobs
64,401companies
189,702added this week
Browse all
Location
Remote (United States)
Employment
Full-Time

First seen by Alion on Oct 2, 2026.

Overview
Company
Impact
Profile match
Nebius is an international technology company that specializes in building full-stack artificial intelligence infrastructure and high-performance cloud GPU platforms for AI model development. Headquartered in Amsterdam, Netherlands, the firm operates energy-efficient data centers across Europe and North America to provide scalable compute, storage, and software tools for machine learning workloads.

About Nebius:

Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.

Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.

Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.

About the Role

You own the company's identity provider: who signs in, from where, with which factors, into which applications — and how that access is granted, reviewed, and revoked.

Microsoft Entra ID is the primary identity plane and the center of gravity for the role. Google Workspace, Cloud Identity, and Google Cloud IAM form a second substantial domain, and you own the federation and provisioning path between them. Microsoft 365 is in scope for tenant, licensing, and access administration.

You are the escalation point for identity incidents from operations, security, service desk, and application teams — expected to resolve them, not route them onward.

What You'll Own

Microsoft Entra ID and Microsoft 365

  • Users, dynamic and assigned groups, administrative units, directory roles, service principals, workload identities.
  • Conditional Access design and rollout: named locations, client app and platform conditions, session controls, sign-in frequency, break-glass exclusions, report-only staging.
  • Authentication methods policy and phishing-resistant factors.
  • Application onboarding over SAML 2.0 (NameID, claims mapping, signing certificate rollover, encrypted assertions) and OIDC / OAuth 2.0 (authorization code with PKCE, client credentials, device code).
  • App registrations: redirect URIs, permissions, admin consent workflow, secret and certificate lifecycle. – SCIM 2.0 provisioning: attribute mappings, scoping filters, expression transformations, quarantined jobs, drift reconciliation.
  • Tenant consent settings, OAuth grant review, remediation of over-permissioned and stale applications; defensible controls for SaaS without SSO or SCIM support.
  • Joiner-mover-leaver as an automated pipeline: provisioning, group-based licensing, revocation with session and refresh token invalidation.
  • Least privilege for admin access: scoped role assignments, RBAC, PIM, access reviews, entitlement management access packages.
  • Service account and workload identity governance: ownership, credential rotation, permission scoping, decommissioning.
  • Microsoft 365 tenant settings, licensing, admin roles; access and permission issues in Exchange Online, SharePoint Online, Power Platform.
  • Diagnostics from sign-in, audit, and provisioning logs, with diagnostic settings routed to Log Analytics and KQL queries.
  • Cross-tenant access settings and B2B external collaboration.

Google Workspace, Cloud Identity, and Google Cloud

  • Google Workspace and Cloud Identity: users, groups, organizational units, admin roles and privileges, licensing, 2-Step Verification enforcement, session controls.
  • Third-party SSO profiles with Microsoft Entra ID as SAML IdP, automated provisioning into Cloud Identity, OU- and group-scoped SSO exclusions.
  • Context-Aware Access policies, third-party OAuth app access control, domain-wide delegation, Drive sharing and external access controls. 2
  • Google Cloud IAM: project and folder membership, predefined and custom roles, allow policies, service accounts and key hygiene, workload identity federation, API enablement, OAuth clients.

Automation

  • PowerShell tooling on the Microsoft Graph PowerShell SDK and Graph REST API: lifecycle, licensing, access reporting, recertification.
  • Google-side automation through the Admin SDK Directory API, Cloud Identity API, and gcloud.
  • Scheduled and event-driven workflows in Azure Automation Runbooks, Azure Logic Apps, or Power Automate.
  • Unattended execution on managed identities and narrowly scoped app registrations, with credential rotation, structured logging, error handling, and retries.
  • Automation treated as production code: version control, peer review, documented rollback.

What You'll Bring

We care about what you can do, not which products appear on your CV. Concretely, you can:

  • Decode a SAML assertion or JWT and pinpoint the failure — audience mismatch, NameID format, expired signing certificate, missing claim — without escalating to the vendor.
  • Diagnose a failing SCIM job and tell scoping from attribute mapping, transformation expressions, or target schema.
  • Replace a manual lifecycle process with automation that logs, retries, and can be handed to someone else to run.

Experience We Expect

  • 3+ years administering Microsoft Entra ID in production as a primary responsibility.
  • Enterprise applications, app registrations, consent and permission models, automated provisioning.
  • Microsoft 365 administration: tenant settings, licensing, admin roles, and access troubleshooting across Exchange Online, SharePoint Online, and Power Platform.
  • Google Workspace and Cloud Identity administration: organizational units, groups, admin roles, SSO profiles, access settings.
  • Google Cloud IAM: projects, roles and policies, service accounts, API access, OAuth credentials.
  • Strong PowerShell with the Microsoft Graph PowerShell SDK and direct REST API work.
  • Azure Automation Runbooks, Azure Logic Apps, Power Automate, or comparable platforms.
  • Least privilege, secure administration, change management, and the discipline to leave configurations documented.
  • Written and spoken English at B2 or higher

Nice to Have

  • SC-300, MS-102, or SC-401 — or equivalent demonstrable expertise.
  • Microsoft Entra ID Governance: entitlement management, lifecycle workflows, Privileged Identity Management.
  • Microsoft Purview (DLP, retention, eDiscovery), Microsoft Defender for Cloud Apps, or Microsoft Sentinel.
  • Google Cloud workload identity federation, custom roles, organization policy constraints.
  • Git, CI/CD practices, Pester, Bicep, or Terraform.
  • Access evidence for SOC 2, ISO 27001, or comparable audit cycles.

Benefits & Perks:

  • Competitive compensation
  • Career growth and learning opportunities
  • Flexibility and ownership
  • Collaborative and innovative culture
  • Opportunity to work on impactful AI projects
  • International environment and talented teams

What's it like to work at Nebius:

Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI

Equal Opportunity Statement:

Nebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.

Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire.

If you need accommodations during the application process, please let us know.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,115,425 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

DevOps
Similar stack
Same company
In your city
≈ $127k – $229k per year (Estimated) • Remote (United States) • Full-Time • 8+ years exp • Bachelor's Degree • Alpharetta
DevOps
Azure
Management
ITIL
Apply
$93k – $125k per year • Remote (United States) • Full-Time • 3+ years exp • Bachelor's Degree • United States
Apply
Remote (Mexico) • Full-Time • 1+ year exp • Bachelor's Degree • Guadalajara
Python
Bash
Databases
OpenSearch
Amazon Aurora
AI/ML
AI Agents
LLM
DevOps
Rest API
Terraform
Ansible
GitHub Actions
New Relic
CloudFormation
Datadog
PagerDuty
Prometheus
GitLab CI
CI/CD
ArgoCD
Jenkins
Git
AWS
Docker
Kubernetes
Grafana
Self-Healing
Opsgenie
Amazon EKS
AWS Fargate
AWS Lambda
Incident Management
SLI/SLO/SLA
GitHub
Amazon ECS
Amazon CloudWatch
AWS Step Functions
Linux
DNS
Cybersecurity
PCI DSS
SOC 2
Management
Jira
Apply
$139k – $189k per year • Remote (United States) • Full-Time • 8+ years exp • Bachelor's Degree • Minneapolis
DevOps
CI/CD
Platform Engineering
Apply
$94k per year • Remote (United States) • Full-Time
Java
PowerShell
Bash
Java
Spring Boot
Apache Tomcat
DevOps
Terraform
Ansible
GCP
Red Hat
CloudFormation
Azure
CI/CD
GitOps
Jenkins
AWS
Kubernetes
Proxmox VE
GitHub
IAM
Linux
Apply
≈ $16k – $41k per year (Estimated) • In office • Pune
Python
SQL
PowerShell
Bash
DevOps
GCP
Datadog
Dynatrace
Prometheus
Azure
Windows Server
AWS
Kubernetes
Grafana
AppDynamics
Azure AKS
Windows
QA
JMeter
Playwright
Locust
Apply
≈ $40k – $94k per year (Estimated) • In office • Bachelor's Degree • Portugal
Python
SQL
Databases
MySQL
PostgreSQL
Snowflake
Databricks
Cassandra
Presto
Apache Kafka
Google BigQuery
Amazon Redshift
BigQuery
AI/ML
Polars
Hadoop
Spark
Scikit-learn
JAX
Multimodal AI
NLP
Flink
TensorFlow
Pandas
NumPy
PyTorch
Hugging Face
Recommender Systems
Machine Learning
DevOps
GCP
Azure
CI/CD
AWS
Docker
Analytics
ETL/ELT
A/B Testing
Azure Data Factory
AWS Glue
QA
Pytest
Apply
Remote (Malta) • Master's Degree
Python
AI/ML
LangChain
LlamaIndex
Fine-tuning
Prompt Engineering
Computer Vision
Haystack
Transformers
TensorFlow
PyTorch
LLM
RAG
Self-Supervised Learning
Hugging Face
DevOps
GCP
Azure
CI/CD
AWS
Docker
Apply
≈ $8k – $24k per year (Estimated) • In office • 3+ years exp • Pune
JavaScript
PowerShell
DevOps
Rest API
Incident Management
SOAP
Cybersecurity
LDAP
Management
ServiceNow
Agile
ITSM
Apply
≈ $47k – $115k per year (Estimated) • Hybrid • Bachelor's Degree • Tokyo
DevOps
GCP
Azure
AWS
Apply
≈ $89k – $208k per year (Estimated) • Remote (location not specified) • Full-Time
Go
C++
DevOps
gRPC
Linux
BGP
Apply
Remote (United States) • Full-Time
Apply
$159k – $193k per year • Remote (United States) • Full-Time
AI/ML
Fine-tuning
RAG
Marketing
Salesforce
HubSpot
Apply
$150k – $188k per year • Remote (United States) • Full-Time
AI/ML
ChatGPT
AI Agents
Gemini
Perplexity
Analytics
Looker
Marketing
GA4
Semrush
Ahrefs
Screaming Frog
Apply
$209k – $261k per year • Remote (United States, Canada) • Full-Time
Python
AI/ML
CUDA Toolkit
OpenCL
Kubeflow
TensorFlow
PyTorch
CUDA
DevOps
Terraform
Ansible
GCP
SLURM
Azure
AWS
Kubernetes
HPC
Apply
See all jobs
This is one of many
1,115,425 more open roles from verified company boards, updated every day.