{"id":1730633,"url":"https://alion.io/job/nebius-cloud-workplace-engineer","title":"Cloud Workplace Engineer","company":{"id":6364,"name":"Nebius","domain":"nebius.com","url":"https://alion.io/company/nebius","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":null},"role":"DevOps","role_family":"DevOps","seniority":null,"employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"inferred_payroll_markers","remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":[],"countries":[],"hiring_countries":["US"],"hiring_countries_total":1,"salary":null,"salary_estimate":null,"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Azure","optional":false},{"name":"GCP","optional":false},{"name":"Google Workspace","optional":false},{"name":"IAM","optional":false},{"name":"Least Privilege","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"Power Automate","optional":false},{"name":"PowerShell","optional":false},{"name":"Rest API","optional":false},{"name":"Service Desk","optional":false},{"name":"SharePoint","optional":false},{"name":"Bicep","optional":true},{"name":"CI/CD","optional":true},{"name":"DLP","optional":true},{"name":"Git","optional":true},{"name":"ISO 27001","optional":true},{"name":"Microsoft Defender","optional":true},{"name":"Microsoft Defender for Cloud","optional":true},{"name":"Microsoft Sentinel","optional":true},{"name":"SOC 2","optional":true},{"name":"Terraform","optional":true}],"status":"live","first_seen_at":"2026-10-02T15:20:54Z","employer_posted_date":null,"last_verified_at":"2026-10-02T15:20:54Z","board_verified":false,"closed_at":null,"days_open":3,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":3},"description":"About Nebius:\n\nNebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.\n\nBuilt by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.\n\nListed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.\n\nAbout the Role\n\nYou own the company's identity provider: who signs in, from where, with which factors, into which applications — and how that access is granted, reviewed, and revoked.\n\nMicrosoft Entra ID is the primary identity plane and the center of gravity for the role. Google Workspace, Cloud Identity, and Google Cloud IAM form a second substantial domain, and you own the federation and provisioning path between them. Microsoft 365 is in scope for tenant, licensing, and access administration.\n\nYou are the escalation point for identity incidents from operations, security, service desk, and application teams — expected to resolve them, not route them onward.\n\nWhat You'll Own\n\nMicrosoft Entra ID and Microsoft 365\n\nUsers, dynamic and assigned groups, administrative units, directory roles, service principals, workload identities.\n\nConditional Access design and rollout: named locations, client app and platform conditions, session controls, sign-in frequency, break-glass exclusions, report-only staging.\n\nAuthentication methods policy and phishing-resistant factors.\n\nApplication onboarding over SAML 2.0 (NameID, claims mapping, signing certificate rollover, encrypted assertions) and OIDC / OAuth 2.0 (authorization code with PKCE, client credentials, device code).\n\nApp registrations: redirect URIs, permissions, admin consent workflow, secret and certificate lifecycle. – SCIM 2.0 provisioning: attribute mappings, scoping filters, expression transformations, quarantined jobs, drift reconciliation.\n\nTenant consent settings, OAuth grant review, remediation of over-permissioned and stale applications; defensible controls for SaaS without SSO or SCIM support.\n\nJoiner-mover-leaver as an automated pipeline: provisioning, group-based licensing, revocation with session and refresh token invalidation.\n\nLeast privilege for admin access: scoped role assignments, RBAC, PIM, access reviews, entitlement management access packages.\n\nService account and workload identity governance: ownership, credential rotation, permission scoping, decommissioning.\n\nMicrosoft 365 tenant settings, licensing, admin roles; access and permission issues in Exchange Online, SharePoint Online, Power Platform.\n\nDiagnostics from sign-in, audit, and provisioning logs, with diagnostic settings routed to Log Analytics and KQL queries.\n\nCross-tenant access settings and B2B external collaboration.\n\nGoogle Workspace, Cloud Identity, and Google Cloud\n\nGoogle Workspace and Cloud Identity: users, groups, organizational units, admin roles and privileges, licensing, 2-Step Verification enforcement, session controls.\n\nThird-party SSO profiles with Microsoft Entra ID as SAML IdP, automated provisioning into Cloud Identity, OU- and group-scoped SSO exclusions.\n\nContext-Aware Access policies, third-party OAuth app access control, domain-wide delegation, Drive sharing and external access controls. 2\n\nGoogle Cloud IAM: project and folder membership, predefined and custom roles, allow policies, service accounts and key hygiene, workload identity federation, API enablement, OAuth clients.\n\nAutomation \n\nPowerShell tooling on the Microsoft Graph PowerShell SDK and Graph REST API: lifecycle, licensing, access reporting, recertification.\n\nGoogle-side automation through the Admin SDK Directory API, Cloud Identity API, and gcloud.\n\nScheduled and event-driven workflows in Azure Automation Runbooks, Azure Logic Apps, or Power Automate.\n\nUnattended execution on managed identities and narrowly scoped app registrations, with credential rotation, structured logging, error handling, and retries.\n\nAutomation treated as production code: version control, peer review, documented rollback.\n\nWhat You'll Bring\n\nWe care about what you can do, not which products appear on your CV. Concretely, you can:\n\nDecode a SAML assertion or JWT and pinpoint the failure — audience mismatch, NameID format, expired signing certificate, missing claim — without escalating to the vendor.\n\nDiagnose a failing SCIM job and tell scoping from attribute mapping, transformation expressions, or target schema.\n\nReplace a manual lifecycle process with automation that logs, retries, and can be handed to someone else to run.\n\nExperience We Expect\n\n3+ years administering Microsoft Entra ID in production as a primary responsibility.\n\nEnterprise applications, app registrations, consent and permission models, automated provisioning.\n\nMicrosoft 365 administration: tenant settings, licensing, admin roles, and access troubleshooting across Exchange Online, SharePoint Online, and Power Platform.\n\nGoogle Workspace and Cloud Identity administration: organizational units, groups, admin roles, SSO profiles, access settings.\n\nGoogle Cloud IAM: projects, roles and policies, service accounts, API access, OAuth credentials.\n\nStrong PowerShell with the Microsoft Graph PowerShell SDK and direct REST API work.\n\nAzure Automation Runbooks, Azure Logic Apps, Power Automate, or comparable platforms.\n\nLeast privilege, secure administration, change management, and the discipline to leave configurations documented.\n\nWritten and spoken English at B2 or higher\n\nNice to Have\n\nSC-300, MS-102, or SC-401 — or equivalent demonstrable expertise.\n\nMicrosoft Entra ID Governance: entitlement management, lifecycle workflows, Privileged Identity Management.\n\nMicrosoft Purview (DLP, retention, eDiscovery), Microsoft Defender for Cloud Apps, or Microsoft Sentinel.\n\nGoogle Cloud workload identity federation, custom roles, organization policy constraints.\n\nGit, CI/CD practices, Pester, Bicep, or Terraform.\n\nAccess evidence for SOC 2, ISO 27001, or comparable audit cycles.\n\nBenefits & Perks:\n\nCompetitive compensation\n\nCareer growth and learning opportunities\n\nFlexibility and ownership\n\nCollaborative and innovative culture\n\nOpportunity to work on impactful AI projects\n\nInternational environment and talented teams\n\nWhat's it like to work at Nebius:\n\nFast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI \n\nEqual Opportunity Statement:\n\nNebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.\n\nApplicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire. \n\nIf you need accommodations during the application process, please let us know.","description_format":"text","description_chars":7542,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Artificial Intelligence","Commerce","Education","Data Centers & Colocation"],"lifecycle":[{"event":"open","at":"2026-10-03T00:01:13Z"}],"visa":[],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":2,"expected_fill_days":26,"reasons":["seen:2","velocity","win:early"],"computed_at":"2026-10-05T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/nebius-cloud-workplace-engineer","json_url":"https://alion.io/job/nebius-cloud-workplace-engineer.json","meta":{"generated_at":"2026-10-06T02:24:30Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3680,"day_limit":5000,"remaining_today":1320,"minute_limit":60,"resets_at":"2026-10-07T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":6364},"rest":"https://alion.io/mcp/rest/get_company?id=6364"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fnebius-cloud-workplace-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fnebius-cloud-workplace-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fnebius-cloud-workplace-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/nebius-cloud-workplace-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fnebius-cloud-workplace-engineer"}]}