Nebius
Cloud Workplace Engineer
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 2 weeks ago · Added 5 days ago
Been open since 2 weeks ago, still being checked, but it has been live a while.
Salary
Not stated
Location
United States only
Timezone
US East
Contract
Full-time
Experience
Mid
Category
Software
This employer didn't state pay. Jobs like this usually pay around $140k–$245k a year, a typical range taken from 591 mid-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "Remote - United States"
- Job description states: "authorized to work in the country in which they apply an"
What Nomaders makes of it
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
About Nebius:
Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.
Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.
Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.
About the Role
You own the company's identity provider: who signs in, from where, with which factors, into which applications — and how that access is granted, reviewed, and revoked.
Microsoft Entra ID is the primary identity plane and the center of gravity for the role. Google Workspace, Cloud Identity, and Google Cloud IAM form a second substantial domain, and you own the federation and provisioning path between them. Microsoft 365 is in scope for tenant, licensing, and access administration.
You are the escalation point for identity incidents from operations, security, service desk, and application teams — expected to resolve them, not route them onward.
What You'll Own
Microsoft Entra ID and Microsoft 365
Users, dynamic and assigned groups, administrative units, directory roles, service principals, workload identities.
Conditional Access design and rollout: named locations, client app and platform conditions, session controls, sign-in frequency, break-glass exclusions, report-only staging.
Authentication methods policy and phishing-resistant factors.
Application onboarding over SAML 2.0 (NameID, claims mapping, signing certificate rollover, encrypted assertions) and OIDC / OAuth 2.0 (authorization code with PKCE, client credentials, device code).
App registrations: redirect URIs, permissions, admin consent workflow, secret and certificate lifecycle. – SCIM 2.0 provisioning: attribute mappings, scoping filters, expression transformations, quarantined jobs, drift reconciliation.
Tenant consent settings, OAuth grant review, remediation of over-permissioned and stale applications; defensible controls for SaaS without SSO or SCIM support.
Joiner-mover-leaver as an automated pipeline: provisioning, group-based licensing, revocation with session and refresh token invalidation.
Least privilege for admin access: scoped role assignments, RBAC, PIM, access reviews, entitlement management access packages.
Service account and workload identity governance: ownership, credential rotation, permission scoping, decommissioning.
Microsoft 365 tenant settings, licensing, admin roles; access and permission issues in Exchange Online, SharePoint Online, Power Platform.
Diagnostics from sign-in, audit, and provisioning logs, with diagnostic settings routed to Log Analytics and KQL queries.
Cross-tenant access settings and B2B external collaboration.
Google Workspace, Cloud Identity, and Google Cloud
Google Workspace and Cloud Identity: users, groups, organizational units, admin roles and privileges, licensing, 2-Step Verification enforcement, session controls.
Requirements
- ·We care about what you can do, not which products appear on your CV. Concretely, you can:
- ·Decode a SAML assertion or JWT and pinpoint the failure — audience mismatch, NameID format, expired signing certificate, missing claim — without escalating to the vendor.
- ·Diagnose a failing SCIM job and tell scoping from attribute mapping, transformation expressions, or target schema.
- ·Replace a manual lifecycle process with automation that logs, retries, and can be handed to someone else to run.
- ·Experience We Expect
Benefits
- ·Competitive compensation
- ·Career growth and learning opportunities
- ·Flexibility and ownership
- ·Collaborative and innovative culture
- ·Opportunity to work on impactful AI projects
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Nebius, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 5d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $140k to $245k per year · You'll be taken to the employer's careers page.