Назад
2 дня назад

Microsoft 365 Engineer (Identity and Access)

Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
UK/US/CR +2 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Microsoft 365 Engineer (Identity and Access) (Microsoft Entra ID/Microsoft 365): Owning identity administration, access governance, application integrations, and automated joiner-mover-leaver workflows with an accent on Conditional Access, SAML/OIDC integrations, SCIM provisioning, and least-privilege administration. Focus on diagnosing identity failures, building production-grade PowerShell and cloud automation, and securing Microsoft and Google identity environments.

Location: Prague, Czech Republic

Company

Nebius is building a full-stack AI cloud platform for data processing, model training, and production deployment, with infrastructure spanning compute, storage, networking, and applied AI.

What you will do

  • Own Microsoft Entra ID as the primary identity platform, including users, groups, roles, service principals, workload identities, and administrative units.
  • Design and roll out Conditional Access, authentication methods, phishing-resistant factors, access reviews, entitlement management, PIM, and least-privilege administration.
  • Onboard and govern enterprise applications using SAML 2.0, OIDC, OAuth 2.0, SCIM 2.0, consent controls, permission reviews, and credential lifecycle management.
  • Administer Microsoft 365 tenant settings, licensing, Exchange Online, SharePoint Online, Power Platform, Microsoft Defender, and related access issues.
  • Build production-grade automation with PowerShell, Microsoft Graph, Google Admin SDK, Azure Automation, Logic Apps, or Power Automate.
  • Resolve identity incidents and diagnose sign-in, audit, provisioning, SAML, JWT, and SCIM failures using logs, Log Analytics, and KQL.

Requirements

  • 3+ years of production administration of Microsoft Entra ID as a primary responsibility.
  • Hands-on experience with Microsoft 365 tenant administration, licensing, roles, Service Health, Exchange Online, Microsoft Defender, and Power Platform.
  • Experience with PowerShell, Microsoft Graph SDK, enterprise applications, app registrations, consent models, and automated provisioning.
  • Experience with Azure Automation Runbooks, Azure Logic Apps, Power Automate, or comparable workflow platforms.
  • Knowledge of least privilege, secure administration, change management, documentation, and production automation practices.
  • Written and spoken English at B2 level or higher; applicants must be authorized to work in the country in which they apply.

Nice to have

  • SC-300, MS-102, or SC-401 certification, or equivalent demonstrable expertise.
  • Experience with Microsoft Entra ID Governance, Microsoft Purview, Defender for Cloud Apps, or Microsoft Sentinel.
  • Experience with Google Cloud IAM, workload identity federation, custom roles, and organization policies.
  • Git, CI/CD, Pester, Bicep, Terraform, or audit evidence for SOC 2 and ISO 27001.

Culture & Benefits

  • Competitive compensation and career growth opportunities.
  • Learning opportunities with flexibility and ownership.
  • Collaborative, innovative, and international environment.
  • Opportunity to work on impactful AI infrastructure projects.
  • Fast-moving culture focused on meaningful impact, trust, and real ownership.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →