Microsoft 365 Engineer

Posted 7hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Microsoft 365 Engineer owning Entra ID, Microsoft 365, and identity automation. Securing access infrastructure for Nebius’s global AI cloud platform.

Responsibilities:

  • Own the company's identity provider and manage authentication, access grants, reviews, and revocation
  • Administer Microsoft Entra ID and Microsoft 365 users, groups, directory roles, service principals, workload identities, licensing, tenant settings, and admin roles
  • Design and roll out Conditional Access policies and authentication methods, including phishing-resistant factors
  • Onboard applications using SAML 2.0, OIDC, and OAuth 2.0
  • Manage app registrations, permissions, admin consent, secrets, and certificates
  • Configure SCIM 2.0 provisioning, attribute mappings, transformations, reconciliation, and remediation
  • Automate joiner-mover-leaver lifecycle processes, licensing, and session/token revocation
  • Govern least-privilege administration through RBAC, PIM, access reviews, and entitlement management
  • Govern service accounts and workload identities, including ownership, credential rotation, permission scoping, and decommissioning
  • Troubleshoot Microsoft 365 access and permission issues across Exchange Online, SharePoint Online, and Power Platform
  • Analyze sign-in, audit, and provisioning logs using Log Analytics and KQL
  • Manage cross-tenant access settings and B2B external collaboration
  • Build production-grade automation using Microsoft Graph, Google APIs, PowerShell, Azure Automation, Logic Apps, or Power Automate
  • Serve as the escalation point for identity incidents and resolve issues for operations, security, service desk, and application teams

Requirements:

  • 3+ years administering Microsoft Entra ID in production as a primary responsibility
  • Microsoft 365 tenant administration, including settings, licensing, admin roles, and Service Health
  • Exchange Online experience with mailbox permissions, groups, mail flow, SPF/DKIM/DMARC
  • Microsoft Defender experience with threat policies, quarantine, and message trace
  • Power Platform experience with environments, DLP connector policies, and maker access
  • PowerShell experience with the Exchange Online module and Microsoft Graph SDK
  • Experience with enterprise applications, app registrations, consent and permission models, and automated provisioning
  • Experience with Azure Automation Runbooks, Azure Logic Apps, Power Automate, or comparable platforms
  • Knowledge of least privilege, secure administration, and change management
  • Discipline to leave configurations documented
  • Written and spoken English at B2 or higher
  • Applicants must be authorized to work in the country in which they apply and provide proof of employment eligibility as a condition of hire

Benefits:

  • Competitive compensation
  • Career growth and learning opportunities
  • Flexibility and ownership
  • Collaborative and innovative culture
  • Opportunity to work on impactful AI projects
  • International environment and talented teams