Junior Identity & Access Engineer (Early Talent)
About Nebius:
Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.
Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.
Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.
About the role
Location: Prague
Duration: 3 months
Start date: January 2027
Compensation: Paid
Eligibility: Current University student (Computer Science or related field), Recent Graduate or Early Career specialist
Work authorization: Permitted to work in the job's location
This is an entry-level position for a recent graduate who wants to build a career in identity and access management. You will work inside our identity and workplace stack — Microsoft Entra ID, Microsoft 365, and Google Workspace — starting with well-defined, documented tasks and taking on more independent work as your judgment develops.
You will be paired with a senior engineer who reviews your work, and you will not be expected to make production changes unsupervised in your first months. What we do expect is curiosity, methodical thinking, and the discipline to document what you touch.
You will work European business hours, in direct overlap with the senior engineers who review your work and answer your questions. Where a task touches the US business day, you will prepare it during your hours and hand it over.
What you will do
- Process access requests: group membership, license assignment, and permission changes, following documented runbooks.
- Execute onboarding and offboarding checklists and verify that every step completed correctly.
- Handle first-line triage of sign-in and access issues: reproduce the problem, collect evidence from sign-in and audit logs, and escalate with a clear summary.
- Assist with application onboarding under supervision: test SSO configurations in non-production, validate SCIM attribute mappings, and document the result.
- Perform day-to-day Google Workspace administration: users, groups, organizational units, licensing.
- Run and gradually improve recurring reports — stale accounts, unused licenses, guest inventory — using PowerShell and Microsoft Graph.
- Keep documentation and runbooks current as configurations change.
- Prepare handover notes for the US-hours engineer: open issues, what you have already checked, and what remains.
What you will learn
- How enterprise authentication works in production: SAML 2.0, OpenID Connect, OAuth 2.0, and SCIM provisioning.
- How Conditional Access, MFA, and phishing-resistant authentication are designed, tested, and rolled out.
- How to automate identity operations with PowerShell and Microsoft Graph instead of clicking through portals.
- How access governance works: least privilege, access reviews, privileged role management.
- How a federated Microsoft and Google estate is kept in sync.
What you bring
- Completed or final-year degree in Computer Science, Information Technology, or a related field.
- Understanding of core identity concepts from coursework, labs, or self-study: authentication vs. authorization, MFA, single sign-on, groups and permissions, least privilege.
- Basic scripting in any language — PowerShell, Python, or Bash — and the intent to specialize in PowerShell.
- Methodical troubleshooting: you read the documentation and the logs before guessing.
- Clear written communication and the habit of writing down what you did.
- Based in Europe and able to work European business hours with regular overlap with US-based colleagues.
- Written and spoken English at B2 or higher.
Nice to have
- Microsoft fundamentals certifications: SC-900, AZ-900, or MS-900.
- A homelab, Microsoft 365 developer tenant, or Google Workspace trial you have experimented with.
- Internship or part-time experience in IT support, service desk, or infrastructure.
- Basic Git.
- Any hands-on exposure to the Microsoft Entra admin center or Google Workspace Admin console.
Benefits & Perks:
- Competitive compensation
- Career growth and learning opportunities
- Flexibility and ownership
- Collaborative and innovative culture
- Opportunity to work on impactful AI projects
- International environment and talented teams
What's it like to work at Nebius:
Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI
Equal Opportunity Statement:
Nebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.
Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire.
If you need accommodations during the application process, please let us know.