Name of position: Senior Google Workspace Administrator
Location: Washington DC
Onsite expectation: Approximately five days onsite every two weeks
Position Summary
The Senior Google Workspace Administrator will serve as the dedicated administrator and primary technical point of contact for the United States Holocaust Memorial Museum’s Google Workspace environment.
The Administrator will manage, secure, govern, optimize, document, and support the Museum’s Google Workspace tenant while ensuring alignment with operational requirements, federal security standards, and institutional policies.
The individual will administer the full Google Workspace ecosystem, support identity and access management, strengthen security and compliance controls, optimize Drive storage and collaboration services, govern Gemini usage, support audits and ATO activities, and provide technical guidance and training to Museum administrators and users.
Key Responsibilities
Google Workspace Administration
• Administer Google Workspace domains, users, groups, organizational units, privileged roles, licenses, subscriptions, and administrative settings.
• Manage user lifecycle activities, including onboarding, transfers, role changes, account suspension, offboarding, retention, and archived-user management.
• Configure role-based access controls and delegated administration using least-privilege principles.
• Review licensing utilization and recommend cost, subscription, and capacity optimizations.
• Maintain accurate inventories of users, groups, shared drives, administrative accounts, licenses, and organizational units.
Core Google Services
• Administer and optimize Gmail, Google Drive, Shared Drives, Docs, Sheets, Slides, Forms, Meet, Chat, Calendar, Google Voice, Vault, and related services.
• Establish secure sharing, ownership, retention, external collaboration, and information-governance standards.
• Assess and improve Google Drive storage architecture, shared-drive governance, data ownership, stale content, external sharing, and storage utilization.
• Configure Google Workspace services to support secure business workflows and user productivity.
• Evaluate new Google Workspace releases and recommend controlled adoption.
Identity and Access Management
• Integrate and administer Google Workspace authentication with Okta.
• Maintain SSO, MFA, account provisioning, identity federation, privileged-access, and session-management controls.
• Enforce MFA for all users and enhanced controls for privileged administrators.
• Coordinate identity lifecycle processes between Google Workspace, Okta, HR, service-management, and endpoint-management systems.
• Conduct periodic access reviews and remediate excessive or inactive privileges.
Security Operations
• Configure password policies, session controls, device trust, contextual access, secure sharing, and third-party application controls.
• Administer Google Workspace Security Center, alerting, investigation, audit, and reporting capabilities.
• Manage Data Loss Prevention, information rights management, email security, OAuth application access, API controls, and external-sharing restrictions.
• Investigate phishing, suspicious logins, compromised accounts, unauthorized access, malicious applications, and data-exfiltration indicators.
• Develop and maintain incident-response procedures for Google Workspace security events and service outages.
• Provide after-hours response for mission-critical incidents when required.
Compliance and ATO Support
• Align Google Workspace configurations with:
o NIST Cybersecurity Framework.
o NIST SP 800-53 controls.
o FISMA requirements.
o FedRAMP Moderate requirements and migration objectives.
• Maintain control implementation evidence, configuration records, audit logs, policies, procedures, and supporting compliance documentation.
• Support security assessments, risk reviews, audits, control testing, POA&M activities, and Authority to Operate processes.
• Coordinate remediation of security and compliance findings.
• Ensure proper retention, eDiscovery, legal-hold, audit, and records-management configurations.
Gemini and Generative AI Governance
• Administer and optimize Gemini for Google Workspace.
• Develop administrative controls and recommendations for responsible Gemini usage.
• Support acceptable-use policies, data-protection controls, access restrictions, audit requirements, and user guidance for generative AI.
• Assess new Gemini capabilities for security, privacy, compliance, operational value, and business applicability.
• Train administrators and users on secure and appropriate Gemini practices.
Operations and Service Management
• Perform routine system-health reviews, configuration assessments, license reviews, and security checks.
• Manage platform changes through documented change-control procedures.
• Respond to incidents, service requests, outages, user escalations, and administrator inquiries.
• Coordinate Google support cases and manage issues through resolution.
• Work within the Museum’s IT service-management and incident-management processes.
• Maintain service continuity and develop backup, escalation, and administrative-recovery procedures.
Optimization and Strategic Planning
• Conduct an initial assessment of the Museum’s Google Workspace environment.
• Prioritize Google Workspace optimization, Drive storage, governance, security, and Gemini requirements.
• Develop a continuous-improvement roadmap with prioritized initiatives, risks, dependencies, and expected benefits.
• Recommend automation using Google Workspace APIs, GAM, Apps Script, administrative workflows, or other approved tools.
• Identify opportunities to improve user experience, collaboration, licensing efficiency, security, and administrative effectiveness.
Documentation, Reporting, and Training
• Develop and maintain:
o Google Workspace governance and administration documentation.
o Security and access-control policies.
o Compliance and control-evidence documentation.
o Operational runbooks.
o Incident-response procedures.
o User lifecycle procedures.
o Configuration standards.
o Administrative recovery procedures.
• Submit monthly reports summarizing completed activities, incidents, risks, metrics, recommendations, and upcoming work.
• Provide technical training and knowledge transfer to approximately five to six Museum administrators.
• Develop user-facing guidance and best-practice training for the Museum community.
• Serve as the liaison among Museum leadership, IT staff, program offices, Google support, vendors, and federal partners.
Required Qualifications
Mandatory or Solicitation-Aligned
• Current Professional Google Workspace Administrator certification.
• Demonstrated experience administering Google Workspace in a large enterprise, public-sector, federal, or federal-adjacent environment.
• Advanced knowledge of Google Admin Console, Gmail, Drive, Shared Drives, Vault, Calendar, Meet, Chat, Docs, Groups, organizational units, licensing, and delegated administration.
• Strong experience with identity federation, SSO, MFA, Okta, identity lifecycle management, and zero-trust principles.
• Hands-on experience implementing DLP, secure sharing, email-security, audit, investigation, retention, and privileged-access controls.
• Experience supporting environments aligned with NIST SP 800-53, FISMA, FedRAMP, and ATO requirements.
• Strong incident management, troubleshooting, documentation, training, and stakeholder communication skills.
• Ability to work onsite in Washington, D.C. approximately five days during each two-week period.
• Ability to provide limited after-hours support for critical outages and security incidents.
• Ability to successfully complete the Museum’s suitability determination, fingerprint-based background investigation, and recurring screening requirements.
Must Require Certificate
The Google Workspace Administrator must possess the following certifications (current and in good standing):
• Google Workspace Administrator Professional
• Google Cloud Certified – Professional Cloud Security Engineer.
• Google Cloud Certified – Professional Cloud Architect.
• Experience with Google Workspace APIs, GAM, Apps Script, automation, and bulk administration.
• Experience with Okta, ServiceNow, CASB platforms, endpoint-management platforms, and Google endpoint controls.
• Experience administering Gemini for Google Workspace and establishing generative-AI governance.
• Experience managing Google Workspace environments with approximately 900 or more active users, hundreds of groups, large Shared Drive inventories, archived-user licensing, and multiple terabytes of Drive data.
• Bachelor’s degree in information technology, cybersecurity, computer science, or a related discipline.
Recommended Experience Thresholds
These thresholds are not explicitly mandated by the RFQ but would strengthen the technical evaluation:
• Eight or more years of enterprise IT administration experience.
• Five or more years of direct Google Workspace administration experience.
• Three or more years supporting security, compliance, or regulated environments.
• At least one engagement involving enterprise Google Workspace governance, security hardening, migration, optimization, or federal compliance.