Google Workspace Administrator

Creative G C

  • Washington, DC
  • 3 days ago
  • $40–$45

Highlights

Demonstrated expertise administering Google Workspace at enterprise scale (hundreds to 1,000+ users; complex OU, group, and shared-drive structures) at a level qualifying as a subject matter expert, not a general administrator. The Museum maintains a staff of approximately 6 8 Google administrators who support the platform day to day; this role sits above them as the single authoritative technical expert, working directly for the Museum's lead system administrator.

Numbers & Facts

LocationWashington, DC
Salary$40–$45

Description

Job details:
Role: Google Workspace Administrator
Location: Hybrid Washington, DC (100 Raoul Wallenberg Pl SW) (~10 onsite days/month, five every two weeks)
Level of Effort: 1,920 hours/year (40 hrs/week, ~4 weeks off)
Period of Performance: 12-month base + 4 option years
Clearance: Public Trust suitability + OPM FBI fingerprint criminal background check with financial/credit review; re-screened annually
Role Summary
This is the Museum's designated Subject Matter Expert for Google Workspace and its lead system administrator. The Museum maintains a staff of approximately 6 8 Google administrators who support the platform day to day; this role sits above them as the single authoritative technical expert, working directly for the Museum's lead system administrator. The sole focus is to maintain the environment, review and own the Workspace architecture, optimize solutions within the platform, and coordinate with other teams at integration points. This is not a peer-admin seat the Museum is buying expertise it does not currently have in house.
Environment
  • ~902 active users (925 provisioned), 22 organizational units, 653 groups
  • 1,294 shared drives; 23.5 TB Drive storage, ~47 TB total
  • 908 Workspace licenses, 1,743 archived-user licenses, 26 Google Voice licenses
  • 1 primary domain, 2 secondary domains/aliases; 40 privileged administrators
  • Commercial Google Workspace tenant, moving toward FedRAMP Moderate
  • Integration points (managed by other vendors): Okta (identity), third-party CASB (DLP), ServiceNow (ITSM), Jamf / Google MDM / Endpoint Central (endpoints)
Core Responsibilities
Architecture Ownership & Optimization
  • Own and continuously review the Google Workspace architecture; recommend and implement improvements
  • Lead optimization of the tenant configuration, OU structure, group and shared-drive design
  • Drive storage optimization and license right-sizing (a named Museum priority)
  • Evaluate new Workspace features for Museum applicability; maintain a continuous-improvement roadmap
Platform Administration
  • Administer all domains and core services: Gmail, Drive, Docs/Sheets/Slides/Forms, Meet, Chat, Calendar
  • Manage users, groups, organizational units, and role-based access controls
  • Own identity lifecycle within Workspace: onboarding, role changes, offboarding
  • Stand up and support Gemini for Workspace and NotebookLM for internal Museum use
Governance, Records & Compliance
  • Establish and enforce Workspace governance policies, standards, and documented procedures
  • Administer Google Vault; support indefinite retention, eDiscovery, and NARA/M-19-21 records-management obligations
  • Maintain alignment with NIST CSF, NIST SP 800-53, and FISMA; support the migration toward FedRAMP Moderate
  • Handle federal PII treated as CUI; support State Privacy Act, PCI, and HIPAA obligations
  • Maintain documentation and evidence supporting audits, assessments, and ATO activities
Security Configuration
  • Configure and enforce Workspace-native security controls: MFA enforcement, password and session policies, device trust, secure sharing, IRM
  • Monitor security alerts; respond to phishing, account compromise, and unauthorized access
  • Configure Workspace-side DLP controls in coordination with the CASB vendor
Integration & Coordination
Okta, the third-party CASB, and ServiceNow are administered by separate contracts and vendors. This role integrates and coordinates with these platforms it does not administer or license them.
  • Maintain SSO/identity federation integration with Okta as the identity source of truth
  • Coordinate DLP policy alignment with the CASB vendor
  • Work incidents, changes, and requests through ServiceNow workflows
  • Coordinate endpoint/mobile policy with the Jamf, Google MDM, and Endpoint Central owners
  • Serve as liaison to Google support and escalation channels
Technical Leadership & Enablement
  • Act as the escalation point and technical authority for the Museum's 6 8 Google administrators
  • Provide technical training, best-practice guidance, and knowledge transfer to Museum staff
  • Author SOPs, runbooks, and operational documentation
  • Provide support across all tiers as the problem requires this is not a Tier-3-only role
Operations
  • Routine health checks, configuration reviews, and change management to minimize disruption
  • Incident, outage, and escalation response
  • Coverage is business hours; after-hours response is required for critical outages only and is expected to be minimal. Hours are tracked and offsetting time off is provided.
Deliverables
Governance and administration documentation; security and access-control policies; NIST/FISMA/FedRAMP-aligned compliance documentation; operational runbooks and incident-response procedures; user lifecycle procedures; monthly status reports.
Required Qualifications
  • Google Workspace Administrator Professional certification, current and in good standing at the time of quotation submission (August 12, 2026).
  • Demonstrated expertise administering Google Workspace at enterprise scale (hundreds to 1,000+ users; complex OU, group, and shared-drive structures) at a level qualifying as a subject matter expert, not a general administrator
  • Experience supporting NIST-, FISMA-, and FedRAMP-aligned environments
  • Able to obtain Public Trust suitability and pass an OPM fingerprint criminal check with credit/financial review
  • Able to work the hybrid onsite schedule in Washington, DC (~10 days/month)
Preferred Qualifications
The Museum has confirmed these are given extra weight during proposal evaluation. A candidate holding either is materially more competitive:
  • Google Cloud Certified Professional Cloud Security Engineer
  • Google Cloud Certified Professional Cloud Architect
Also valuable: Google Vault / eDiscovery and federal records-management depth (FOIA, NARA); Okta SSO/SAML integration experience; ServiceNow workflow familiarity; scripting and automation (GAM, Python, Bash); prior federal agency experience.

Similar Jobs

See more jobs