The Google Workspace Administrator is the single dedicated full-time resource responsible for administering, governing, and optimizing USHMM''s entire Google Workspace tenant.
Administer all Workspace domains and services as primary owner
Manage users, groups, OUs, and role-based access controls
Own identity lifecycle: onboarding, role changes, offboarding
Manage licensing, subscriptions, and cost/storage optimization (Drive storage and license right-sizing are named priorities)
Administer and optimize Gmail, Drive, Docs/Sheets/Slides/Forms, Meet, Chat, and Calendar
Stand up and support Gemini for Workspace and NotebookLM for internal Museum use
Enforce MFA for all users, mandatory for privileged accounts
Configure and maintain SSO/identity federation via Okta
Enforce password, session-control, and device-trust policies
Manage DLP, IRM, and secure-sharing controls in coordination with the CASB
Monitor security alerts; respond to phishing, account compromise, and unauthorized access
Maintain alignment with NIST CSF, NIST SP 800-53, and FISMA
Support the migration toward FedRAMP Moderate consistent with Museum direction
Maintain documentation and evidence supporting audits, assessments, and ATO activities
Understand that federal PII is treated as CUI, with State Privacy Acts, PCI, and HIPAA also in scope, and NARA/M-19-21 records-management requirements in effect
Routine health checks, configuration reviews, and policy/feature updates
Change management to minimize disruption; incident, outage, and escalation response
After-hours/weekend response for critical or mission-critical outages (normal coverage is business hours)
Lead strategic planning for Workspace adoption; maintain a continuous-improvement roadmap
Evaluate new features for Museum applicability; recommend automation and UX improvements
Serve as liaison among Museum leadership, IT, program offices, and Google support
Provide technical training and best-practice guidance to the Museum''s Google administrators and broader community