Cloud Security & Identity Administrator
Listed on 2026-10-02
-
IT/Tech
Cybersecurity
The Cloud Security & Identity Administrator owns day-to-day operations of the organization's cloud control plane — Google Workspace, Google Cloud Platform, and the Fresh service service management environment. The role is the primary operator of the access request pipeline: evaluating, fulfilling, and documenting permission changes across cloud platforms and AI tooling within the security policy and hardening standards set by the Cybersecurity Engineer.
This position is operations- and governance-focused: the work is executing access decisions correctly, consistently, and with evidence.
The Cybersecurity Engineer sets security policy, hardening standards, and CIS baselines, and owns security architecture, detection engineering and SIEM content development, endpoint management, and the vulnerability management program. This role operates within those standards with a defined escalation path for high-risk access decisions — you won’t be making org-level architecture calls on your own.
Key ResponsibilitiesGoogle Workspace Operations and Security Configuration
Administer users, groups, OUs, shared drives, and delegated admin roles under a least-privilege model. Maintain configured security controls in production: 2-Step Verification (2SV) enforcement, context-aware access rules, session policy, OAuth app allow listing, and third-party app access. Apply and maintain Chrome Browser Cloud Management policy against the CIS baselines defined by the Cybersecurity Engineer; report configuration drift and exceptions. Maintain Gmail protections in production (SPF/DKIM/DMARC records, quarantine review, attachment and link policy state).
Google Cloud Platform Administration
Administer IAM at org, folder, and project scope: role bindings, custom roles, service accounts, workload identity, and key rotation. Maintain org policy constraints in production; identify and report drift, and remediate within delegated authority. Triage Security Command Center findings, route remediation to system owners, and track to closure. Maintain aggregated logging, log sinks, retention configuration, and the health of cloud log sources feeding the SIEM.
Run intake and baseline configuration for new GCP projects; maintain inventory of vendor-managed and externally owned projects and OAuth clients.
Access Request Management and Identity Governance Operations
Own intake, triage, and fulfillment of cloud access requests in Fresh service — GCP project permissions, Workspace admin roles, service account grants, and elevated access. Evaluate each request against least privilege, separation of duties, and documented business justification; approve within delegated authority, scope down, or escalate. Escalate to the Cybersecurity Engineer for the defined high-risk categories: org- and folder-level bindings, privileged/admin roles, production service account keys, new external identities, and any request requiring a policy exception.
Review AI tool access requests (Gemini, Vertex AI, third-party AI services), including data scope, API and service account permissions, and whether the use case is approved. Implement time-bound and just-in-time access where standing access is not justified; track and revoke on expiry. Execute recurring user access review campaigns end to end — extract entitlement data, drive reviewer response, remove revoked access, and retain evidence.
Operate joiner/mover/leaver workflows for cloud identities and validate that deprovisioning actually revokes access.
Fresh service Administration
Administer Fresh service securely: agent roles and scopes, groups, SSO/SAML integration, API credentials, and third-party integrations. Build and maintain approval…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).