Cloud Security & Identity Administrator

MTNSat Holdings LLCFort Lauderdale, FloridaOn-siteFull-timeListed 2 hours ago

Apply now

About this role

Job Description:

Position Summary

The Cloud Security & Identity Administrator owns day-to-day operations of the organization's cloud control plane — Google Workspace, Google Cloud Platform, and the Freshservice service management environment. The role is the primary operator of the access request pipeline: evaluating, fulfilling, and documenting permission changes across cloud platforms and AI tooling within the security policy and hardening standards set by the Cybersecurity Engineer. This position is operations- and governance-focused: the work is executing access decisions correctly, consistently, and with evidence.

How This Role Works with the Cybersecurity Engineer

The Cybersecurity Engineer sets security policy, hardening standards, and CIS baselines, and owns security architecture, detection engineering and SIEM content development, endpoint management, and the vulnerability management program. This role operates within those standards with a defined escalation path for high-risk access decisions — you won’t be making org-level architecture calls on your own.

Key Responsibilities

1. Google Workspace Operations and Security Configuration

- Administer users, groups, OUs, shared drives, and delegated admin roles under a least-privilege model.
- Maintain configured security controls in production: 2-Step Verification (2SV) enforcement, context-aware access rules, session policy, OAuth app allowlisting, and third-party app access.
- Apply and maintain Chrome Browser Cloud Management policy against the CIS baselines defined by the Cybersecurity Engineer; report configuration drift and exceptions.
- Maintain Gmail protections in production (SPF/DKIM/DMARC records, quarantine review, attachment and link policy state).

2. Google Cloud Platform Administration

- Administer IAM at org, folder, and project scope: role bindings, custom roles, service accounts, workload identity, and key rotation.
- Maintain org policy constraints in production; identify and report drift, and remediate within delegated authority.
- Triage Security Command Center findings, route remediation to system owners, and track to closure.
- Maintain aggregated logging, log sinks, retention configuration, and the health of cloud log sources feeding the SIEM.
- Run intake and baseline configuration for new GCP projects; maintain inventory of vendor-managed and externally owned projects and OAuth clients.

3. Access Request Management and Identity Governance Operations

- Own intake, triage, and fulfillment of cloud access requests in Freshservice — GCP project permissions, Workspace admin roles, service account grants, and elevated access.
- Evaluate each request against least privilege, separation of duties, and documented business justification; approve within delegated authority, scope down, or escalate.
- Escalate to the Cybersecurity Engineer for the defined high-risk categories: org- and folder-level bindings, privileged/admin roles, production service account keys, new external identities, and any request requiring a policy exception.
- Review AI tool access requests (Gemini, Vertex AI, third-party AI services), including data scope, API and service account permissions, and whether the use case is approved.
- Implement time-bound and just-in-time access where standing access is not justified; track and revoke on expiry.
- Execute recurring user access review campaigns end to end — extract entitlement data, drive reviewer response, remove revoked access, and retain evidence.
- Operate joiner/mover/leaver workflows for cloud identities and validate that deprovisioning actually revokes access.

4. Freshservice Administration

- Administer Freshservice securely: agent roles and scopes, groups, SSO/SAML integration, API credentials, and third-party integrations.
- Build and maintain approval workflows and automation rules so access requests carry a complete, auditable trail.
- Maintain service catalog items for access and application requests with the correct approval chains and mandatory justification fields.
- Maintain asset and CMDB records where they support access decisions or audit evidence.
- Ensure ticket data handling, retention, and administrative access meet compliance requirements.

5. Security Platform Operations Support

- Perform day-to-day administration of assigned security tooling across endpoint detection, SIEM, email security, and cloud security posture management — including console access and role management, integration health, agent and connector status, and license hygiene.
- Execute remediation of cloud-asset vulnerability findings assigned by the Cybersecurity Engineer and report status.
- Build and maintain automations and reports that reduce manual access-administration effort.

6. Compliance Evidence and Documentation

- Collect and maintain control evidence for SOC 2 and CMMC, with primary responsibility for access control, identification and authentication, and audit and accountability artifacts.
- Maintain runbooks and standard operating procedures for all administered platforms.
- Support audit requests with access and configuration evidence.

Required Qualifications

- 2–4 years in cloud, identity, or systems administration, with at least 2 years hands-on in Google Workspace and GCP
- Working knowledge of GCP IAM, org policies, service accounts, and cloud audit logging
- Experience fulfilling and documenting access requests against a least-privilege standard
- Hands-on administration experience with an ITSM platform (Freshservice preferred)
- Scripting or automation ability (Python, Bash, gcloud, or PowerShell) for reporting and bulk administration
- Strong written documentation skills
- Ability to work independently in a fully remote environment

Preferred Qualifications

- Google Workspace Administrator or Associate Cloud Engineer certification
- CompTIA Security+ or equivalent
- Exposure to SOC 2, CMMC, or NIST 800-171 evidence collection
- Terraform or infrastructure-as-code experience with IAM and org policy

MTN is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.