Google Workspace & DLP Specialist

Lyra Health
1d$95,000 - $131,000Remote

About The Position

Lyra Health is the leading provider of mental health solutions for employers supporting more than 20 million people globally. The company has delivered 13 million sessions of mental health care, published more than 20 peer-reviewed studies, and delivered unmatched outcomes in terms of access, clinical effectiveness and cost efficiency. Extensive peer-reviewed research confirms Lyra’s transformative care model helps people recover twice as fast and results in a 26% annual reduction in overall healthcare claims costs. Lyra is transforming access to life-changing mental health care through Lyra Empower, the only fully integrated, AI-powered platform combining the highest-quality care and technology solutions. About the Role: We are looking for a talented and tenured Google Workspace Administrator to act as the primary technical expert for our Google Workspace environment. This critical role involves advanced administration, configuration, security, and automation to ensure a secure, optimized, and compliant cloud-based operation. Along with Google Workspace expertise, this specialist will drive various DLP and security ops efforts. Remote candidates must be physically located within the United States.

Requirements

  • Expert-level proficiency in administering and securing Google Workspace (Enterprise/Plus features).
  • Professional Google Workspace Administrator Certification preferred.
  • CLI Tools: Mastery of GAM/GAM7 for command-line administration.
  • Strong experience with the Google Workspace Admin Console for managing users, services, security settings, and OUs.
  • Architect-level experience with Google Cloud Identity and integrating GWS with external identity providers (IdP) via SAML/OAuth.
  • Directory Sync: Experience with Google Cloud Directory Sync (GCDS) or Azure AD/Okta provisioning.
  • Proficiency in Google Apps Script (GAS) or other scripting languages for administrative automation.
  • Familiarity with general cloud computing concepts and the Google Cloud ecosystem.
  • Solid understanding of security protocols, data privacy, and the ability to maintain the security of the Google Workspace domain.
  • Experience with large-scale GWS deployments, migrations, and hybrid environments.

Responsibilities

  • Serve as the Tier 3 administrator and escalation point for all aspects of Google Workspace, managing complex configurations, security settings, and Organizational Units (OUs).
  • Manage the full user lifecycle (provisioning, de-provisioning) across the GWS domain.
  • Demonstrate deep, hands-on expertise in the entire GWS suite, including the Security Center, Investigation Tool, Google Vault, and Audit Logs.
  • Develop and implement automation solutions using Google Apps Script (GAS) and/or Google Cloud Platform (GCP) services (e.g., Cloud Functions) to streamline provisioning, reporting, and administrative workflows.
  • Implement and manage advanced security controls, including Context-Aware Access (CAA), advanced phishing/malware protection, and secure data sharing policies.
  • Utilize GWS Audit Logs for security monitoring, compliance, and internal investigations.
  • Provide advanced technical support for all end-user issues related to core Google Workspace services.
  • Third-Party App Governance: Responsibility for vetting and managing OAuth tokens and third-party marketplace apps to prevent data exfiltration.
  • Project Management: Proven ability to lead complex projects, such as domain consolidations, tenant-to-tenant migrations, or global security hardening initiatives.
  • Lead and execute security and HR-mandated internal investigations using the Google Workspace Investigation Tool for complex data searches across Drive, Gmail, and Chat.
  • Manage eDiscovery and Legal Hold processes using Google Vault, ensuring chain-of-custody for evidentiary purposes and exporting compliant data sets.
  • Develop and deliver security awareness training focused on safe data handling and proper use of Google Workspace tools.
  • DLP (Data Loss Prevention): Designing and maintaining DLP rules for Drive and Gmail to protect PII/PHI.
  • Chrome Browser Management: Managing Chrome at the enterprise level (profiles, extensions, and security policies).
  • Mobile Device Management (MDM): Overseeing Google Endpoint Management for mobile and laptop devices.
  • Establish and maintain Shared Drive governance, including naming conventions, membership lifecycle, and external sharing restrictions.
  • Develop long-term storage optimization strategies to balance user productivity with organizational costs.

Benefits

  • Comprehensive healthcare coverage (including medical, dental, vision, FSA/HSA, life and disability insurances)
  • Lyra for Lyrians; coaching and therapy services
  • Equity in the company through discretionary restricted stock units
  • Competitive time off with pay policies including vacation, sick days, and company holidays
  • Paid parental leave
  • 401K retirement benefits
  • Monthly tech allowance
  • We like to spread joy throughout the year with well-being perks and activities, surprise swag, free food, regular community celebration…and more!
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service